SPNs, WCF and Impersonation


hi,

i have nlb cluster pointing 2 windows server 2008 r2 (iis 7.5) web machines containing asp.net web site uses impersonation. web site runs under app pool running domain account. web site calls wcf service on separate windows server 2008 r2 (iis 7.5) machine.

i have not managed wcf call working receiving typical "the http request unauthorized client authentication scheme 'negotiate'" error. have tried setting impersonation , delegation on wcf service no luck.

my question follows:

  • i have spns setup domain account running application pool , cluster url, because web site uses impersonation, mean need setup spns actual user account being impersonated?
  • if browse directly 1 of machines (instead of going via nlb cluster) wcf call works! not sure why works in case , not when browse cluster?

all machines have been setup trusted delegation.

any ideas?

thanks!

1) no - should not necessary

2) far understand, expected (http://support.microsoft.com/kb/325608)

hth
marcin



Windows Server  >  Directory Services



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS