Home   |    About   |    Contact               Twitter   |    Facebook   |    Flickr    MCMSfaq.com: Content Management Server Resources
   MCA | SharePoint 2010
 
   MCM | SharePoint 2010 & 2007
 
MVP - Office SharePoint Server
 
 

 
 
Content Management Server Resources

The posts on this weblog are provided “AS IS” with no warranties, and confer no rights.
The opinions expressed herein are personal and do not represent those of my employer.

 
 

London SUGUK meeting: Kerberos and what not

Many thanks to all those who attended the SUGUK meeting in London on Wednesday evening. Another excellent SUGUK event thanks to the great work by Nick Swan and Steve Smith. It's fantastic to see a consistently high turn out and this is a great sign that SharePoint continues on it's rightful path to world domination.

Ben Robb's talk on managing deployment was superb and must see material for those working on medium and large scale development projects.

My talk wasn't as good - but it was on a boring infrastructure topic - so I have an excuse (kind of!). Apologies for overrunning which meant the demo section suffered and I didn't have time to cover some pieces. I will try and make up for that here with more details in the near future.

I do hope the talk provided a good 101 on Kerberos and SharePoint and welcome any feedback you may have. I am considering a "two part" thing for the future with a second session on large farm issues, more examples on things like Excel Services and Reporting Services and diving into more of the devil around Shared Services and Kerberos.

In the meantime, you can grab the slide deck here. The slide animations don't work in PDF but it should still make sense. I did make an XPS of the deck, but damn it's a bit big and my upload speed at present really sucks!

I did do a quick show and tell on the Kerberos/Delegation Configuration Reporting Tool which isn't referenced in the deck - you can find this over on IIS.NET. The dude who put it together, the very clever Brian Murphy Booth, has a blog entry on it here. Like I said in the talk, don't be slapping this bad boy on your SharePoint web apps in production :) and you'll need to tweak the CAS policy for it to work with SharePoint.

Ken Schaefer's blog is over here. You can see the trend right? If you want to find out about Kerberos, don't go looking at SharePoint people's blogs!! Go check out the IIS stuff, because that's where it's at (at present).

Before you ask, no I can't provide a timeline for the white paper or the SharePoint Kerberos Config Wizard. They'll be done when they're done and to the right level of quality - and I don't know when that will be. :)

One question that came up in the pub afterwards was on DCOM configuration required - this is sometimes not a requirement and it could also be argued this not a Kerberos issue. I will be following up with an article here on this topic in the next few weeks. In the meantime, the pesky 10016 issue is not a Kerberos thing, it's a least privilege thing. The delegation issue is an altogether separate conversation.

I briefly mentioned IIS7 and Kerberos AuthN improvements in the kernel - this came up in the pub also, and W2K8 does introduce some differences in configuration - these will be covered in the white paper as well.

If you would like to see more on this topic, please leave comments here.

Print | posted on Friday, February 29, 2008 11:25 AM

Feedback

Gravatar

# re: London SUGUK meeting: Kerberos and what not

Spencer,
Thanks for going through Kerberos on Weds - found it really useful and also finally got it up and running yesterday - hurrah. I owe you a beer!

Regards
Simon
iThink SharePoint

2/29/2008 3:15 PM | Simon Doy
Gravatar

# re: London SUGUK meeting: Kerberos and what not

any download slides on this stuff as am new to it?
thanks

3/4/2008 9:40 AM | kzfredo
Gravatar

# re: London SUGUK meeting: Kerberos and what not

kzfredo: the slide deck can be downloaded from the link in the main post above.

3/10/2008 7:13 AM | spence
Gravatar

# re: London SUGUK meeting: Kerberos and what not

The presentation on Wednesday was excellent, we have already implemented kerberos in one environment and now hope to do the rest. It was good to understand the authentication process of NTLM & Kerberos in more details.

What error messages would you see if you were experiencing the bottleneck issue with NTLM? Would it be:

Event Source: NETLOGON

Event ID: 5783

Description:
The session setup to the Windows NT or Windows 2000 Domain Controller {nameofDC} for the domain {domainname} is not responsive. The current RPC call from Netlogon on {SharePointServer} to {nameofDC} has been cancelled.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Thanks,

Jenny Everett
http://www.sharepointblogs.com/jennyeverett

3/10/2008 4:01 PM | Jenny Everett
Gravatar

# re: London SUGUK meeting: Kerberos and what not

Hi Jenny, The NETLOGON 5783 error is generally un-related to Kerberos and is a common problem with RPC communications between an application server and domain controller. Some 3rd Party Anti Virus products also can cause this issue.

There are no error/warning events generated because of the NTLM bottleneck - the symptoms being poor end user request times and the like. I will be posting details of what performance counters can be interrogated to get stats on this.

Cheers
Spence

3/10/2008 6:12 PM | Spence
Gravatar

# re: London SUGUK meeting: Kerberos and what not

Thanks Spence, I look forward to the post!

Jenny

3/11/2008 4:08 PM | Jenny Everett
Gravatar

# re: London SUGUK meeting: Kerberos and what not

Hi Spence,

Thank you for the Kerberos presentation back on the 27th and for posting up the slides.

An excellent presentation (to get so many laughs whilst speaking about authentication is somewhat mind-boggling) and I have employed my new-found knowledge in a few meetings already.

Hope to catch you for a beer again soon!
N.

3/14/2008 11:33 AM | Nick Rosewall

Post Comment

Title  
Name  
Email
Url
Comment   
Please add 1 and 1 and type the answer here: