Having strange Kerberos behaviour with Delegation
Hi everyone, I'm having issues regarding setting up delegation:
I've got the following error: datatype cannot be converted to/from a native DS datatype
I will explain a few.
We've set up DNS as follows:
SharePoint
dev.portal.company.net (svc-dev-sp-webapp)
test.portal.company.net (svc-test-sp-webapp)
acc.portal.company.net (svc-acc-sp-webapp)
portal.company.net (svc-sp-webapp)
Web Service
dev.webservice.company.net (svc-dev-webservice)
test.webservice.company.net (svc-test-webservice)
acc.webservice.company.net (svc-acc-webservice)
webservice.company.net (svc-webservice)
We've set-up kerberos for the service accounts with their app pool. All sites run on another machines. So for every environment their are machine.
We enabled delegation between svc-dev-sp-webapp -> svc-dev-webservice (Works perfectly)
When we do this for test / acc / prod we're having problems with datatype cannot be converted to/from a native DS datatype
When we enable delegation test (svc-test-sp-webapp) -> acc (svc-acc-webservice) we don't run in any problems. So crossing works perfectly.
But yet, we don't want crossing of service accounts. Anyone have a clue?
The problem here I think is that Active Directory (Windows Server 2003 Native Domain) is corrupted by upgrading from Windows 2000 to Windows Server 2003 in the past. Is this know behaviour? Or is something really wrong here?
Thanks in advance.
May 27th, 2011 12:29am
Hi,
Is there any relative logs of error in the event viewer?
Please install the latest service pack for windows server 2003 to check if the issue can be resolved.
How to obtain the latest service pack for Windows Server 2003
http://support.microsoft.com/kb/889100
If the issue persists, please try the following KB.
You may receive a "The directory datatype cannot be converted to / from a native DS datatype" error message in Windows Server 2003 or
in Windows 2000 Server
http://support.microsoft.com/kb/907462
Meanwhile, to troubleshoot Active Directory problems, please refer to:
I would start by running some diagnostic utilities.
http://blogs.dirteam.com/blogs/paulbergson/archive/2009/01/26/troubleshooting-active-directory-issues.aspx
http://technet.microsoft.com/en-us/library/bb727052.aspx
Regards,
Bruce
This posting is provided "AS IS" with no warranties, and confers no rights. Please remember to click "Mark as Answer" on the post that helps you, and to click "Unmark as Answer" if a marked post does not actually answer your
question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
May 27th, 2011 1:01pm
Thanks, I shall check your information, and check if I can find anything. If there is something wrong hopefully I will find the information.
I will come back when I have new information.
Thanks in advance.
May 27th, 2011 3:28pm