I have a SDK service running under a domain user account, but it tries to register the SPN for the computer account of the machine?!
Therefore I get the following alert:
The System Center Data Access service failed to register an SPN. A domain admin needs to add MSOMSdkSvc/WIN-9IAJC0HS9RJ and MSOMSdkSvc/WIN-9IAJC0HS9RJ.domainxx.local to the servicePrincipalName of CN=WIN-9IAJC0HS9RJ,CN=Computers,DC=domainxx,DC=local
Which makes sense because it has not the permissions to do that.
When I make the domain user account member of domain admins it has the concerning permissions and it indeed registers that SPN to the computer account. But why?? The SPN should be registered to the domain user account instead (and therefore I had given the domain user account the read/write permissions to itself to do that).
I have the following SPN registered now for the computer and domain user account:
setspn -l WIN-9IAJC0HS9RJ
Registered ServicePrincipalNames for CN=WIN-9IAJC0HS9RJ,CN=Computers,DC=domainxx
DC=local:
MSOMSdkSvc/WIN-9IAJC0HS9RJ
MSOMSdkSvc/WIN-9IAJC0HS9RJ.domainxx.local
MSOMHSvc/WIN-9IAJC0HS9RJ
MSOMHSvc/WIN-9IAJC0HS9RJ.domainxx.local
TERMSRV/WIN-9IAJC0HS9RJ
TERMSRV/WIN-9IAJC0HS9RJ.domainxx.local
WSMAN/WIN-9IAJC0HS9RJ
WSMAN/WIN-9IAJC0HS9RJ.domainxx.local
RestrictedKrbHost/WIN-9IAJC0HS9RJ
HOST/WIN-9IAJC0HS9RJ
RestrictedKrbHost/WIN-9IAJC0HS9RJ.domainxx.local
HOST/WIN-9IAJC0HS9RJ.domainxx.local
setspn -l domainxx\omdas
Registered ServicePrincipalNames for CN=OMDAS,CN=Users,DC=domainxx,DC=local:
none for this account
I don't get it. Anyone?
I am using SCOM 2012 R2
Pls help.
Thanx in advance.
Regards
Chris
- Edited by Chris20052005 Monday, March 03, 2014 8:39 PM