Article ID: 914137 - Last Review: October 25, 2007 - Revision: 1.5 Exchange Protocol Security authentication fails after you install Windows Server 2003 Service Pack 1 on a server that has multiple SMTP virtual servers in Exchange Server 2003On This PageSYMPTOMSYou install Microsoft Windows Server 2003 Service Pack 1 (SP1) on Microsoft Exchange Server 2003 Service Pack 2 (SP2). You do this on a server that has multiple SMTP virtual servers. After you do this, Exchange Protocol Security (EXPS) authentication fails. Additionally, the following errors are logged:
CAUSEThis problem occurs when the following conditions are true:
The SPN is registered in Active Directory under a user account as an attribute that is called Service-Principal-Name. The SPN is assigned to the account under which the service that the SPN identifies is running. Any service can look up the SPN for another service. When the SMTP service must authenticate to another Exchange Server SMTP service, it uses that service’s SPN to differentiate that service from other services that are running on that computer. Generally, only one SPN should be set for each service. Multiple SPNs can cause clients to connect to the wrong system. Alternatively, the ticket may be encrypted by using the wrong key. If there is no SPN, authentication failures occur between virtual servers. RESOLUTIONTo resolve this problem, use one of the following methods. Method 1: Use the Setspn.exe toolUse the Setspn.exe tool to add an SPN that has the correct FQDN to the Active Directory object for the server that is running Exchange Server. To do this, follow these steps:
Method 2: Add the FQDN of the SMTP virtual server to the BackConnectionHostNames multi_sz registry valueFor more information about how to do this, click the following article number to view the article in the Microsoft Knowledge Base:896861
(http://support.microsoft.com/kb/896861/
)
You receive error 401.1 when you browse a Web site that uses Integrated Authentication and is hosted on IIS 5.1 or IIS 6
STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. | Article Translations
|

Back to the top
