Applications that perform Kerberos Constrained Delegation (KCD) may not finish the Service-for-User (S4U) process on a computer that is running Windows Server 2008 or Windows Server 2003. This issue occurs in the following scenario:
This issue occurs because the Windows operating system does not have the additional mapping data that is required. By default, the additional mapping data is not populated in Active Directory Domain Services (AD DS). Therefore, the operating system is unable to search the whole forest and the whole trust structure to resolve the mappings between unqualified domains and fully qualified domains.
To resolve this issue, follow these steps:
- Use the Active Directory Service Interfaces Edit tool to edit the ms-DS-SPNSuffixes attribute in the following configuration container in AD DS:
(CN=Partitions, CN=Configuration, DC=DomainNamingContext)Edit the ms-DS-SPNSuffixes attribute to add NB domain names for all domains in the local domain tree.
- Repeat step 1 for each root domain in the trusted forest.
- Edit the Name Suffix Routing list in the trusting forest to enable all the following suffixes for all the trusted domains:
- *.NBDomain suffixes
- *.FQDN suffixes
- Repeat step 3 for each forest that trusts the forest that is modified in step 1.
- Repeat steps 1 through 4 as necessary for the remaining forests and trees.
Article ID: 949015 - Last Review: June 18, 2008 - Revision: 1.0
- Windows Server 2008 Datacenter
- Windows Server 2008 Enterprise
- Windows Server 2008 Standard
- Windows Web Server 2008
- Windows Server 2008 for Itanium-Based Systems
- Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
- Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
- Microsoft Windows Server 2003, Datacenter x64 Edition
- Microsoft Windows Server 2003, Enterprise x64 Edition
- Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
- Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
- Microsoft Windows Server 2003, Standard x64 Edition
- Microsoft Windows Server 2003, Standard Edition (32-bit x86)
|kbexpertiseadvanced kbtshoot KB949015|