Article ID: 959202 - Last Review: December 11, 2008 - Revision: 1.0
The Active Directory Users and Computers snap-in cannot display service principal names (SPNs) that have non-numeric port values when you configure the Delegation properties of a computer account in Windows Server 2003
A Windows Server 2003-based domain has the Windows Server 2003 domain functional level.
You configure a constrained delegation in the Active Directory Users and Computers MMC snap-in. You select the Trust this computer for delegation to specified services only option.
You select a user or computer account that has a service principal name (SPN) and a non-numeric value for the port number, such as a named instance.
In this scenario, the SPN is not listed in the Available services list.
Additionally, assume that you try to manually update the msDS-AllowedToDelegateTo attribute by adding the SPN that has the non-numeric port value, and then you edit services in the Services to which this account can present delegated credentials list. However, any SPN that has a non-numeric port value is dropped from the msDS-AllowedToDelegateTo attribute.
This problem occurs because the Active Directory Users and Computers MMC snap-in expects all ports to have numeric values. Therefore, any SPN that has a non-numeric port value is dropped.
A supported hotfix is available from Microsoft. However, this hotfix is intended to correct only the problem that is described in this article. Apply this hotfix only to systems that are experiencing the problem described in this article. This hotfix might receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next software update that contains this hotfix.
If the hotfix is available for download, there is a "Hotfix download available" section at the top of this Knowledge Base article. If this section does not appear, contact Microsoft Customer Service and Support to obtain the hotfix.
Note If additional issues occur or if any troubleshooting is required, you might have to create a separate service request. The usual support costs will apply to additional support questions and issues that do not qualify for this specific hotfix. For a complete list of Microsoft Customer Service and Support telephone numbers or to create a separate service request, visit the following Microsoft Web site:
Note The "Hotfix download available" form displays the languages for which the hotfix is available. If you do not see your language, it is because a hotfix is not available for that language.
Prerequisites
To apply this hotfix, you must have the following installed on the domain controller:
Windows Server 2003 Service Pack 1 (SP1) or Windows Server 2003 Service Pack 2 (SP2)
For more information, click the following article number to view the article in the Microsoft Knowledge Base:
889100
(http://support.microsoft.com/kb/889100/
)
How to obtain the latest service pack for Windows Server 2003
The Active Directory Users and Computers snap-in
Restart requirement
You must restart the computer after you apply this hotfix.
Hotfix replacement information
This hotfix does not replace any other hotfixes.
File information
The English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.
Windows Server 2003 with Service Pack 1, x86-based versions
Collapse this tableExpand this table
File name
File version
File size
Date
Time
Platform
SP requirement
Adprop.dll
5.2.3790.3239
777,216
04-Nov-2008
14:46
x86
SP1
Dsprop.dll
5.2.3790.3239
153,600
04-Nov-2008
14:46
x86
SP1
Ntdsapi.dll
5.2.3790.3239
74,752
04-Nov-2008
14:46
x86
SP1
W03a2409.dll
5.2.3790.3239
39,424
04-Nov-2008
10:41
x86
SP1
Windows Server 2003 with Service Pack 2, x86-based versions
Collapse this tableExpand this table
File name
File version
File size
Date
Time
Platform
SP requirement
Adprop.dll
5.2.3790.4403
777,216
04-Nov-2008
14:27
x86
SP2
Dsprop.dll
5.2.3790.4403
153,600
04-Nov-2008
14:27
x86
SP2
Ntdsapi.dll
5.2.3790.4403
73,728
04-Nov-2008
14:27
x86
SP2
W03a3409.dll
5.2.3790.4357
15,360
19-Aug-2008
10:25
x86
SP2
Windows Server 2003 with Service Pack 1, Itanium-based versions
Collapse this tableExpand this table
File name
File version
File size
Date
Time
Platform
SP requirement
Service branch
Adprop.dll
5.2.3790.3239
1,851,904
04-Nov-2008
13:39
IA-64
SP1
Not Applicable
Dsprop.dll
5.2.3790.3239
369,664
04-Nov-2008
13:39
IA-64
SP1
Not Applicable
Ntdsapi.dll
5.2.3790.3239
213,504
04-Nov-2008
13:39
IA-64
SP1
Not Applicable
W03a2409.dll
5.2.3790.3239
38,400
04-Nov-2008
13:39
IA-64
SP1
Not Applicable
Wadprop.dll
5.2.3790.3239
777,216
04-Nov-2008
13:39
x86
SP1
WOW
Wdsprop.dll
5.2.3790.3239
153,600
04-Nov-2008
13:39
x86
SP1
WOW
Wntdsapi.dll
5.2.3790.3239
74,752
04-Nov-2008
13:39
x86
SP1
WOW
Ww03a2409.dll
5.2.3790.3239
39,424
04-Nov-2008
13:39
x86
SP1
WOW
Windows Server 2003 with Service Pack 2, Itanium-based versions
Collapse this tableExpand this table
File name
File version
File size
Date
Time
Platform
SP requirement
Service branch
Adprop.dll
5.2.3790.4403
1,851,904
04-Nov-2008
13:44
IA-64
SP2
Not Applicable
Dsprop.dll
5.2.3790.4403
369,664
04-Nov-2008
13:44
IA-64
SP2
Not Applicable
Ntdsapi.dll
5.2.3790.4403
213,504
04-Nov-2008
13:44
IA-64
SP2
Not Applicable
W03a3409.dll
5.2.3790.4357
14,336
04-Nov-2008
13:44
IA-64
SP2
Not Applicable
Wadprop.dll
5.2.3790.4403
777,216
04-Nov-2008
13:44
x86
SP2
WOW
Wdsprop.dll
5.2.3790.4403
153,600
04-Nov-2008
13:44
x86
SP2
WOW
Wntdsapi.dll
5.2.3790.4403
73,728
04-Nov-2008
13:44
x86
SP2
WOW
Ww03a3409.dll
5.2.3790.4357
15,360
04-Nov-2008
13:44
x86
SP2
WOW
Windows Server 2003 with Service Pack 1, x64-based versions
Collapse this tableExpand this table
File name
File version
File size
Date
Time
Platform
SP requirement
Service branch
Adprop.dll
5.2.3790.3239
1,130,496
04-Nov-2008
13:40
x64
SP1
Not Applicable
Dsprop.dll
5.2.3790.3239
217,600
04-Nov-2008
13:40
x64
SP1
Not Applicable
Ntdsapi.dll
5.2.3790.3239
133,632
04-Nov-2008
13:40
x64
SP1
Not Applicable
W03a2409.dll
5.2.3790.3239
39,936
04-Nov-2008
13:40
x64
SP1
Not Applicable
Wadprop.dll
5.2.3790.3239
777,216
04-Nov-2008
13:40
x86
SP1
WOW
Wdsprop.dll
5.2.3790.3239
153,600
04-Nov-2008
13:40
x86
SP1
WOW
Wntdsapi.dll
5.2.3790.3239
74,752
04-Nov-2008
13:40
x86
SP1
WOW
Ww03a2409.dll
5.2.3790.3239
39,424
04-Nov-2008
13:40
x86
SP1
WOW
Windows Server 2003 with Service Pack 2, x64-based versions
To work around this problem, you must manually add SPNs with non-numeric port values to the msDS-AllowedToDelegateTo attribute.
For more information about how to do this, click the following article number to view the article in the Microsoft Knowledge Base:
936628
(http://support.microsoft.com/kb/936628/
)
The SPN does not appear in the list of services that can be delegated to an account when you try to configure constrained delegation on a computer that is running Windows Server 2003