Article ID: 942304 - Last Review: October 9, 2007 - Revision: 2.2 SPNs are not registered in an Active Directory site that includes only read-only domain controllersSYMPTOMSIn an Active Directory site that includes only read-only domain controllers (RODCs), service principal names (SPNs) are not registered. Therefore, you may experience various problems on client computers that are running Windows Vista, Windows Server 2003, or Windows XP. For example, you cannot install Microsoft ISA Server. Or, mutual authentication fails. CAUSEThese problems occur when account credentials are not cached on an RODC. If the account credentials are not cached, RODCs cannot write SPNs for client computer accounts on a writable domain controller. WORKAROUNDTo work around these problems, use one of the following methods:
STATUSMicrosoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section. APPLIES TO
| Article Translations
|
Back to the top
