cancel
Showing results for 
Search instead for 
Did you mean: 

constrained delegation problem with windows and owa

maxime_simard_
New Contributor

constrained delegation problem with windows and owa

I've make it work in the lab perfectly but at one client i've got the following error :

Constrained Delegation TGS fetch error: KDC
can't fulfill requested option

Constrained Delegation TGS fetch error: KDC can't fulfill requested option

here is a summary of the option from the log:

authtime: Tue Jan 19 13:40:09 2010,

startime: Tue Jan 19 13:40:09 2010, endtime: Tue Jan 19 23:40:08 2010, endtime sec:

1263962408, current sec: 1263926409, Flags reserved: 0, forwardable: 1, forwarded: 0,

proxiable: 0, proxy: 0, may_postdate: 0, postdated: 0, invalid: 0, renewable: 0,

initial: 0, pre_authent: 1, hw_authent: 0, transited_policy_checked: 0, ok_as_delegate:

0, anonymous: 0

so the ticket is fowardable. there is not much help on the web for this, as the only explanation i have found is this :

KDC policy rejects request

KDC can't fulfill requested option
á Requesting a forwardable ticket for a /root or /admin instance
á Trying to forward an unforwardable ticket, or renew an unrenewable one
I dont know how to correct the problem. What does /root or /admin means in a windows environement ? JTAC support is not helping very much.
thanks.
2 REPLIES 2
filbert_
Frequent Contributor

Re: constrained delegation problem with windows and owa

Be sure to check that you set the SPN correctly. Is your delegation account, OWA, and user account all in the same domain?

SVK_
Regular Contributor

Re: constrained delegation problem with windows and owa

How is the sahrepoint resource configured on the backend?

Is the sharepoint server Hostname and the Resource url have the same name?