Questions on SETSPN syntax and what is required for MANUAL AD auth

I'll preface this by stating that I don't need to do all the extra stuff for Vintela SSO, SSO to database, etc.  I just need to know precisely what is necessary to do to get AD authentication working.  I managed to get it working in XIr2 previously but it's been so long and I'm not 100% sure that everything I wound up doing was absolutely necessary that I wanted to sort it out for good as we look at going to XI 3.1 SP3.
In the XI 3.1 SP3 admin guide, page 503, the SETSPN command which is
used as part of the setup process to establish a service account to
enable AD authentication is outlined as follows:
SETSPN.exe -A <ServiceClass>/<DomainName> <Serviceaccount>
The guide suggests that the <ServiceClass> can be anything you want to
arbitrarily assign. If I choose something other than the
suggested "BOBJCentralMS" value, is there anywhere else I have to
specify this value to allow the service account to function properly?
The guide suggests that the <DomainName> should be the domain name on
which the service account exists however I've seen many posts online which seem to
indicate this <DomainName> should actually be the FQDN of the server
running the CMS service instead of the general domain name.
Clarification there would be very helpful if anyone has some insight.

The CMS account can have an SPN of spaghetti/meatballs, there are no requirements (cept 2 characters on each side of the / I believe). The SPN created should be the value entered in the CMC > Authentication > Windows AD
The account must run the SIA and it therefore must have AD permissions. Now if you are using IIs or client tools you don't even need an SPN. The SPN is for kerberos only which is required for java app servers.
The vintela SSO white paper in the this forums sticky post explains the roles of a service account.
Regards,
Tim

Similar Messages

  • I am trying to download a free trial of photoshop for my macbook pro and it says there is an error and that the requirements for the new version is not supported for the mac I have. I have looked at the list of requirements but have no idea how to tell wh

    I am trying to download a free trial of photoshop for my macbook pro and it says there is an error and that the requirements for the new version is not supported for the mac I have. I have looked at the list of requirements but have no idea how to tell what I do and do not have?

    Apple Menu --> About this Mac.
    Mylenium

  • Quick question regarding best practice and dedicating NIC's for traffic seperation.

    Hi all,
    I have a quick question regarding best practice and dedicating NIC's for traffic seperation for FT, NFS, ISCSI, VM traffic etc.  I get that its best practice to try and separate traffic where you can and especially for things like FT however I just wondered if there was a preferred method to achieving this.  What I mean is ...
    -     Is it OK to have everything on one switch but set each respective portgroup to having a primary and failover NIC i.e FT, ISCSI and all the others failover (this would sort of give you a backup in situations where you have limited physical NICs.
    -    Or should I always aim to separate things entirely with their own respective NICs and their own respective switches?
    During the VCAP exam for example (not knowing in advance how many physical NIC's will be available to me) how would I know which stuff I should segregate on its own separate switch?  Is there some sort of ranking order of priority /importance?  FT for example I would rather not stick on its own dedicated switch if I could only afford to give it a single NICs since this to me seems like a failover risk.

    I know the answer to this probably depends on however many physical NICs you have at your disposal however I wondered if there are any golden 100% rules for example FT must absolutely be on its own switch with its own NICs even at the expence of reduced resiliency should the absolute worst happen?  Obviously I know its also best practice to seperate NICs by vender and hosts by chassis and switch etc 

  • Why does this site have online chat when you can never actually chat - always "not available"?  I was trying to get a simple question answered without calling and being on hold for 10 minutes?

    Why does this site have online chat when you can never actually chat - always "not available"?  I was trying to get a simple question answered without calling and being on hold for 10 minutes?

        Hello flabucki,
    Help is just a post away for you my friend! I can help with your questions right here. May I ask what question do you have? Both myself and the community would love to assist in any way that we can.
    Thank you…
    ArnettH_VZW
    Follow us on Twitter @VZWSupport

  • What is ACCD DMG file and what is it for?

    What is ACCD DMG file and what is it for?

    See the last post in this thread: https://discussions.apple.com/thread/2084745?start=90&tstart=0

  • HT204003 if i open passbook on iphone 5, it always say cannot connect to itunes, any fix from apple tech support? and whats the reason for this problem? why do we have to figure it out and not even apple can give answer??

    if i open passbook on iphone 5, it always say cannot connect to itunes, any fix from apple tech support? and whats the reason for this problem? why do we have to figure it out and not even apple can give answer??

    actually i found out how to fix it
    1 sign out of apple account
    2 close down passbook app
    3 change year to 2013
    4 reopen passbook and sign in at the button with your apple ID
    5 change the time to auto update and it should work from now on.
    this worked for me let me know if it work for you:)

  • Please let me know when unlocked iphone 5 is going to lunch in Florida, USA and what is price for that...

    Please let me know when unlocked iphone 5 is going to lunch in Florida, USA and what is price for that...

    Only Apple knows. This isn't Apple.  But I have heard rumours that the unlocked iPhone 5 is due to take a light supper around seven o'clock.

  • What apps can I download for my account, Photoshop CC, and what is best for that program

    What apps can I download for my account, Photoshop CC, and what is best for that program

    Hi Bosseb,
    You can install products listed in the Download Center, all are included except Photoshop Touch
    https://creative.adobe.com/products
    On the left hand margin you can see products based on field, Audio/Video, Gaming, Graphic Design, Photography, etc.
    If you have a fulll membership you can download any that are included that interest you.
    -Dave

  • To read COMTRADE file in Labview there is an example provided. Can somebody provide the sample .cfg and .dat files required for its working?

    To read COMTRADE file in Labview there is an example provided. Can somebody provide the sample .cfg and .dat files required for its working?

    Thanks for the reply.
    But this library doesn't contain any sample .cfg and .dat files which can be read and understood. Can you please provide the same?

  • WEB Server And Database Space requirements for deploying Web Application

       Hi,
         We are in requirement of WEB Server  And Database Space requirements for deploying  our Web Application in cloud server. We want to know technical requirements and feasibilities laid by Microsoft team for deploying web
    application.......
    Regards,
    Sreenivasa M S

    Hi,
    Please refer this link and check if it helps:
    http://blogs.technet.com/b/cbernier/archive/2013/09/24/deploy-your-web-application-to-windows-azure-from-with-visual-studio.aspx
    Regards,
    Azam Khan

  • Can we attach requirement for manual condition type

    Hi,
    Pricing question....
    ZOTH is the manual condition type
    (The condition type configuration: - Manually editable, no access sequence attached )
    (Pricing procedure : - No alternative calculation type attached)
    Can I attach a requirement to ZOTH in the pricing procedure?
    Laxman

    hi,
    we can very well have requirements for manual conditions also. Like we have standard requirement "2" Item with pricing and this is assigned to PN00 ( Net price ) condition which is a manual condition.
    you can check in RVAA01 pricing proc. also
    regards
    sadhu kishore

  • 2 questions: validity of my machine's status as a 3.1 Mac Pro, and what PCIE cables for Radeon 4870?

    Hello, I bought a used mac pro from a guy that said it was a 3.1.  It runs great and when I go to "About this Mac" and then to "More info" and look at the hardware info, it says that it is indeed a 3,1.  However, the serial number sticker on the back says it's a 2.8!  Any insights into that?  I'm very new to Mac Pro desktops and I just want to make sure I didn't get ripped off. 
    My second question.  The machine came with the standard X2 quad 2.88 GHz processor, 8gb of Ram, and a Radeon 2200 graphics card.  I bought an ATI Radeon HD 4870 from a guy on craigslist but he didn't have the power cables for it.  He said it wasn't a big deal and after I did some research it looks like I need some PCIE power connectors.  The card takes two, 6 pin power cables.  My question is where do I plug them in on the logic board?  Should it be a 6 pin plug in also meaning I want a 6pin to 6pin cable like this (http://www.newegg.com/Product/Product.aspx?Item=N82E16812200975&nm_mc=KNC-Google Adwords&cm_mmc=KNC-GoogleAdwords-_-pla-_-Internal+Power+Cables-_-N82E16812200975 &gclid=CMW8u4Po5LUCFcdDMgodx2AAyA). 
    So yeah, the simplest answer I'm looking for is what cables do i need to power my ATI Radeon 4870 in my Mac Pro?  Another way to answer that I guess would be to explain to me the way my power supply works in my mac pro.
    Thanks!
    Mickey

    That is an 8-pin. And I just posted Amazon link to 6-pin in another graphic card upgrade thread minutes ago.
    And  it had a ATI 2600XT. good thing you replaced it.
    10.6.8  tends to run best but try - andkeep 10.8.x and see  how it goes. Also more options later in graphic cards.
    Call Apple and have them check  the serial number and they can provide for small $20?fee the OEM  DVDs it shipped with (10.5.x) and  Apple Hardware Test. They can  also sell 10.6.3 DVD
    I would have looked for the ATI 5770, better support, the 4870 lacks some ML (Mountain Lion) support for OpenCL.
    ATI Radeon 5770
    http://store.apple.com/us/product/MC742ZM/A
    http://www.amazon.com/Apple-ATI-Radeon-5770-MC742ZM/dp/B003Z6QH6M
    http://www.bhphotovideo.com/c/product/726537-REG/Apple_MC742ZM_A_ATI_Radeon_HD_5 770.html
    How To Install and Remove Memory Mac Pro
    https://support.apple.com/kb/HT4433
    2008 Mac Pro Memory Arrangement
    http://eshop.macsales.com/Customized_Pages/Framework.cfm?page=install_videos/mac pro/macpro_quicksheet.html
    2x2GB FBDIMM DDR2 667MHz @ $31
    http://www.amazon.com/BUFFERED-PC2-5300-FB-DIMM-APPLE-Memory/dp/B002ORUUAC/
    Hardware Monitor
    http://www.bresink.com/osx/HardwareMonitor.html
    UPS
    http://www.amazon.com/CyberPower-CP1500PFCLCD-Compatible-1500VA-Tower/dp/B00429N 19W/
    PCI-e Power Aux Power cable
    http://www.amazon.com/PCIe-Power-Cable-nVidia-Video/dp/B002UR1654/

  • I signed up for an Apple ID and now its requiring for payment information but i dont have a card what can i do?

    I just want to download free apps and i dont have a bank card yet but it requires for card code what can i do?

    Hi Huyen1110,
    You can use the steps in this article to create an iTunes Store account that does not use a credit or debit card for payment -
    Create an iTunes Store, App Store, or iBooks Store account without a credit card or other payment method - Apple Support
    Thanks for using Apple Support Communities.
    Best,
    Brett L 

  • Tough question, but how much study is usually required for cert. exams

    I have been working for 3-4 years as a Configuration Manager administrator, mostly in CM12. I have strong areas, like OSD and application deployment, and weaker areas, like PKI/https and Compliance Settings. I consider myself to be an advanced technician
    or engineer.
    I am considering System Center Configuration Manager certification (70-243), but am wondering how much of an endeavor this is likely to be. Can others that have taken this or similar certificate exams please advise me? In weighing the value of certification,
    I am wondering if I will be likely to succeed with a 100 hour commitment, or is it going to much more substantial a time investment?
    I know this will vary wildly depending on how quickly a person learns and what they already know, but would love to have some idea before I decide to go down this path. I welcome your feedback and experience.
    Gary

    Hi Gary-
    As you mentioned, the time it takes to properly prepare for an exam varies quite a bit.  So it will be helpful if other people chime in with their experiences too.  For most Microsoft exams, there are topics that you know and work with, topics
    that you've read about but not worked with, and topics that are new to you.  Let me break down how this impacts the amount of time required to study:
    Topics that you know and work with.  Some people might think that these topics don't require study time.  I think they do require study time.  That's because most admins have a specific method that they use in their work. 
    That might not be the method that the exam tests you on.  For example, in ConfigMgr you might use the management console for the  majority of your work.  The exam may test you on PowerShell.  It may ask a basic question about performing
    a task that you know how to do in the management console but the only answer choices are PowerShell.  Or, they may test you on a new feature in R2 when your environment isn't running R2.  I recommend that you review the latest enhancements to R2
    and spend a bit of time investigating alternate methods to perform tasks.  I estimate about 4 or 5 hours on this.
    Topics that you've read about but not worked with.  These topics require study.  I recommend that you read about them and work with them.  For example, you should read about configuration items AND implement them in a lab
    environment.  There are several learning styles and often people don't know which style is most effective for them.  Some learn by reading, some learn by doing, some learn by hearing, etc.  Typically, you will retain more knowledge by combining
    the learning styles.  For me, I typically start by playing with a technology in my lab for a few hours.  Afterward, I will read about it.  Then maybe go back to the lab.  For others, it may be different.  But definitely experiment
    to see what feels right for you.  I recommend that you avoid just reading about something that you've never worked with because it will make the exam difficult to pass.
    Topics that are new to you.  These topics require the most study.  As Alberto pointed out, use the Skills Measured section.  Print it out.  Each time you finish reading and exploring a technology and feel comfortable,
    cross it off.  For these new topics, definitely get your hands on them in a lab.  Even if you only spend a few minutes with each one.
    For me, I usually allocate about 2 weeks to study for an exam.  But study time during that two weeks comes in between regular work and family stuff.  Maybe a couple of hours a day total and a few extra hours the day before the exam.  In the
    past, I've allocated as little as 1 week to prepare for an exam.  For beta exams, I've walked in several times without any preparation.  In all cases, I always think that I should've spent a couple of extra hours.
    If you've never taken a certification exam or a Microsoft certification exam, you'll want to spend more time than others who have taken exams.  But, one thing I typically tell people is not to spend too much time studying.  It will work against
    you.  If you spend 8 weeks studying, by the half way point you will start forgetting the stuff you studied in the first week.  When the exam comes up, you'll have probably forgotten half of the stuff you studied.  I recommend a maximum of 4
    weeks of study for an exam like this.  A book dedicated to 70-243 will be helpful but should be combined with hands on time in a lab environment.  If you don't have a lab to work in, check out the free TechNet labs for Configuration Manager at
    http://technet.microsoft.com/en-us/virtuallabs/bb467605.aspx.  Finally, don't worry about failing an exam.  It is often the one thing that can help you the most in your exam
    preparation!  I advise that you schedule the exam.  Pick a date a couple of weeks out and commit by scheduling it.  If you fail, you will know exactly what you need to do before you take the exam again!
    Brian

  • SAP R3 and BI system requirement for loading Inventory data (0IC_C03)

    Hi,
    I have installed the Business content for 0IC_C03,activated the required datasources in R3 and replicated the same in SAP BI.
    However, while filling up setup tables the load is getting failed and it is giving error "No internal table space....".
    This is related to memory issues in SAP R3.Please let me know the minimum system requirement to do the above activity,
    for example RAM,parameters to be set from basis point of view,etc.The backend is MSSQL 2003 having RAM of 20GB.There is around one crore of data.
    Please let me as  soon as possible.
    Regards
    Deepak.

    Thank you Murali.
    But approximately can you tell me what is the memory requirement for SAP R3 and SAP BI for such type of applications.
    Regards
    Deepak.

Maybe you are looking for

  • How to set target to Play button on begining DVD

    Man you dont use this program for a few months and you gotta take a course on it all over again. Ive completely forgotten how to set the PLAY button to activate at the beginning of the DVD. As in I was burning several DVDs and I tested them on my com

  • How do I set the default printer to pdf in Firefox 8?

    Wish to set default printer to PDF, in specific folder. Always tries to print to .ps in my home folder. Using Linux, Fedora 16. I have had the same problem in Fedora 14.

  • Unable to create or update the Excel Personal data provider in Web Rich

    Hi All, Iam getting the below error message ,when iam using Excel as personal data provider in WEBI Rich Client. "Unable to create or update the Excel Personal data provider in Web Rich Client Cannot open the workbook WIS:10872" Please suggest a solu

  • In cfchart tip text is colored blue when applying xml style file!

    Foregroundcolor is set to black also, but it just colored chart text - not tips, which remained blue. And there seems to be no way to change this and make tip text black... Nobody replied. So - can it be considered as a BUG? If so - how to report abo

  • Getting error comment not terminated properly

    Hi All, On running below sql query I am getting the error ORA-01742: comment not terminated properly SELECT "SPLITTER_INPUT_SUBQUERY"."LEVEL_FK_KEY" "LEVEL_FK_KEY", "SPLITTER_INPUT_SUBQUERY"."LEVEL_FK" "LEVEL_FK", "SPLITTER_INPUT_SUBQUERY"."PARENT_FK