Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > EFS file sharing with constrained delegation

Reply
Thread Tools Display Modes

EFS file sharing with constrained delegation

 
 
Ondrej Sevecek
Guest
Posts: n/a

 
      06-02-2009
hello,

is it supported to configure the remote EFS file server not with the
unconstrained delegation but with only a limited set of constrained
delegation SPNs? which SPNs must be used?

thank you very much

ondrej.


 
Reply With Quote
 
 
 
 
Martin Rublik
Guest
Posts: n/a

 
      06-04-2009
Ondrej Sevecek wrote:
> hello,
>
> is it supported to configure the remote EFS file server not with the
> unconstrained delegation but with only a limited set of constrained
> delegation SPNs? which SPNs must be used?
>
> thank you very much
>
> ondrej.


Hi,

this is what worked for me,

FS delegate: cifs/DC, ldap/DC, protectedstorage/DC
(note, if you have multiple domain controllers in site you should add them all)
FS delegate: HOST/CA

However, I could not find any documentation regarding constrained delegation,
technet does not mention whether this configuration is supported or not.

HTH

Pozdravuje (Greetings)

Martin

--
Replace nospam with google's mail for e-mail communication
 
Reply With Quote
 
Ondrej Sevecek
Guest
Posts: n/a

 
      06-04-2009
yes, no documentation at all to this, but it actually doesn't work for me,
even previously i tested something similar:

fs1: can delegate to CIFS/DC1
fs1: can delegate to LDAP/DC1
fs1: can delegate to ProtectedStorage/DC1
fs1: can delegate to GC/DC1
fs1: can dleegate to RPCSS/CA1
fs1: can delegate to HOST/CA1

but it stops after obtaining the last ticket from DC, no further ip traffic
occuring from the FS. it must have been that the FS dindn't know something
or was thinking something incorrectly, but it didn't repair even after
restarts.

ale dekuju moc za podporu. pokusim se to jeste nejak poresit a dam vedet :-)

ondrej





"Martin Rublik" <> wrote in message
news:...
> Ondrej Sevecek wrote:
>> hello,
>>
>> is it supported to configure the remote EFS file server not with the
>> unconstrained delegation but with only a limited set of constrained
>> delegation SPNs? which SPNs must be used?
>>
>> thank you very much
>>
>> ondrej.

>
> Hi,
>
> this is what worked for me,
>
> FS delegate: cifs/DC, ldap/DC, protectedstorage/DC
> (note, if you have multiple domain controllers in site you should add them
> all)
> FS delegate: HOST/CA
>
> However, I could not find any documentation regarding constrained
> delegation,
> technet does not mention whether this configuration is supported or not.
>
> HTH
>
> Pozdravuje (Greetings)
>
> Martin
>
> --
> Replace nospam with google's mail for e-mail communication


 
Reply With Quote
 
Martin Rublik
Guest
Posts: n/a

 
      06-04-2009
Just a simple question,

is it possible to log on the server locally and to encrypt a file using EFS?

Martin

Ondrej Sevecek wrote:
> yes, no documentation at all to this, but it actually doesn't work for
> me, even previously i tested something similar:
>
> fs1: can delegate to CIFS/DC1
> fs1: can delegate to LDAP/DC1
> fs1: can delegate to ProtectedStorage/DC1
> fs1: can delegate to GC/DC1
> fs1: can dleegate to RPCSS/CA1
> fs1: can delegate to HOST/CA1
>
> but it stops after obtaining the last ticket from DC, no further ip
> traffic occuring from the FS. it must have been that the FS dindn't know
> something or was thinking something incorrectly, but it didn't repair
> even after restarts.
>
> ale dekuju moc za podporu. pokusim se to jeste nejak poresit a dam vedet
> :-)
>
> ondrej
>
>
>
>
>
> "Martin Rublik" <> wrote in message
> news:...
>> Ondrej Sevecek wrote:
>>> hello,
>>>
>>> is it supported to configure the remote EFS file server not with the
>>> unconstrained delegation but with only a limited set of constrained
>>> delegation SPNs? which SPNs must be used?
>>>
>>> thank you very much
>>>
>>> ondrej.

>>
>> Hi,
>>
>> this is what worked for me,
>>
>> FS delegate: cifs/DC, ldap/DC, protectedstorage/DC
>> (note, if you have multiple domain controllers in site you should add
>> them all)
>> FS delegate: HOST/CA
>>
>> However, I could not find any documentation regarding constrained
>> delegation,
>> technet does not mention whether this configuration is supported or not.
>>
>> HTH
>>
>> Pozdravuje (Greetings)
>>
>> Martin
>>
>> --
>> Replace nospam with google's mail for e-mail communication

>


--
--
Replace nospam with google's mail for e-mail communication
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
remote EFS file share and constrained delegation Ondrej Sevecek Server Security 0 05-27-2009 08:51 PM
Re: Active Directory Delegation and File Sharing in Domain Controllers Jorge Silva Active Directory 0 02-26-2008 07:06 PM
Trouble w/ Constrained Delegation Virtual Server & SBS Dale Networkguy Windows Small Business Server 2 07-06-2006 12:09 PM
Re: Kerberos Constrained Delegation For Access To A Single Application Pool Al Mulnick Active Directory 0 04-23-2006 01:45 AM
Outlook Delegation or Sharing => Unable to display the folder. HEL Lee Taylor Windows Small Business Server 4 03-20-2006 01:45 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59