Skip to main content


 

Symptoms


I am getting this error, but I do not have Kerberos installed:

K2 Windows Token Service
------------------------
Analysis Result: Failed.
Constrained delegation is not enabled for the Active Directory account: Server Name]
The K2 Windows Token Service is a Windows Identity Foundation (WIF) feature that extracts UPN claims from SAML tokens and generates Windows security tokens. This allows K2, as the relying party, to impersonate a claims user for access to a line of business system, such as SQL.
Important: If you have configured Kerberos in your environment, a domain administrator must configure constrained delegation in Active Directory. For more information see the link below.
URL http://msdn.microsoft.com/en-us/library/ff649317.aspx, : Text How To: Use Protocol Transition and Constrained Delegation in ASP.NET 2.0 (MSDN)
Duration: 0.0156226 seconds
 

Diagnoses


The error indicates that HTTP service for the computer account has not been set up yet. You need to set up delegation to delegate HTTP service for the computer account to itself per the following KB, http://help.k2.com/kb001607_
 

Resolution

Configure the HTTP delegation for the computer account per http://help.k2.com/kb001607_ resolved the issue.




 
Be the first to reply!

Reply