Options

Delegatino issue NAV 2013R2 on Win server 2012 R2

vremeni4vremeni4 Member Posts: 323
edited 2014-10-29 in NAV Three Tier
Hi,

I installed NAV 2013 R2 on three machines, all machines are Windows Server 2012 R2.
On the first machine is SQL server, second NAV Service (uses dedicate account, so it does not use Network Services) and on the third one we have Web client.
All works fine except the Web client.
On the local machine (where web client is installed aka. IIS) the web client works fine but it does not work on any other machine.
I suspected that Setspn needs to be created, so I followed the instruction on
http://msdn.microsoft.com/en-us/library/jj551742%28v=nav.71%29.aspx

All is fine until I get to the point 10
In the list of available services, press and hold the Ctrl key, select DynamicsNAV for port 7046 and HOST, and then choose the OK button.
The problem is that the Service Type DynamicsNAV does not appear in the list ?!?!?
I tried with another name too e.g. NAVLIVE but that one also does not appear.
I checked the SETSPN -l and the entry is there.

The only way to make it work was to use the option
Trust this user for delegation to any service (Kerberos only).
which basically means trust to all services. (this is probably not very secure)
if I use the option
Trust this user for delegation to specified services only
as suggested in the MSDN article the name of the service does not appear in the list in the step 10.
I have no idea why.

Did someone had similar issue and discovered what is wrong?

Thanks for your help.

Comments

  • Options
    vremeni4vremeni4 Member Posts: 323
    Hi,

    Just to give everyone an updated on this, as the problem is resolved in the meantime.
    It was an error in the Instructions on the Microsoft web site. This was corrected by Microsoft.
    The most important bit is
    In the Enter the object names to select box, type the name of the computer that is running Microsoft Dynamics NAV Server, in this case NAVSSERVER, and then choose the OK button.

    In order to see the services you need to select the computer where NAV server runs and not the user as the previous instructions were.
    It is also important to remember that SPN entry will be automatically added when NAV Service is created from
    “Microsoft Dynamics NAV 2013 R2 Administration”
    The only problem is that SPN entry will be created always with the name DynamicsNAV and not with the name of the NAV server.
    For example If the NAV server instance is called MyNAVServer on the port 7245, then the SPN that will be created automatically are
    DynamicsNAV/MCNAVSVC:7245
    DynamicsNAV/MCNAVSVC.corp:7245
    Important bit is that these entries must not be deleted otherwise you will get error message that wrong SPN is set. (Always look at the port number as an indicator)

    I hope this helps someone. :-)

    Thanks.
Sign In or Register to comment.