SharePoint 2013 平台Kerberos 配置详细说明 (Configure Kerberos Guideline)

一个项目用到,考虑到很多项目会用到,方便同事和自己也能方便别人参加。所以写出详细技术细节

所有抓图均来自与服务器,由于这个项目时英文的,所有我写也是英文admin guideline

Ok  let‘s begin.

All Programs > Microsoft SharePoint 2013 Products > SharePoint 2013 Central Administration  Enter farm administrator credentials when requested.  Click on “Security”

and then Click on “Configureservice accounts

Select from the list of services the service “Windows Service – Claims to Windows  Token Service” Select from the list of services the service “Windows Service – Claims to Windows  Token Service”

这里我简单说明一下 这里就是你在windows服务里的Claims to Windows  Token Service 管理登录名

Add the WSS_WPG Windows Group to the c2wtshost.exe.config file

Start > All Programs > Accessories > Windows Explorer

Navigate to the following path: “C:\ Program Files\Windows Identity Foundation\v3.5\”

Open the file “c2wtshost.exe.config” in notepad  Locate section “<allowedCallers>”

Insert following section “<add value-”WSS_WPG”>”

And then you must to Reset IIS  you know that?

next step.  Start the service on the application servers

All Programs > Microsoft SharePoint 2013 Products > SharePoint 2013 Central Administration    Enter farm administrator credentials when requested.Click on “Application Management”

Click on “Manageservices on server”  and then  Look for the “Claims to Windows Token Service” and check if it’s started If it is stopped, click on “Start” next to its title

Set the local permissions for the claims to windows token service

Start > Administrative Tools > Computer Management  Select node “Local Users and Groups”  Select node “Groups” Select the “Administrators”  group.Right Click and select “Add to Group …”

Click on “Add”.Enter the Claims To Windows token Service Name %Kerberos_C2WTSAccount%. Click on “Check Names”.Click on “OK”

And then 

Start > All Programs > Administrative Tools > Local Security Policy.

Select the node “Local Policies”. Select the node “User Rights Assignment”. In the “Local Security Policy”, on the right side, double click on “Act as part of the operating system”

Click on “Add User or Group” Enter the Claims To Windows token Service Name %Kerberos_C2WTSAccount% Click on “Check Names”Click on “OK”

Click on “Add User or Group” Enter the Claims To Windows token Service Name %Kerberos_C2WTSAccount% Click on “Check Names”Click on “OK”

In the “Local Security Policy”, on the right side, double click on “Impersonate a client after authentication

Click on “Add User or Group”

Enter the Claims To Windows token Service Name %Kerberos_C2WTSAccount%

Click on “Check Names”

Click on “OK”

In the “Local Security Policy”, on the right side, double click on “Log on as a service”

Click on “Add User or Group”

Enter the Claims To Windows token Service Name %Kerberos_C2WTSAccount%

Click on “Check Names”

Click on “OK”

And then Set a service dependency

Please note that this steps should be proceeded on each server that will be hosting BI services in SharePoint Farm.

Start > Administrative Tools > Services

Look for the “Claims to Windows Token Service” And double click on the title

In the “Dependencies” tab check if it the service depends on other system components

If this is the case, and there is no dependency, you can continue with this section. Otherwise you can jump to the following section

Start > All Programs > Accessories

Launch a Command Prompt as an administrator

To add the dependency, type the following command :”sc config c2wts depend= CryptSvc”

Note that a space is required between the equal sign and the value

You can then go back to the services list and check for the “Claims to Windows Token” service that the dependency has been added

时间: 2024-10-13 00:53:30

SharePoint 2013 平台Kerberos 配置详细说明 (Configure Kerberos Guideline)的相关文章

BEGINNING SHAREPOINT&amp;#174; 2013 DEVELOPMENT 第1章节--SharePoint 2013 介绍 SharePoint 2013 平台

BEGINNING SHAREPOINT? 2013 DEVELOPMENT 第1章节--SharePoint 2013 介绍 SharePoint 2013 平台 SharePoint保持了一个高级的架构.由很多部件组成(例如以下图). 你首先在Windows上安装核心软件.这样你能够创建SharePoint场. 本质上,SharePoint场是一个或多个构成你SharePoint实例的server.作为一个开发者.你应该理解三层结构和SharePoint场架构的角色--包括Webserver

BEGINNING SHAREPOINT&#174; 2013 DEVELOPMENT 第1章节--SharePoint 2013 介绍 SharePoint 2013 平台

BEGINNING SHAREPOINT? 2013 DEVELOPMENT 第1章节--SharePoint 2013 介绍 SharePoint 2013 平台 SharePoint保持了一个高级的架构,由许多部件组成(如下图).你首先在Windows上安装核心软件,这样你可以创建SharePoint场.本质上,SharePoint场是一个或多个构成你SharePoint实例的服务器.作为一个开发人员,你应该理解三层结构和SharePoint场架构的角色--包含Web服务器角色(一个响应用户

SharePoint 2013 平台 创建 Power view Report 共享数据源(RSDS)

SharePoint 2013 平台 创建 Power view Report 共享数据源(RSDS) 由于项目需求,在SharePoint  门户上集成 BI部分,完成了所有Excel Power report 后,需要在SharePoint 页面上 开发.编辑power view  报表. 也就是 RSDS  当然如果你想插入其他类型数据愿 也可以按照此方法操作! 以下正文:由于项目可能是设计密码数据,请允许我打上噪点.也可以加入群交流:212099235 本文使用:平台 SharePoin

SharePoint 2013 Power Pivot 安装详细说明(图解)

SharePoint 2013 Power Pivot 安装配置详细说明 前提必要条件,SharePoint 2013 为企业版本,已经安装成功.数据库为SQL Server BI 或企业版本. 一,安装 1,打开SQLServer 2014  企业版 安装程序 开始安装. 选择安装--全新SQL Server 独立安装或向现有安装添加功能. 选中SQL Server PowerPivot for SharePoint 如下图. 然后下一步,默认实例.如下图 录入账号和密码 下一步,数据库引擎配

SharePoint 2013 安装和配置 Project Server 2013

如何在SharePoint Server 2013 服务器场中安装 Project Server 2013 并创建 Project Server Service 应用程序. 第一步:安装 Project Server 2013 安装会吧  就不多啰嗦了.  第二部 :运行 SharePoint 产品和技术配置向导 依次单击"开始"."所有程序"."Microsoft SharePoint 2013 产品"和"SharePoint 201

Sharepoint 2013 开启App 配置App

如果没有Enable app,打开app store的时候出出现错误: Sorry, apps are turned off. If you know who runs the server, tell them to enable apps. 要开启他,首先要有一个App的DNS,如下新建,如果管理工具里面没有DNS,那么到feature中增加. Control Panel\System and Security\Administrative Tools 右击Forward Lookup Zo

SharePoint 2013 为站点配置基于主机标头的双域名

SharePoint的应用中,经常需要配置双域名,为不同的认证方式提供访问入口,下面简单介绍下,如何以主机标头的方式为SharePoint配置双域名: 配置基于主机标头的双域名 1.原本可以访问的测试站点,如下图 2.去管理中心,为应用程序创建扩展应用程序,如下图: 3.填写扩展应用程序的名字,也就是第二个域名,如下图: 4.可以到IIS中查看,多出来一个Web站点,如下图: 5.然后就可以访问这个站点的地址了,如下图: 修改SharePoint站点主机标头 1.进入IIS,站点,如下图: 点击

SharePoint 2013 搜索高级配置

SharePoint2013里面的搜索配置. 1.首先,新建页面,用于搜索, 2.添加搜索框.搜索结果部件: 选择<搜索>类别,找到”搜索框”.”搜索结果”两个部件,添加到页面: 3.配置搜索框部件: 点击编辑WebPart,右侧可以指定搜索结果显示在本页.指定搜索页面(我这里默认,就是本页),配置查询建议和设置等. 4.配置搜索结果部件,如下图: 点击右侧WebPart属性”更改查询”,弹出编辑对话框,在里面选择需要编辑的选项卡进行编辑(后面有介绍). 5.配置查询条件 在查询文本里填写”

安装和配置SharePoint 2013 Workflow

SharePoint 2013中的工作流概述 安装并配置工作流管理器 配置工作流管理器 与 SharePoint Server 2013 一起使用 测试是否正确安装和配置SharePoint Workflow 2013 小结 SharePoint 2013中的工作流概述 在SharePoint 2013中,Workflow(建立在Windows Workflow Foundation 4.5)和WCF承载在Workflow Manager中,即Workflow Manager提供了工作流定义的管