Kerberos authentication

Jun 10, 2011 at 4:31 PM

How can specify Kerberos authentication in the script for for Central Admin and other new web applications? Is there a script reference that I can use to provide custom changes in the XML input file? Thanks in advance for your help.

Jun 14, 2011 at 2:56 AM

Sorry but there currently isn't any support in the script for creating any web apps (including Central Admin) as Kerberos-enabled right from the start. You'd need to create it as NTLM (default) then do the Kerberos config changes (including creating the SPN in Active Directory) manually afterwards.


Jun 14, 2011 at 2:57 PM

Hi Brian - For Central Admin, what if I change the parameter -WindowsAuthProivder to Kerberos here in the AutoSPInstallerFunction.ps1 file, do you think that would work? Do I also need to provide the same value in the Input file for the Funtion file to process it?

# Create Central Admin for farm
    Write-Host -ForegroundColor White " - Creating Central Admin site..."
    $NewCentralAdmin = New-SPCentralAdministration -Port $CentralAdminPort -WindowsAuthProvider "NTLM" -ErrorVariable err

Also for Web Applications, can I provide the same value here:

# Configure new web app to use Claims-based authentication
      $AuthProvider = New-SPAuthenticationProvider -UseWindowsIntegratedAuthentication
      New-SPWebApplication -Name $WebAppName -ApplicationPoolAccount $account -ApplicationPool $AppPool -DatabaseName $database -HostHeader $HostHeader -Url $url -Port $port -SecureSocketsLayer:$UseSSL -AuthenticationProvider $AuthProvider | Out-Null



Jun 17, 2011 at 11:24 AM

As I mentioned in your other post, you could either set the $AuthProvider parameter (which in the script currently doesn't look for or support Kerberos) or just hard-code it in your copy of the AutoSPInstallerFunctions.ps1 file.


Jun 17, 2011 at 11:24 AM
This discussion has been copied to a work item. Click here to go to the work item and continue the discussion.