Options

Three tier installation using service account

sendohsendoh Member Posts: 207
edited 2012-03-16 in NAV Three Tier
Hi Expert,


I have a situation below(as this just for POC).

AD - 192.168.0.1 - Domain controller(Windows Server 2008 R2)
DB - 192.168.0.2 - Database server(MSSQL 2008R2 in Windows Server 2008 R2)
NST - 192.168.0.3 - Nav Service Tier(NAV2009R2 in Windows Server 2008 R2).

I already set up the object listener as my ReplacewithServerName = NAVPOC\NST$
and based on the walkthorugh I don't need to set SPN as I used Service Account in my NST and in SQL.

when I connect using NST computer(using domain account as NAVPOC\Admin, I can connect to the database and succesfully run the RTC, but when I tried to connect using remote user(using same account NAVPOC\Admin) by setting up "UserName" in Credential configfile. it gives an error

Microsoft Dynamics NAV
The login failed when connecting to SQL Server 192.168.0.2
OK
Please help, what I missed?

Thanks.
Sendoh
be smart before being a clever.

Comments

  • Options
    mikmik Member Posts: 79
    Hi!

    I am no expert but I was wondering because of your post ..
    .. and based on the walkthorugh I don't need to set SPN as I used Service Account in my NST and in SQL ..

    Please have a look on the installation guide again.
    Walkthrough

    In my opinion you can not connect from a client without SPN in your current configuration. There is no permission for the service account that he is allowed to impersonate from your middle tier.
    Please correct me if I am wrong.

    greetings mik

    With kind regards
    mik
  • Options
    sendohsendoh Member Posts: 207
    meaning I need to create an SPN for network service?
    Sendoh
    be smart before being a clever.
  • Options
    kinekine Member Posts: 12,562
    No, you need to create SPNs for the server accounts (DB$ and NST$ in your case). See my blog article about this subject...
    Kamil Sacek
    MVP - Dynamics NAV
    My BLOG
    NAVERTICA a.s.
  • Options
    sendohsendoh Member Posts: 207
    Hi Kine, will try your advise, Thanks.
    Sendoh
    be smart before being a clever.
Sign In or Register to comment.