WCF Kerberos SSPI Fails When One Domain Controller Disconnects

My WCF service uses Windows authentication with Kerberos, we disabled NTLM. The service runs under the same domain user account and client in the domain user account . And both are configured using UPN . Client and service are in the same domain . And in the domain there are two domain controllers .

Communication between the client and the service runs smoothly without any problems when both domain controllers are on the network. If one of the domain controllers does not work, I received the following error.

Failed to call SSPI call, see internal exception. ---> System.Security.Authentication.AuthenticationException: SSPI call failed, see internal exception. ---> System.ComponentModel.Win32Exception: the system detected a possible attempt to compromise security. Make sure you can contact the server that authenticated you

Please give advice on what I should do to resolve this error. Thank.

+4
source share
1 answer

Yes, I know what it is from. I just spent 2 and a half days trying to figure it out. This caused absolute chaos in my network of 60 workstations. Ahhhh! I pulled out my hair. MCSE since 2005.

IP6. - comcast IP4 . , , IP6 . IP6 , .

, - , - . , . , - .

+4

Source: https://habr.com/ru/post/1568567/


All Articles