locked
Configure Kerberos / Windows Authentication RRS feed

  • Question

  • Hi,

    I've been trying to set this up for a while as well as ECS but I'll discuss the issue I'm having with PAS in this post. Basically my configuration consists of the following:
    - PAS32 (Proclarity Analytics Server)
    - SSASNLB01 and SSASNLB02 (SQL Server 2008 R2 Analysis Services configured with NLB)
    - SSDB (SQL Server 2008 R2 Database Services)

    The configuration is PAS32 database is hosted in SSDB and PAS32 connects to the virtual IP of the NLB to acces the cubes.

    The steps I've done are as follows:
    1. Configure application pool of the PAS server to use spnaccount
    2. Configure SSASNLB01 and SSASNLB02 SSAS service account to use spnaccount
    3. Configure SSDB database service account to use spnaccount
    4. Created the following SPNs to spnaccount
          - HTTP/PAS site URL (A record)
          - MSOLAPSvc.3/NLB Virtual name
          - MSOLAPSvc.3/NLB Virtual name FQDN
          - MSOLAPSvc.3/SSASNLB01
          - MSOLAPSvc.3/SSASNLB02
          - MSOLAPSvc.3/SSASNLB01 FQDN
          - MSOLAPSvc.3/SSASNLB02 FQDN
    5. Configured spnaccount to Trust this user for delegation to any service (Kerberos only)
    6. Configured the PAS site to use Windows authentication

    The problem:
    The issue is that I can view reports when I select Professional but when I use Standard, it generates this error:
    "The selected page could not be opened because the cube could not be found. Please choose a different page"

    Troubleshooting:
    1. I've checked all the logs from PAS, SSASNLB01, SSASNLB02 and it doesn't show any logon failure. In one of the SSAS server, it even shows a successful network logon using my account and using Kerberos.

    Any inputs or ideas will be appreciated.

    Thanks,
    Marvin

    Thursday, July 1, 2010 1:24 PM

Answers

All replies