harbar.net component based software & platform hygiene

More on the Infrastructure Updates: Kerberos and SSP Web Services

posted @ Wednesday, July 16, 2008 1:20 PM | Feedback (0)

What's the best thing about the recently released Infrastructure Updates for SharePoint 2007? The super cool new search functionality? Content Deployment fixes? Improvements in performance and security?

Nope, none of those me ole china, it's the new support for Kerberos Authentication for the SSP Web Services. This was only previously possible with a heinous hack that I promised I would never detail publicly due to it's nastiness.

The problem was that the SSP Web Services run under a IIS Virtual Web Site with a high port. It's client (the .NET Framework) along with SharePoint was unable to construct the correct request to match the SPNs configured (if you configured them correctly, and not many did). So setting the setsharedwebserviceauthn to negotiate using STSADM would make your SSP Web Services nice and secure, but break your farm. Try doing this and then click Manage Search Service within Application Management and you'll see! (Everything is OK on a single server, but erm, who runs them in production!!).

The Infrastructure Updates address this, and it's now possible to configure the SSP Web Services to use Kerberos. This is a pretty big deal for enterprises who are serious about their farm build and configuration. It's not all great news, as there is an extra step (a reg key). This is something that I will be adding to the SharePoint Kerberos Configuration utility, which as it happens I've been delaying until these updates were shipped.

In addition to the updates, the IT Pro UA folk have done a great job of updating the Kerberos Configuration Guide on Tech Net. The section relevant specifically to this change is at:

http://technet.microsoft.com/en-us/library/cc263449(TechNet.10).aspx#section14

Infrastructure Updates Available

posted @ Tuesday, July 15, 2008 7:44 PM | Feedback (0)

The Infrastructure Updates for WSS 3.0 and MOSS 2007 are now available. I've also updated my Post SP1 Hotfixes article.

Key updates for Windows SharePoint Services 3.0 include:

  • Platform performance improvements and fixes.
  • Several backup and restore fixes.
  • Several core Workflow fixes.

Key updates for SharePoint Server 2007 include:

  • New Search features such as federated search and a unified search administration dashboard.
  • Several core fixes to Search to improve performance and scale.
  • Platform performance improvements and fixes.
  • Several core fixes to the publishing Content Deployment features to improve reliability.

It is strongly recommended you install these updates which are also cumulative and include previous roll ups.

Infrastructure Update for Windows SharePoint Services 3.0 (KB951695) - x86
http://www.microsoft.com/downloads/details.aspx?FamilyId=256CE3C3-6A42-4953-8E1B-E0BF27FD465B&displaylang=en

Infrastructure Update for Windows SharePoint Services 3.0 (KB951695) - x64
http://www.microsoft.com/downloads/details.aspx?FamilyId=3A74E566-CB4A-4DB9-851C-E3FBBE5E6D6E&displaylang=en

Infrastructure Update for Microsoft Office Servers (KB951297) - x86
http://www.microsoft.com/downloads/details.aspx?FamilyId=3811C371-0E83-47C8-976B-0B7F26A3B3C4&displaylang=en

Infrastructure Update for Microsoft Office Servers (KB951297) - x64
http://www.microsoft.com/downloads/details.aspx?FamilyId=6E4F31AB-AF25-47DF-9BF1-423E248FA6FC&displaylang=en