Re: SSPI Contexts



Chris,

A very good source for troubleshooting the error is
http://support.microsoft.com/default.aspx?scid=kb;en-us;811889. You might
also want to have a look at
http://blogs.msdn.com/sql_protocols/archive/2005/10/15/481297.aspx for more
information.

Sometimes these errors have to do with SQL Server registering the Service
Principle Name (SPN) for the service in Active Directory, but later having
a problem like an incorrect shutdown of the SQL service (and/or a change in
the service account that runs SQL) which does not remove this entry from
AD, which later results in Kerberos errors. Forcibly removing machine
entries from the AD may help in certain cases. These two links should
provide more than enough background and guidance.

HTH,
Doug Girard [MSFT]

Note: This posting is provided "AS IS" with no warranties, and confers no
rights.
--------------------
From: "Tomas Restrepo \(MVP\)" <tomasr@xxxxxxxx>
References: <1126160472.535055.122950@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: SSPI Contexts
Date: Thu, 8 Sep 2005 06:15:17 -0500
Lines: 35
X-Priority: 3
X-MSMail-Priority: Normal
X-Newsreader: Microsoft Outlook Express 6.00.3790.1830
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
X-RFC2646: Format=Flowed; Original
Message-ID: <uGTHdaGtFHA.2008@xxxxxxxxxxxxxxxxxxxx>
Newsgroups: microsoft.public.biztalk.general
NNTP-Posting-Host: cable200-116-204-143.epm.net.co 200.116.204.143
Path:
TK2MSFTNGXA02.phx.gbl!TK2MSFTNGXA03.phx.gbl!TK2MSFTNGP08.phx.gbl!TK2MSFTNGP1
0.phx.gbl
Xref: TK2MSFTNGXA02.phx.gbl microsoft.public.biztalk.general:30740
X-Tomcat-NG: microsoft.public.biztalk.general

Chris,

We have our BizTalk server setup in a DMZ and the SQL Server database
is housed internally on another server. Recently we noticed in the
event logs the following errors:

An attempt to connect to "BizTalkMgmtDb" SQL Server database on server
"sqlsvr" failed with error: "Cannot generate SSPI context".

Immediately following this error, the BizTalkServerApplication host
recycles itself. Once it has done this it works okay for approximately
another 30 minutes where this same process repeats itself.

Has anyone ever seen this occur and if so, what troubleshooting or
resolution did you conclude? I'm just not sure what could cause this
"SSPI context" generation process to fail. My IT group and I have read
a number of Microsoft articles but nothing stands out at us that leads
us to finding anything incorrect.

Usually, an SSPI Context problem means that you have connectivity problems
to your domain controller. One thing I've seen that can cause a lot of
trouble is the machine's clock getting out of sync with the domain
controller's one (you might want to check that the server in the DMZ can
synchronize its clock with the domain controller correctly, for example).

Also, start looking for netlogon errors in the server's eventlog, you
might
find something there that can pinpoint the cause.


--
Tomas Restrepo
tomasr@xxxxxxxx
http://www.winterdom.com/




.



Relevant Pages

  • Re: Disappearing printers
    ... Check the time service on both the SBS server and the windows2003 ... Domain Controller Diagnostics Tool ... Active Directory Diagnostics, Troubleshooting, and Recovery ... refer to the following article to check the FSMO roles to ...
    (microsoft.public.windows.server.sbs)
  • RE: Installing SQL server on a domain controller?
    ... A Domain Controller has too much network traffic to compete with a SQL Server ... A SQL Server installation, ...
    (microsoft.public.sqlserver.server)
  • dcpromod cluster node to non-domain controller, now SQL server wont start
    ... I am trying to remove domain controller from ... catalog server to them, and all the operation masters roles. ... and then tried to move the cluster group that contains my SQL server to ... with SQL server as I can move groups with just network names, ...
    (microsoft.public.windows.server.clustering)
  • Re: Server Setup Question
    ... It is my full intention to NOT have this network being able to access the ... be used as a gateway for the corporate users to access SQL server? ... Run your separate domain and allow corporate IT to connect to your server ... same machine that is the domain controller, and DHCP server and WINS server. ...
    (microsoft.public.sqlserver.setup)
  • Re: The RPC server is unavailable
    ... Windows 2003 Server STD SP1 ... SQL Server 2000 SP3 ... If this computer is a domain controller for the specified domain, ... he browser service was unable to retrieve a list of servers from the browser ...
    (microsoft.public.windows.server.general)