AD 用户模拟不会传播到具有集成安全性的数据库
我有一个设置,可以按照此处<的描述来模拟 AD 用户/a>.该应用程序使用集成安全性连接到 (Oracle) 数据库,但模拟的凭据不会传播到数据库。
模拟 AD 用户和访问具有集成安全性的数据库是否存在任何已知问题?
I have a setup where I impersonate an AD user as described here. The app connects to the (Oracle) database using integrated security, but the impersonated credentials are not propagated to the database.
Are there any known issues with impersonating AD users and accessing the database with integrated security?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
我在 Windows Web 应用程序中看到过这种情况,其中 AD 模拟不起作用,因为 SQL Server 不信任中继方,即 IIS。在我的示例中,基本上 IIS 告诉 SQL Server 提供的凭据是合法的,但 SQL Server 不信任 Web 服务器提供这些凭据,有时称为双跃点问题。您是否尝试过在 AD 中信任您的应用程序/Web 服务器对于授权?
I've seen this in Windows Web Applications where AD impersonation would not work because SQL Server would not trust the relaying party, i.e. IIS. In my example, basically IIS was telling SQL Server that the credentials provided are legitimate, but SQL Server would not trust the web server to present these credentials, some times called the double hop issue. Have you tried in AD to trust your application/web server for delegation?