在 Lync Server 2013 中,从站点中删除 Kerberos 身份验证In Lync Server 2013 remove Kerberos authentication from a site

 

上次修改的主题: 2012-01-16Topic Last Modified: 2012-01-16

要成功完成此过程,应以 RTCUniversalServerAdmins 组成员的身份登录。To successfully complete this procedure you should be logged on as a user who is a member of the RTCUniversalServerAdmins group.

如果需要从网站中删除 Kerberos 身份验证或淘汰网站,则必须使用 CsKerberosAccountAssignment cmdlet 从网站中删除 kerberos 身份验证帐户分配。If you need to remove Kerberos authentication from a site or retire a site, you must remove the Kerberos authentication account assignment from the site by using the Remove-CsKerberosAccountAssignment cmdlet. 使用以下过程可删除 Kerberos 身份验证帐户分配,这将从网站中的所有计算机中删除分配。Use the following procedure to remove the Kerberos authentication account assignment, which removes the assignment from all computers in the site.

警告

如果要永久停用已启用 Kerberos 的帐户,则在删除分配后,应使用 Active Directory 用户和计算机将其从 Active Directory 域服务中删除。If you are permanently retiring the Kerberos-enabled account, you should use Active Directory Users and Computers to delete it from Active Directory Domain Services after you have removed the assignment. 如果将来打算使用该对象,则可能需要保留 Active Directory 对象。If you plan to use the object in the future, you might want to keep the Active Directory object.

从站点中删除 Kerberos 身份验证To remove Kerberos authentication from a site

  1. 作为 RTCUniversalServerAdmins 组的成员,登录到运行 Lync Server 2013 的域中的计算机或登录到安装了管理工具的计算机。As a member of the RTCUniversalServerAdmins group, log on to a computer in the domain running Lync Server 2013 or on to a computer where the administrative tools are installed.

  2. 启动 Lync Server 命令行管理程序:依次单击“开始”****、“所有程序”****、“Microsoft Lync Server 2013”**** 和“Lync Server 命令行管理程序”****。Start the Lync Server Management Shell: Click Start, click All Programs, click Microsoft Lync Server 2013, and then click Lync Server Management Shell.

  3. 通过命令行运行以下两个命令:From the command line, run the following two commands:

     Remove-CsKerberosAccountAssignment -Identity "site:SiteName"
    
     Enable-CsTopology
    

    例如:For example:

     Remove-CsKerberosAccountAssignment -Identity "site:Redmond"
    
     Enable-CsTopology
    

    重要

    在对 Kerberos 身份验证(如添加帐户或删除帐户)进行任何更改之后,您必须从 Lync Server 命令行管理程序命令提示符处运行 Enable-enable-cstopologyAfter making any changes to Kerberos authentication, such as adding an account or removing an account, you must run Enable-CsTopology from the Lync Server Management Shell command prompt.