在 Lync Server 2013 中将 Kerberos 身份验证帐户密码同步到 IISSynchronize a Kerberos authentication account password to IIS in Lync Server 2013

 

上次修改的主题: 2010-11-08Topic Last Modified: 2010-11-08

要成功完成此过程,应以 RTCUniversalServerAdmins 组成员的身份登录。To successfully complete this procedure you should be logged on as a user who is a member of the RTCUniversalServerAdmins group.

在网站中,前端服务器、Standard Edition 服务器和控制器可以使用 Kerberos 身份验证帐户,以对 Web 服务服务的请求进行身份验证。In a site, Front End Servers, Standard Edition servers, and Directors can use a Kerberos authentication account for purposes of authenticating requests to the Web Services service. 此过程将查找在已分配 Kerberos 帐户的站点中运行 Web 服务的每台服务器,并将 Internet 信息服务 (IIS) 配置设置更新为使用 Kerberos 帐户。This procedure locates each server running Web Services in a site that has been assigned a Kerberos account and updates the Internet Information Services (IIS) configuration settings to use the Kerberos account. 有关详细信息,请参阅 在 Lync server 2013 中的服务器上设置 Kerberos 身份验证帐户密码For details, see Set a Kerberos authentication account password on a server in Lync Server 2013.

设置和配置 Kerberos 身份验证帐户密码To set and configure a Kerberos authentication account password

  1. 以 RTCUniversalServerAdmins 组成员的身份登录到源计算机(例如 fe01.contoso.com)。Log on to a source computer (such as fe01.contoso.com) as a member of RTCUniversalServerAdmins group.

  2. 启动 Lync Server 命令行管理程序:依次单击“开始”****、“所有程序”****、“Microsoft Lync Server 2013”**** 和“Lync Server 命令行管理程序”****。Start the Lync Server Management Shell: Click Start, click All Programs, click Microsoft Lync Server 2013, and then click Lync Server Management Shell.

  3. 在 Lync Server 命令行管理程序命令行中,运行以下两个命令:From the Lync Server Management Shell command line, run the following two commands:

    Set-CsKerberosAccountPassword -FromComputer SourceComputer -ToComputer DestinationComputer
    

    例如:For example:

    Set-CsKerberosAccountPassword -FromComputer fe01.contoso.com -ToComputer dir01.contoso.com
    

    重要

    源计算机和目标计算机的名称必须是服务器的完全限定域名 (FQDN)。除非池名称与要用作源计算机或目标计算机的计算机名称相同,否则不能使用池 FQDN。The name of the source computer and destination computer must be a fully qualified domain (FQDN) name of the server. You cannot use the pool FQDN unless the pool name is the same as the name of the computer that you are using as a source computer or destination computer.

    重要

    在对 Kerberos 身份验证(如添加帐户或删除帐户)进行任何更改之后,您必须从 Lync Server 命令行管理程序命令提示符处运行 Enable-enable-cstopologyAfter making any changes to Kerberos authentication, such as adding an account or removing an account, you must run Enable-CsTopology from the Lync Server Management Shell command prompt.