I have a Kerberos SQL cross forest authentication issue. Kerberos works if the SQL instance runs under the local system account and the SPN is registered as "MSSQLSvc/servername.domainname:1433" and correctly delegated on the computer account. When the SQL instance runs under a service account with the SPN registered for delegation on the service account the cross forest authentication does not work. Local domain Kerberos authentication does work. Forest trust is set as selective authentication.
↧