Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8523897
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 11, 20262026-06-11T07:32:25+00:00 2026-06-11T07:32:25+00:00

We are attempting to use CredSSP authentication for multi-hop PowerShell remoting , and one

  • 0

We are attempting to use CredSSP authentication for multi-hop PowerShell remoting, and one of our clients is running into a snag that prevents them from creating PSSessions using CredSSP when specifying the FQDN of the target server. Both server and client are joined to the same domain, and there’s nothing fancy going on with disjoint namespaces.

In the course of debugging, we’ve opened up all of the related security options we can think of; in specific:

  • We’ve enabled the GP settings to Allow Delegating Fresh Credentials (standard and ‘With NTLM only’) with the wildcard SPN wsman/*
  • We’ve enabled the WSMan Trusted Hosts setting with *.domain.com
  • We’ve (of course) enabled WSMan for CredSSP on the server and the client
  • We’ve set the LocalAccountTokenFilterPolicy on the server

With all those settings opened up, here’s what we get when trying different authentication methods for PSSessions:

  • Using Kerberos for delegation with explicit domain credentials works fine.
  • Using Negotiate for delegation with explicit domain credentials works fine.
  • Using CredSSP for delegation:
    • Using domain credentials, connecting to the FQDN of the server, fails with the error There are currently no logon servers available to service the logon request
    • Using domain credentials, connecting to just the hostname of the server, fails with the same error
    • Using credentials for a local account on the server (thus forcing NTLM for server identity verification, I believe), connecting to the FQDN of the server, works fine
    • Using domain credentials, connecting to the IP address of the server (thus forcing NTLM for server identity verification), works fine

So, in short, CredSSP works as long as we’re using NTLM for server authentication and fails when we use Kerberos, but Kerberos definitely works fine if we’re using Kerberos for delegation as well. How is that possible, and what can we do to make it so that CredSSP+Kerberos works?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-11T07:32:27+00:00Added an answer on June 11, 2026 at 7:32 am

    We figured out the issue with the help of some engineers from Microsoft: the domain controller at the customer site is Server 2003, which does not support CredSSP (Server 2008 or greater is required).

    That is, CredSSP with NTLM works because NTLM doesn’t involve the domain controller–it’s just between the client (Windows 7 x64) and the server (Server 2008 R2 x64). When you use CredSSP with Kerberos, you’re now involving the domain controller (KDC), which doesn’t know how to handle a CredSSP connection, so it fails.

    So, until the customer can upgrade their domain controller, they’re going to use a local user account to remote with our deployment tool, thus cutting the domain out of the picture.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

Attempting to use XStream's JavaBeanConverter and running into an issue. Most likely I'm missng
I'm attempting to use Python to convert a multi-page PDF into a series of
In attempting to use std::select1st from <functional> in a VS2008 project I found that
I am attempting to use XMLParse against content that is not valid xhtml. In
Attempting to use asp.net mvc's Action Result of File. So it would seem that
I am attempting to use a button to go from one View (XIB) to
I'm attempting to use Ninject to inject repositories into controllers of my MVC project.
We are attempting to use a SQL Server 2003 database for our test records
I'm attempting to use the getc() function to copy the contents of one file
I am attempting to use an Ant build script to build a project that

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.