<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Kerberors auth against MS AD in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/kerberors-auth-against-ms-ad/m-p/29826#M15271</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello Everyone,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm new to Alfresco. First of all everything is working fine with my configuration.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The Authentication over LDAP to the Active Directory works fine.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now I want activate CIFS and authentification with Kerberos.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I finished all steps succesfully from here: &lt;/SPAN&gt;&lt;A href="http://docs.alfresco.com/5.0/tasks/auth-kerberos-ADconfig.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/5.0/tasks/auth-kerberos-ADconfig.html&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;But If I start Alfresco, in the log comes the following failures:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2015-03-26 13:13:18,612 ERROR [org.alfresco.filesys.auth.cifs.EnterpriseCifsAuthenticator] [localhost-startStop-1] CIFS Kerberos authenticator error&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;javax.security.auth.login.LoginException: Client not found in Kerberos database (6)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; Caused by: KrbException: Client not found in Kerberos database (6)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; Caused by: KrbException: Identifier doesn't match expected value (906)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2015-03-26 13:13:18,617 WARN&amp;nbsp; [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Startup of 'Authentication' subsystem, ID: [Authentication, managed, kerberos1] failed&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;org.springframework.beans.factory.BeanCreationException: Error creating bean with name 'cifsAuthenticator' defined in URL [jar:file:/opt/alfresco-5.0.d/tomcat/webapps/alfresco/WEB-INF/lib/alfresco-repository-5.0.d.jar!/alfresco/subsystems/Authentication/kerberos/kerberos-authentication-context.xml]: Invocation of init method failed; nested exception is org.alfresco.jlan.server.config.InvalidConfigurationException: Failed to login CIFS server service&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; Caused by: org.alfresco.jlan.server.config.InvalidConfigurationException: Failed to login CIFS server service&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have installed Alfresco 5.0.d (and with Alfresco 5.0.c I have the same Problem).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The Authentication works against a Windows Server 2012 R2 Active Directory.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;If I execute the command 'kinit -V -k -t /etc/keys/AlfrescoCIFS.keytab "cifs/sles-alfresco.my.domain"' everything works fine - &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Using existing cache: :/run/user/0/krb5cc/tkt&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Using principal: cifs/sles-alfresco.my.domain@MY.DOMAIN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Using keytab: /etc/keys/AlfrescoCIFS.keytab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Authenticated to Kerberos v5&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Here are some examples from my configs:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;krb5.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[libdefaults]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default_realm = EXAMPLE.COM&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default_realm = my.domain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default_keytab_name = FILE:/etc/keys/AlfrescoCIFS.keytab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default_tkt_enctypes = rc4-hmac aes256-cts aes128-cts des3-cbc-sha1 des-cbc-md5 des-cbc-crc&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default_tgs_enctypes = rc4-hmac aes256-cts aes128-cts des3-cbc-sha1 des-cbc-md5 des-cbc-crc&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permitted_enctypes = rc4-hmac aes256-cts aes128-cts des3-cbc-sha1 des-cbc-md5 des-cbc-crc&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dns_lookup_kdc = true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dns_lookup_realm = false&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[realms]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; EXAMPLE.COM = {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; kdc = kerberos.example.com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; admin_server = kerberos.example.com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CONSENSO.LOCAL = {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; kdc = dc01.my.domain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; admin_server = dc01.my.domain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[domain_realm]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dc01.my.domain = MY.DOMAIN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; .dc01.my.domain = MY.DOMAIN&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[logging]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; kdc = FILE:/var/log/krb5/krb5kdc.log&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; admin_server = FILE:/var/log/krb5/kadmind.log&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; default = SYSLOG:NOTICE&lt;img id="smileyvery-happy" class="emoticon emoticon-smileyvery-happy" src="https://connect.hyland.com/i/smilies/16x16_smiley-very-happy.png" alt="Smiley Very Happy" title="Smiley Very Happy" /&gt;AEMON&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;alfresco-global.properties:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;## cifs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;filesystem.name=Alfresco&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.enabled=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.serverName=sles-alfresco&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.domain=my.domain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.hostannounce=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.pseudoFiles.enabled=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.pseudoFiles.explorerURL.enabled=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.pseudoFiles.explorerURL.fileName=__Alfresco.url&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.pseudoFiles.shareURL.enabled=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.pseudoFiles.shareURL.fileName=__Share.url&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ftp.enabled=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nfs.enabled=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;java.login.config:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Alfresco {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;AlfrescoCIFS {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; storeKey=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; doNotPrompt=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; keyTab="/etc/keys/AlfrescoCIFS.keytab"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; principal="cifs/sles-alfresco.my.domain";&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;AlfrescoHTTP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;{&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; storeKey=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; doNotPrompt=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; keyTab="/etc/keys/AlfrescoHTTP.keytab"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; principal="HTTP/sles-alfresco.my.domain";&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;com.sun.net.ssl.client {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;other {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Hope you can help me.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Patrick&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Mar 2015 13:07:27 GMT</pubDate>
    <dc:creator>patsch</dc:creator>
    <dc:date>2015-03-26T13:07:27Z</dc:date>
    <item>
      <title>Kerberors auth against MS AD</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberors-auth-against-ms-ad/m-p/29826#M15271</link>
      <description>Hello Everyone,I'm new to Alfresco. First of all everything is working fine with my configuration.The Authentication over LDAP to the Active Directory works fine.Now I want activate CIFS and authentification with Kerberos.I finished all steps succesfully from here: http://docs.alfresco.com/5.0/tasks</description>
      <pubDate>Thu, 26 Mar 2015 13:07:27 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberors-auth-against-ms-ad/m-p/29826#M15271</guid>
      <dc:creator>patsch</dc:creator>
      <dc:date>2015-03-26T13:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberors auth against MS AD</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberors-auth-against-ms-ad/m-p/29827#M15272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I found a solution, so my Configuration works for me.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;There is another file, that I must edit.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;/opt/alfresco/tomcat/shared/classes/web-extension/share-config-custom.xml&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Patrick&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Mar 2015 14:42:21 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberors-auth-against-ms-ad/m-p/29827#M15272</guid>
      <dc:creator>patsch</dc:creator>
      <dc:date>2015-03-30T14:42:21Z</dc:date>
    </item>
  </channel>
</rss>

