<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Kerberos difficulties in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220875#M174005</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;This is now fixed in HEAD.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 25 Aug 2009 12:14:39 GMT</pubDate>
    <dc:creator>dward</dc:creator>
    <dc:date>2009-08-25T12:14:39Z</dc:date>
    <item>
      <title>Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220865#M173995</link>
      <description>Hi,I have been trying to get Kerberos and LDAP chaining to work using the instructions athttp://wiki.alfresco.com/wiki/Alfresco_Authentication_SubsystemsIn Share, I can log in through the login screen and authenticate against Kerberos users; LDAP synchronization is also working.However, I can't log</description>
      <pubDate>Wed, 05 Aug 2009 17:00:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220865#M173995</guid>
      <dc:creator>doiheartwentyon</dc:creator>
      <dc:date>2009-08-05T17:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220866#M173996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;1. I think you have exposed a problem with the Kerberos authentication subsystem. The http.password indeed should only be relevant when kerberos.authentication.sso.enabled=true but it is trying to validate everything at startup. For now, you will have to work around this by creating the HTTP principal anyway (as you have done). I have logged&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://issues.alfresco.com/jira/browse/ETHREEOH-2617" rel="nofollow noopener noreferrer"&gt;https://issues.alfresco.com/jira/browse/ETHREEOH-2617&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Does any of this help:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.sun.com/thread.jspa?threadID=5250326" rel="nofollow noopener noreferrer"&gt;http://forums.sun.com/thread.jspa?threadID=5250326&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://jhelvoort.wordpress.com/2009/01/02/integrity-check-on-decrypted-field-failed-31/" rel="nofollow noopener noreferrer"&gt;http://jhelvoort.wordpress.com/2009/01/02/integrity-check-on-decrypted-field-failed-31/&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://mailman.mit.edu/pipermail/kerberos/2006-November/010849.html" rel="nofollow noopener noreferrer"&gt;http://mailman.mit.edu/pipermail/kerberos/2006-November/010849.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;3. Good question. It shouldn't and soon won't.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 10:04:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220866#M173996</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-08-06T10:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220867#M173997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;1. I think you have exposed a problem with the Kerberos authentication subsystem. The http.password indeed should only be relevant when kerberos.authentication.sso.enabled=true but it is trying to validate everything at startup. For now, you will have to work around this by creating the HTTP principal anyway (as you have done)&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;OK, good - FYI the same is true of the CIFS principal - I needed to create it even with &lt;/SPAN&gt;&lt;STRONG&gt;kerberos.authentication.authenicateCIFS&lt;/STRONG&gt;&lt;SPAN&gt; set to false.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;2. Does any of this help:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.sun.com/thread.jspa?threadID=5250326" rel="nofollow noopener noreferrer"&gt;http://forums.sun.com/thread.jspa?threadID=5250326&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://jhelvoort.wordpress.com/2009/01/02/integrity-check-on-decrypted-field-failed-31/" rel="nofollow noopener noreferrer"&gt;http://jhelvoort.wordpress.com/2009/01/02/integrity-check-on-decrypted-field-failed-31/&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://mailman.mit.edu/pipermail/kerberos/2006-November/010849.html" rel="nofollow noopener noreferrer"&gt;http://mailman.mit.edu/pipermail/kerberos/2006-November/010849.html&lt;/A&gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;1. No, realm is already in uppercase.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. This poster gets the message from kinit, but I have no problems logging in with kinit (including java kinit)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3. I think this poster had problems with the enctype - I suppose this may be possible, but I haven't found out how I can force JAAS to use a particular one, and surely that would also impact kinit.java ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt; I tried switching from keytab to password and providing this password in the properties file (and the principal in java.login.config). kinit and kinit.java were fine, but no luck with Alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Finally, I get the 'integrity check' message from kinit.java if I supply the wrong password, so I'm now wondering if the keytab file is being misread somehow&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2009 10:41:31 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220867#M173997</guid>
      <dc:creator>doiheartwentyon</dc:creator>
      <dc:date>2009-08-06T10:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220868#M173998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;To followup…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I changed the java.login.config to use my own principal instead of HTTP/server.x.y.z , supplying my password in the properties file, and this worked[1], so I guess it's something on the kerberos side. The only thing I can think of is that for some reason Alfresco needs a user principal not a host principal, but I'm not clear on the difference.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[1] Well, it allowed me to access the Alfresco web client with SSO disabled, at least.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Aug 2009 12:40:55 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220868#M173998</guid>
      <dc:creator>doiheartwentyon</dc:creator>
      <dc:date>2009-08-11T12:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220869#M173999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;FYI a fix has been checked in to HEAD,&amp;nbsp; revision 15729. Here's the change comment:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;ETHREEOH-2617: When SSO is disabled in a subsystem, disable initialization of its filters &lt;BR /&gt;- Do not validate filter configuration parameters in NTLM and Kerberos authentication filters when the filter is disabled&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;FYI there did not appear to be a problem with the CIFS authenticators, which already suppress their initialization when disabled.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Aug 2009 11:53:22 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220869#M173999</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-08-13T11:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220870#M174000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I am able to login with accounts in my Active Directory in the Share webapp, but I can not access the Alfresco webapp:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://imgur.com/U4Jn7.png" rel="nofollow noopener noreferrer"&gt;[img]http://imgur.com/U4Jn7l.png[/img]&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;11:40:57,528 ERROR [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] HTTP Kerberos web filter error&lt;BR /&gt;&lt;BR /&gt;javax.security.auth.login.LoginException: Pre-authentication information was invalid (24)&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Aug 2009 18:58:05 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220870#M174000</guid>
      <dc:creator>dannyboy</dc:creator>
      <dc:date>2009-08-19T18:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220871#M174001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Please let me know if I am not clear. I am not an expert &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Also, though I have Cifs.enabled = false everywhere I can find, I still get the following error when I login via kerberos on the Share app:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;14:59:41,586 ERROR [org.alfresco.web.scripts.AbstractRuntime] Exception from executeScript - redirecting to status template error: Error creating bean with name 'cifsAuthenticator' defined in file [C:\Alfresco\tomcat\webapps\alfresco\WEB-INF\classes\alfresco\subsystems\Authentication\kerberos\kerberos-authentication-context.xml]: Invocation of init method failed; nested exception is org.alfresco.jlan.server.config.InvalidConfigurationException: Failed to login CIFS server service&lt;BR /&gt;org.springframework.beans.factory.BeanCreationException: Error creating bean with name 'cifsAuthenticator' defined in file [C:\Alfresco\tomcat\webapps\alfresco\WEB-INF\classes\alfresco\subsystems\Authentication\kerberos\kerberos-authentication-context.xml]: Invocation of init method failed; nested exception is org.alfresco.jlan.server.config.InvalidConfigurationException: Failed to login CIFS server service&lt;BR /&gt;Caused by: org.alfresco.jlan.server.config.InvalidConfigurationException: Failed to login CIFS server service&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;I thought it wasn't supposed to try Cifs authentication if it is disabled in kerberos-authentication.xml. I have file server disabled as well.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Aug 2009 21:33:05 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220871#M174001</guid>
      <dc:creator>dannyboy</dc:creator>
      <dc:date>2009-08-21T21:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220872#M174002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Did you include this in alfresco-global.properties ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.authenticateCIFS=false&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 09:31:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220872#M174002</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-08-24T09:31:14Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220873#M174003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Did you include this in alfresco-global.properties ?&lt;BR /&gt;&lt;BR /&gt;kerberos.authentication.authenticateCIFS=false&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for the reply! &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I already had 'kerberos.authentication.authenticateCIFS=false' in my kerberos authentication properties file, but to humor the point I added it to alfresco global properties as well. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I still get the same error:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;10:39:32,347 ERROR [org.alfresco.web.scripts.AbstractRuntime] Exception from executeScript - redirecting to status template error: Error creating bean with name 'cifsAuthenticator' defined in file [C:\Alfresco\tomcat\webapps\alfresco\WEB-INF\classes\alfresco\subsystems\Authentication\kerberos\kerberos-authentication-context.xml]: Invocation of init method failed; nested exception is org.alfresco.jlan.server.config.InvalidConfigurationException: Failed to login CIFS server service&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Regardless, I am more concerened about not being able to login into the alfresco webapp when kerberos authentication is enabled, as you can see from my screenshot 3 posts up.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 15:44:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220873#M174003</guid>
      <dc:creator>dannyboy</dc:creator>
      <dc:date>2009-08-24T15:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220874#M174004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;You need to understand how to control subsystem properties rather than randomly editing different files.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I've just double-checked the configuration and think I have found the problem. I will re-open the bug and ensure that it is fixed in HEAD.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It's this line in network-protocol-context.xml&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;&amp;lt;!– CIFS authentication –&amp;gt;&lt;BR /&gt;&amp;lt;bean id="cifsAuthenticatorBase" abstract="true" init-method="initialize"&amp;gt;&lt;BR /&gt;…&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Even though CifsAuthenticatorBase implements InitializingBean, initialize() has been declared as the init-method. This means that the logic that only calls initialize() when the active flag is set will be bypassed.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;A workaround is to put the following in $TOMCAT_HOME/shared/classes/alfresco/extension/temp-context.xml&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&amp;lt;?xml version='1.0' encoding='UTF-8'?&amp;gt;&lt;BR /&gt;&amp;lt;!DOCTYPE beans PUBLIC '-//SPRING//DTD BEAN//EN' '&lt;A href="http://www.springframework.org/dtd/spring-beans.dtd" rel="nofollow noopener noreferrer"&gt;http://www.springframework.org/dtd/spring-beans.dtd&lt;/A&gt;'&amp;gt;&lt;BR /&gt; &lt;BR /&gt;&amp;lt;beans&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!– Fix initialization of CIFS authenticators –&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;bean id="cifsAuthenticatorBase" abstract="true"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="config"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ref bean="fileServerConfiguration" /&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="authenticationService"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ref bean="authenticationService" /&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="authenticationComponent"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ref bean="authenticationComponent" /&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="nodeService"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ref bean="NodeService" /&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="personService"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ref bean="personService" /&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="transactionService"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ref bean="transactionService" /&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="authorityService"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ref bean="authorityService" /&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;property name="diskInterface"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ref bean="contentDiskDriver" /&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/bean&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;lt;/beans&amp;gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Aug 2009 10:54:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220874#M174004</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-08-25T10:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220875#M174005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;This is now fixed in HEAD.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Aug 2009 12:14:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220875#M174005</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-08-25T12:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220876#M174006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thank you for your time and patience. I will confess that after changing kerberos authentication properties and the error persisted I declared war on all things cifs in /alfresco. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I followed your instructions but there was a "The processing instruction target matching "[xX][mM][lL]" error when importing the file. It had to do with whitespace in the file, I think it was a formatting problem when copying it over. Anyways, deleted the whitespace and it imported and ran fine.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I no longer get the "Failed to login CIFS server service" error when each time I login with an AD account. Good catch!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I still receive the following error when trying to access the Alfresco webapp. The problem in the screenshot I posted a while back still happens. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;11:40:57,528 ERROR [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] HTTP Kerberos web filter error&lt;BR /&gt;&lt;BR /&gt;javax.security.auth.login.LoginException: Pre-authentication information was invalid (24)"&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Does this mean that I am doing something wrong? Did I setup my keytab incorrectly or something? However, I am able to login with AD accounts just fine…&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Aug 2009 16:19:29 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220876#M174006</guid>
      <dc:creator>dannyboy</dc:creator>
      <dc:date>2009-08-25T16:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220877#M174007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I don't understand. The screenshot is of the HTTP service login problem, which was fixed by&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://issues.alfresco.com/jira/browse/ETHREEOH-2617" rel="nofollow noopener noreferrer"&gt;https://issues.alfresco.com/jira/browse/ETHREEOH-2617&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Aren't you running with a recent 3.3 build?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;As for the other error, what do you mean by "I am able to login with AD accounts just fine". What are you trying to log in with then?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If you are trying to log in as an internal Alfresco user, such as admin, you will need alfrescoNtlm in your authentication chain.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If this explains the problem, but you are still getting a nast exception on your screen when you enter an invalid password, there is still a bug somewhere.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm hoping to set up a Kerberos system soon so that I can investigate properly.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Aug 2009 16:34:11 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220877#M174007</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-08-25T16:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220878#M174008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Sorry for being unclear.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am running Alfresco 3.2 but will download the latest build now. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am able to login to the Share webapp with Active Directory user-names. The user is then auto-created inside of Alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now, when I try to access the Alfresco webapp, the screenshot error occurs. I never see the login screen… nothing except for that screenshot. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So it probably is this SSO bug, I will try it out on the new build.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Edit: Tried it in 3.3&lt;/STRONG&gt;&lt;SPAN&gt; and the same error occurs. I really think it might be I misconfigured kerberos, though I can use the Share webapp just fine.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Aug 2009 16:53:16 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220878#M174008</guid>
      <dc:creator>dannyboy</dc:creator>
      <dc:date>2009-08-25T16:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos difficulties</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220879#M174009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Did you build from HEAD? It does work, I promise!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I've managed to set up Kerberos on a VM and I think I've resolved the problem with the CIFS and HTTP service principals.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;See this bug comment &lt;/SPAN&gt;&lt;A href="https://issues.alfresco.com/jira/browse/ETHREEOH-425?focusedCommentId=29595&amp;amp;page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel#action_29595" rel="nofollow noopener noreferrer"&gt;https://issues.alfresco.com/jira/browse/ETHREEOH-425?focusedCommentId=29595&amp;amp;page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel#action_29595&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It seems that if you did change the accounts to use DES encryption,&amp;nbsp; you would have to reset the passwords, as otherwise they are not cached with DES encryption.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;And for Java 6, you can use RC4-HMAC-NT encryption instead. So the new ktpass commands are the following (after deselecting the use DES encryption option and resetting the password on both accounts). I've updated the wiki.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ktpass -princ cifs/&amp;lt;cifs-server-name&amp;gt;.&amp;lt;domain&amp;gt;@&amp;lt;realm&amp;gt; -pass &amp;lt;password&amp;gt; -mapuser &amp;lt;domainnetbios&amp;gt;\alfrescocifs -crypto RC4-HMAC-NT -ptype KRB5_NT_PRINCIPAL -out c:\temp\alfrescocifs.keytab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ktpass -princ HTTP/&amp;lt;web-server-name&amp;gt;.&amp;lt;domain&amp;gt;@&amp;lt;realm&amp;gt; -pass &amp;lt;password&amp;gt; -mapuser &amp;lt;domainnetbios&amp;gt;\alfrescohttp -crypto RC4-HMAC-NT -ptype KRB5_NT_PRINCIPAL -out c:\temp\alfrescohttp.keytab&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Aug 2009 12:45:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-difficulties/m-p/220879#M174009</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2009-08-26T12:45:30Z</dc:date>
    </item>
  </channel>
</rss>

