<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Kerberos SSO (against AD) sometimes fails on Share (4.0.d) in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-against-ad-sometimes-fails-on-share-4-0-d/m-p/279597#M232727</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I've recently implemented Kerberos SSO on both CIFS and Share. At first glance everything looks fine, it works smooth.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Until later durring the day, when users starts to be prompted for passwords.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;My first instinct is that we're dealing with expired Kerberos tickets. Enabling debugging, yup, it seems so:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;Found ticket for OLEH@MYDOMAIN.LOCAL to go to HTTP/alfresco.local@DOMAIN.LOCAL expiring on Fri May 17 03:47:56 WGST 2013&lt;BR /&gt;04:52:06,730&amp;nbsp; DEBUG [site.servlet.SSOAuthenticationFilter] Kerberos logon error&lt;BR /&gt;java.lang.IllegalStateException: This ticket is no longer valid&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I restart my borwser and get issued a new ticket and everything is good.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;After this I check my ticket with klist. I have a nice valid and renewable ticket that lasts for 10 hours.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1-5 hours later (random, no system in the timeframe) I experience EXACTLY the same thing. Login prompt (windows login, not Share login page). Verify the ticket, it's still valid. I restart the browser and we're good to go again.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;However, from the logs it does not say that my ticket is no longer valid, it says:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;&lt;BR /&gt;Search Subject for Kerberos V5 ACCEPT cred (HTTP/alfresco.DOMAIN.LOCAL@DOMAIN.LOCAL, sun.security.jgss.krb5.Krb5AcceptCredential)&lt;BR /&gt;Found key for HTTP/alfresco.DOMAIN.LOCAL@DOMAIN.LOCAL(23)&lt;BR /&gt;Entered Krb5Context.acceptSecContext with state=STATE_NEW&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; EType: sun.security.krb5.internal.crypto.ArcFourHmacEType&lt;BR /&gt;Using builtin default etypes for permitted_enctypes&lt;BR /&gt;default etypes for permitted_enctypes: 3 1 23 16 17 18.&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; EType: sun.security.krb5.internal.crypto.ArcFourHmacEType&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; Config reset default kdc DOMAIN.LOCAL&lt;BR /&gt;replay cache for oleh@DOMAIN.LOCAL is null.&lt;BR /&gt;object 0: 1368700723000/198&lt;BR /&gt;object 0: 1368700723000/198&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; KrbApReq: authenticate succeed.&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; EType: sun.security.krb5.internal.crypto.ArcFourHmacEType&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt;Delegated Creds have pname=oleh@DOMAIN.LOCAL sname=krbtgt/DOMAIN.LOCAL@DOMAIN.LOCAL authtime=null starttime=20130516102536Z endtime=20130516202533ZrenewTill=2013052310253&lt;BR /&gt;3Z&lt;BR /&gt;Krb5Context setting peerSeqNumber to: 145069278&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; EType: sun.security.krb5.internal.crypto.ArcFourHmacEType&lt;BR /&gt;Krb5Context setting mySeqNumber to: 607740720&lt;BR /&gt;Entered Krb5Context.initSecContext with state=STATE_NEW&lt;BR /&gt;&lt;BR /&gt;Found ticket for HTTP/alfresco.DOMAIN.LOCAL@DOMAIN.LOCAL to go to krbtgt/DOMAIN.LOCAL@DOMAIN.LOCAL expiring on Thu May 16 15:49:24 WGST 2013&lt;BR /&gt;Found ticket for OLEH@DOMAIN.LOCAL to go to HTTP/alfresco.DOMAIN.LOCAL@DOMAIN.LOCAL expiring on Thu May 16 15:16:15 WGST 2013&lt;BR /&gt;&lt;BR /&gt;Service ticket not found in the subject&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; Credentials acquireServiceCreds: same realm&lt;BR /&gt;default etypes for default_tgs_enctypes: 23.&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; CksumType: sun.security.krb5.internal.crypto.RsaMd5CksumType&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; EType: sun.security.krb5.internal.crypto.ArcFourHmacEType&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; KrbKdcReq send: kdc=10.66.60.20 UDP:88, timeout=30000, number of retries =3, #bytes=1627&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; KDCCommunication: kdc=10.66.60.20 UDP:88, timeout=30000,Attempt =1, #bytes=1627&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; KrbKdcReq send: #bytes read=116&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; KrbKdcReq send: #bytes read=116&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; KDCRep: init() encoding tag is 126 req type is 13&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt;KRBError:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sTime is Thu May 16 08:38:43 WGST 2013 1368700723000&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; suSec is 284507&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; error code is 52&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; error Message is Response too big for UDP, retry with TCP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; realm is DOMAIN.LOCAL&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sname is HTTP/alfresco.DOMAIN.LOCAL&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; msgType is 30&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; KrbKdcReq send: kdc=10.66.60.20 TCP:88, timeout=30000, number of retries =3, #bytes=1621&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt;DEBUG: TCPClient reading 1578 bytes&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; KrbKdcReq send: #bytes read=1578&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; KrbKdcReq send: #bytes read=1578&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; EType: sun.security.krb5.internal.crypto.ArcFourHmacEType&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; EType: sun.security.krb5.internal.crypto.ArcFourHmacEType&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; KrbApReq: APOptions are 00100000 00000000 00000000 00000000&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt; EType: sun.security.krb5.internal.crypto.ArcFourHmacEType&lt;BR /&gt;Krb5Context setting mySeqNumber to: 857087925&lt;BR /&gt;Created InitSecContextToken:&lt;BR /&gt;0000: 01 00 6E 82 0C 14 30 82&amp;nbsp;&amp;nbsp; 0C 10 A0 03 02 01 05 A1&amp;nbsp; ..n…0………&lt;BR /&gt;0010: 03 02 01 0E A2 07 03 05&amp;nbsp;&amp;nbsp; 00 20 00 00 00 A3 82 04&amp;nbsp; ……… ……&lt;BR /&gt;0020: FB 61 82 04 F7 30 82 04&amp;nbsp;&amp;nbsp; F3 A0 03 02 01 05 A1 15&amp;nbsp; .a…0……….&lt;BR /&gt;0030: 1B 13 4E 55 4B 49 53 53&amp;nbsp;&amp;nbsp; 49 4F 52 46 49 49 54 2E&amp;nbsp; ..DOMAIN.&lt;BR /&gt;0040: 49 4E 54 52 41 A2 2E 30&amp;nbsp;&amp;nbsp; 2C A0 03 02 01 00 A1 25&amp;nbsp; INTRA..0,……%&lt;BR /&gt;0050: 30 23 1B 04 48 54 54 50&amp;nbsp;&amp;nbsp; 1B 1B 6E 75 6B 69 64 6F&amp;nbsp; 0#..HTTP..alfresc&lt;BR /&gt;0060: 63 2E 6E 75 6B 69 73 73&amp;nbsp;&amp;nbsp; 69 6F 72 66 69 69 74 2E&amp;nbsp; o.DOMAIN.&lt;BR /&gt;0070: 69 6E 74 72 61 A3 82 04&amp;nbsp;&amp;nbsp; A3 30 82 04 9F A0 03 02&amp;nbsp; local….0……&lt;BR /&gt;0080: 01 17 A1 03 02 01 0E A2&amp;nbsp;&amp;nbsp; 82 04 91 04 82 04 8D F7&amp;nbsp; …………….&lt;BR /&gt;0090: 22 0C A3 CB 00 21 0F 90&amp;nbsp;&amp;nbsp; 81 A9 9B 5E 1E 43 CD 36&amp;nbsp; "….!…..^.C.6&lt;BR /&gt;00A0: 33 F0 93 EC E8 5D E0 55&amp;nbsp;&amp;nbsp; AA 7F A5 AE 34 5E 4F 98&amp;nbsp; 3….].U….4^O.&lt;BR /&gt;00B0: F2 EB 80 5C 56 23 D8 3F&amp;nbsp;&amp;nbsp; CF 9F EA 0D 8B 2C E7 73&amp;nbsp; …\V#.?…..,.s&lt;BR /&gt;00C0: E4 F5 BB 06 84 56 DA D4&amp;nbsp;&amp;nbsp; 25 EE D4 A8 F0 D4 C5 29&amp;nbsp; …..V..%……)&lt;BR /&gt;00D0: 6A 32 2C DD A0 50 1B DD&amp;nbsp;&amp;nbsp; 14 78 CA 98 9B AD 34 B0&amp;nbsp; j2,..P…x….4.&lt;BR /&gt;00E0: AF 87 E4 A6 47 BF FF E1&amp;nbsp;&amp;nbsp; EA 14 6A B8 C8 BC D9 EA&amp;nbsp; ….G…..j…..&lt;BR /&gt;[a lot more hex code]&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What could cause this? &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I checked time on the servers and they were NOT in sync. I setup NTP and now they are, but the problem still persists.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I also experience that I have to restart Share every 10 hours, after the Kerberos ticket for my AlfrescoHTTP expires,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;it can't renew it. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It only seems to be a problem with Share. Alfresco explorer and CIFS works just fine.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any pointers could be most welcome!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;More details about my setup:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Alfresco 4.0.d&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Win 2008 r2 server (AD)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Alfresco config:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;kerberos.authentication.realm=DOMAIN.LOCAL&lt;BR /&gt;kerberos.authentication.sso.enabled=true&lt;BR /&gt;kerberos.authentication.authenticateCIFS=true&lt;BR /&gt;kerberos.authentication.user.configEntryName=Alfresco&lt;BR /&gt;kerberos.authentication.cifs.configEntryName=AlfrescoCIFS&lt;BR /&gt;kerberos.authentication.http.configEntryName=AlfrescoHTTP&lt;BR /&gt;kerberos.authentication.stripUsernameSuffix=true&lt;BR /&gt;kerberos.authentication.cifs.password=[pass]&lt;BR /&gt;kerberos.authentication.http.password=[pass]&lt;BR /&gt;kerberos.authentication.defaultAdministratorUserNames=oleh&lt;BR /&gt;authentication.chain=kerberos1:kerberos,ldap1:ldap&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;share-config-custom.xml:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;lt;config evaluator="string-compare" condition="Kerberos" replace="true"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;kerberos&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;password&amp;gt;[pass]&amp;lt;/password&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;realm&amp;gt;DOMAIN.LOCAL&amp;lt;/realm&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;endpoint-spn&amp;gt;HTTP/alfresco.domain.local@DOMAIN.LOCAL&amp;lt;/endpoint-spn&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;config-entry&amp;gt;ShareHTTP&amp;lt;/config-entry&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/kerberos&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;lt;/config&amp;gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 May 2013 08:02:34 GMT</pubDate>
    <dc:creator>oleh</dc:creator>
    <dc:date>2013-05-17T08:02:34Z</dc:date>
    <item>
      <title>Kerberos SSO (against AD) sometimes fails on Share (4.0.d)</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-against-ad-sometimes-fails-on-share-4-0-d/m-p/279597#M232727</link>
      <description>I've recently implemented Kerberos SSO on both CIFS and Share. At first glance everything looks fine, it works smooth.Until later durring the day, when users starts to be prompted for passwords.My first instinct is that we're dealing with expired Kerberos tickets. Enabling debugging, yup, it seems s</description>
      <pubDate>Fri, 17 May 2013 08:02:34 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-against-ad-sometimes-fails-on-share-4-0-d/m-p/279597#M232727</guid>
      <dc:creator>oleh</dc:creator>
      <dc:date>2013-05-17T08:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO (against AD) sometimes fails on Share (4.0.d)</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-against-ad-sometimes-fails-on-share-4-0-d/m-p/279598#M232728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there anyone who has solved this problem?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Mar 2019 09:57:19 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-against-ad-sometimes-fails-on-share-4-0-d/m-p/279598#M232728</guid>
      <dc:creator>mvlcek</dc:creator>
      <dc:date>2019-03-25T09:57:19Z</dc:date>
    </item>
  </channel>
</rss>

