<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Kerberos setup with cluster and load balancer in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-setup-with-cluster-and-load-balancer/m-p/284078#M237208</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Loftux, &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Have you seen anything to make you think that Apache is not forwarding on the Kerberos ticket?&amp;nbsp; Generally the Kerberos ticket is included in the request from a client in the "Authentication" header, as part of a GSSAPI token, so I don't know if there's anything in Apache that strips this - I assume you're not using auth_mod_kerb since you want Alfresco to do the authentication?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Do you know if you can authenticate with the Alfresco Explorer app using SSO through Apache?&amp;nbsp; I just ask because Share delegates back to Alfresco for Kerrberos authentication and that extra layer of complexity can often have its own issues.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'd be very interested in if you find a solution for this as I'm in a similar situation currently as well (using hardware load balancer instead of Apache), looking into how we can get&amp;nbsp; SSO to work properly through the load balancer.&amp;nbsp; Similarly we had successfully tested in single server environments and in clustered environments going directly to the server, but we're still having issues with SSO through the balancer.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have a hunch that our problem at least is to do with aligning the SPNs &amp;amp; associated keytabs on both hosts with the name of the load balanced service rather than the host names, but I'm not sure.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Steven&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Sep 2015 15:36:03 GMT</pubDate>
    <dc:creator>steven_okennedy</dc:creator>
    <dc:date>2015-09-01T15:36:03Z</dc:date>
    <item>
      <title>Kerberos setup with cluster and load balancer</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-setup-with-cluster-and-load-balancer/m-p/284077#M237207</link>
      <description>I'm setting up a 4.2.4 cluster with two nodes (node1.example.comn, node2.example.com). Each have alfresco and share running.Users access an apache front-end that acts as a load balancer (alfresco.example.com) using Apache.The goal is to have users SSO when accessing the loadbalancer.I've been able t</description>
      <pubDate>Wed, 10 Jun 2015 08:45:51 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-setup-with-cluster-and-load-balancer/m-p/284077#M237207</guid>
      <dc:creator>loftux</dc:creator>
      <dc:date>2015-06-10T08:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos setup with cluster and load balancer</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-setup-with-cluster-and-load-balancer/m-p/284078#M237208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Loftux, &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Have you seen anything to make you think that Apache is not forwarding on the Kerberos ticket?&amp;nbsp; Generally the Kerberos ticket is included in the request from a client in the "Authentication" header, as part of a GSSAPI token, so I don't know if there's anything in Apache that strips this - I assume you're not using auth_mod_kerb since you want Alfresco to do the authentication?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Do you know if you can authenticate with the Alfresco Explorer app using SSO through Apache?&amp;nbsp; I just ask because Share delegates back to Alfresco for Kerrberos authentication and that extra layer of complexity can often have its own issues.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'd be very interested in if you find a solution for this as I'm in a similar situation currently as well (using hardware load balancer instead of Apache), looking into how we can get&amp;nbsp; SSO to work properly through the load balancer.&amp;nbsp; Similarly we had successfully tested in single server environments and in clustered environments going directly to the server, but we're still having issues with SSO through the balancer.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have a hunch that our problem at least is to do with aligning the SPNs &amp;amp; associated keytabs on both hosts with the name of the load balanced service rather than the host names, but I'm not sure.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Steven&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Sep 2015 15:36:03 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-setup-with-cluster-and-load-balancer/m-p/284078#M237208</guid>
      <dc:creator>steven_okennedy</dc:creator>
      <dc:date>2015-09-01T15:36:03Z</dc:date>
    </item>
  </channel>
</rss>

