<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Kerberos: Share fails to renew/refresh ticket in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-share-fails-to-renew-refresh-ticket/m-p/286858#M239988</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;We're currently having trouble with Share, we need to restart it every 10 hours.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Our setup:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Alfresco 4.0.d (community) running on Ubuntu 12.04&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Windows 2008R2 AD&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Kerberos SSO&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Windows 7 client, IE9&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Everything works fine on the Alfresco side. Alfresco Explorer and CIFS is just fine, but as soon as Share has been running for 10 hours (default ticket life time in AD) we're unable to log in. First we'll be prompted with a browser login, then windows login and after that the Share login form. If I reload the page and enter my password a couple of times it will eventually let me in and we can run for another 10 hours.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If I restart Share I get straight in after it comes up. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Is this a common issue? For me it seems Share should be able to renew the TGT?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I get this exception in the logs:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;&lt;BR /&gt;13:55:18,443&amp;nbsp; DEBUG [site.servlet.SSOAuthenticationFilter] Kerberos logon error&lt;BR /&gt;java.lang.IllegalStateException: This ticket is no longer valid&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at javax.security.auth.kerberos.KerberosTicket.toString(KerberosTicket.java:638)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.lang.String.valueOf(String.java:2854)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.lang.StringBuilder.append(StringBuilder.java:128)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.jgss.krb5.SubjectComber.findAux(SubjectComber.java:150)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.jgss.krb5.SubjectComber.find(SubjectComber.java:59)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.jgss.krb5.Krb5Util.getTicket(Krb5Util.java:155)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.jgss.krb5.Krb5Context$1.run(Krb5Context.java:606)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.jgss.krb5.Krb5Context$1.run(Krb5Context.java:599)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.security.AccessController.doPrivileged(Native Method)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.jgss.krb5.Krb5Context.initSecContext(Krb5Context.java:598)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.jgss.GSSContextImpl.initSecContext(GSSContextImpl.java:248)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.jgss.GSSContextImpl.initSecContext(GSSContextImpl.java:179)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.web.site.servlet.KerberosSessionSetupPrivilegedAction.run(KerberosSessionSetupPrivilegedAction.java:127)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.web.site.servlet.KerberosSessionSetupPrivilegedAction.run(KerberosSessionSetupPrivilegedAction.java:44)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.security.AccessController.doPrivileged(Native Method)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at javax.security.auth.Subject.doAs(Subject.java:356)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.web.site.servlet.SSOAuthenticationFilter.doKerberosLogon(SSOAuthenticationFilter.java:1009)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.web.site.servlet.SSOAuthenticationFilter.doFilter(SSOAuthenticationFilter.java:441)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.servlet.ServletHandler$CachedChain.doFilter(ServletHandler.java:1326)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.servlet.ServletHandler.doHandle(ServletHandler.java:479)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:119)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.security.SecurityHandler.handle(SecurityHandler.java:520)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.session.SessionHandler.doHandle(SessionHandler.java:227)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.handler.ContextHandler.doHandle(ContextHandler.java:940)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.servlet.ServletHandler.doScope(ServletHandler.java:409)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.session.SessionHandler.doScope(SessionHandler.java:186)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.handler.ContextHandler.doScope(ContextHandler.java:874)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:117)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.handler.ContextHandlerCollection.handle(ContextHandlerCollection.java:250)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.handler.HandlerCollection.handle(HandlerCollection.java:149)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.handler.HandlerWrapper.handle(HandlerWrapper.java:110)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.Server.handle(Server.java:349)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.HttpConnection.handleRequest(HttpConnection.java:441)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.HttpConnection$RequestHandler.headerComplete(HttpConnection.java:904)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.http.HttpParser.parseNext(HttpParser.java:565)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.http.HttpParser.parseAvailable(HttpParser.java:217)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.server.AsyncHttpConnection.handle(AsyncHttpConnection.java:46)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.io.nio.SelectChannelEndPoint.handle(SelectChannelEndPoint.java:545)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.io.nio.SelectChannelEndPoint$1.run(SelectChannelEndPoint.java:43)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.util.thread.QueuedThreadPool.runJob(QueuedThreadPool.java:598)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.eclipse.jetty.util.thread.QueuedThreadPool$3.run(QueuedThreadPool.java:533)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.lang.Thread.run(Thread.java:722)&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any info or pointers will be very welcome!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Some setup info:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;share-config-custom.xml:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;lt;config evaluator="string-compare" condition="Kerberos" replace="true"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;kerberos&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;password&amp;gt;password&amp;lt;/password&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;realm&amp;gt;DOMAIN.LOCAL&amp;lt;/realm&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;endpoint-spn&amp;gt;HTTP/alfresco.domain.local@DOMAIN.LOCAL&amp;lt;/endpoint-spn&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;config-entry&amp;gt;ShareHTTP&amp;lt;/config-entry&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/kerberos&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;lt;/config&amp;gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Jun 2013 12:16:23 GMT</pubDate>
    <dc:creator>oleh</dc:creator>
    <dc:date>2013-06-05T12:16:23Z</dc:date>
    <item>
      <title>Kerberos: Share fails to renew/refresh ticket</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-share-fails-to-renew-refresh-ticket/m-p/286858#M239988</link>
      <description>We're currently having trouble with Share, we need to restart it every 10 hours.Our setup:Alfresco 4.0.d (community) running on Ubuntu 12.04Windows 2008R2 ADKerberos SSOWindows 7 client, IE9Everything works fine on the Alfresco side. Alfresco Explorer and CIFS is just fine, but as soon as Share has</description>
      <pubDate>Wed, 05 Jun 2013 12:16:23 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-share-fails-to-renew-refresh-ticket/m-p/286858#M239988</guid>
      <dc:creator>oleh</dc:creator>
      <dc:date>2013-06-05T12:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos: Share fails to renew/refresh ticket</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-share-fails-to-renew-refresh-ticket/m-p/286859#M239989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any update here? Same is happening to us.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Oct 2014 06:25:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-share-fails-to-renew-refresh-ticket/m-p/286859#M239989</guid>
      <dc:creator>jspuchau</dc:creator>
      <dc:date>2014-10-23T06:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos: Share fails to renew/refresh ticket</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-share-fails-to-renew-refresh-ticket/m-p/286860#M239990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This post came up again (see&amp;nbsp;&lt;A href="https://issues.alfresco.com/jira/browse/ALF-21938" rel="nofollow noopener noreferrer"&gt;ALF-21938&lt;/A&gt;). Talking to the team, we are confident it is a misconfiguration on the Active Directory side, rather than with the Alfresco product.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From&amp;nbsp;Ole Hejlskov: If memory serves me correct . . .&amp;nbsp;it was the issue with time sync. We had an issue back in the day where the AD was syncing with a different ntp server than the repo did. We ended up syncing everything with the AD server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 13:20:24 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-share-fails-to-renew-refresh-ticket/m-p/286860#M239990</guid>
      <dc:creator>resplin</dc:creator>
      <dc:date>2017-08-30T13:20:24Z</dc:date>
    </item>
  </channel>
</rss>

