<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSO doesn't work with reverse proxy in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/sso-doesn-t-work-with-reverse-proxy/m-p/287342#M240472</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi all!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I use Alfresco 4.2.2 Enterprice on a Linux platform.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have setup SSO via: &lt;/SPAN&gt;&lt;A href="http://docs.alfresco.com/4.2/tasks/auth-kerberos-ADconfig.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/4.2/tasks/auth-kerberos-ADconfig.html&lt;/A&gt;&lt;SPAN&gt; it works fine. But, I need to setup a reverse proxy (I use nginx). It works too, but SSO.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;PLEASE read my logs and sheme, I'd like if you help me.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So, I have the following scheme:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Webbrowser (Firefox) -&amp;gt; &lt;/SPAN&gt;&lt;A href="https://portal.company.ru" rel="nofollow noopener noreferrer"&gt;https://portal.company.ru&lt;/A&gt;&lt;SPAN&gt; (server A with nginx as a reverse proxy) -&amp;gt; &lt;/SPAN&gt;&lt;A href="http://alfresco-prd.company.local:8080" rel="nofollow noopener noreferrer"&gt;http://alfresco-prd.company.local:8080&lt;/A&gt;&lt;SPAN&gt; (alfresco local server)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So, if I connect to alfresco without server A, I have success, but when I use nginx I have fail… &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://connect.hyland.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please read my logs:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;2014-07-17 09:48:03,169&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-bio-8080-exec-2] New Kerberos auth request from 192.168.9.2 (192.168.9.2:50938)&lt;BR /&gt; 2014-07-17 09:48:03,169&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-bio-8080-exec-2] Issuing login challenge to browser.&lt;BR /&gt; 2014-07-17 09:48:03,216&amp;nbsp; ERROR [org.alfresco.fileserver] [http-bio-8080-exec-3] Error from JLAN&lt;BR /&gt; GSSException: Failure unspecified at GSS-API level (Mechanism level: Checksum failed)&lt;BR /&gt;….&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.lang.Thread.run(Thread.java:722)&lt;BR /&gt;Caused by: KrbException: Checksum failed&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.krb5.internal.crypto.ArcFourHmacEType.decrypt(ArcFourHmacEType.java:102)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.krb5.internal.crypto.ArcFourHmacEType.decrypt(ArcFourHmacEType.java:94)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.krb5.EncryptedData.decrypt(EncryptedData.java:177)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.krb5.KrbApReq.authenticate(KrbApReq.java:278)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.krb5.KrbApReq.&amp;lt;init&amp;gt;(KrbApReq.java:144)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.jgss.krb5.InitSecContextToken.&amp;lt;init&amp;gt;(InitSecContextToken.java:108)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.jgss.krb5.Krb5Context.acceptSecContext(Krb5Context.java:771)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;… 36 more&lt;BR /&gt;Caused by: java.security.GeneralSecurityException: Checksum failed&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.krb5.internal.crypto.dk.ArcFourCrypto.decrypt(ArcFourCrypto.java:408)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.krb5.internal.crypto.ArcFourHmac.decrypt(ArcFourHmac.java:91)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.security.krb5.internal.crypto.ArcFourHmacEType.decrypt(ArcFourHmacEType.java:100)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;… 42 more&lt;BR /&gt;2014-07-17 09:48:03,217&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-bio-8080-exec-3] No SPNEGO response, Kerberos logon failed&lt;BR /&gt; 2014-07-17 09:48:03,218&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-bio-8080-exec-3] Failed SPNEGO authentication.&lt;BR /&gt; 2014-07-17 09:48:03,218&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-bio-8080-exec-3] Clearing session.&lt;BR /&gt; 2014-07-17 09:48:03,218&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-bio-8080-exec-3] Issuing login challenge to browser.&lt;BR /&gt; 2014-07-17 09:48:03,267&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-bio-8080-exec-4] Login page requested, chaining …&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have the following ngnix conf:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;root@gateway:~# cat /etc/nginx/conf.d-backup/alfresco.conf&lt;BR /&gt;proxy_cache_path /var/cache/nginx/alfresco levels=1 keys_zone=alfrescocache:256m max_size=512m inactive=1440m;&lt;BR /&gt;&lt;BR /&gt;upstream alfresco {&lt;BR /&gt; server alfresco-prd.company.local:8080;&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;upstream sharepoint {&lt;BR /&gt; server alfresco-prd.company.local:7071;&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;server {&lt;BR /&gt; listen 80 ;&lt;BR /&gt; server_name portal.company.ru &lt;A href="http://www.portal.company.ru" rel="nofollow noopener noreferrer"&gt;www.portal.company.ru&lt;/A&gt;&lt;BR /&gt; server_name_in_redirect off;&lt;BR /&gt; rewrite ^ &lt;A href="https://$host$request_uri" rel="nofollow noopener noreferrer"&gt;https://$host$request_uri&lt;/A&gt;? permanent;&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;server {&lt;BR /&gt; listen 443 ssl;&lt;BR /&gt; server_name portal.company.ru &lt;A href="http://www.portal.company.ru" rel="nofollow noopener noreferrer"&gt;www.portal.company.ru&lt;/A&gt;;&lt;BR /&gt; root /etc/nginx/conf.d/alfresco;&lt;BR /&gt; index index.html index.htm;&lt;BR /&gt; rewrite ^/$ /share;&lt;BR /&gt;&lt;BR /&gt; ssl on;&lt;BR /&gt; ssl_certificate /etc/nginx/conf.d/alfresco/alfserver.crt;&lt;BR /&gt; ssl_certificate_key /etc/nginx/conf.d/alfresco/alfserver.key;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;location /robots.txt {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; alias /etc/nginx/conf.d/alfresco/robots.txt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;location / {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;try_files $uri $uri/ /index.html;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;&lt;BR /&gt; error_page 502 503 504 /maintenance.html;&lt;BR /&gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;location = /maintenance.html {&lt;BR /&gt; &amp;nbsp;&amp;nbsp;&amp;nbsp;root /etc/nginx/conf.d/alfresco;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;location /alfresco {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;client_max_body_size 0;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_http_version 1.1;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header Host $http_host;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_pass &lt;A href="http://alfresco" rel="nofollow noopener noreferrer"&gt;http://alfresco&lt;/A&gt;;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Real-IP $remote_addr;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Forwarded-Server $host;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;location /share {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;client_max_body_size 0;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_http_version 1.1;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_pass &lt;A href="http://alfresco" rel="nofollow noopener noreferrer"&gt;http://alfresco&lt;/A&gt;;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header Host $http_host;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Real-IP $remote_addr;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Forwarded-Server $host;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;location /share/proxy/alfresco {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;client_max_body_size 0;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_http_version 1.1;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_pass &lt;A href="http://alfresco" rel="nofollow noopener noreferrer"&gt;http://alfresco&lt;/A&gt;;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header Host $http_host;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Real-IP $remote_addr;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Forwarded-Host $http_host;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Forwarded-Server $host;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_intercept_errors on;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;error_page 502 503 504 =401 /maintenance.html;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;location /share/res/ {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_http_version 1.1;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_pass &lt;A href="http://alfresco" rel="nofollow noopener noreferrer"&gt;http://alfresco&lt;/A&gt;;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header Host $http_host;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_cache alfrescocache;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_cache_min_uses 1;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_cache_valid 200 302 1440m;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_cache_valid 404 1m;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_cache_use_stale updating error timeout invalid_header http_500 http_502 http_503 http_504;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;server {&lt;BR /&gt; listen 7070 ssl;&lt;BR /&gt; server_name portal.company.ru;&lt;BR /&gt; ssl on;&lt;BR /&gt; ssl_certificate /etc/nginx/conf.d/alfresco/alfserver.crt;&lt;BR /&gt; ssl_certificate_key /etc/nginx/conf.d/alfresco/alfserver.key;&lt;BR /&gt; ssl_session_timeout 5m;&lt;BR /&gt; ssl_protocols SSLv2 SSLv3 TLSv1;&lt;BR /&gt; ssl_ciphers HIGH:!aNULL:!MD5;&lt;BR /&gt; ssl_prefer_server_ciphers on;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;location / {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;client_max_body_size 0;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_http_version 1.1;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_buffering off;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_pass &lt;A href="http://sharepoint" rel="nofollow noopener noreferrer"&gt;http://sharepoint&lt;/A&gt;;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header Host $http_host;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Real-IP $remote_addr;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Forwarded-Host $http_host;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxy_set_header X-Forwarded-Server $host;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;BR /&gt;}&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I think it is bad because I rewrite hostname during in reverse proxy…&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have setup different SPN in kerberos: portal.company.ru alfresco-prd.company.local without success. &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://connect.hyland.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Is it possible to use reverse proxy with alfresco and SSO?&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Jul 2014 06:50:44 GMT</pubDate>
    <dc:creator>vgusev2007</dc:creator>
    <dc:date>2014-07-17T06:50:44Z</dc:date>
    <item>
      <title>SSO doesn't work with reverse proxy</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-doesn-t-work-with-reverse-proxy/m-p/287342#M240472</link>
      <description>Hi all!I use Alfresco 4.2.2 Enterprice on a Linux platform.I have setup SSO via: http://docs.alfresco.com/4.2/tasks/auth-kerberos-ADconfig.html it works fine. But, I need to setup a reverse proxy (I use nginx). It works too, but SSO.PLEASE read my logs and sheme, I'd like if you help me.So, I have t</description>
      <pubDate>Thu, 17 Jul 2014 06:50:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-doesn-t-work-with-reverse-proxy/m-p/287342#M240472</guid>
      <dc:creator>vgusev2007</dc:creator>
      <dc:date>2014-07-17T06:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: SSO doesn't work with reverse proxy</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-doesn-t-work-with-reverse-proxy/m-p/287343#M240473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;The reverse proxy based approach is quite flexible and supports multiple SSO solutions. This approach is considered the best practice when configuring SSO for CentraSite. &lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Sep 2014 06:42:48 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-doesn-t-work-with-reverse-proxy/m-p/287343#M240473</guid>
      <dc:creator>kimberlydeborah</dc:creator>
      <dc:date>2014-09-19T06:42:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSO doesn't work with reverse proxy</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-doesn-t-work-with-reverse-proxy/m-p/287344#M240474</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have setup mod_jk + apache - it works fine for me.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2014 06:20:31 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-doesn-t-work-with-reverse-proxy/m-p/287344#M240474</guid>
      <dc:creator>vgusev2007</dc:creator>
      <dc:date>2014-10-07T06:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: SSO doesn't work with reverse proxy</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-doesn-t-work-with-reverse-proxy/m-p/287345#M240475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;we use mod_proxy_ajp + apache and this works fine (Ubuntu 4.2.e/f and Ubuntu 12.04 LTS) but this aproach has other problems since Alfresco Share is so hungry in terms of http threads per share page. It is not easy to scale with several hundred concurrent users if you use apache reverse proxy. You need to tune apache for that.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I've seen a lot of configs which solves this issue much better with nginx but I haven't seen a working nginx config so far which has no problem with WebDAV, SPP, Kerberos.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Are there any nginx experts having experience with Alfresco config working with WebDAV, SPP and Kerberos?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2014 16:32:47 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-doesn-t-work-with-reverse-proxy/m-p/287345#M240475</guid>
      <dc:creator>heiko_robert</dc:creator>
      <dc:date>2014-10-15T16:32:47Z</dc:date>
    </item>
    <item>
      <title>Re: SSO doesn't work with reverse proxy</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-doesn-t-work-with-reverse-proxy/m-p/287346#M240476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I don't use ajp. I use: jk&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It lookss like this one:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;&amp;lt;VirtualHost *:80&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ServerName test.company.ru&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ServerAlias &lt;A href="http://www.test.company.ru" rel="nofollow noopener noreferrer"&gt;www.test.company.ru&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Redirect / &lt;A href="https://test.company.ru/share" rel="nofollow noopener noreferrer"&gt;https://test.company.ru/share&lt;/A&gt;&lt;BR /&gt;&amp;lt;/VirtualHost&amp;gt;&lt;BR /&gt;&amp;lt;virtualhost *:443&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ServerName test.company.ru&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ServerAlias &lt;A href="http://www.test.company.ru" rel="nofollow noopener noreferrer"&gt;www.test.company.ru&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSLEngine On&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSLCertificateFile /etc/apache2/cert/test.company.ru.crt&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSLCertificateKeyFile /etc/apache2/cert/test.company.ru.key&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSLCACertificateFile /etc/apache2/cert/SSL123_CA_Bundle.pem&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ErrorDocument&amp;nbsp;&amp;nbsp; 503&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "/custom_errors/maintenance.html"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RedirectMatch ^/$ /share/&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; jkMount /alfresco ajp13_worker&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; jkMount /alfresco/* ajp13_worker&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; jkMount /share ajp13_worker&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; jkMount /share/* ajp13_worker&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Oct 2014 05:44:27 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-doesn-t-work-with-reverse-proxy/m-p/287346#M240476</guid>
      <dc:creator>vgusev2007</dc:creator>
      <dc:date>2014-10-17T05:44:27Z</dc:date>
    </item>
  </channel>
</rss>

