<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alfresco authentication using kerberos in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-authentication-using-kerberos/m-p/289216#M242346</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Mates,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am writing this hopefully somebody will help me to fix the issue regarding Kerberos Authentication. I follow to this documentation &lt;/SPAN&gt;&lt;A href="http://www.anotherstrangerme.com/afresco-integration-with-active-directory-using-kerberos/" rel="nofollow noopener noreferrer"&gt;http://www.anotherstrangerme.com/afresco-integration-with-active-directory-using-kerberos/&lt;/A&gt;&lt;SPAN&gt; to configure kerberos authentication, but can't get it working. Below is my configuration:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication.chain=kerberos1:kerberos&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.realm=MYCOMPANY.COM&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.sso.enabled=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.authenticateCIFS=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.user.configEntryName=Alfresco&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.cifs.configEntryName=alfrescocifs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.http.configEntryName=alfrescohttp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.cifs.password=secrect&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.http.password=secrect&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.defaultAdministratorUserNames=alfrescocifs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.cifs.enableTicketCracking=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.stripUsernameSuffix=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;3. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Alfresco {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AlfrescoCIFS {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; storeKey=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; debug=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; keyTab="/opt/alfresco/alfrescocifs.keytab"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isInitiator=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; principal="cifs/alfresco.vng.com.vn";&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AlfrescoHTTP {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; storeKey=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; debug=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; keyTab="/opt/alfresco/alfrescohttp.keytab"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isInitiator=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; principal="HTTP/alfresco.vng.com.vn";&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ShareHTTP {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; storeKey=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; keyTab="/etc/krb5.alfresco.http.keytab"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; isInitiator=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; principal="HTTP/alfresco.vng.com.vn";&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;com.sun.net.ssl.client {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;other {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;4.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;ktpass /princ &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:cifs/alfresco.vng.com.vn@MYCOMPANY.COM" rel="nofollow noopener noreferrer"&gt;cifs/alfresco.vng.com.vn@MYCOMPANY.COM&lt;/A&gt;&lt;SPAN&gt; -pass secrect /mapuser VNG\alfrescocifs -crypto All /ptype KRB5_NT_PRINCIPAL /mapop set +desonly -out D:\Alfresco\alfrescocifs.keytab&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;SPAN&gt;ktpass /princ &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:HTTP/alfresco.vng.com.vn@MYCOMPANY.COM" rel="nofollow noopener noreferrer"&gt;HTTP/alfresco.vng.com.vn@MYCOMPANY.COM&lt;/A&gt;&lt;SPAN&gt; /pass secrect&amp;nbsp; /mapuser VNG\alfrescohttp -crypto All /ptype KRB5_NT_PRINCIPAL /mapop set +desonly -out D:\Alfresco\alfrescohttp.keytab&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;setspn -a cifs/alfresco alfrescocifs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;setspn -a cifs/alfresco.mycompany.com alfrescocifs&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;setspn -a HTTP/alfresco alfrescohttp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;setspn -a HTTP/alfresco.mycompany.com alfrescohttp&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;setspn -l alfrescocifs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;setspn -l alfrescohttp&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;5.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[libdefaults]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;default_realm = MYCOMPANY.COM&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[realms]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;MYCOMPANY.COM = {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kdc = vnghcmads03.vng.com.vn&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;admin_server = vnghcmads01.mycompany.com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[domain_realm]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;vnghcmads01.mycompany.com = MYCOMPANY.COM&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;.vnghcmads01.mycompany.com = MYCOMPANY.COM&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;But when I login to &lt;/SPAN&gt;&lt;A href="http://alfresco.mycompany.com:8080/alfresco" rel="nofollow noopener noreferrer"&gt;http://alfresco.mycompany.com:8080/alfresco&lt;/A&gt;&lt;SPAN&gt; - I'm getting the error &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Error creating bean with name 'cifsAuthenticator' defined in file [/opt/alfresco/tomcat/webapps/alfresco/WEB-INF/classes/alfresco/subsystems/Authentication/kerberos/kerberos-authentication-context.xml]: Invocation of init method failed; nested exception is org.alfresco.jlan.server.config.InvalidConfigurationException: Failed to login CIFS server service&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any help would be appriciated !&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Best regards,&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Sep 2013 02:56:01 GMT</pubDate>
    <dc:creator>thanhdc</dc:creator>
    <dc:date>2013-09-18T02:56:01Z</dc:date>
    <item>
      <title>Alfresco authentication using kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-authentication-using-kerberos/m-p/289216#M242346</link>
      <description>Hi Mates,I am writing this hopefully somebody will help me to fix the issue regarding Kerberos Authentication. I follow to this documentation http://www.anotherstrangerme.com/afresco-integration-with-active-directory-using-kerberos/ to configure kerberos authentication, but can't get it working. Bel</description>
      <pubDate>Wed, 18 Sep 2013 02:56:01 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-authentication-using-kerberos/m-p/289216#M242346</guid>
      <dc:creator>thanhdc</dc:creator>
      <dc:date>2013-09-18T02:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco authentication using kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-authentication-using-kerberos/m-p/289217#M242347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I literarly just figured out what this error is. So how Kerberos is divided up in alfresco is through two files, kerberos-authentication and kerberos-filter . The authentication file is responsible for CIFS/FTP/NFS while the filter is responsible for share/SSO. you're getting this error because in the filter file, the default is kerberos.authentication.sso.enabled=true if you don't need share(keep in mind just to turn it to true doesn't mean share SSO is done, there is more config that I haven't figured out), then turn it to false. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I hope that helps!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks, &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Michael&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Oct 2013 16:58:54 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-authentication-using-kerberos/m-p/289217#M242347</guid>
      <dc:creator>msmorcos</dc:creator>
      <dc:date>2013-10-11T16:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco authentication using kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-authentication-using-kerberos/m-p/289218#M242348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Also watch case sensitivity for the JASS and Kerberos principals.&amp;nbsp; You have inconsistent names above.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Oct 2013 20:31:08 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-authentication-using-kerberos/m-p/289218#M242348</guid>
      <dc:creator>mrogers</dc:creator>
      <dc:date>2013-10-13T20:31:08Z</dc:date>
    </item>
  </channel>
</rss>

