<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSO Kerberos in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291039#M244169</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you include your&amp;nbsp;&lt;STRONG&gt;krb5.ini&lt;/STRONG&gt; content?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Nov 2016 09:50:39 GMT</pubDate>
    <dc:creator>angelborroy</dc:creator>
    <dc:date>2016-11-28T09:50:39Z</dc:date>
    <item>
      <title>SSO Kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291038#M244168</link>
      <description>I want to make SSO environment with ActiveDirectory but I can't...I worked in accordance with below;&amp;nbsp;http://docs.alfresco.com/5.0/tasks/auth-kerberos-ADconfig.html&amp;nbsp;http://docs.alfresco.com/5.0/tasks/auth-kerberos-shareSSO.htmlPlease teach me right way to configure SSO.&amp;lt;Environment&amp;gt;ActiveDirect</description>
      <pubDate>Mon, 28 Nov 2016 07:29:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291038#M244168</guid>
      <dc:creator>tkim</dc:creator>
      <dc:date>2016-11-28T07:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSO Kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291039#M244169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you include your&amp;nbsp;&lt;STRONG&gt;krb5.ini&lt;/STRONG&gt; content?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2016 09:50:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291039#M244169</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2016-11-28T09:50:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSO Kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291040#M244170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is my krb5.ini.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;[logging]&lt;BR /&gt;&amp;nbsp;default = FILE:C:\work\krb5libs.log&lt;BR /&gt;&amp;nbsp;kdc = FILE:C:\work\krb5kdc.log&lt;BR /&gt;&amp;nbsp;admin_server = FILE:C:\work\kadmind.log&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;[libdefaults]&lt;BR /&gt;default_realm = OURDOMAIN.LOCAL&lt;BR /&gt;default_tkt_enctypes = rc4-hmac&lt;BR /&gt;default_tgs_enctypes = rc4-hmac&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[realms]&lt;BR /&gt;OURDOMAIN.LOCAL = {&lt;BR /&gt;&amp;nbsp;&amp;nbsp; kdc = dcsvr.ourdomain.local&lt;BR /&gt;&amp;nbsp;&amp;nbsp; admin_server = dcsvr.ourdomain.local&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[domain_realm]&lt;BR /&gt;dcsvr.ourdomain.local = OURDOMAIN.LOCAL&lt;BR /&gt;.dcsvr.ourdomain.local = OURDOMAIN.LOCAL&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2016 10:40:34 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291040#M244170</guid>
      <dc:creator>tkim</dc:creator>
      <dc:date>2016-11-28T10:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSO Kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291041#M244171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try removing encryption lines:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #727174; background-color: #ffffff;"&gt;default_tkt_enctypes = rc4-hmac&lt;/SPAN&gt;&lt;BR style="color: #727174;" /&gt;&lt;SPAN style="color: #727174; background-color: #ffffff;"&gt;default_tgs_enctypes = rc4-hmac&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2016 11:33:05 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291041#M244171</guid>
      <dc:creator>angelborroy</dc:creator>
      <dc:date>2016-11-28T11:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSO Kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291042#M244172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thx for reply!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I&amp;nbsp; modified java.login.config; adding "@OURDOMAIN.LOCAL", and also removed encryption lines from krb5.ini.&lt;BR /&gt;Now, when I started Alfresco service, no error was happened and the logs appeared like below;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2016-11-29 13:54:25,483 INFO&amp;nbsp; [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Starting 'Authentication' subsystem, ID: [Authentication, managed, kerberos1]&lt;BR /&gt;2016-11-29 13:54:25,593 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [localhost-startStop-1] HTTP Kerberos login successful&lt;BR /&gt;2016-11-29 13:54:25,593 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [localhost-startStop-1] Logged on using principal HTTP/xxxx&lt;BR /&gt;2016-11-29 13:54:25,624 DEBUG [org.alfresco.repo.webdav.auth.KerberosAuthenticationFilter] [localhost-startStop-1] HTTP Kerberos login successful&lt;BR /&gt;2016-11-29 13:54:25,624 DEBUG [org.alfresco.repo.webdav.auth.KerberosAuthenticationFilter] [localhost-startStop-1] Logged on using principal HTTP/xxxx&lt;BR /&gt;2016-11-29 13:54:25,686 INFO&amp;nbsp; [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Startup of 'Authentication' subsystem, ID: [Authentication, managed, kerberos1] complete&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I can not do SSO.&lt;BR /&gt;When I access alfresco from IE, the basic authentication dialog appears; maybe come from Alfrescontlm.&lt;BR /&gt;&lt;SPAN&gt;IE settings is OK like &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://docs.alfresco.com/4.0/tasks/auth-kerberos-clientconfig.html" rel="nofollow noopener noreferrer" target="_blank"&gt;http://docs.alfresco.com/4.0/tasks/auth-kerberos-clientconfig.html&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1:Kerberos SSO means that no authentication dialog appears, right?&lt;BR /&gt;2:my configuration is wrong or not enogh?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;krb5.ini&amp;gt;&lt;BR /&gt;---&lt;BR /&gt;[logging]&lt;BR /&gt;&amp;nbsp;default = FILE:C:\work\krb5libs.log&lt;BR /&gt;&amp;nbsp;kdc = FILE:C:\work\krb5kdc.log&lt;BR /&gt;&amp;nbsp;admin_server = FILE:C:\work\kadmind.log&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;[libdefaults]&lt;BR /&gt;default_realm = OURDOMAIN.LOCAL&lt;BR /&gt;default_tkt_enctypes = rc4-hmac&lt;BR /&gt;default_tgs_enctypes = rc4-hmac&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[realms]&lt;BR /&gt;OURDOMAIN.LOCAL = {&lt;BR /&gt;&amp;nbsp;&amp;nbsp; kdc = dcsvr.ourdomain.local&lt;BR /&gt;&amp;nbsp;&amp;nbsp; admin_server = dcsvr.ourdomain.local&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[domain_realm]&lt;BR /&gt;dcsvr.ourdomain.local = OURDOMAIN.LOCAL&lt;BR /&gt;.dcsvr.ourdomain.local = OURDOMAIN.LOCAL&lt;BR /&gt;---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;java.login.config&amp;gt;&lt;BR /&gt;---&lt;BR /&gt;Alfresco {&lt;BR /&gt;com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;BR /&gt;};&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AlfrescoCIFS {&lt;BR /&gt;com.sun.security.auth.module.Krb5LoginModule required&lt;BR /&gt;&amp;nbsp;&amp;nbsp; storeKey=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp; keyTab="C:/etc/cifs.keytab"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; principal="cifs/alfrescoserver.ourdomain.local@OURDOMAIN.LOCAL";&lt;BR /&gt;};&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AlfrescoHTTP {&lt;BR /&gt;com.sun.security.auth.module.Krb5LoginModule required&lt;BR /&gt;&amp;nbsp;&amp;nbsp; storeKey=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp; keyTab="C:/etc/http7.keytab"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; principal="HTTP/alfrescoserver.ourdomain.local@OURDOMAIN.LOCAL";&lt;BR /&gt;};&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ShareHTTP&lt;BR /&gt;{&lt;BR /&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;BR /&gt;&amp;nbsp;&amp;nbsp; storeKey=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp; keyTab="C:/etc/http.keytab"&lt;BR /&gt;&amp;nbsp;&amp;nbsp; principal="HTTP/alfrescoserver.ourdomain.local@OURDOMAIN.LOCAL";&lt;BR /&gt;};&lt;BR /&gt;com.sun.net.ssl.client {&lt;BR /&gt;com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;BR /&gt;};&lt;BR /&gt;other {&lt;BR /&gt;com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;BR /&gt;};&lt;BR /&gt;---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;share-config-custom.xml(a part of)&amp;gt;&lt;BR /&gt;---&lt;BR /&gt;&amp;lt;config evaluator="string-compare" condition="Kerberos" replace="true"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;lt;kerberos&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;password&amp;gt;mypassword&amp;lt;/password&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;realm&amp;gt;OURDOMAIN.LOCAL&amp;lt;/realm&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;endpoint-spn&amp;gt;HTTP/alfrescoserver.ourdomain.local@OURDOMAIN.LOCAL&amp;lt;/endpoint-spn&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;config-entry&amp;gt;AlfrescoHTTP&amp;lt;/config-entry&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;stripUserNameSuffix&amp;gt;true&amp;lt;/stripUserNameSuffix&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;lt;/kerberos&amp;gt;&lt;BR /&gt;&amp;lt;/config&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and uncomment &amp;lt;config evaluator="string-compare" condition="Remote"&amp;gt; sections.&lt;BR /&gt;---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;kerberos-filter.properties&amp;gt;&lt;BR /&gt;---&lt;BR /&gt;kerberos.authentication.http.configEntryName=AlfrescoHTTP&lt;BR /&gt;kerberos.authentication.http.password=mypassword&lt;BR /&gt;kerberos.authentication.sso.enabled=true&lt;BR /&gt;kerberos.authentication.browser.ticketLogons=true&lt;BR /&gt;kerberos.authentication.sso.fallback.enabled=true&lt;BR /&gt;---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;alfresco-global.properties&amp;gt;&lt;BR /&gt;---&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;authentication.chain=kerberos1:kerberos,ldap1:ldap-ad,alfrescoNtlm1:alfrescoNtlm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#NTLM&lt;BR /&gt;ntlm.authentication.sso.enabled=false&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#LDAP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#LADAP Sync&lt;BR /&gt;ldap.authentication.userNameFormat=%s@ourdomain.local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ldap.authentication.java.naming.provider.url=ldap://IPAddress for domain controller:389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ldap.synchronization.java.naming.security.principal=username@ourdomain.local&lt;BR /&gt;ldap.synchronization.java.naming.security.credentials=mypassword&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ldap.synchronization.userSearchBase=DC\=ourdomain,DC\=local&lt;BR /&gt;ldap.synchronization.personType=person&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ldap.synchronization.userIdAttributeName=sAMAccountName&lt;BR /&gt;ldap.synchronization.userFirstNameAttributeName=givenName&lt;BR /&gt;ldap.synchronization.userLastNameAttributeName=sn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#group&lt;BR /&gt;ldap.synchronization.groupSearchBase=DC\=ourdomain,DC\=local&lt;BR /&gt;ldap.synchronization.groupType=organizationalUnit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# Sync&lt;BR /&gt;synchronization.synchronizeChangesOnly=false&lt;BR /&gt;synchronization.allowDeletions=true&lt;BR /&gt;synchronization.syncWhenMissingPeopleLogIn=true&lt;BR /&gt;synchronization.syncOnStartup=true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ldap.synchronization.enableProgressEstimation=true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ldap.synchronization.active=true&lt;BR /&gt;ldap.authentication.allowGuestLogin=true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;synchronization.synchronizeChangesOnly=false&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2016 05:09:04 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291042#M244172</guid>
      <dc:creator>tkim</dc:creator>
      <dc:date>2016-11-29T05:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: SSO Kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291043#M244173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;adding information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I accessed Alfresco from IE and appears basic authentication dialog, these logs were put out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2016-11-29 14:50:52,728 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-5] Authentication not required (filter), chaining ...&lt;BR /&gt;2016-11-29 14:50:52,806 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-6] Authentication not required (filter), chaining ...&lt;BR /&gt;2016-11-29 14:50:52,822 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-7] New Kerberos auth request from 127.0.0.1 (127.0.0.1:58954)&lt;BR /&gt;2016-11-29 14:50:52,822 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-7] Issuing login challenge to browser.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Nov 2016 06:01:19 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/sso-kerberos/m-p/291043#M244173</guid>
      <dc:creator>tkim</dc:creator>
      <dc:date>2016-11-29T06:01:19Z</dc:date>
    </item>
  </channel>
</rss>

