<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: alfresco 5.0c and kerberos in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292187#M245317</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sorry for the delay I was in vacation…&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;To be honest I never tried Kerberos SSO for HTTP with share (does not make sense for us as users needs to log on from the Internet).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I know that you need to configure extra things for HTTP SSO like delegation on AD.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Do you have the opportunity to test Kerberos SSO using on CIFS connector ? (this may help to identify the source of the issue) &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Vincent&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Apr 2015 13:24:58 GMT</pubDate>
    <dc:creator>vincent-kali</dc:creator>
    <dc:date>2015-04-21T13:24:58Z</dc:date>
    <item>
      <title>alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292178#M245308</link>
      <description>Hi,I'm facing issues to setup kerberos authentication against 2008R2 AD domain controller on an Alfresco Community 5c platform (on linux debian 7).I followed the procedure that we applied on alf 4.2, which was working fine.  I made the following:- create services accounts on AD (alfrescoCIFS &amp;amp; a</description>
      <pubDate>Fri, 06 Feb 2015 14:22:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292178#M245308</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2015-02-06T14:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292179#M245309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;After further analysis, I see that :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Alfresco is getting the initial TGT correctly for CIFS at startup&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- User fails to get TGS for alfresco with error KRB5KDC_ERR_BADOPTION 'STATUS_NOT_SUPPORTED'&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;any suggestion ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;really nobody can help ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;thanks&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Feb 2015 21:28:37 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292179#M245309</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2015-02-09T21:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292180#M245310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Issue has been identified on AD side.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Tricky problem: mixed upper/lowercase in the domain name, and consequently in the Kerberos TGS (refused by alfresco JAAS).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;No easy solution at this time.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Vincent.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Feb 2015 11:32:06 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292180#M245310</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2015-02-11T11:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292181#M245311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;After digging out Kerberos and AD, I finally found that the problem was (again) a kvno issue.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;conclusions:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-&amp;nbsp; kinit does NOT validate the keytab file, even if you use it as parameter as it requests to get a TGT. kvno is not checked at this step (it does validate the Kerberos config only - krb5.conf)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;-&amp;nbsp; you need to check the kvno on AD U&amp;amp;C directly, parameters (constructed): msDS-KeyVersionNumber&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Vincent&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Mar 2015 13:22:11 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292181#M245311</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2015-03-06T13:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292182#M245312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Would you please send me the settings for you installation?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Apr 2015 12:10:19 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292182#M245312</guid>
      <dc:creator>borisstankov</dc:creator>
      <dc:date>2015-04-03T12:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292183#M245313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;could you please give me some details about the settings you want me to send ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;as explain above the issue is solved (kvno issue), but I'm of course ready to &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;share everything you need if it can help….&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Apr 2015 19:43:05 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292183#M245313</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2015-04-04T19:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292184#M245314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Well, I can see those error messeges in the catalina.out:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2015-04-07 11:22:18,591&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-5] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-07 11:22:18,658&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-10] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-07 11:22:18,674&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-1] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-07 11:22:18,691&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-3] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-07 11:22:18,697&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-6] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-07 11:22:18,720&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-2] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-07 11:22:19,264&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-7] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-07 11:22:19,272&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-9] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-07 11:22:20,093&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-5] New Kerberos auth request from 192.168.192.240 (192.168.192.240:50747)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-07 11:22:20,093&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-5] Issuing login challenge to browser.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-07 11:22:20,660&amp;nbsp; DEBUG [webdav.auth.KerberosAuthenticationFilter] [http-apr-8080-exec-1] Performing fallback authentication…&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-07 11:22:20,697&amp;nbsp; DEBUG [webdav.auth.KerberosAuthenticationFilter] [http-apr-8080-exec-1] Issuing login challenge to browser.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-07 11:22:20,698&amp;nbsp; DEBUG [webdav.auth.KerberosAuthenticationFilter] [http-apr-8080-exec-1] Fallback authentication failed. Restarting login…&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 11:22:20,699 WARN&amp;nbsp; [org.alfresco.wcm.client.util.impl.GuestSessionFactoryImpl] WQS unable to connect to repository: Unauthorized&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;At this time my browser asks me about my password in a loop and never goes our of it.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I edited: global.properties files with:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication.chain=kerberos1:kerberos&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.realm=CORP.INT&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.sso.enabled=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.authenticateCIFS=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.user.configEntryName=Alfresco &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.cifs.password=Password123!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.cifs.configEntryName=AlfrescoCIFS&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.stripUsernameSuffix=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.http.password=Password123!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.http.configEntryName=AlfrescoHTTP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.browser.ticketLogons=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Also I edited the /opt/alfresco-5.0/tomcat/shared/classes/alfresco/web-extension/share-config-custom.xml as expalined here: &lt;/SPAN&gt;&lt;A href="http://docs.alfresco.com/community/tasks/auth-kerberos-shareSSO.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/community/tasks/auth-kerberos-shareSSO.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have this configs in my JAVA_OPTS which are located in this file :&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;JAVA_HOME=/opt/alfresco-5.0/java&lt;BR /&gt;JRE_HOME=$JAVA_HOME&lt;BR /&gt;JAVA_OPTS="-XX:+DisableExplicitGC -Djava.awt.headless=true -Dalfresco.home=/opt/alfresco-5.0 -Dcom.sun.management.jmxremote -Dsun.security.krb5.msinterop.kstring=true -XX:ReservedCodeCacheSize=128m $JAVA_OPTS "&lt;BR /&gt;JAVA_OPTS="-XX:MaxPermSize=5120M -Xms4096M -Xmx5120M $JAVA_OPTS " # java-memory-settings&lt;BR /&gt;export JAVA_HOME&lt;BR /&gt;export JRE_HOME&lt;BR /&gt;export JAVA_OPTS&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;THose are the configs for my /etc/krb5.conf file (the DOMAIN is my domain and it's the correct one in the real file):&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[logging]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; default = FILE:/var/log/krb5libs.log&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; kdc = FILE:/var/log/krb5kdc.log&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; admin_server = FILE:/var/log/kadmind.log&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[libdefaults]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; default_realm = DOMAIN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; dns_lookup_realm = false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; dns_lookup_kdc = false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; ticket_lifetime = 24h&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; renew_lifetime = 7d&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; default_tkt_enctypes = rc4-hmac&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; default_tgs_enctypes = rc4-hmac&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; forwardable = true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; proxiable = true&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[realms]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; DOMAIN= {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; kdc = dc1.domain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; admin_server = dc1.domain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; }&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[domain_realm]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; .corp.int = DOMAIN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; corp.int = DOMAIN&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Both keyfiles are location in the /etc dir.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I created a file java.login.config under here:/opt/alfresco-5.0/java/lib/security with the following code (system.domain = my alfresco fqdn):&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;Alfresco {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; };&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; AlfrescoCIFS {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; storeKey=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keyTab="/etc/cifsportal2.keytab"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; principal="cifs/system.domain";&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; };&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; AlfrescoHTTP {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; storeKey=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keyTab="/etc/httpportal2.keytab"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; principal="HTTP/system.domain";&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; };&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ShareHTTP {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; storeKey=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keyTab="/etc/httpportal2.keytab"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; principal="HTTP/system.domain";&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; };&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.net.ssl.client {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; };&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; other {&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; };&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I also edited the java.security file in the same dir by adding this line:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;login.config.url.1=file:${java.home}/lib/security/java.login.config&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Do you have any idea if I'm missing some and I should add it, or I setup some of the setting not in the right way?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Apr 2015 08:45:49 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292184#M245314</guid>
      <dc:creator>borisstankov</dc:creator>
      <dc:date>2015-04-07T08:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292185#M245315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you first validate your SSO Kerberos config using CIFS (you'll bypass all possible misconfiguration on the client browser) ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Are you running Alfresco on Linux ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Here are the main steps to follow: (Assuming your KDC is an MS AD DC)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Service account creation with correct UPN/SPN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Linux Keberos client config (krb5.conf)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Test Kinit (krb5-user package on debian) to check that authentication is correct&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; -&amp;gt; kinit -V cifs/alfrescoserver.mydomain.loc@MYDOMAIN.LOC&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Generate keytab (with correct kvno !!)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; -&amp;gt; I'm using ktpass on linux. Check service account's kvno on AD (attribute msDS-KeyVersionNumber, don't forget to show 'constructed' user attributes on AD Users&amp;amp;Computers)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Test Kinit using keytab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; -&amp;gt; kinit -V cifs/alfrescoserver.mydomain.loc@MYDOMAIN.LOC -k -t myKeytabFile&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you confirm you did this successfully ? (I'll post my alf config soon if you need).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Vincent&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Apr 2015 14:07:05 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292185#M245315</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2015-04-07T14:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292186#M245316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You assumed correctly. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;My alfresco version 5.0.c is on centOS 6.5 and our MS AD is on Windows Server 2012.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for the notes you sent, we checked them closely with our team here. At this point:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kinit -V cifs/alfrescoserver.mydomain.loc@MYDOMAIN.LOC -&amp;gt;&amp;gt;&amp;gt; this one was Authorized, but&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kinit -V cifs/alfrescoserver.mydomain.loc@MYDOMAIN.LOC -k -t myKeytabFile -&amp;gt;&amp;gt;&amp;gt; this one failed&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Then we generated the keytabs with the correct knvo. It was version 4, but generated it with 0 at first.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Now both commands are returning the Authozired:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kinit -V cifs/alfrescoserver.mydomain.loc@MYDOMAIN.LOC &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kinit -V cifs/alfrescoserver.mydomain.loc@MYDOMAIN.LOC -k -t myKeytabFile &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;However I'm still not able to use the single-sign on authentication and I can't login to alfresco using this type of authentication. here is what I can see now in the "catalina.out":&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Apr 08, 2015 11:50:21 AM org.apache.catalina.startup.Catalina start&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;INFO: Server startup in 139796 ms&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2015-04-08 11:50:21,763&amp;nbsp; WARN&amp;nbsp; [scripts.solr.AlfrescoModelsDiff] [http-bio-8443-exec-2] Unable to fetch model changes from /alfresco/service/api/solr/modelsdiff&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-08 11:50:21,768&amp;nbsp; WARN&amp;nbsp; [scripts.solr.AlfrescoModelsDiff] [http-bio-8443-exec-1] Unable to fetch model changes from /alfresco/service/api/solr/modelsdiff&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 2015-04-08 11:50:22,233&amp;nbsp; DEBUG [webdav.auth.KerberosAuthenticationFilter] [http-apr-8080-exec-2] Performing fallback authentication…&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; Apr 08, 2015 11:50:22 AM org.apache.catalina.core.StandardWrapperValve invoke&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SEVERE: Servlet.service() for servlet [cmisatom10] in context with path [/alfresco] threw exception&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;org.alfresco.service.namespace.InvalidQNameException: A QName must consist of a local name&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.service.namespace.QName.createQName(QName.java:87)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.person.PersonServiceImpl.getChildNameLower(PersonServiceImpl.java:1768)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.person.PersonServiceImpl.getPersonOrNullImpl(PersonServiceImpl.java:537)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.person.PersonServiceImpl.getUserIdentifier(PersonServiceImpl.java:1880)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.authentication.AuthenticationComponentImpl$1$1.doWork(AuthenticationComponentImpl.java:93)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.authentication.AuthenticationComponentImpl$1$1.doWork(AuthenticationComponentImpl.java:90)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.tenant.TenantUtil.runAsWork(TenantUtil.java:119)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.tenant.TenantUtil.runAsTenant(TenantUtil.java:88)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.tenant.TenantUtil$1.doWork(TenantUtil.java:62)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.authentication.AuthenticationUtil.runAs(AuthenticationUtil.java:548)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.tenant.TenantUtil.runAsUserTenant(TenantUtil.java:58)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.tenant.TenantUtil.runAsSystemTenant(TenantUtil.java:112)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.authentication.AuthenticationComponentImpl$1.execute(AuthenticationComponentImpl.java:89)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.authentication.AuthenticationComponentImpl$1.execute(AuthenticationComponentImpl.java:86)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.transaction.RetryingTransactionHelper.doInTransaction(RetryingTransactionHelper.java:454)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.transaction.RetryingTransactionHelper.doInTransaction(RetryingTransactionHelper.java:342)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.authentication.AuthenticationComponentImpl.authenticateImpl(AuthenticationComponentImpl.java:84)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.authentication.AbstractAuthenticationComponent.authenticate(AbstractAuthenticationComponent.java:162)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.authentication.AuthenticationServiceImpl.authenticate(AuthenticationServiceImpl.java:68)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.authentication.AbstractChainingAuthenticationService.authenticate(AbstractChainingAuthenticationService.java:195)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.lang.reflect.Method.invoke(Unknown Source)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.aop.support.AopUtils.invokeJoinpointUsingReflection(AopUtils.java:317)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.aop.framework.ReflectiveMethodInvocation.invokeJoinpoint(ReflectiveMethodInvocation.java:183)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:150)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at net.sf.acegisecurity.intercept.method.aopalliance.MethodSecurityInterceptor.invoke(MethodSecurityInterceptor.java:80)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:172)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.security.permissions.impl.ExceptionTranslatorMethodInterceptor.invoke(ExceptionTranslatorMethodInterceptor.java:46)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:172)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.audit.AuditMethodInterceptor.invoke(AuditMethodInterceptor.java:159)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:172)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.transaction.interceptor.TransactionInterceptor$1.proceedWithInvocation(TransactionInterceptor.java:96)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.transaction.interceptor.TransactionAspectSupport.invokeWithinTransaction(TransactionAspectSupport.java:260)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.transaction.interceptor.TransactionInterceptor.invoke(TransactionInterceptor.java:94)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:172)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.aop.framework.JdkDynamicAopProxy.invoke(JdkDynamicAopProxy.java:204)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at com.sun.proxy.$Proxy64.authenticate(Unknown Source)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.webdav.auth.SSOFallbackBasicAuthenticationDriver.authenticateRequest(SSOFallbackBasicAuthenticationDriver.java:120)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.webdav.auth.BaseSSOAuthenticationFilter.performFallbackAuthentication(BaseSSOAuthenticationFilter.java:604)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.webdav.auth.BaseKerberosAuthenticationFilter.authenticateRequest(BaseKerberosAuthenticationFilter.java:279)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.webdav.auth.BaseSSOAuthenticationFilter.doFilter(BaseSSOAuthenticationFilter.java:155)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.lang.reflect.Method.invoke(Unknown Source)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.management.subsystems.ChainingSubsystemProxyFactory$1.invoke(ChainingSubsystemProxyFactory.java:112)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:172)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.aop.framework.JdkDynamicAopProxy.invoke(JdkDynamicAopProxy.java:204)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at com.sun.proxy.$Proxy274.doFilter(Unknown Source)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.repo.web.filter.beans.BeanProxyFilter.doFilter(BeanProxyFilter.java:82)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:241)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:208)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.web.app.servlet.CmisSecurityContextCleanerFilter.doFilter(CmisSecurityContextCleanerFilter.java:49)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:241)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:208)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.web.app.servlet.GlobalLocalizationFilter.doFilter(GlobalLocalizationFilter.java:61)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:241)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:208)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:220)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:122)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:501)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:170)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:98)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.valves.AccessLogValve.invoke(AccessLogValve.java:950)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:116)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:408)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.coyote.http11.AbstractHttp11Processor.process(AbstractHttp11Processor.java:1040)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process(AbstractProtocol.java:607)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.tomcat.util.net.AprEndpoint$SocketWithOptionsProcessor.run(AprEndpoint.java:2378)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.lang.Thread.run(Unknown Source)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;b&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;11:50:22,377 WARN&amp;nbsp; [org.alfresco.wcm.client.util.impl.GuestSessionFactoryImpl] WQS unable to connect to repository: Internal Server Error&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2015-04-08 11:50:24,388&amp;nbsp; DEBUG [webdav.auth.KerberosAuthenticationFilter] [http-apr-8080-exec-3] Performing fallback authentication…&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;/b&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;All the BEST!&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Apr 2015 08:59:42 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292186#M245316</guid>
      <dc:creator>borisstankov</dc:creator>
      <dc:date>2015-04-08T08:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292187#M245317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sorry for the delay I was in vacation…&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;To be honest I never tried Kerberos SSO for HTTP with share (does not make sense for us as users needs to log on from the Internet).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I know that you need to configure extra things for HTTP SSO like delegation on AD.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Do you have the opportunity to test Kerberos SSO using on CIFS connector ? (this may help to identify the source of the issue) &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Vincent&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Apr 2015 13:24:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292187#M245317</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2015-04-21T13:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292188#M245318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Vincent,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Nice to hear form you again and there is no problem in the delay.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ok, let's try from a different point of view.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Here is what I want to achive:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Our alfresco is only for internal use of all employees of our company. Every employee has a LDAP AD account and we want to configure those accounts to use single-sign on, meaning then do not have to enter user and passowrd when they open the url link for the alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I never used kerberos before and maybe I'm doing it wrong.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please let me know if you think that I need to do some changes or I should do something else entirely.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Boris&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Apr 2015 08:11:58 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292188#M245318</guid>
      <dc:creator>borisstankov</dc:creator>
      <dc:date>2015-04-23T08:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292189#M245319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Boris,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I understand your needs.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;My point is that I never experienced kerberos SSO on share (what you want to do).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;But I configured very often kerberos sso on CIFS connector. My suggestion is to try first&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;to make this working (kerberos sso on CIFS) which is less complicated, and could valide the whole config (alfresco, AD, kerberos client).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Did you enable CIFS connector ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Vincent&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Apr 2015 16:14:50 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292189#M245319</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2015-04-23T16:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292190#M245320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Vicent,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for helping me about this problem - its much appriciated!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Sorry, but I'm not sure how I can do the thing you described above. Would you please give me some pointers, steps, advice or etc? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://connect.hyland.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Bobi&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Apr 2015 13:23:51 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292190#M245320</guid>
      <dc:creator>borisstankov</dc:creator>
      <dc:date>2015-04-24T13:23:51Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292191#M245321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Boris,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;here's a config example to make CIFS with Kerberos SSO working (alfresco-share.properties)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you make this working: accessing the CIFS share from a Workstation in your domain ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;###LDAP###&lt;BR /&gt;ldap.authentication.active=true&lt;BR /&gt;ldap.synchronization.active=true&lt;BR /&gt;&lt;BR /&gt;#ldap.authentication.allowGuestLogin=false&lt;BR /&gt;ldap.authentication.userNameFormat=%s@MYDOMAIN.LOC&lt;BR /&gt;ldap.authentication.java.naming.provider.url=ldap://1.2.3.4:389&lt;BR /&gt;ldap.authentication.defaultAdministratorUserNames=administrator&lt;BR /&gt;ldap.synchronization.java.naming.security.principal=userThatCanReadADUsersProperties@MYDOMAIN.LOC&lt;BR /&gt;ldap.synchronization.java.naming.security.credentials=userPassword&lt;BR /&gt;&lt;BR /&gt;###ldap.synchronization.groupQuery=(objectclass\=group)&lt;BR /&gt;ldap.synchronization.groupDifferentialQuery=(&amp;amp;(objectclass\=group)(!(whenChanged&amp;lt;\={0})))&lt;BR /&gt;###ldap.synchronization.groupDifferentialQuery=(objectclass\=group)&lt;BR /&gt;###ldap.synchronization.personQuery=(&amp;amp;(objectclass\=user)(userAccountControl\:1.2.840.113556.1.4.803\:\=512))&lt;BR /&gt;ldap.synchronization.personDifferentialQuery=(&amp;amp;(objectclass\=user)(userAccountControl\:1.2.840.113556.1.4.803\:\=512)(!(whenChanged&amp;lt;\={0})))&lt;BR /&gt;###ldap.synchronization.personDifferentialQuery=(&amp;amp;(objectclass\=user)(userAccountControl\:1.2.840.113556.1.4.803\:\=512))&lt;BR /&gt;ldap.synchronization.groupSearchBase=ou\=GROUPS,dc\=MYDOMAIN,dc=LOC&lt;BR /&gt;ldap.synchronization.userSearchBase=ou\=USERS,dc\=MYDOMAIN,dc=LOC&lt;BR /&gt;&lt;BR /&gt;## fileserver subsystem&lt;BR /&gt;filesystem.name=NAME_OF_CIFS_SHARE&lt;BR /&gt;cifs.enabled=true&lt;BR /&gt;cifs.serverName=myServerName&lt;BR /&gt;cifs.domain=MYDOMAIN.LOC&lt;BR /&gt;cifs.hostannounce=false&lt;BR /&gt;##cifs.pseudoFiles.enabled=true&lt;BR /&gt;## turn off Desktop actions&lt;BR /&gt;cifs.pseudoFiles.enabled=false&lt;BR /&gt;cifs.pseudoFiles.explorerURL.enabled=false&lt;BR /&gt;cifs.pseudoFiles.explorerURL.fileName=__Alfresco.url&lt;BR /&gt;cifs.pseudoFiles.shareURL.enabled=false&lt;BR /&gt;cifs.pseudoFiles.shareURL.fileName=__Share.url&lt;BR /&gt;ftp.enabled=false&lt;BR /&gt;nfs.enabled=false&lt;BR /&gt;&lt;BR /&gt;### AUTH &amp;amp; SYNC ###&lt;BR /&gt;authentication.chain=kerberos1:kerberos,my-domain:ldap-ad,alfrescoNtlm1:alfrescoNtlm&lt;BR /&gt;### LDAP SYNC SUBSYSTEM ###&lt;BR /&gt;# startup and authent sync process always is differential mode sync mode (if false, sync is in full mode):&lt;BR /&gt;synchronization.synchronizeChangesOnly=true&lt;BR /&gt;&lt;BR /&gt;# The cron expression defining when imports should take place&lt;BR /&gt;## Synchro toutes les 30 minutes&lt;BR /&gt;synchronization.import.cron=0 0/15 * * * ?&lt;BR /&gt;&lt;BR /&gt;synchronization.syncWhenMissingPeopleLogIn=true&lt;BR /&gt;# Should we trigger a differential sync on startup?&lt;BR /&gt;synchronization.syncOnStartup=true&lt;BR /&gt;&lt;BR /&gt;synchronization.allowDeletions=true&lt;BR /&gt;## disable home folders creation&lt;BR /&gt;ldap.synchronization.defaultHomeFolderProvider=companyHomeFolderProvider&lt;BR /&gt;&lt;BR /&gt;## KERBEROS&lt;BR /&gt;kerberos.authentication.realm=MYDOMAIN.LOC&lt;BR /&gt;kerberos.authentication.authenticateCIFS=true&lt;BR /&gt;kerberos.authentication.sso.enabled=false&lt;BR /&gt;&lt;BR /&gt;kerberos.authentication.user.configEntryName=Alfresco&lt;BR /&gt;kerberos.authentication.defaultAdministratorUserNames=administrator&lt;BR /&gt;&lt;BR /&gt;kerberos.authentication.cifs.configEntryName=Alfresco5-CIFS // should match JAAS config entry and AD account&lt;BR /&gt;kerberos.authentication.cifs.password=userPassword&lt;BR /&gt;&lt;BR /&gt;kerberos.authentication.http.configEntryName=Alfresco5-HTTP&amp;nbsp; // should match JAAS config entry and AD account&lt;BR /&gt;kerberos.authentication.http.password=userPassword&lt;BR /&gt;kerberos.authentication.browser.ticketLogons=true&lt;BR /&gt;kerberos.authentication.stripUsernameSuffix=true&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Apr 2015 21:13:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292191#M245321</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2015-04-29T21:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292192#M245322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;HI Vincent,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Sorry for the late reply, but I was out of office.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm not sure how to use those:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;## fileserver subsystem&lt;BR /&gt;filesystem.name=NAME_OF_CIFS_SHARE&lt;BR /&gt;cifs.enabled=true&lt;BR /&gt;cifs.serverName=myServerName&lt;BR /&gt;cifs.domain=MYDOMAIN.LOC&lt;BR /&gt;cifs.hostannounce=false&lt;BR /&gt;##cifs.pseudoFiles.enabled=true&lt;BR /&gt;## turn off Desktop actions&lt;BR /&gt;cifs.pseudoFiles.enabled=false&lt;BR /&gt;cifs.pseudoFiles.explorerURL.enabled=false&lt;BR /&gt;cifs.pseudoFiles.explorerURL.fileName=__Alfresco.url&lt;BR /&gt;cifs.pseudoFiles.shareURL.enabled=false&lt;BR /&gt;cifs.pseudoFiles.shareURL.fileName=__Share.url&lt;BR /&gt;ftp.enabled=false&lt;BR /&gt;nfs.enabled=false&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Would you please give me more details about them and how to use them correctly? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://connect.hyland.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;(I already tested with the configs, but nothing much happens, because I'm not sure what are the correct values of those properties.)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks a lot man!&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 May 2015 12:26:24 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292192#M245322</guid>
      <dc:creator>borisstankov</dc:creator>
      <dc:date>2015-05-08T12:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292193#M245323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;the most important is:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;filesystem.name=NAME_OF_CIFS_SHARE -&amp;gt; name of your CIFS share&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.enabled=true -&amp;gt; enable CIFS for Alfresco&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.serverName=myServerName -&amp;gt; the NetBIOS name of the CIFS server&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;cifs.domain=MYDOMAIN.LOC -&amp;gt; the domain name, must match your AD domain and kerberos realm&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;-&amp;gt; could you check your log when starting alfresco, and look for&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;'Startup of 'Authentication' subsystem…' and&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;'Starting 'fileServers' subsystem…'&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;try to access your alfresco using \\alfrescoServerName\NAME_OF_CIFS_SHARE &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;and check here for options: &lt;/SPAN&gt;&lt;A href="http://docs.alfresco.com/community/concepts/fileserv-subsystem-CIFS.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/community/concepts/fileserv-subsystem-CIFS.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Vincent&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 May 2015 12:36:23 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292193#M245323</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2015-05-12T12:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292194#M245324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have followed the documentation to set up kerberos for AD authentication .Your config files match with mine .There are no errors found in the log file&amp;nbsp; during startup of alfresco services.The web application is working fine.However when i access from windows 7 machine connected to AD(Microsoft 2008 R2&amp;nbsp; server)the CIFS shared folders i get an error as shown in the image. I have implemented Alfresco on Ubuntu server.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Any suggestions on this issue,and also please post your config files.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank You,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Sudheer &lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 May 2015 12:13:12 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292194#M245324</guid>
      <dc:creator>sudheer424</dc:creator>
      <dc:date>2015-05-23T12:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: alfresco 5.0c and kerberos</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292195#M245325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;When you say "windows 7 machine connected to AD" you mean integrated in a 2008 R2 AD domain ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you please post the Catalina.out trace when error occurs ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you please confirm that you have kerberos enabled for CIFS ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Did you check that the KVNO set in your keytab file is matching the service account in AD ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Vincent&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 May 2015 19:21:10 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0c-and-kerberos/m-p/292195#M245325</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2015-05-26T19:21:10Z</dc:date>
    </item>
  </channel>
</rss>

