<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Kerberos issue Client sent an NTLMSSP security blob not able to SSO in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-issue-client-sent-an-ntlmssp-security-blob-not-able-to/m-p/292490#M245620</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Forum ,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;i am setting kerberos authentication .&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;In my logs i am able to see&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt; INFO&amp;nbsp; [management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Starting 'Authentication' subsystem, ID: [Authentication, managed, kerberos1]&lt;BR /&gt; 2015-02-09 10:52:19,943&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [localhost-startStop-1] HTTP Kerberos login successful&lt;BR /&gt;&lt;BR /&gt; &lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;But when I login from client it prompts for Windows pop up for login.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I want to achieve SSO with kerberos to both Explorer and Share.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Below is my configuration&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have refereed below link for kerberos configuration&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://www.anotherstrangerme.com/afresco-integration-with-active-directory-using-kerberos/" rel="nofollow noopener noreferrer"&gt;http://www.anotherstrangerme.com/afresco-integration-with-active-directory-using-kerberos/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Step 1: Created two accounts in AD AlfresoHTTP and AlfrescoCIFS with settings given in link above.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Step 2: used ktpass command&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;blockcode&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ktpass -princ cifs/&amp;lt;cifs-server-name&amp;gt;.&amp;lt;domain&amp;gt;@&amp;lt;realm&amp;gt; -pass &amp;lt;password&amp;gt; -mapuser &amp;lt;domainnetbios&amp;gt;\alfrescocifs -crypto DES-CBC-MD5 -ptype KRB5_NT_PRINCIPAL -mapop set +desonly -out c:\temp\alfrescocifs.keytab&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ktpass -princ HTTP/&amp;lt;web-server-name&amp;gt;.&amp;lt;domain&amp;gt;@&amp;lt;realm&amp;gt; -pass &amp;lt;password&amp;gt; -mapuser &amp;lt;domainnetbios&amp;gt;\alfrescohttp -crypto DES-CBC-MD5 -ptype KRB5_NT_PRINCIPAL -mapop set +desonly -out c:\temp\alfrescohttp.keytab&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;/blockcode&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please note I have used -crypto DES-CBC-MD5&amp;nbsp; will this really matters??am i right here?can i use this??Please suggest right approach.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Step 3: krb5.ini&amp;nbsp; (ini file as i am doing it on windows server 2008 R2 )&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;[libdefaults]&lt;BR /&gt;default_realm = ALFRESCO.ORG&lt;BR /&gt;[realms]&lt;BR /&gt;ALFRESCO.ORG = {&lt;BR /&gt;kdc = adsrv.alfresco.org&lt;BR /&gt;admin_server = adsrv.alfresco.org&lt;BR /&gt;}&lt;BR /&gt;[domain_realm]&lt;BR /&gt;adsrv.alfresco.org = ALFRESCO.ORG&lt;BR /&gt;.adsrv.alfresco.org = ALFRESCO.ORG&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;SPAN&gt; with my appropriate settings&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;But here i have not mentioned &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;default_tkt_enctypes =&amp;nbsp; and&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;default_tgs_enctypes =&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;i tried with using DES-CBC-MD5 but it did not work&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;step 4 :&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;Alfresco {&lt;BR /&gt;com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;BR /&gt;};&lt;BR /&gt;AlfrescoCIFS {&lt;BR /&gt;com.sun.security.auth.module.Krb5LoginModule required&lt;BR /&gt;storeKey=true&lt;BR /&gt;useKeyTab=true&lt;BR /&gt;keyTab=”C:/temp/alfrescocifs.keytab”&lt;BR /&gt;principal=”cifs/&amp;lt;cifs-server-name&amp;gt;.&amp;lt;domain&amp;gt;”;&lt;BR /&gt;};&lt;BR /&gt;AlfrescoHTTP {&lt;BR /&gt;com.sun.security.auth.module.Krb5LoginModule required&lt;BR /&gt;storeKey=true&lt;BR /&gt;useKeyTab=true&lt;BR /&gt;keyTab=”C:/temp/alfrescohttp.keytab”&lt;BR /&gt;principal=”HTTP/&amp;lt;web-server-name&amp;gt;.&amp;lt;domain&amp;gt;”;&lt;BR /&gt;};&lt;BR /&gt;com.sun.net.ssl.client {&lt;BR /&gt;com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;BR /&gt;};&lt;BR /&gt;other {&lt;BR /&gt;com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;BR /&gt;}&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;step 5: in JRE\lib\security\java.security.&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;login.config.url.1=file:C:/Alfresco/java/jre/lib/security/java.login.config &lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;and chain as below:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication.chain=kerberos1:kerberos,ldap1:ldap-ad&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;My Qproblem :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;1) not able to SSO on Alfresco ( Share not yet configured )&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2) On attempt to login with link&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://server-name:8080/alfresco/" rel="nofollow noopener noreferrer"&gt;http://server-name:8080/alfresco/&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;It prompt me windows login screen and then alfresco login screen if my password is correct.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;My Log says as bwlow :&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt; 2015-02-09 10:54:36,959&amp;nbsp; INFO&amp;nbsp; [site.servlet.SSOAuthenticationFilter] [localhost-startStop-1] SSOAuthenticationFilter initialised.&lt;BR /&gt; 2015-02-09 10:55:39,407&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-3] New Kerberos auth request from 10.0.2.22 (10.0.2.22:60268)&lt;BR /&gt; 2015-02-09 10:55:39,407&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-3] Issuing login challenge to browser.&lt;BR /&gt; 2015-02-09 10:55:39,438&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-4] Client sent an NTLMSSP security blob&lt;BR /&gt; 2015-02-09 10:55:39,438&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-4] Clearing session.&lt;BR /&gt; 2015-02-09 10:55:39,438&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-4] Issuing login challenge to browser.&lt;BR /&gt; 2015-02-09 10:56:06,785&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-6] Login page requested, chaining …&lt;BR /&gt; 2015-02-09 10:56:07,503&amp;nbsp; DEBUG [app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-8] Authentication not required (filter), chaining …&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;version using 4.2e&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Please help me to understand and to solve where i am going wrong&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Please let me know if any other information is required.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Feb 2015 05:52:54 GMT</pubDate>
    <dc:creator>aditya_chaudhar</dc:creator>
    <dc:date>2015-02-09T05:52:54Z</dc:date>
    <item>
      <title>Kerberos issue Client sent an NTLMSSP security blob not able to SSO</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-issue-client-sent-an-ntlmssp-security-blob-not-able-to/m-p/292490#M245620</link>
      <description>Hi Forum ,i am setting kerberos authentication .In my logs i am able to see INFO&amp;nbsp; [management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Starting 'Authentication' subsystem, ID: [Authentication, managed, kerberos1] 2015-02-09 10:52:19,943&amp;nbsp; DEBUG [app.servlet.KerberosAuthentic</description>
      <pubDate>Mon, 09 Feb 2015 05:52:54 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-issue-client-sent-an-ntlmssp-security-blob-not-able-to/m-p/292490#M245620</guid>
      <dc:creator>aditya_chaudhar</dc:creator>
      <dc:date>2015-02-09T05:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos issue Client sent an NTLMSSP security blob not able to SSO</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-issue-client-sent-an-ntlmssp-security-blob-not-able-to/m-p/292491#M245621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Forum,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have configured Kerberos Authentication with SSO on explorer and share.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I was stuck at above mentioned error.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;i.e&amp;nbsp; Client sent an NTLMSSP security blob&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I change one property in AD .&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;the Use DES encryption types for this account&amp;nbsp; is unchecked. And few related settings and all works great.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;After a week of struggle i able to configure this , i feel like happiest person on the earth when i achieve this.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks to forum all comments here helps a lot.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Feel free to ask me if you want all my configuration . I would be happy to help you.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks and Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Aditya C Chaudhari&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2015 11:42:45 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-issue-client-sent-an-ntlmssp-security-blob-not-able-to/m-p/292491#M245621</guid>
      <dc:creator>aditya_chaudhar</dc:creator>
      <dc:date>2015-02-12T11:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos issue Client sent an NTLMSSP security blob not able to SSO</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-issue-client-sent-an-ntlmssp-security-blob-not-able-to/m-p/292492#M245622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Aditya,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please let us know what configuration changes are required on AD side and how can we achieve that.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Supriya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2019 09:49:32 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-issue-client-sent-an-ntlmssp-security-blob-not-able-to/m-p/292492#M245622</guid>
      <dc:creator>supriya_verma</dc:creator>
      <dc:date>2019-04-17T09:49:32Z</dc:date>
    </item>
  </channel>
</rss>

