<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 4.2e kerberos auth error in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/4-2e-kerberos-auth-error/m-p/307023#M260153</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Some updates:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm facing EXACTLY the problem described here: &lt;/SPAN&gt;&lt;A href="http://social.technet.microsoft.com/Forums/windowsserver/fr-FR/1fcca58d-ea35-423e-9c59-9c1329642e16/client-not-found-in-kerberos-database-while-getting-initial-credentials" rel="nofollow noopener noreferrer"&gt;http://social.technet.microsoft.com/Forums/windowsserver/fr-FR/1fcca58d-ea35-423e-9c59-9c1329642e16/client-not-found-in-kerberos-database-while-getting-initial-credentials&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Not an Alfresco Issue, but a Kerberos/Keytab issue.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;When creating a keytab file for a regular user using KTPASS.EXE on AD Contrl, everything is OK (tested using kinit from alfresco server)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;When creating a keytab for the service account HTTP/alfrescoserver.mydomain.local, the following error occurs:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt; kinit -V AlfrescoHTTP -k -t keys/AlfrescoHTTP.keytab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Using default cache: /tmp/krb5cc_0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Using principal: AlfrescoHTTP@MYDOMAIN.LOCAL&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Using keytab: keys/AlfrescoHTTP.keytab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; kinit: Key table entry not found while getting initial credentials&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The domain controller send back "PRINCIPAL UNKNOWN", but the SPN is correcly set.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;It seeam that the syntact "HTTP/myserver…." using "/" is not supported.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Did one of you implement kerberos auth against 2008R2 DC successfully ? &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Any idea ? &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank in advance&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Nov 2013 14:02:29 GMT</pubDate>
    <dc:creator>vincent-kali</dc:creator>
    <dc:date>2013-11-20T14:02:29Z</dc:date>
    <item>
      <title>4.2e kerberos auth error</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/4-2e-kerberos-auth-error/m-p/307022#M260152</link>
      <description>[Alfresco CE 4.2e on linux debian, MS2008R2 AD Ctrl]Hi,I'm trying to setup kerberos auth with MSAD / SSO for fileserver and HTTP.I'm always facing the same error when starting alfresco:&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; javax.security.auth.login.LoginException: Client not found in Kerberos database (6)I did the following:1) Cre</description>
      <pubDate>Tue, 19 Nov 2013 15:55:36 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/4-2e-kerberos-auth-error/m-p/307022#M260152</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2013-11-19T15:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: 4.2e kerberos auth error</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/4-2e-kerberos-auth-error/m-p/307023#M260153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Some updates:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm facing EXACTLY the problem described here: &lt;/SPAN&gt;&lt;A href="http://social.technet.microsoft.com/Forums/windowsserver/fr-FR/1fcca58d-ea35-423e-9c59-9c1329642e16/client-not-found-in-kerberos-database-while-getting-initial-credentials" rel="nofollow noopener noreferrer"&gt;http://social.technet.microsoft.com/Forums/windowsserver/fr-FR/1fcca58d-ea35-423e-9c59-9c1329642e16/client-not-found-in-kerberos-database-while-getting-initial-credentials&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Not an Alfresco Issue, but a Kerberos/Keytab issue.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;When creating a keytab file for a regular user using KTPASS.EXE on AD Contrl, everything is OK (tested using kinit from alfresco server)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;When creating a keytab for the service account HTTP/alfrescoserver.mydomain.local, the following error occurs:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;gt; kinit -V AlfrescoHTTP -k -t keys/AlfrescoHTTP.keytab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Using default cache: /tmp/krb5cc_0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Using principal: AlfrescoHTTP@MYDOMAIN.LOCAL&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Using keytab: keys/AlfrescoHTTP.keytab&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; kinit: Key table entry not found while getting initial credentials&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The domain controller send back "PRINCIPAL UNKNOWN", but the SPN is correcly set.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;It seeam that the syntact "HTTP/myserver…." using "/" is not supported.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Did one of you implement kerberos auth against 2008R2 DC successfully ? &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Any idea ? &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank in advance&lt;/SPAN&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Nov 2013 14:02:29 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/4-2e-kerberos-auth-error/m-p/307023#M260153</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2013-11-20T14:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: 4.2e kerberos auth error</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/4-2e-kerberos-auth-error/m-p/307024#M260154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I finally found the issues:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Duplicate UPN (I checked for duplicate SPN using setspn -X not for UPN. Finally did it using ldap query, and remove duplicates).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- Issue with ktpass using /mapuser option: this reset user password on 2008R2 DC (at least in my context); Then I had to map user manually, and run ktpass without this option.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Vincent&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 10:09:40 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/4-2e-kerberos-auth-error/m-p/307024#M260154</guid>
      <dc:creator>vincent-kali</dc:creator>
      <dc:date>2013-11-22T10:09:40Z</dc:date>
    </item>
  </channel>
</rss>

