<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Kerberos SSO for Share (and Alfresco) struggles in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311974#M265104</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi folks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm looking for some help on this subject really, and any assistance is greatly appreciated.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I basically followed the instructions in the below guides to get to the position I am currently in now:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://docs.alfresco.com/4.0/tasks/auth-kerberos-ADconfig.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/4.0/tasks/auth-kerberos-ADconfig.html&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://docs.alfresco.com/4.0/tasks/auth-kerberos-shareSSO.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/4.0/tasks/auth-kerberos-shareSSO.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Firstly I should start my saying my knowledge of Alfresco ranges between none and very little (remove "of Alfresco" from that statement and the same could still be said!) but I've been tasked with configuring Kerberos SSO for Share and Alfresco web apps. So imagine my surprise when I actually managed to get it working, quickly followed by my dismay when it suddenly decided to stop working. I've read over a number of other posts where people are experiencing similar issues but have not found anything that has helped to resolve my issue as yet.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Current state of affairs - When browsing (in both Chrome and IE) to /alfresco or /share, a credentials dialog box now appears, which when cancelled takes me to the respective app login page where I am able to log in using Windows credentials. Previously I would be logged straight into the app without any prompts - the only thing I know to have changed from the working config is a new keytab file was created, although this does appears to authenticate properly ("kinit -k -t…" comes back successful).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Our environment looks something like the below:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Alfresco Community Edition 4.0.d (running on Ubuntu 12.04 LTS)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Java 7 (OpenJDK 7)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Server 2008 R2 Active Directory Domain Controller&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have enabled Kerberos debugging but the Alfresco.log isn't really forthcoming with any useful information (to me at least) so I was wondering how else I can find the root cause of this problem?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Unfortunately I'm unable to attach files so I have reluctantly pasted below various config/log files (or extracts), having removed actual config specific to our environment.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;###alfresco-global.properties:###&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#Authentication Chain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;authentication.chain=kerberos1:kerberos,dc1:ldap-ad,alfinst:alfrescoNtlm&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ntlm.authentication.sso.enabled=false&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;###kerberos-authentication.properties###&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.realm=DOMAIN.LOCAL&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.sso.enabled=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.authenticateCIFS=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.user.configEntryName=Alfresco&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.cifs.password=&amp;lt;Password&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.cifs.configEntryName=AlfrescoCIFS&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.stripUsernameSuffix=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.http.password=&amp;lt;Password&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.http.configEntryName=AlfrescoHTTP&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.defaultAdministratorUserNames=admin,administrator&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;kerberos.authentication.browser.ticketLogons=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;###krb5.conf###&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;[libdefaults]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;default_realm = &amp;lt;MYDOMAIN.LOCAL&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;# The following krb5.conf variables are only for MIT Kerberos.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;krb4_config = /etc/krb.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;krb4_realms = /etc/krb.realms&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;kdc_timesync = 1&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;ccache_type = 4&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;forwardable = true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;proxiable = true&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;default_tgs_enctypes = arcfour-hmac-md5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;default_tkt_enctypes = arcfour-hmac-md5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;permitted_enctypes = arcfour-hmac-md5&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;# The following libdefaults parameters are only for Heimdal Kerberos.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;v4_instance_resolve = false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;v4_name_convert = {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;host = {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;rcmd = host&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;ftp = ftp&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;plain = {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;something = something-else&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;fcc-mit-ticketflags = true&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[realms]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;MYDOMAIN.LOCAL&amp;gt; = {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;kdc = &amp;lt;domaincontroller.mydomain.local&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;admin_server = &amp;lt;domaincontroller.mydomain.local&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;default_domain = &amp;lt;MYDOMAIN.LOCAL&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;}&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[domain_realm]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;.&amp;lt;mydomain.local&amp;gt; = &amp;lt;MYDOMAIN.LOCAL&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;mydomain.local&amp;gt; = &amp;lt;MYDOMAIN.LOCAL&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;###java.security###&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;login.config.url.1=file:${java.home}/lib/security/java.login.config&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;###java.login###&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Alfresco {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;AlfrescoCIFS {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; storeKey=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; keyTab="/etc/keys/cifs&amp;lt;server FQDN&amp;gt;.keytab"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; principal="cifs/cifs&amp;lt;server FQDN&amp;gt;";&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ShareHTTP {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; storeKey=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; keyTab="/etc/keys/http&amp;lt;server FQDN&amp;gt;.keytab"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; principal="HTTP/&amp;lt;server FQDN&amp;gt;";&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;AlfrescoHTTP {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; storeKey=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; keyTab="/etc/keys/http&amp;lt;server FQDN&amp;gt;.keytab"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; principal="HTTP/&amp;lt;server FQDN&amp;gt;";&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;com.sun.net.ssl.client {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;other {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule sufficient;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;};&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;###share-config-custom.xml###&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &amp;lt;!– Kerberos settings –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &amp;lt;!– To enable kerberos rename this condition to "Kerberos" –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &amp;lt;config evaluator="string-compare" condition="Kerberos" replace="true"&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;kerberos&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!–&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Password for HTTP service account.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The account name *must* be built from the HTTP server name, in the format :&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP/&amp;lt;server_name&amp;gt;@&amp;lt;realm&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (NB this is because the web browser requests an ST for the&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HTTP/&amp;lt;server_name&amp;gt; principal in the current realm, so if we're to decode&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; that ST, it has to match.)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;password&amp;gt;Password&amp;lt;/password&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!–&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Kerberos realm and KDC address.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;realm&amp;gt;MYDOMAIN.LOCAL&amp;lt;/realm&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!–&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service Principal Name to use on the repository tier.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This must be like: HTTP/host.name@REALM&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;endpoint-spn&amp;gt;HTTP/serverFQDN@MYDOMAIN.LOCAL&amp;lt;/endpoint-spn&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!–&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; JAAS login configuration entry name.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;config-entry&amp;gt;ShareHTTP&amp;lt;/config-entry&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/kerberos&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &amp;lt;/config&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;!– example port config used to access remote Alfresco server (default is 8080) –&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I also uncommented the two following "&amp;lt;config evaluator="string-compare" condition="Remote"&amp;gt;" sections in this file.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;###Alfresco.log###&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:25:00,559 INFO&amp;nbsp; [org.apache.chemistry.opencmis.browser.BrowseServlet] Allow pattern: http.*&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:26:54,832 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] HTTP Kerberos login successful&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:26:54,833 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Logged on using principal HTTP/server.mydomain.local@MYDOMAIN.LOCAL&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:26:54,845 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:26:54,891 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:26:54,917 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:26:54,935 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] New Kerberos auth request from 127.0.0.1 (127.0.0.1:39732)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:12,794 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] New Kerberos auth request from 127.0.0.1 (127.0.0.1:38034)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:12,804 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] New Kerberos auth request from 127.0.0.1 (127.0.0.1:47490)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:12,816 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:12,854 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:12,868 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:13,647 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:13,661 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:13,714 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] New Kerberos auth request from 127.0.0.1 (127.0.0.1:49959)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:13,720 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] New Kerberos auth request from 127.0.0.1 (127.0.0.1:57950)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:14,185 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:14,199 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:14,220 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Authentication not required (filter), chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:14,742 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] New Kerberos auth request from 127.0.0.1 (127.0.0.1:49811)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:14,749 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] New Kerberos auth request from 127.0.0.1 (127.0.0.1:49266)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:43,509 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] New Kerberos auth request from 127.0.0.1 (127.0.0.1:57304)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:43,513 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] New Kerberos auth request from 127.0.0.1 (127.0.0.1:58560)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:48,110 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] New Kerberos auth request from x.x.x.x (x.x.x.x:38935)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:48,115 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Client sent an NTLMSSP security blob **prompted in browser for domain credentials at this point**&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;15:27:52,152 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Login page requested, chaining …&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Apologies for the information overload! Again, thanks to anyone who takes the time to look at this, it's a real pain.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;John&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Nov 2014 18:57:30 GMT</pubDate>
    <dc:creator>john_pen</dc:creator>
    <dc:date>2014-11-10T18:57:30Z</dc:date>
    <item>
      <title>Kerberos SSO for Share (and Alfresco) struggles</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311974#M265104</link>
      <description>Hi folks,I'm looking for some help on this subject really, and any assistance is greatly appreciated.I basically followed the instructions in the below guides to get to the position I am currently in now:http://docs.alfresco.com/4.0/tasks/auth-kerberos-ADconfig.htmlhttp://docs.alfresco.com/4.0/tasks</description>
      <pubDate>Mon, 10 Nov 2014 18:57:30 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311974#M265104</guid>
      <dc:creator>john_pen</dc:creator>
      <dc:date>2014-11-10T18:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO for Share (and Alfresco) struggles</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311975#M265105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I noticed this in your file:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;keyTab="/etc/keys/http.keytab"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;If you look here:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems#Kerberos" rel="nofollow noopener noreferrer"&gt;http://wiki.alfresco.com/wiki/Alfresco_Authentication_Subsystems#Kerberos&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;An example is keyTab="/etc/alfrescohttp.keytab"&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So you have a folder in between were the file should be???&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Just an idea.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I myself have tried and failed to get Kerberos to work, so i know little about this software also. All i got working was passthru &amp;amp; LDAP-AD.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Nov 2014 03:07:23 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311975#M265105</guid>
      <dc:creator>sab</dc:creator>
      <dc:date>2014-11-20T03:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO for Share (and Alfresco) struggles</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311976#M265106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have tried and implemented Kerberos successfully . It works.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;John ,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Pricipal can not be just HTTP/&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It should be like below &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;AlfrescoHTTP {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; storeKey=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; keyTab="/etc/keys/prod_int_merged.keytab"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; principal="HTTP/edms.deltads.ent";&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; };&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; ShareHTTP {&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; com.sun.security.auth.module.Krb5LoginModule required&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; storeKey=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; useKeyTab=true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; keyTab="/etc/keys/prod_int_merged.keytab"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; principal="HTTP/edms.deltads.ent";&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; };&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Http/servername&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Dec 2014 18:20:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311976#M265106</guid>
      <dc:creator>swatnew1</dc:creator>
      <dc:date>2014-12-01T18:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO for Share (and Alfresco) struggles</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311977#M265107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Sab,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Firstly thanks for taking the time to reply, I appreciate it. Secondly, apologies for the delayed response.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Yes, the keytab files are stored in '/etc/keys/', but as long as the keytabs can be found in the path specified in the java.login.config file I don't think this is the issue. Kerberos SSO was working with this config but for the life of me I can't find what has changed to break it. That said, I'm completely out of ideas at this point so I'm willing to try anything.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;John&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Dec 2014 10:48:52 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311977#M265107</guid>
      <dc:creator>john_pen</dc:creator>
      <dc:date>2014-12-03T10:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO for Share (and Alfresco) struggles</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311978#M265108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Swatnew1,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for your response, again it's greatly appreciated.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Sorry - I've removed a number of references to our domain/network from the config files but overlooked the fact I hadn't padded out the principal with some dummy info. The principals are actually more like 'principal="HTTP/servername.domain.local"' and "cifs/servername.domain.local". These point at the users/SPN's created in Active Directory and keytab authentication against these principals (using kinit command in Ubuntu) is successful.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I also did have kerberos SSO working for a brief period of time and as far as I can tell nothing has changed in terms of config, but now I get a basic authentication prompt from the browser (IE or Chrome) when accessing alfresco and share sites.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Dec 2014 11:00:22 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311978#M265108</guid>
      <dc:creator>john_pen</dc:creator>
      <dc:date>2014-12-03T11:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO for Share (and Alfresco) struggles</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311979#M265109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Did you have any luck in resolving this? We have hit the exact same problem (or if not,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;something very similar anyway). I would be interested to hear if you have found a solution.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Angelos&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Mar 2015 05:18:32 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311979#M265109</guid>
      <dc:creator>a_varvitsiotis</dc:creator>
      <dc:date>2015-03-24T05:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO for Share (and Alfresco) struggles</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311980#M265110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;…and it may help you, too, so I am giving out some hints here.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Your logs state that Kerberos is not attempted at all by your browser:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt; 15:27:48,110 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] New Kerberos auth request from x.x.x.x&amp;nbsp; (x.x.x.x:38935)&lt;BR /&gt; 15:27:48,115 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Client sent an NTLMSSP security blob&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;"Client sent an NTLMSSP security blob" means that the Authorize: HTTP header that your browser is sending&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;does not contain a Kerberos ticket, but instead an NTLMSSP protocol blob, containing negotiation data. The&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;next question is, why?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In order to debug this, you should use a sniffer like Wireshark to capture the conversation between your&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;client and your KDC/AS (your domain controller). Look for a possible failure when the client sends a&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;TGS-REQ request to the KDC/AS, asking for the service ticket to Alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In our case, we found that the culprit was a misconfiguration in the encrytpion types. I noticed that in&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;your krb5.conf, you allow only arcfour-hmac-md5, and it may be the case that one of your service accts&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;is using DES or some other encryption type.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In our case, DES was set for the service account (and that was dropped by the default security policies&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;of Windows 7). In your case it may be something similar, having to do with encryption types, but it can&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;equally well be a misspelling in the service name.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Alas, these misconfigurations seem to be common and it I could not find many good replies in forums&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(this one, stackoverflow or others). I hope this one will help you.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Angelos&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Mar 2015 04:20:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311980#M265110</guid>
      <dc:creator>a_varvitsiotis</dc:creator>
      <dc:date>2015-03-27T04:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO for Share (and Alfresco) struggles</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311981#M265111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Angelos,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Apologies for the delayed response. I'd given up checking on this post due to lack of replies, but I did manage to get kerberos SSO working in the end. However, it was not using Alfresco Community Edition 4.0.d mentioned in this post, as our development team made the decision to make use of Alfresco Community Edition 4.2.f instead. If you're not using the same version of Alfresco as ourselves, I'm not sure whether my config will work in your environment, but I did make some notes detailing the steps I took to configure SSO if you're interested. I'd have to clean them up a little, but I'd gladly send them to yourself if you want them. I'll check back on the post every now and again to see if you have replied.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;John&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Apr 2015 09:59:41 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311981#M265111</guid>
      <dc:creator>john_pen</dc:creator>
      <dc:date>2015-04-02T09:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO for Share (and Alfresco) struggles</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311982#M265112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Would you mind send me your settings for the Kerberos so I can check it? I'm having issues with it too, so I want to check the configurations. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://connect.hyland.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Apr 2015 07:57:37 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311982#M265112</guid>
      <dc:creator>borisstankov</dc:creator>
      <dc:date>2015-04-07T07:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO for Share (and Alfresco) struggles</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311983#M265113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Boris,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Apologies for the delay, I don't really check this post any longer. However attached is the contents of our /etc/krb5.conf. I had to rename the file ".txt" in order to upload it, if you need to open the file in a text editor use something like Notepad++, as Windows Notepad loses the formatting.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I've replaced any reference to our domain/server names, obviously you'll need to replace "DOMAIN.NAME" with your own domain information and reference your own domain controller, and note that some values are UPPER CASE. If you were looking for any other information please post a reply and I'll see if I can help.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 May 2015 11:53:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311983#M265113</guid>
      <dc:creator>john_pen</dc:creator>
      <dc:date>2015-05-13T11:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO for Share (and Alfresco) struggles</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311984#M265114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;SPAN style="border: 0px; font-weight: inherit; text-decoration: underline;"&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;Question:&amp;nbsp;NOT ABLE TO ESTABLISH SSO using Kerberos.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;&lt;SPAN style="border: 0px; font-weight: inherit; text-decoration: underline;"&gt;Environment Details&lt;/SPAN&gt;:&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;alfresco-community-installer-201611-EA-win-x64&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;Windows server 2008 R2 Standard.&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;*****&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="border: 0px; font-weight: inherit; text-decoration: underline;"&gt;Find all the files in the attachments&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;SPAN style="border: 0px; font-weight: inherit; text-decoration: underline;"&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;SPAN style="border: 0px; font-weight: inherit; text-decoration: underline;"&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;Steps Performed:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;1)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: #727174; background-color: #ffffff; border: 0px; font-weight: inherit;"&gt;created two LDAP users -&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color: #727174; background-color: #ffffff; border: 0px; font-weight: inherit;"&gt;name: AlfrescoHTTP,&lt;/SPAN&gt;&lt;SPAN style="color: #727174; background-color: #ffffff; border: 0px; font-weight: inherit;"&gt;&amp;nbsp;password:&amp;nbsp;***,&amp;nbsp;&lt;/SPAN&gt;name: AlfrescoCIFS, password: ***&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;2)&amp;nbsp;a&lt;SPAN style="border: 0px; font-weight: inherit;"&gt;)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;Enable&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;Password never expires.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;b)&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;Disable&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;User must change password at next logon.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;c) Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;Account&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tab and enable the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;Do not require Kerberos preauthentication&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;option in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;Account&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Options section.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; d)&lt;/SPAN&gt;&lt;SPAN class="" style="border: 0px; font-weight: inherit;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;In the user&amp;nbsp;&lt;SPAN style="border: 0px; font-weight: bold;"&gt;&lt;STRONG class="" style="border: 0px; font-weight: bold;"&gt;Delegation&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;tab, select the&amp;nbsp;&lt;SPAN style="border: 0px; font-weight: bold;"&gt;&lt;STRONG class="" style="border: 0px; font-weight: bold;"&gt;Trust this user for delegation to any service (Kerberos only)&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;check box.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;3) Created Keytab files for both users, kept at location C:\alf\ on server (aaa),&amp;nbsp;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;4) Created "krb5.ini" file on server (aaa) at location,&amp;nbsp;C:\Windows\&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;5) Created "java.login.config" file at location &amp;lt;install-path&amp;gt;:\Alfresco\instance\java\lib\security\&amp;nbsp;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;6) Edited "java.security" file at&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="border: 0px; font-weight: inherit;"&gt;&amp;lt;install-path&amp;gt;&lt;/SPAN&gt;:\Alfresco\instance\java\lib\security\ path and appended following,&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;login.config.url.1=file:${java.home}/lib/security/java.login.config&amp;nbsp;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;7) Edited alfresco-global.properties file.&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Edited share-config-custom.xml file.&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;9) Restarted the alfresco services.&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;SPAN style="border: 0px; font-weight: inherit; text-decoration: underline;"&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;Log Files:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;alfrescotomcat-stdout.2017-06-12.log&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;2017-06-12 12:34:36,168 INFO [alfresco.repo.admin] [localhost-startStop-1] Using database URL 'jdbc&lt;img id="smileytongue" class="emoticon emoticon-smileytongue" src="https://connect.hyland.com/i/smilies/16x16_smiley-tongue.png" alt="Smiley Tongue" title="Smiley Tongue" /&gt;ostgresql://localhost:5432/alfresco' with user 'alfresco'.&lt;BR /&gt;2017-06-12 12:34:36,168 INFO [alfresco.repo.admin] [localhost-startStop-1] Connected to database PostgreSQL version 9.4.4&lt;BR /&gt;2017-06-12 12:34:45,980 INFO [domain.schema.SchemaBootstrap] [localhost-startStop-1] Ignoring script patch (post-Hibernate): patch.db-V4.2-metadata-query-indexes&lt;BR /&gt;2017-06-12 12:34:45,980 INFO [domain.schema.SchemaBootstrap] [localhost-startStop-1] Ignoring script patch (post-Hibernate): patch.db-V5.1-metadata-query-indexes&lt;BR /&gt;2017-06-12 12:34:45,980 INFO [domain.schema.SchemaBootstrap] [localhost-startStop-1] Ignoring script patch (post-Hibernate): patch.db-V5.2-remove-jbpm-tables-from-db&lt;BR /&gt;2017-06-12 12:34:57,667 INFO [management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Starting 'Authentication' subsystem, ID: [Authentication, managed, kerberos1]&lt;BR /&gt;2017-06-12 12:34:57,902 DEBUG [app.servlet.KerberosAuthenticationFilter] [localhost-startStop-1] HTTP Kerberos login successful&lt;BR /&gt;&lt;SPAN style="border: 0px; font-weight: inherit;"&gt;2017-06-12 12:34:57,902 DEBUG [app.servlet.KerberosAuthenticationFilter] [localhost-startStop-1] Logged on using principal&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A class="" href="mailto:HTTP/HOST.comp.com@COMP.COM" style="color: #1e88e5; background-color: transparent; border: 0px; font-weight: inherit; padding: 1px 0px 1px calc(12px + 0.35ex);" rel="nofollow noopener noreferrer"&gt;HTTP/HOST.comp.com@COMP.COM&lt;/A&gt;&lt;BR /&gt;2017-06-12 12:34:57,933 DEBUG [webdav.auth.KerberosAuthenticationFilter] [localhost-startStop-1] HTTP Kerberos login successful&lt;BR /&gt;&lt;SPAN style="border: 0px; font-weight: inherit;"&gt;2017-06-12 12:34:57,933 DEBUG [webdav.auth.KerberosAuthenticationFilter] [localhost-startStop-1] Logged on using principal&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A class="" href="mailto:HTTP/DMUAT.edelcap.com@EDELCAP.COM" style="color: #1e88e5; background-color: transparent; border: 0px; font-weight: inherit; padding: 1px 0px 1px calc(12px + 0.35ex);" rel="nofollow noopener noreferrer"&gt;HTTP/HOST.comp.com@COMP.COM&lt;/A&gt;&lt;BR /&gt;2017-06-12 12:34:58,042 INFO [management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Startup of 'Authentication' subsystem, ID: [Authentication, managed, kerberos1] complete&lt;BR /&gt;2017-06-12 12:34:58,042 INFO [management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Starting 'Authentication' subsystem, ID: [Authentication, managed, ldap1]&lt;BR /&gt;2017-06-12 12:34:58,324 INFO [management.subsystems.ChildApplicationContextFactory] [localhost-startStop-1] Startup of 'Authentication' subsystem, ID: [Authentication, managed, ldap1] complete&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;Alfresco.log file&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;2017-06-12 17:05:21,669 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-3] New Kerberos auth request from 127.0.0.1 (127.0.0.1:57333)&lt;BR /&gt;2017-06-12 17:05:21,669 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-3] Issuing login challenge to browser.&lt;BR /&gt;2017-06-12 17:05:27,888 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-7] New Kerberos auth request from 127.0.0.1 (127.0.0.1:57341)&lt;BR /&gt;2017-06-12 17:05:27,888 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-7] Issuing login challenge to browser.&lt;BR /&gt;2017-06-12 17:05:28,044 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-12] New Kerberos auth request from 127.0.0.1 (127.0.0.1:57341)&lt;BR /&gt;2017-06-12 17:05:28,044 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-12] Issuing login challenge to browser.&lt;BR /&gt;2017-06-12 17:05:28,982 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-15] New Kerberos auth request from 127.0.0.1 (127.0.0.1:57339)&lt;BR /&gt;2017-06-12 17:05:28,982 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] [http-apr-8080-exec-15] Issuing login challenge to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="mailto:browser.@" style="color: #1e88e5; background-color: transparent; border: 0px; font-weight: inherit; padding: 1px 0px 1px calc(12px + 0.35ex);" rel="nofollow noopener noreferrer"&gt;browser.@#&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;STRONG style="border: 0px; font-weight: bold;"&gt;Question:&amp;nbsp;W&lt;SPAN style="color: #222222; background-color: #ffffff; border: 0px; font-weight: inherit;"&gt;ant to know whether the steps which are performed for Kerberso sso are correct or some more config need to be done. Not able to figure out from the logs files what is the exact error. How do I proceed further in investigating and establishing SSO.&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Jun 2017 08:37:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/kerberos-sso-for-share-and-alfresco-struggles/m-p/311984#M265114</guid>
      <dc:creator>tanmaysalve</dc:creator>
      <dc:date>2017-06-14T08:37:14Z</dc:date>
    </item>
  </channel>
</rss>

