<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Kerberos SSO with FQDN in Firefox in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93031#M27538</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/80184"&gt;@Zhoel&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;I'm not sure if you've seen this &lt;A href="https://hub.alfresco.com/t5/alfresco-content-services-forum/problems-on-configuring-sso-kerberos-against-active-directory/td-p/7167" target="_self" rel="nofollow noopener noreferrer"&gt;thread&lt;/A&gt;, but there is some useful information about debugging kerberos &amp;amp; FQDN.&lt;/P&gt;
&lt;P&gt;HTH,&lt;/P&gt;</description>
    <pubDate>Wed, 04 Mar 2020 09:35:13 GMT</pubDate>
    <dc:creator>EddieMay</dc:creator>
    <dc:date>2020-03-04T09:35:13Z</dc:date>
    <item>
      <title>Kerberos SSO with FQDN in Firefox</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93029#M27536</link>
      <description>&lt;P&gt;When i enter alfresco site with FQDN i get sso fallback to prompt hostname and password.&lt;/P&gt;&lt;P&gt;If i use just hostname, SSO works in Firefox&lt;/P&gt;&lt;P&gt;Chrome works in both ways&lt;/P&gt;&lt;P&gt;Is it firefox related case?&lt;/P&gt;&lt;P&gt;Log:&lt;/P&gt;&lt;P&gt;SEVERE: Servlet.service() for servlet [wcapiServlet] in context with path [/alfresco] threw exception&lt;BR /&gt;org.alfresco.rest.framework.core.exceptions.NotFoundException: 02040001 /sites/query not found&lt;BR /&gt;at org.alfresco.rest.api.PublicApiDeclarativeRegistry.findWebScript(PublicApiDeclarativeRegistry.java:250)&lt;BR /&gt;at org.alfresco.repo.webdav.auth.BaseSSOAuthenticationFilter.doFilter(BaseSSOAuthenticationFilter.java:204)&lt;BR /&gt;at jdk.internal.reflect.GeneratedMethodAccessor475.invoke(Unknown Source)&lt;BR /&gt;at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)&lt;BR /&gt;at java.base/java.lang.reflect.Method.invoke(Method.java:566)&lt;BR /&gt;at org.alfresco.repo.management.subsystems.ChainingSubsystemProxyFactory$1.invoke(ChainingSubsystemProxyFactory.java:119)&lt;BR /&gt;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:186)&lt;BR /&gt;at org.springframework.aop.framework.JdkDynamicAopProxy.invoke(JdkDynamicAopProxy.java:212)&lt;BR /&gt;at com.sun.proxy.$Proxy150.doFilter(Unknown Source)&lt;BR /&gt;at org.alfresco.repo.web.filter.beans.BeanProxyFilter.doFilter(BeanProxyFilter.java:89)&lt;BR /&gt;at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)&lt;BR /&gt;at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)&lt;BR /&gt;at org.alfresco.web.app.servlet.WebScriptSSOAuthenticationFilter.doFilter(WebScriptSSOAuthenticationFilter.java:124)&lt;BR /&gt;at jdk.internal.reflect.GeneratedMethodAccessor475.invoke(Unknown Source)&lt;BR /&gt;at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)&lt;BR /&gt;at java.base/java.lang.reflect.Method.invoke(Method.java:566)&lt;BR /&gt;at org.alfresco.repo.management.subsystems.ChainingSubsystemProxyFactory$1.invoke(ChainingSubsystemProxyFactory.java:119)&lt;BR /&gt;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:186)&lt;BR /&gt;at org.springframework.aop.framework.JdkDynamicAopProxy.invoke(JdkDynamicAopProxy.java:212)&lt;BR /&gt;at com.sun.proxy.$Proxy150.doFilter(Unknown Source)&lt;BR /&gt;at org.alfresco.repo.web.filter.beans.BeanProxyFilter.doFilter(BeanProxyFilter.java:89)&lt;BR /&gt;at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)&lt;BR /&gt;at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)&lt;BR /&gt;at org.alfresco.web.app.servlet.WebscriptCookieAuthenticationFilter.doFilter(WebscriptCookieAuthenticationFilter.java:77)&lt;BR /&gt;at jdk.internal.reflect.GeneratedMethodAccessor475.invoke(Unknown Source)&lt;BR /&gt;at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)&lt;BR /&gt;at java.base/java.lang.reflect.Method.invoke(Method.java:566)&lt;BR /&gt;at org.alfresco.repo.management.subsystems.ChainingSubsystemProxyFactory$1.invoke(ChainingSubsystemProxyFactory.java:132)&lt;BR /&gt;at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:186)&lt;BR /&gt;at org.springframework.aop.framework.JdkDynamicAopProxy.invoke(JdkDynamicAopProxy.java:212)&lt;BR /&gt;at com.sun.proxy.$Proxy150.doFilter(Unknown Source)&lt;BR /&gt;at org.alfresco.repo.web.filter.beans.BeanProxyFilter.doFilter(BeanProxyFilter.java:89)&lt;BR /&gt;at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)&lt;BR /&gt;at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)&lt;BR /&gt;at org.alfresco.web.app.servlet.GlobalLocalizationFilter.doFilter(GlobalLocalizationFilter.java:68)&lt;BR /&gt;at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)&lt;BR /&gt;at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)&lt;BR /&gt;at org.alfresco.web.app.servlet.ClearSecurityContextFilter.doFilter(ClearSecurityContextFilter.java:53)&lt;BR /&gt;at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:193)&lt;BR /&gt;at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:166)&lt;BR /&gt;at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:200)&lt;BR /&gt;at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:96)&lt;BR /&gt;at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:543)&lt;BR /&gt;at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:139)&lt;BR /&gt;at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:81)&lt;BR /&gt;at org.apache.catalina.valves.AbstractAccessLogValve.invoke(AbstractAccessLogValve.java:678)&lt;BR /&gt;at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:87)&lt;BR /&gt;at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:343)&lt;BR /&gt;at org.apache.coyote.http11.Http11Processor.service(Http11Processor.java:609)&lt;BR /&gt;at org.apache.coyote.AbstractProcessorLight.process(AbstractProcessorLight.java:65)&lt;BR /&gt;at org.apache.coyote.AbstractProtocol$ConnectionHandler.process(AbstractProtocol.java:810)&lt;BR /&gt;at org.apache.tomcat.util.net.NioEndpoint$SocketProcessor.doRun(NioEndpoint.java:1623)&lt;BR /&gt;at org.apache.tomcat.util.net.SocketProcessorBase.run(SocketProcessorBase.java:49)&lt;BR /&gt;at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128)&lt;BR /&gt;at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628)&lt;BR /&gt;at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)&lt;BR /&gt;at java.base/java.lang.Thread.run(Thread.java:834)&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 06:42:45 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93029#M27536</guid>
      <dc:creator>Zhoel</dc:creator>
      <dc:date>2020-03-04T06:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO with FQDN in Firefox</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93030#M27537</link>
      <description>&lt;P&gt;Also SSO doesnt work until i log in on chrome&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 07:20:56 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93030#M27537</guid>
      <dc:creator>Zhoel</dc:creator>
      <dc:date>2020-03-04T07:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO with FQDN in Firefox</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93031#M27538</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/80184"&gt;@Zhoel&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;I'm not sure if you've seen this &lt;A href="https://hub.alfresco.com/t5/alfresco-content-services-forum/problems-on-configuring-sso-kerberos-against-active-directory/td-p/7167" target="_self" rel="nofollow noopener noreferrer"&gt;thread&lt;/A&gt;, but there is some useful information about debugging kerberos &amp;amp; FQDN.&lt;/P&gt;
&lt;P&gt;HTH,&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 09:35:13 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93031#M27538</guid>
      <dc:creator>EddieMay</dc:creator>
      <dc:date>2020-03-04T09:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO with FQDN in Firefox</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93032#M27539</link>
      <description>&lt;P&gt;Yeah ive seen that post. I follow check list, but all was fine. I will be using hostname instead FQDN thats no problem&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 09:51:52 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93032#M27539</guid>
      <dc:creator>Zhoel</dc:creator>
      <dc:date>2020-03-04T09:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO with FQDN in Firefox</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93033#M27540</link>
      <description>&lt;P&gt;I added nginx reverse proxy. Chrome (and even IE) works fine, but Firefox&lt;/P&gt;&lt;P&gt;ERROR [alfresco.web.site] [http-nio-8080-exec-1] javax.servlet.ServletException: Possible CSRF attack noted when asserting referer header '&lt;A href="https://alf601.clinic.odb45.ru/share/page?pt=login" target="_blank" rel="nofollow noopener noreferrer"&gt;https://alf601.clinic.odb45.ru/share/page?pt=login&lt;/A&gt;'. Request: POST /share/page/dologin, FAILED TEST: Assert referer POST /share/page/dologin :: referer: '&lt;A href="https://alf601.clinic.odb45.ru/share/page?pt=login" target="_blank" rel="nofollow noopener noreferrer"&gt;https://alf601.clinic.odb45.ru/share/page?pt=login&lt;/A&gt;' vs server &amp;amp; context: &lt;A href="http://alf601.clinic.odb45.ru/" target="_blank" rel="nofollow noopener noreferrer"&gt;http://alf601.clinic.odb45.ru/&lt;/A&gt; (string) or (regexp)&lt;/P&gt;&lt;P&gt;If i use hostname in link, sso works and no error in log. Dirty black magic&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 08:48:22 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93033#M27540</guid>
      <dc:creator>Zhoel</dc:creator>
      <dc:date>2020-03-05T08:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: Kerberos SSO with FQDN in Firefox</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93034#M27541</link>
      <description>&lt;P&gt;So it seems ther is misconfiguration in official doc for 6.0. I did conf like &lt;IMG src="https://docs.alfresco.com/sites/docs.alfresco.com/files/public/images/docs/default6_0/auth-kerberos-clientconfig.png" border="0" /&gt;&lt;/P&gt;&lt;P&gt;And sso works only for hostname. Now i made chage in GPO user-adm template-mozilla-firefox-authentication:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Delegated - i enter &lt;A href="http://alf601.clinic.odb45.ru:8080" target="_blank" rel="nofollow noopener noreferrer"&gt;http://alf601.clinic.odb45.ru:8080&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;NTLM i did as 1&lt;/LI&gt;&lt;LI&gt;SPNEGO i did as 1&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Now i can do SSO in firefox with fqnd&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2020 09:56:38 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/kerberos-sso-with-fqdn-in-firefox/m-p/93034#M27541</guid>
      <dc:creator>Zhoel</dc:creator>
      <dc:date>2020-03-05T09:56:38Z</dc:date>
    </item>
  </channel>
</rss>

