10-27-2012 07:30 AM
12:38:33,471 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] New Kerberos auth request from 10.211.55.9 (10.211.55.9:1167)
12:38:33,473 ERROR [org.alfresco.fileserver] Error from JLAN
GSSException: Failure unspecified at GSS-API level (Mechanism level: Encryption type AES256 CTS mode with HMAC SHA1-96 is not supported/enabled)
[logging]
default = FILE:/var/log/krb5libs.log
kdc = FILE:/var/log/krb5kdc.log
admin_server = FILE:/var/log/kadmind.log
[libdefaults]
default_realm = AC.FR
dns_lookup_realm = false
dns_lookup_kdc = false
ticket_lifetime = 24h
renew_lifetime = 7d
forwardable = true
[realms]
AC.FR = {
kdc = ipa1.ac.fr
admin_server = ipa1.ac.fr
}
[domain_realm]
.ac.fr = AC.FR
ac.fr = AC.FR
kerberos-filter.properties
kerberos.authentication.http.configEntryName=AlfrescoHTTP
kerberos.authentication.http.password=mot_de_passe
kerberos.authentication.sso.enabled=true
kerberos.authentication.browser.ticketLogons=true
kerberos.authentication.realm=AC.FR
kerberos.authentication.user.configEntryName=Alfresco
kerberos.authentication.defaultAdministratorUserNames=mon_login
kerberos.authentication.http.configEntryName=AlfrescoHTTP
kerberos.authentication.http.password=mot_de_passe
kerberos.authentication.cifs.configEntryName=AlfrescoCIFS
kerberos.authentication.cifs.password=mot_de_passe
kerberos.authentication.cifs.enableTicketCracking=false
kerberos.authentication.authenticateCIFS=false
kerberos.authentication.stripUsernameSuffix=true
kerberos.authentication.sso.enabled=true
…
authentication.chain=alfrescoNtlm1:alfrescoNtlm,krb:kerberos,ldap1:ldap
…
…
login.config.url.1=file:${java.home}/lib/security/java.login.config
….
Alfresco {
com.sun.security.auth.module.Krb5LoginModule sufficient;
};
AlfrescoCIFS {
com.sun.security.auth.module.Krb5LoginModule required
storeKey=true
useKeyTab=true
keyTab="/etc/alfrescocifs.keytab"
principal="cifs/alfresco.ac.fr@AC.FR";
};
AlfrescoHTTP {
com.sun.security.auth.module.Krb5LoginModule required
storeKey=true
useKeyTab=true
keyTab="/etc/alfrescohttp.keytab"
principal="HTTP/alfresco.ac.fr@AC.FR";
};
ShareHTTP {
com.sun.security.auth.module.Krb5LoginModule required
storeKey=true
useKeyTab=true
keyTab="/etc/keys/alfrescohttp.keytab"
principal="HTTP/alfresco.ac.fr@AC.FR";
};
com.sun.net.ssl.client {
com.sun.security.auth.module.Krb5LoginModule sufficient;
};
other {
com.sun.security.auth.module.Krb5LoginModule sufficient;
};
10-29-2012 03:55 AM
…
13:57:13,379 INFO [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] Starting 'Authentication' subsystem, ID: [Authentication, managed, krb1]
13:57:13,552 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] HTTP Kerberos login successful
13:57:13,552 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Logged on using principal HTTP/alfresco.ac.fr@AC.FR
13:57:14,476 DEBUG [org.alfresco.repo.webdav.auth.KerberosAuthenticationFilter] HTTP Kerberos login successful
13:57:14,476 DEBUG [org.alfresco.repo.webdav.auth.KerberosAuthenticationFilter] Logged on using principal HTTP/alfresco.ac.fr@AC.FR
13:57:14,503 INFO [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] Startup of 'Authentication' subsystem, ID: [Authentication, managed, krb1] complete
13:57:14,503 INFO [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] Starting 'Authentication' subsystem, ID: [Authentication, managed, ldap1]
13:57:14,582 INFO [org.alfresco.repo.management.subsystems.ChildApplicationContextFactory] Startup of 'Authentication' subsystem, ID: [Authentication, managed, ldap1] complete
…
…
13:57:38,227 DEBUG [org.alfresco.web.app.servlet.KerberosAuthenticationFilter] Authentication not required (filter), chaining …
…
…
13:59:05,591 WARN [org.alfresco.web.site.servlet.KerberosSessionSetupPrivilegedAction] Caught GSS Error
GSSException: Failure unspecified at GSS-API level (Mechanism level: Encryption type AES256 CTS mode with HMAC SHA1-96 is not supported/enabled)
…
10-30-2012 04:26 AM
GSSException: Failure unspecified at GSS-API level (Mechanism level: Encryption type AES256 CTS mode with HMAC SHA1-96 is not supported/enabled)
11-02-2012 07:38 AM
WARN [org.alfresco.web.site.servlet.KerberosSessionSetupPrivilegedAction] credentials can not be delegated!
WARN [org.alfresco.web.site.servlet.KerberosSessionSetupPrivilegedAction] credentials can not be delegated!
11-02-2012 08:02 AM
11-02-2012 04:53 PM
11-04-2012 06:24 AM
Tags
Find what you came for
We want to make your experience in Hyland Connect as valuable as possible, so we put together some helpful links.