cancel
Showing results for 
Search instead for 
Did you mean: 

Kerberos not working for only 1 sub-domain

Former Member
0 Kudos

Hi All,

We have successfully integrated Portal with Multiple LDAP Domains (1

internal and 3 external).There are 4 sub-domains for the 1 internal

domain.

We have configured Kerberos for all the internal sub-domains, however

its NOT working for only 1 sub-domain.

Erros found in the log:

-------------------------------------------------------------------------------------------------------------------------

Can't map exception.

[EXCEPTION]

com.sap.engine.services.security.exceptions.BaseLoginException: Cannot authenticate the user.

Caused by: javax.security.auth.login.LoginException: Trigger SPNEGO authentication.

at com.sap.security.core.server.jaas.SPNegoLoginModule.initialStateException(SPNegoLoginModule.java:366)

at com.sap.security.core.server.jaas.SPNegoLoginModule.login(SPNegoLoginModule.java:173)

at com.sap.engine.services.security.login.LoginModuleLoggingWrapperImpl.login(LoginModuleLoggingWrapperImpl.java:254)

at com.sap.engine.services.security.login.ModulesProcessAction.run(ModulesProcessAction.java:66)

... 64 more

------------------------------------------------------------------------------------------------------------------------

NegoEx token found in authorization header during SPNEGO authentication.

------------------------------------------------------------------------------------------------------------------------

Can't map exception.

[EXCEPTION]

com.sap.engine.services.security.exceptions.BaseLoginException: Cannot authenticate the user

Caused by: javax.security.auth.login.LoginException: NegoEx token received in authorization header.

at com.sap.security.core.server.jaas.SPNegoLoginModule.failedAuthenticationException(SPNegoLoginModule.java:351)

at com.sap.security.core.server.jaas.SPNegoLoginModule.checkAuthorizationHeaderToken(SPNegoLoginModule.java:450)

at com.sap.security.core.server.jaas.SPNegoLoginModule.processAuthorizationHeader(SPNegoLoginModule.java:473)

at com.sap.security.core.server.jaas.SPNegoLoginModule.login(SPNegoLoginModule.java:157)

at com.sap.engine.services.security.login.LoginModuleLoggingWrapperImpl.login(LoginModuleLoggingWrapperImpl.java:254)

at com.sap.engine.services.security.login.ModulesProcessAction.run(ModulesProcessAction.java:66)

... 64 more

-------------------------------------------------------------------------------------------------------------------------

Any help would be highly appreciated.

Thank you,

Regards,

Disha

Accepted Solutions (0)

Answers (1)

Answers (1)

richard_silhan2
Discoverer
0 Kudos

Hi Disha,

we have the same problem and I can't figure out how to solve this.

Have you found out the solution?

Thank you in advance for any help.

Regards,

Richard

jtretina
Explorer
0 Kudos

Hi, I am facing the same issue, did you solve it?

Thanks,

Jan

UPDATE: we started to face this issues after the migration, after new SPN registration in KDC on ADS (for new hostname), OSS via SNEGO is working again.

rezaejersbo
Participant
0 Kudos

Hello Alle.

I am facing the same problem; did any body solve this?

Thanks

Reza