cancel
Showing results for 
Search instead for 
Did you mean: 

SAPGUI SSO Given Error GSS-APO(maj): NO Credential's were supplied

Former Member
0 Kudos

Hello All

Using   this   URL  for  configuration  time                              

http://scn.sap.com/community/sso/blog/2012/08/17/how-to-configure-sap-netweaver-single-sign-on-for-s...

Implementing  SAP  ERP 6 SR3 ABAP Stack  with  SSO 1.0

SNC Configuration   done successfully   here it is attach  screen  shots

      

While using   SAP  GUI 7.30    with SNC   it shows  error

Thanks

Tejas Gandhi

Accepted Solutions (0)

Answers (2)

Answers (2)

former_member185954
Active Contributor
0 Kudos

Hello Tejas,

Also, the SAPGUI network tab entry should have the following:

p:CN=<Service Principal Name set in Active Directory>@ROYAL.COM

Regards,

Siddhesh

Former Member
0 Kudos

Hello  Siddhesh

Still   found  same  issue   please  review my  SU01  screen , SAP GUI  Network tab  screen

SAP GUI

SU01

former_member185954
Active Contributor
0 Kudos

Hello Tejas,

Can you please provide details of the following:

Service Principal Name set in the Active Directory

Keytab entry set SAP server

Regards,

Siddhesh

Former Member
0 Kudos

Hello Siddhesh

Please  review   Service Principal Name  for NSP  &  before  I  try with  EHP5   with SPNGEO  similar  type  Service principal using it is works fine but   try to NSP (SAP ERP 6.0SR3)  system  it is  given error

Tejas

former_member185954
Active Contributor
0 Kudos

Hello Tejas,

Can you post the screenshot of the Keytab Entry in SAP ?

Regards,

Siddhesh

Former Member
0 Kudos

Hello  Siddhesh

Where I  should see   Keytab Entry  in SAP?

Tcode  -  SNC1 ?

Thanks

Tejas

former_member185954
Active Contributor
0 Kudos

Point number 3. in the blog you said you used to configure this setup.

Former Member
0 Kudos

I am    creating  key tab    using  this  command    please  check

c:\usr\sap\NSP\DVEBMGS00\SLL>snc crtkeytab -s KerberosNSP@royal.com -P abcd1234

former_member185954
Active Contributor
0 Kudos

Hello,

That password should match the password that you set for the service user on Active Directory for which you set the Service Principal name.

Regards,

Siddhesh

Former Member
0 Kudos

Sir

creating pse file   using  password :::::    password123$

Creating keytab password ,  OS level & Service User Password  ( for Example : abcd1234)

Thanks

Tejas

former_member185954
Active Contributor
0 Kudos

Hello Tejas,

Looks like you are implementing sections of the blog out of sequence.

Take a step back and review the blog again, read it from the beginning again if required and then review what activities haven't been done.

The blog you shared was written with certain assumptions about the implementors know how of SSO and SNC and hence certain pieces of configuration may have been missed by you.

If you are unable to find any issues with your configuration or are unsure, read the following document, it describes detailed steps with a bit more clarity:

Hope that helps.

Regards,

Siddhesh

Former Member
0 Kudos

Hi Tejas,

Try Right Click --> 'Enroll' on the Kerberos Token on the Secude window.

Please check if it's p/: or p: on SU01 screen.

Regards,

Uday

Former Member
0 Kudos

Hello  Uday

Please   Review   SU01   & RZ10  Screenhots

Kerberos  Token

SU01   using   p:CN

RZ10

Thanks

Tejas

former_member185954
Active Contributor
0 Kudos

Hello Tejas,

The SNC Name in SU01 is wrong. It should be whatever is displayed in your kerberos token.

So it should be: p/:CN=TEJASG8@ROYAL.COM

The SNC name should uniquely map the SAP Userid within a SAP system. The note given below gives some examples.

184277 - Length Limitation of SNC-Names