<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSO configuration between Windows ADS and AS JAVA. in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/sso-configuration-between-windows-ads-and-as-java/m-p/6545985#M1428839</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dalibor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While the service account user object has &lt;STRONG&gt;Use DES&lt;/STRONG&gt; selected it would appear your user session is still sending the AS Java an RC4 service ticket.  This might occur if your user had requested a service ticket before &lt;STRONG&gt;Use DES&lt;/STRONG&gt; was selected, or before that setting had replicated to the appropriate domain controller.  The fix might be as simple and logging out and logging back in now that some time has passed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also download the Microsoft kerbtray utility and inspect the service ticket enc type to validate this.  kerbtray can also be used to clear old tickets and is generally useful for troubleshooting this kind of thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Kyle&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Jan 2010 20:34:35 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2010-01-13T20:34:35Z</dc:date>
    <item>
      <title>SSO configuration between Windows ADS and AS JAVA.</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sso-configuration-between-windows-ads-and-as-java/m-p/6545984#M1428838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We had activated SPnego for authenticating users with Kerberos SSO for AS Java CE 7.11, the UME Data Source is AS ABAP Solution manager 7.0 EHP1.&lt;/P&gt;&lt;P&gt;All configuration was done according documentation and SAP notes (NOTE#994791).&lt;/P&gt;&lt;P&gt;Regardless login form (SAP NW) appears so the Kerberos SSO with Spnego does not work for our AS Java system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In trace files there are error messages:&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;com.sap.engine.services.security.autentification.calllbackhandler.handle(HttpGetterCallback) Cookie MYSAPSSO2 is not found &lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;CreateContext failed: GSSException: Failure unspecified at GSS-API level (Mechanism level: Invalid argument (400) - Cannot find key of appropriate type to decrypt AP REP - RC4 with HMAC) &lt;/P&gt;&lt;P&gt;[EXCEPTION]&lt;/P&gt;&lt;P&gt; &lt;SPAN __jive_macro_name="0"&gt;&lt;/SPAN&gt;#1#GSSException: Failure unspecified at GSS-API level (Mechanism level: Invalid argument (400) - Cannot find key of appropriate type to decrypt AP REP - RC4 with HMAC)&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;Login Module&lt;/P&gt;&lt;P&gt;    Flag        Initialize  Login      Commit     Abort      Details&lt;/P&gt;&lt;P&gt;1. com.sap.security.core.server.jaas.EvaluateTicketLoginModule&lt;/P&gt;&lt;P&gt;    SUFFICIENT  ok          false                 true&lt;/P&gt;&lt;P&gt;2. com.sap.security.core.server.jaas.SPNegoLoginModule&lt;/P&gt;&lt;P&gt;    OPTIONAL    ok          exception             true       Failure&lt;/P&gt;&lt;P&gt;unspecified at GSS-API level (Mechanism level: Invalid argument (400)&lt;/P&gt;&lt;P&gt;- Cannot find key of appropriate type to decrypt AP REP - RC4 with&lt;/P&gt;&lt;P&gt;HMAC)&lt;/P&gt;&lt;P&gt;3. com.sap.security.core.server.jaas.CreateTicketLoginModule&lt;/P&gt;&lt;P&gt;    SUFFICIENT  ok          false                 true&lt;/P&gt;&lt;P&gt;4. com.sap.engine.services.security.server.jaas.BasicPasswordLoginModule&lt;/P&gt;&lt;P&gt;  REQUISITE   ok          false                 false&lt;/P&gt;&lt;P&gt;5. com.sap.security.core.server.jaas.CreateTicketLoginModule&lt;/P&gt;&lt;P&gt;    REQUISITE   ok          false                 true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;Neither SPNego resolution mode simple nor prefixbased doen't work.&lt;/P&gt;&lt;P&gt;The ADS user j2ee-&amp;lt;AS_JAVA_SID&amp;gt; has appropriate property DES encryption.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dalibor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 08:30:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sso-configuration-between-windows-ads-and-as-java/m-p/6545984#M1428838</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-01-13T08:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: SSO configuration between Windows ADS and AS JAVA.</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sso-configuration-between-windows-ads-and-as-java/m-p/6545985#M1428839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dalibor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While the service account user object has &lt;STRONG&gt;Use DES&lt;/STRONG&gt; selected it would appear your user session is still sending the AS Java an RC4 service ticket.  This might occur if your user had requested a service ticket before &lt;STRONG&gt;Use DES&lt;/STRONG&gt; was selected, or before that setting had replicated to the appropriate domain controller.  The fix might be as simple and logging out and logging back in now that some time has passed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also download the Microsoft kerbtray utility and inspect the service ticket enc type to validate this.  kerbtray can also be used to clear old tickets and is generally useful for troubleshooting this kind of thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;Kyle&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 20:34:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sso-configuration-between-windows-ads-and-as-java/m-p/6545985#M1428839</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2010-01-13T20:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSO configuration between Windows ADS and AS JAVA.</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/sso-configuration-between-windows-ads-and-as-java/m-p/6545986#M1428840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are interested to use an SPNEGO loginmodule which supports RC4 (even when using Java 1.4) then you can find one on SAP EcoHub - just search for spnego.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 23:33:35 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/sso-configuration-between-windows-ads-and-as-java/m-p/6545986#M1428840</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2010-01-13T23:33:35Z</dc:date>
    </item>
  </channel>
</rss>

