<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NTLM Issue! in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450242#M828856</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maryam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup a test environment to test the same scenario you have, and when I logon from a computer which is not joined to the Active Directory domain, and accessing the network where SAP is installed via a VPN I get the SAP logon screen in browser as expected and don't get any browser popup signon screen for NTLM logon. I tried with IE7 and Firefox web browsers. I am using NetWeaver 2004s SP9.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My test environment uses the login modules which our company provide to SAP customers, and which I support. If you were using these same login modules I could provide you with more support on this issue, but I am afraid it has got to a point where I need to ask if you can open a message with SAP and get SAP to assist you with this problem. That is unless somebody else on SDN can help you with SAP login modules ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 16 Feb 2008 10:03:29 GMT</pubDate>
    <dc:creator>tim_alsop</dc:creator>
    <dc:date>2008-02-16T10:03:29Z</dc:date>
    <item>
      <title>NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450225#M828839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   Is there any body remember, how we can stop NTLM show up when we lunch Portal?&lt;/P&gt;&lt;P&gt;   when our user login internaly to Portal they just see the Portal login page ,but when they login from outside of our network, they see NTLM first and after cancel that they see Portal login page, any idea how we can stop them NTLM to show up, without make changes in user browser?&lt;/P&gt;&lt;P&gt;  We are in EP6 SP15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Thanks,&lt;/P&gt;&lt;P&gt;   Maryam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2008 15:14:17 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450225#M828839</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-14T15:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450226#M828840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maryam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From your explanation it looks like you haven't configured any SSO solution for access to portal, and you are accessing it on your intranet and using SAP userid+password to logon to portal. Is this correct ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you confirm what you ticket login stack looks like in NetWeaver ? Are you using the BasicPasswordLoginModule ? Are any other login modules configured ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2008 15:47:14 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450226#M828840</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2008-02-14T15:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450227#M828841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Actually, we do have Kerbros  SSO and SPNego and the internal users are different are external users but both login to the same portal(we don't seperate Internal from external Portal),  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; As I'm new to this environment, do me a favor and tell me how can I find out the answers of your questions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thanks,&lt;/P&gt;&lt;P&gt;  Maryam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2008 16:50:40 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450227#M828841</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-14T16:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450228#M828842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maryam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you have now told me you are using SPNEGO and Kerberos, some of the information I asked for previously is not needed anymore. Thankyou.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First let me explain why you are getting the popup signon screen at browser:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The web browser is configured for IWA (Integrated Windows Authentication) which means it will use either Kerberos or NTLM via the negotiate protocol (aka SPNEGO). On the server you are using the SAP SPNEGO login module, which only supports SPNEGO with Kerberos tokens, and not SPNEGO with NTLM tokens. Your browser cannot send a Kerberos token since there are no Kerberos credentials on workstation when user is external/not on intranet. Instead, the browser sends the NTLM token which the SAP server doesn't like, so it is rejected, and browser just knows the user is trying to authenticate, and displays its default logon screen as a popup screen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you see the popup signon screen displayed by the browser you cannot enter any valid userid and password into this screen because there is no code on SAP server waiting to check this userid and password is correct or not. So, you need to press cancel and allow SAP to show the default logon screen in browser after you see the popup signon screen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully the above info explains why you are getting the popup signon screen ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The solution:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could add a Kerberos login module (available from a vendor called CyberSafe) to your ticket stack (configured using SAP Visual Administrator) so that a user can enter a valid Active Directory account/principal name and password in the SAP signon screen displayed, instead of a SAP user and password normally entered in this screen. If you configure this login module as a fallback login module, when the SPNEGO login module fails to authenticate the user (e.g. when they are not on Intranet) the fallback login module will be invoked, authenticating the user. Then an SSO2 ticket will be issued by SAP for SSO purposes. If you do this, the browser will not get confused when the NTLM token is not accepted by the server SPNEGO login module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you have any questions ? I appreciate that some of this might be confusing, so please ask if it is not clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2008 18:12:19 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450228#M828842</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2008-02-14T18:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450229#M828843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Thanks alot for your answer, you find a problem right, appreciate it, but to apply the solution we do have a problem, we already have a  database for our external users not an active directory, is it gonna work? where can I download this login module,is this the right address(http://java.sun.com/j2se/1.4.2/docs/guide/security/jaas/spec/com/sun/security/auth/module/Krb5LoginModule.html)? how can I apply on Visual admin? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Again Thanks for your responses,&lt;/P&gt;&lt;P&gt;  Maryam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2008 19:21:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450229#M828843</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-14T19:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450230#M828844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maryam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am pleased I can help you in some way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you tell me more about your database of external users ? Do you know more about how your external users are authetnicated to the portal using this external database ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have come across companies before that have separate authentication of external users, and the often use an authenticaftion server running in DMZ, and use the HTTP Header Login Module in SAP to determine the user from a variable in HTTP header. Is this the case with your setup ? I need to know this to help you, since if you are using this method of logon a Kerberos login module like I suggested is not going to help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I mentioned the Kerberos login module, I was not referring to the one available from SUN. I was referring to one provided by my company (CyberSafe) as a commercially available and supported product. It is in many ways better than the one provided by SUN and I don't even know if the SUN login module will work with SAP - probably not. Anyway, as mentioned in paragraph above it is likely that you don't need any Kerberos login module to solve your specific problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2008 19:50:01 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450230#M828844</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2008-02-14T19:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450231#M828845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Again thanks for your response, we use the UME to store our external users.&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;  What do you think we should do,now?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;  Maryam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2008 20:25:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450231#M828845</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-14T20:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450232#M828846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maryam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thankyou for the information regarding your external users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make sure I am clear - can you confirm my understanding:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For external users you display the SAP logon screen and the user enters userid+password, and SAP checks this against UME to see if the user's password is correct. Can I assume that UME is configured to use an ABAP user store, or is it using LDAP to access a user store in an LDAP directory, for password checking ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For internal users you use SPNEGO/Kerberos so that users are authenticated against Active Directory when they logon to their workstation, and the Kerberos credentials are used to authenticate them to SAP portal. Is this correct ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2008 20:31:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450232#M828846</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2008-02-14T20:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450233#M828847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Actually , you are right about this part:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"For external users you display the SAP logon screen and the user enters userid+password, and SAP checks this against UME to see if the user's password is correct"&lt;/P&gt;&lt;P&gt;But we do have our users just in UME database, no ABAP no LDAP.&lt;/P&gt;&lt;P&gt;I believe  SPNEGO/Kerberos is going to authenticate the users no matter the user is external or internal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this is going to help you to let us know what's the next step for us to solve the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt; Maryam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2008 21:16:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450233#M828847</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-14T21:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450234#M828848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;&amp;gt; I believe  SPNEGO/Kerberos is going to authenticate the users no matter the user is external or internal.&lt;/P&gt;&lt;P&gt;Actually, SPNEGO/Kerberos will only be able to authenticate the user when they logon to SAP if the workstation they are using with browser installed is joined to the Active Directory domain, and they have logged onto a domain account and the workstation has a network connection with the Active Directory domain controllers when they use the browser to logon to SAP. If all these conditions are true, then SPNEGO/Kerberos will work, so for your external users I am assuming this is not the case. Can you confirm please ?&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; I hope this is going to help you to let us know what's the next step for us to solve the issue.&lt;/P&gt;&lt;P&gt;I thinkI am getting closer to understanding your current implementation so that I can explain how to solve the problem. Thankyou for your patience.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Feb 2008 23:34:33 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450234#M828848</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2008-02-14T23:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450235#M828849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  I really appreciate your help and time, no doubt on it!&lt;/P&gt;&lt;P&gt;  About the "SPNEGO/Kerberos will only be able to authenticate the user when they logon to SAP " you are right, but I guess no matter what every time that a user hit this url SPNEGO/Kerberos is functioning and check for the user authentication if it's from the same domain going for authentication ,otherwise(it's our issue) it's calling NTLM, am I right? if I'm right , this is the place that we have to stop calling NTLM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again Thank you so much for your time and effort,&lt;/P&gt;&lt;P&gt; Maryam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 14:14:00 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450235#M828849</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T14:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450236#M828850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maryam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try and explain again. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is over simplified explanation, and so is not 100% complete, but shows the important steps to help you understand the issue:&lt;/P&gt;&lt;P&gt;1. browser on remote users computer connects to your SAP system.&lt;/P&gt;&lt;P&gt;2. Your SAP system is configured to use SPNEGO/Kerberos so it asks browser for an authentication token.&lt;/P&gt;&lt;P&gt;3. browser is unable to get Kerberos ticket to create a token, since workstation is not logged onto domain account and/or browser cannot contact the domain controller to get tickets. So, browser falls back to using NTLM instead of Kerberos and sends an NTLM token.&lt;/P&gt;&lt;P&gt;4. Your SAP system is not configured to handle the NTLM token since your login module is not supporting NTLM, so the login fails in SAP system and finishes.&lt;/P&gt;&lt;P&gt;5. Browser is expecting response from SAP after it sent NTLM token and response it gets indicates authentication is still required, so it displays the default browser signon screen. This signon screen is not going to function since SAP is not waiting for the userid and password entered in this screen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, to stop the browser showing the signon screen you need to use a login module which supports NTLM or configure a fallback to a login module which will allow remove users to logon. Since you are using user store in Java system via UME for remote users you need to configure the BasicPasswordLoginModule as a fallback so if SPNEGO login module is unable to recognise the NTLM token it receives it will fallback to using another login mdoule (BasicPasswordLoginMoodule).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First I think we need to check your ticket stack configuration. To do this, please:&lt;/P&gt;&lt;P&gt;1. On your SAP J2EE Engine system (portal ?), navigate to your /usr/sap/&amp;lt;SID&amp;gt;/DVEBMGS00/j2ee/admin directory and run the script in this directory to launch Visual Administrator tool, then login.&lt;/P&gt;&lt;P&gt;2. In Visual Admin, in left side you will be able to see Services under the Server node. In Services scroll down to find "Security Provider"&lt;/P&gt;&lt;P&gt;3. Now on right you will see list of various components. Near the top (about 6th line down) you will see a component called "ticket". Please select ticket&lt;/P&gt;&lt;P&gt;4. On right side of screen you will see a list of login modules with various flags and options. Can you let me know what they are set to ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 14:28:54 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450236#M828850</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2008-02-15T14:28:54Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450237#M828851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  This is the setting:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                    &lt;/P&gt;&lt;P&gt;  1. &lt;STRONG&gt;Login Modules&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;        Com.sap.security.core.server.jass.EvaluateTicketLoginModule       &lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;Flag&lt;/STRONG&gt;    Sufficient                 &lt;/P&gt;&lt;P&gt;    &lt;STRONG&gt;Options&lt;/STRONG&gt;        {UME.configuration.active=true,                                  trustediss1=CN=QMC, trusteddn1=CN=QMC, trustedsys1=QMC,010}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.    &lt;STRONG&gt;Login Modules&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;       SPNegoLoginModule                                                                &lt;/P&gt;&lt;P&gt;     &lt;STRONG&gt;Flag&lt;/STRONG&gt;        OPTIONAL                &lt;/P&gt;&lt;P&gt;   &lt;STRONG&gt;Options&lt;/STRONG&gt;      {com.sap.spnego.uid.resolution.mode=prefixbased, com.sap.spnego.uid.resolution.attr=kpnprefix, com.sap.spnego.jgss.name...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.  &lt;STRONG&gt;Login Modules&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt; Com.sap.security.core.server.jass.CreateTicketLoginModule           &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Flag&lt;/STRONG&gt;    Sufficient                &lt;/P&gt;&lt;P&gt;   &lt;STRONG&gt;Options&lt;/STRONG&gt;       {UME.configuration.active=true}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4.   &lt;STRONG&gt;Login Modules&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt; BasicPasswordLoginModule                                                        &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Flag&lt;/STRONG&gt;    Requisite           &lt;/P&gt;&lt;P&gt;   &lt;STRONG&gt;Options&lt;/STRONG&gt;       {}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5.   &lt;STRONG&gt;Login Modules&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;Com.sap.security.core.server.jass.CreateTicketLoginModule          &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Flag&lt;/STRONG&gt;   OPTIONAL             &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Options&lt;/STRONG&gt;    {UME.configuration.active=true}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6.   &lt;STRONG&gt;Login Modules&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt; SAMLLoginModule                                                       &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Flag&lt;/STRONG&gt;                  Sufficient                 &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Options&lt;/STRONG&gt;    {AcceptedAuthenticationMethods=*,Mode=Standard}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help,&lt;/P&gt;&lt;P&gt; Maryam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edited by: Maryam Vatandoust on Feb 15, 2008 5:01 PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 15:57:12 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450237#M828851</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T15:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450238#M828852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maryam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please confirm the exact version of SAP NetWeaver your portal is running on, including patch level of J2EE engine ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The login module stack looks ok, since BasicPasswordLoginModule is set as a fallback when SPNEGO fails, but clearly something is confusing the browser. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you confirm if this problem occurs for all users, or just some of them ? Does it occur all the time ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 16:14:26 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450238#M828852</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2008-02-15T16:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450239#M828853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  We are EP6 SP17 and unfortunately this issue happen for all of our external users everytime that they login.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt; Maryam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 16:26:45 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450239#M828853</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T16:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450240#M828854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thankyou.&lt;/P&gt;&lt;P&gt;I will do some more research and get back to you later.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIm&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 16:43:47 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450240#M828854</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2008-02-15T16:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450241#M828855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Tim!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Feb 2008 16:45:21 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450241#M828855</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-15T16:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450242#M828856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maryam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup a test environment to test the same scenario you have, and when I logon from a computer which is not joined to the Active Directory domain, and accessing the network where SAP is installed via a VPN I get the SAP logon screen in browser as expected and don't get any browser popup signon screen for NTLM logon. I tried with IE7 and Firefox web browsers. I am using NetWeaver 2004s SP9.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My test environment uses the login modules which our company provide to SAP customers, and which I support. If you were using these same login modules I could provide you with more support on this issue, but I am afraid it has got to a point where I need to ask if you can open a message with SAP and get SAP to assist you with this problem. That is unless somebody else on SDN can help you with SAP login modules ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 16 Feb 2008 10:03:29 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450242#M828856</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2008-02-16T10:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450243#M828857</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  Thanks alot for all your help,and I'm going to give you the max point for your help, but just one question&lt;/P&gt;&lt;P&gt;    I'm just wondering about another way, do you think is possible we make changes on "authschem" value for LOGON PAGE in Portalapp.xml file on com.sap.portal.runtime.logon folder, or make changes on Authschem.xml file and make "Basicauthentication" priority less than the "uidpassword" priority? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt; Maryam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2008 13:58:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450243#M828857</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2008-02-22T13:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM Issue!</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450244#M828858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maryam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thankyou, I hope I have been of some assistance, even though you don't yet have a solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding authscheme.xml - if you change this, the portal logon will be effected for all users, regardless of whether they are internal or external, so I doubt it will fix anything. From experience I have found the best way to solve these kinds of problems is to fix the login module so that fallback works correctly, or change the configuration of the ticket stack if it is wrong (in your case this looks ok). I suspect the version of SAP software you are using is the cause, so you either need to get SAP to help you fix it, upgrade to later version, or use a login module like the one sold by my company (CyberSafe) that I have confirmed works in the scenario you have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2008 14:04:38 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/ntlm-issue/m-p/3450244#M828858</guid>
      <dc:creator>tim_alsop</dc:creator>
      <dc:date>2008-02-22T14:04:38Z</dc:date>
    </item>
  </channel>
</rss>

