Hi I'm configuring a CAS server (3.2.1) installed on a Windows Server 2012 (jvm oracle 1.7) and I need to implement the Intergated Windows Authentication with the AD domain. I've created a casspnego user on AD and I've used the ktpass command to map the service and create the keytab file. I've used these parameters: -crypto RC4-HMAC-NT -ptype KRB5_NT_PRINCIPAL
These are the CAS configurations <property name="jcifsServicePrincipal" value="HTTP/[email protected]" /> <property name="jcifsServicePassword" value="xxxxx" /> <property name="jcifsUsername" value="casspnego" /> <property name="jcifsPassword" value="xxxxxx" /> <property name="kerberosDebug" value="true" /> <property name="kerberosRealm" value="DOMAIN.AD" /> <property name="kerberosKdc" value="xxx.xxx.xxx.xxx" /> <property name="loginConf" value="................../webapps/cas/WEB-INF/login.conf" /> Testing the automatic login with the IE on the local server the process fails. Here the CAS server log SPNEGO Authorization header found with 164 bytes Obtained token: `y + �o0m�00. + �7 *�H�� *�H�� + �7 �9 7NTLMSSP �� � 1 But this is not a problem. I need that it works on the users workstations. Testing from a user workstation in the domain I can see in the log a longer token that looks like a kerberos token, but the CAS server can't obtains the principal name. I tried to change the DES encryption flag and resetting the password but nothing change Can someone help me to understand where the problem is. Thanks Andrea -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
