Hi

I'm configuring a CAS server (3.2.1) installed on a Windows Server 2012 
(jvm oracle 1.7) and I need to implement the Intergated Windows 
Authentication with the AD domain.
I've created a casspnego user on AD and I've used the ktpass command to map 
the service and create the keytab file.
I've used  these parameters:  -crypto RC4-HMAC-NT -ptype KRB5_NT_PRINCIPAL

These are the CAS configurations
<property name="jcifsServicePrincipal" 
value="HTTP/[email protected]" />
<property name="jcifsServicePassword" value="xxxxx" />
<property name="jcifsUsername" value="casspnego" />
<property name="jcifsPassword" value="xxxxxx" />
<property name="kerberosDebug" value="true" />
<property name="kerberosRealm" value="DOMAIN.AD" />
<property name="kerberosKdc" value="xxx.xxx.xxx.xxx" />
<property name="loginConf" 
value="................../webapps/cas/WEB-INF/login.conf" /> 

Testing the automatic login with the IE on the local server the process 
fails. Here the CAS server log

SPNEGO Authorization header found with 164 bytes
Obtained token: `y  +     �o0m�00. 
+    �7  
  *�H��      *�H��     
+    �7   �9 7NTLMSSP �� �  1

But this is not a problem. I need that it works on the users workstations. 
Testing from a user workstation in the domain I can see in the log a longer 
token that looks like a kerberos token, but the CAS server can't obtains 
the principal name. I tried to change the DES encryption flag and resetting 
the password but nothing change  
Can someone help me to understand where the problem is.
Thanks
Andrea  

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to