BO Edge XI-3.1, WinAD login (Tomcat)

There doesn’t appear to be an EDGE 3.1 specific document, for setting-up WinAD login on a Tomcat WebServer (Windows Server 2003 STD).

Therefore, I have referred to all the WinAD content in Chapter 12 of the “Business Objects Enterprise Administrator’s Guide 3.1” - and a little bit from Miles Escow’s SCN document for the IIS set-up (eg. Service Account and SETSPN, etc).

In the CMC, I can see the WinAD group and users…and I have given them access-rights.

When I try to login to the Java CMC - http://:8080/CmcApp/logon.faces - using one of these WinAD accounts, and the WinAD drop-down, I get the following error…

Account Information Not Recognized: Active Directory Authentication failed to log you on.
Please contact your system administrator to make sure you are a member of a valid mapped group and try again.
If you are not a member of the default domain, enter your user name as UserName@DNS_DomainName, and then try again.
(FWM 00006)

My guess is that it is an “EFFECTIVE RIGHTS” issue as discussed on Page 502 of the Admin Guide, but the document doesn’t include any screenshots of what these rights look like when “Checked”.

If anyone who has this working can post some screenshots of those settings, or knows the cause of this “FWM 00006” error it would be appreciated.

Thanks in advance!


MJRBIM :canada: (BOB member since 2007-03-23)

Hey bud,

I did one of these a couple of weeks ago (Edge 3.1 specifically). I just followed the regular BOXI R3 setup instructions for AD Tomcat and Kerberos and all that.

If youve gone through that and it looks configured ok (and youve done the troubleshooting steps that are in the guide and they return no errors), wait a few minutes. I got a similar error as soon as I did it, but after waiting, it started working. Which made me think AD was catching up or something…


ABILtd :uk: (BOB member since 2006-02-08)

Thanks for the info - still no luck…

Do you think it makes any difference that my SIA is running under the display name " Server Intelligence Agent (SERVERNAME) " - but my SPN is configured under the FQDN name for the server SERVERNAME.HQ.COMPANY.ORG …?

Needle, meet Haystack.


MJRBIM :canada: (BOB member since 2007-03-23)

I have gone through the steps in the very helpful post at - Yet another Kerberos/AD login problem

This helped me to determine, that when running the KINIT.EXE trace, we are getting an error -

Exception: krb_error 14 KDC has no support for encryption type (14) KDC has no support for encryption type

Error is the same for both the “des-cbc-crc” and “rc4-hmac” types listed in the XI-3.1 documentation.

This leads me to think that something needs to be set-up on the WinAD Domain Controllers to support those encryption types.

Anyone know where to check/modify those settings on the on the WinAD Domain Controllers…?


MJRBIM :canada: (BOB member since 2007-03-23)

What version is the AD? 2000 or 2003 or 2008?


lgonzalez (BOB member since 2002-07-17)

We have opened a ticket with SAP Support.

It’s a mix of DCs running on either Windows-Server-2003 (SP2) or Windows-Server-2008…and but they are running in 2003 mode.

Have a support call on Thursday (25th) - so I will post the fix if we find it.


MJRBIM :canada: (BOB member since 2007-03-23)

Hi MJRBM,

we are facing a similar issue at a client where we have BOEDGE and WIN2008 AD Server Domain Controller. Once we upgraded our AD servers to Win2008 users can no longer login to AD via Kerberos.

We got the similar error as you described when i ran Kinit on the BO server.

Did you find a resolution with SAP Tech Support?

De


dehuang83 :afghanistan: (BOB member since 2006-01-18)

Which specific errors did you get…?

Was this working OK when you were on the older DC (2003)…?


MJRBIM :canada: (BOB member since 2007-03-23)

Hi,

I am currently running into the same error. The funny thing is that this error happens only with some users :shock: . I am myself also a victim of this problem :frowning: :hb: . But I used to be able to login with my AD name. It seems that the problem started when I changed my password.
I enclose my Tomcat log, both accounts belong to the same AD group and I am not aware of any setup difference. Both users appear in CMC users and groups and I can log with my AD account into Desktop intelligence.
If you can share with me what the SAP support told you maybe it would also work for me.
Thanks!!!

[Krb5LoginModule] user entered username: Quentin.XXXXXX@AG.XXXXX.NET
Acquire TGT using AS Exchange
[Krb5LoginModule] authentication failed
KDC has no support for encryption type (14)
Debug is true storeKey false useTicketCache false useKeyTab false doNotPrompt false ticketCache is null isInitiator true KeyTab is null refreshKrb5Config is false principal is null tryFirstPass is false useFirstPass is false storePass is false clearPass is false

[Krb5LoginModule] user entered username: shuhei.XXXXX@AG.XXXXX.NET
Acquire TGT using AS Exchange
principal is shuhei.XXXXX@AG.XXXXX.NET
EncryptionKey: keyType=3 keyBytes (hex dump)=0000: 10 58 85 C7 68 8C A7 16
EncryptionKey: keyType=1 keyBytes (hex dump)=0000: 10 58 85 C7 68 8C A7 16
EncryptionKey: keyType=23 keyBytes (hex dump)=0000: C5 B3 2F A7 61 4A 93 E9 49 BC 41 BB 3F 5D 2F 41 …/.aJ…I.A.?]/A

EncryptionKey: keyType=16 keyBytes (hex dump)=0000: 98 49 34 25 25 B3 BF DF 51 98 C2 CD 64 CE 68 5B .I4%%…Q…d.h[
0010: 70 D5 CD 9D 68 FE 16 6B
EncryptionKey: keyType=17 keyBytes (hex dump)=0000: CD C1 DC 39 02 9F F9 CC 47 2F 26 0E FE 7F 95 14 …9…G/&…

Commit Succeeded


kontan (BOB member since 2008-03-17)

Hi, kontan.

What version is your AD?

And what are the contents of your krb5.ini file?


lgonzalez (BOB member since 2002-07-17)

I have the same problem as Kontan: "But I used to be able to login with my AD name. It seems that the problem started when I changed my password. "

Any update or insight into this?


hens4th :us: (BOB member since 2009-03-29)

I wish MJRBIM shared with us the information he got from SAP.
No, unfortunately, the issue is still pending, the project manager considered that we already spent too much time on that and decided to go with the enterprise signon. Kind of sad though.

I own MJRBIM an answer: Active directory is 2008’s version.


kontan (BOB member since 2008-03-17)

…It was a really detailed issue - and the only way we fixed it was to open a SAP support ticket - and have one of their staff WebEx in to our system with our AD Admin.

I would suggest that you do the same thing.


MJRBIM :canada: (BOB member since 2007-03-23)