After the implementation of Kerberos on PeopleSoft, Active Directory Auth does not work

Hello

We need your help to solve problems 1 question we receive many users after application PeopleSoft Kerberos SSO against AD. This problem is specific to Windows 7 PC and where the Kerberos token is not available.

A few facts we know:

Kerberos fails for users who are not connected to the system using AD domain (like Kerberos token is not valid).

These users are not on AD Doamin so SSO fails, which is understandable. But - we've designed our solution in such a way - when AUTHENTICATION fails, it will trigger a Peoplesoft login screen. The user can manually provide its credentials (name of user/AD password) and authentication LDAP directory will be triggered using ad servers.

Note: our site is enabled for SSL (HTTPS)

Windows 7 when the person tries to connect which is outside AD domain, SSO fails (in the form of token not found)-> PeopleSoft Login sreen rises to the HTTPS-> user to connect using AD userid and password-> PeopleSoft login screen gets refreshed and notheing happens.

Surprising - even works on Googgle Crome or if I change the http URL.

We put in login secuity 'True' in the Web.XML for Kerberos settings.

Here is the Fiddler trace when we click on "registration" - in area no AD.

===============================================================

Request header

POST/psp/PIMSTEST /? cmd = login & languageCd = ENG-HTTP/1.1

Accept: application/x-ms-application, image/jpeg, xaml application / + xml, image/gif, image/pjpeg, application/x-ms-application xbap, application / vnd.ms - excel, application / vnd.ms - powerpoint, application/msword, * / *.

Referer: https://pimstest.equant.com/psp/PIMSTEST/?cmd=start&languageCd=ENG&cmd=login&errorCode=105

Accept-Language: en-US, en - US; q = 0.5

User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2 .NET CLR 2.0.50727; .NET CLR 3.5.30729 .NET CLR 3.0.30729)

Content-Type: application/x-www-formulaires-urlencoded

Accept-Encoding: gzip, deflate

Host: pimstest.equant.com

Content-Length: 0

Connection: Keep-Alive

Cache-Control: no cache

Cookie: ggnptestap1-80-PORTAL-PSJSESSIONID = KbhXRpGQ52hLJtWbbK0DJ1XGDbSJ9Wn2! 386905482; SignOnDefault =

Authorization: Negotiate TlRMTVNTUAABAAAAl4II4gAAAAAAAAAAAAAAAAAAAAAGAbEdAAAADw is

Response header

HTTP/1.1 200 OK

Cache-Control: no cache

Connection: close

Date: Thu, 11 July 2013 10:19:09 GMT

Content-Length: 13010

Content-Type: text/html; CHARSET = utf-8

Expires: Thu, December 1, 1994 16:00:00 GMT

Set-Cookie: ggnptestap1-80-PORTAL-PSJSESSIONID = HBT3RpGdCX1q8W51ZxTz8hpQ2bCpMFKh! 386905482; Path = /; HttpOnly

Set-Cookie: PS_TOKEN =; domain =; expires = Thu, January 1, 1970 01:00:00 GMT; Path = /.

RespondingWithSignonPage: true

X-Powered-By: Servlet/2.5/JSP 2.1

=====================================================

Thanks for help

Rajat

Hi René,.

 

The question you posted would be better suited in the TechNet Forums. I would recommend posting your query in the TechNet Forums.

TechNet Forum

http://social.technet.Microsoft.com/forums/en-us/w7itpronetworking/threads

 

Hope this information helps.

Tags: Windows

Similar Questions

  • After the update to 2015.3: Unsharp Mask threshold Slider does not work

    Title pretty much everything said. I worked on a few corrections in an ongoing project after the recent update and images seemed to be returned to its original sharpness. After noodling a bit, I noticed that it is because the threshold slider now don't goes from 0 to 1, basically making it a bypass switch (I got my 2 enabled effect). I've always loved that you could control the degree of color a little noise with the threshold slider and it's a little frustrating that it is no longer an option. Does anyone know if it's a mistake or a voluntary choice by Adobe? Can we say if the Lumetri sharpen slider is a better tool for use even in light of this change?

    I think it's a bug. IMO, it should read 0-255.

    Feature request/Bug Report Form

    Lumetri can be a good choice, its accelerated gpu as Unsharpen mask is not.

  • After the installation of widows7 my laptop computer function key does not work

    After windows7 install my laptop function key not working.i have downloaded several hp website.but software does not. My laptop model number: hp pavilion g4 2191se serial number: [edited by Moderator] product id: B6X40EA #ABVt

    Try this

    http://ftp.HP.com/pub/SoftPaq/sp55001-55500/sp55152.exe

  • After the automatic update of Windows 7 - Manager of tasks does not work

    Automatic update has occurred.  Now the Task Manager does not come with window with tabs upward.  Only a window with two columns ('Mission' and 'Status') and three option buttons ("end task", go to "and new task" ").  Even not a 'close button' - may not only close to the taskbar.

    Hi rw9683,

    ·         Have updates you installed?

    Follow these methods.

    Method 1: Performs a search using the Microsoft safety scanner.

    http://www.Microsoft.com/security/scanner/en-us/default.aspx

    Note: If bad sectors are found in the hard drive, then it could try to fix this particular sector. If you have any data on that, it can get lost.

    Method 2: Follow the steps in the article.

    Using the Task Manager: frequently asked questions

    http://Windows.Microsoft.com/en-us/Windows7/using-Task-Manager-frequently-asked-questions

    Method 3: Scan the file system (CFS) auditor to repair corrupted files.

    How to use the System File Checker tool to fix the system files missing or corrupted on Windows Vista or Windows 7

    http://support.Microsoft.com/kb/929833

  • Active Directory plugin does not work correctly

    I'm having some weird problems with the Active Directory plugin uses the native vCO in vCAC.

    • When I use virtually any element of the workflow associated with the AD plugin I get a UI glitch and cannot select anything, this happens especially with the AD:Host selector.
    • When I use the AD:OU selector I can only watch the OUs that are at the root of the domain and can not enter in the OU structure.
    • When I use the ActiveDirectory.search function I have still no matches.
    • I get a lot of these errors for various object in the newspapers: [ADObjectFactory] error creating object ID: OR OR = Groups, DC =, DC = domain


    So far, I tried the following:

    • Updated the host AD to use different users who have domain administrator rights.
    • Tried to change the host to use the catalogue global (3268) and regular LDAP port (389)
    • Restart the services server and vCO several times.
    • Temporary files deleted through the configurator.

    Anyone have any ideas on what could be the problem? The ad server is Server 2012.

    So I thought that the problem. When you configure endpoint AD you must specify the root of the advertising in the field of the ldapBase. If there is a space after the comma that separates values DC (dc =, dc = server) you will end up with the weird error state.

    Really of VMware, really?

  • The Remote option for matching seems to have disappeared (file/devices/Remote). This discovered after the last updated at 12.4 and Remote app would not work. Suggestions?

    The Remote for iPhone & Remote app matching option seems to have disappeared (file/devices/Remote). This discovered after the last updated at 12.4 and Remote app would not work. Suggestions?

    Fixed. I removed the Remote, reloaded app to my iPhone and then reinstated the info Apple ID and password in the app all connected immediately. The 'Remote' option is not always present under file/devices/Remote, but everything works well at this point.

  • I have Photoshop CS and when I tried to open it I got an activation screen that does not work.  I have used this product for years and want to continue.  I paid for him and all of a sudden I can't use it!  Please help me to get the program I pai

    I have Photoshop CS and when I tried to open it I got an activation screen that does not work.  How can I get my program works?

    Hello

    Activation for CS and CS2 products now unavailable server.

    In this case the best you can do is to install Photoshop CS2 at the bottom of the link with the serial number that is mentioned on the Web site

    Error: Unavailable activation server | CS2, Acrobat 7, pass a hearing 3

  • I downloaded the new software recently and now my Epsom printer does not work

    iMac late 2009. Processor 3.06 GHz

    Hi, I downloaded the new software recently and now my Epsom printer does not work and my Wi - Fi on the computer keeps dropping out.

    I spoke with Epsom and they recommended to remove the drivers and reinstall them. Now, I can not install the ad pilots Wi - Fi does not work correctly. The research on this forum I see there have been many problems with the new version of the software. Can someone help me?

    < re-titled by host >

    Try a reboot.

    Make a backup using Time Machine or a cloning program, to ensure that data files can be recovered. Two backups are better than one.

    Try to set up another admin user account to see if the same problem persists. If back to my Mac is enabled in system preferences, the guest account will not work. The intention is to see if it is specific to an account or a system wide problem. This account can be deleted later.

    Isolate a problem by using a different user account

    If the problem is still there, try to start safe mode using your usual account.  Disconnect all devices except those necessary for the test. Shut down the computer and then put it up after a 10 second wait. Immediately after hearing the startup chime, hold down the SHIFT key and continue to hold it until the gray Apple icon and a progress bar appear. Startup is considerably slower than normal. This will reset some caches, forces a check for directory and disables all start-up and connection, among other things. When you restart normally, the initial restart may be slower than normal. If the system is operating normally, there may be 3rd party applications that pose a problem. Try to delete/disable the third-party applications after a reboot using the UN-Installer. For each disable/remove, you need to restart if you do them all at once.

    Safe mode - on El Capitan

    Start Mode without failure-El Capitan.

  • I just recently upgraded to OS El Capitan.  Now, none of my movies to quicktime does not work.  I have the old version of Quick time 7 and it does not work either.  They do not convert.  Help?

    I just recently upgraded to OS El Capitan.  Now, none of my movies to quicktime does not work.  I have the old version of Quick time 7 and it does not work either.  They do not convert.  Help?

    VLC will play them?

    http://www.videolan.org/

  • I already have an annual subscription to the export of Adobe and Adobe track, but it does not work on my new computer (Windows 10). Help, please.

    I already have an annual subscription to the export of Adobe and Adobe track, but it does not work on my new computer (Windows 10). Help, please.

    Look under Tools.

  • How to reset the password for CC? -My former CC password does not work. I can't find that link 'forgot my password' My Adobe password does not work in CC

    How to reset the password for CC? -My former CC password does not work. I can't find that link 'forgot my password' My Adobe password does not work in CC

    Contact support Adobe by clicking here and, when available, click on "still need help," https://helpx.adobe.com/contact.html

  • The function ' copy to ' in folio Builder... does not work

    So it would appear that the function "copy to" in folio Builder... does not work,... it DOES well, but when you try and publish the folio, it errors saying there is an article in your folio is the bad resolution for the folio...

    What a bore... ! I thought I'd hit goldust to my retina display folio. :-(

    A strange thing about the feature copy, it's that you can use to add any item to any folio. For example, you can add an article to the iPhone to an iPad folio, but you will end up having to delete this article if you want to preview or publish. In your case, it seems that you've added an article from 1024 x 768 to a folio of 2048 x 1536.

    Using the function "Add" is not an effective method for creating applications. I recommend that you configure your files to import. See the following article:

    http://helpx.Adobe.com/Digital-Publishing-Suite/help/structuring-folders-imported-articles .html

  • D7 3180 US: after the upgrade to windows 10, hp dv7 remote control does not

    Hi guys!

    I have a HP DV7 3180 us that I have upgraded to windows 10.  I have 3 basic system devices that are listed as unable to find drivers for them.  I guess that one of them is one that allows me to use my remote, as now it does not work. I was unable to find a windows 10 driver, or anything that can help me solve the problem.  I tried to have HP scan my computer and update all the drivers, but course who has failed several times.

    Thank you

    Kyle

    Hi, Kyle:

    You need this driver for basic system devices...

    This package contains the driver for laptop models JMicron card reader supported and operating systems.

    File name: sp45010.exe

    You can use this driver for the IR remote...

    This package contains the ENE CIR Receiver driver for laptop models supported and operating systems.

    File name: sp44983.exe

  • "the key to upgrade to an edition of windows does not work with Windows Anytime Upgrade" was the message received when you use the code comes to purchase Microsoft online. Any suggestions? »

    Upgrade Windows 7 Home Premium to professional.

    Windows 7 Anytime Upgrade fails:

    If your getting the following: error: Windows Anytime Upgrade failed
    This problem may occur if Windows 7 SP1 was downloaded by Windows Update, but has not yet been installed.
    See: http://support.microsoft.com/kb/2660811

    = Other reasons and possible corrections.

    Windows Anytime Upgrade fails with the error:
    "every time that the upgrade has failed. Go online to solve the problem.
    http://support.Microsoft.com/kb/2658652

    If Anytime Upgrade still does not work:

    Shut down and restart your computer.

    Make sure that the Windows updates have been installed.

    Download the hotfix that contains a tool called CheckSUR, this tool will look at the package and the maintenance of records and difficulty any data corrupted, the tool is listed under kb947821 he can be found at the following link http://support.microsoft.com/?kbid=947821

    If Anytime Upgrade still does not work, turn off the user account control:

    1. go in user accounts in Control Panel

    2 change user account control settings

    3. pull the slider to the level as low as possible

    4. restart the PC

    5. pass by the "Anytime Upgrade" as usual

    Try the following:

    1 disable any security software before attempting to upgrade

    2. make sure that your computer is updated (devices and applications)

    3. disconnect all external devices before installing.

    4. check your hard disk for errors:

    Click Start

    Type: CMD, according to the results, right-click CMD

    Click on "Run as Administrator"

    At the command prompt, type: chkdsk /f /r

    When you restart your system, your computer will be scanned for errors and will try to correct them.

    1. click on start, type msconfig in the search box and press ENTER.

    User account control permission

    If you are prompted for an administrator password or a confirmation, type the password, or click on continue.

    2. in the general tab, click Selective startup.

    3. under Selective startup, clear the check box load startup items.

    4. click on the Services tab, select the hide all Microsoft Services check box, and then click Disable all.

    5. click on OK.

    6. When you are prompted, click on restart.

    7. after the computer starts, check if the problem is resolved.

    Also run the Windows 7 Upgrade Advisor:

    http://www.Microsoft.com/Windows/Windows-7/Upgrade-Advisor.aspx

    Who should I contact if I have problems installing and / or activation of my product key card?

    Please contact to the: www.windows7.com/getkeysupport.

    If all above fails them, install Windows 7 Service Pack 1, and then try the Express Upgrade:

    Learn how to install Windows 7 Service Pack 1 (SP1)
    http://Windows.Microsoft.com/en-us/Windows7/learn-how-to-install-Windows-7-Service-Pack-1-SP1

    If your key is not valid and you will need to change the keys, you may need to Open regedit and remove first the ProductKey value in the following registry key:
     
    HKCU\Software\Microsoft\Windows\CurrentVersion\WindowsAnytimeUpgrade

  • The mode of "Guided" edition of Photoshop elements 11 does not work!

    Using the "Guided" edition of Photoshop elements 11 mode line of work progress hangs at 75% and the guided mode does not work! The 'Quick' and 'Expert' mode, on the other hand, works well.

    Attention, please! I said that I use Mac OS X Lion 10.7.5 and I don't have AntiVirus or firewall active... I already tried to delete all preferences, all folders hide 11 elements, etc, tried to uninstall and reinstall the software... but without success. I hope you can help me.

    On Photoshop Elements guided editing mode does not.

    My LAST solution to the problem. (But I also hope for an intelligent patch Adobe...)

    I finally understand why the 'screen of welcome... '. "and the IMPORTANT"Guided"editing did not work in Photoshop elements 11 (or with Photoshop Elements 10); the Panel "Guided" does not appear with the options, but on the right, the progress bar freezes at 75% of the Panel options and the Panel remains blank.

    After days of hard work and after many attempts on the Adobe troubleshooting, I realized that the problem through the functions of Mac OS X-Squared (XProtect process). But I did not understand why the question not shown PES running in a new account; Maybe, it's because Mac OS X still not always intercepted and blocked the old Flash Player plugin, installed by PSE11. Examining the preferences system and security-> advanced Panel, you see the option that allows the automatic control of Mac OS X for the blacklist of malware.

    As seen in the attached screeshot, if you open XCode or with a text editor the "/System/Library/CoreServices/CoreTypes.bundle/ Contents/Resources/XProtect.meta.plist" file you can read that Mac OS X (from 10.6 Snow Leopard) inserted older versions of Flash Player plugin (minor of "11.3.300.271") in the plug-ins from black list, so they block.

    I don't understand why Adobe left this obsolete "Flash Player.bundled" Photoshop plug-in elements 11 or 10! In fact, the PSE11, does not use the plugin "Flash Player.bundle" , but it uses "AdobeSWFL.bundle", appearing in "/ System_Disk/Library/Application Support/Adobe/APE/3.101/adbeapecore.framework/Versions/A/Resources/". The fact that maybe Adobe don't know, maybe, the existence of a black list of Mac OS X that blocks the plugin Flash Player prior to version 11.3.300.271? ... Is it really useful to install that plugin so obsolete (for Mac OS X 10.4 - 10.5) PSE11 works from version 10.6 "Snow Leopard" go?

    The Flash Player plugin installed by PSE11 is the old "10.1.82.73" version that you can read in this info.plist file (or in my screenshot attached here) and I think if you use Mac OS X Lion or Mountain Lion you can remove it because, as we read in his "Info.plist" file, the plugin is only for Mac OS X 10.4 or 10.5...

    A hypothesis about the occasional occur any question about the "Guided" mode or "Home screen" does not is that PSE11, at startup, a "program call" old-fashioned "Flash Player" plugin installed by PSE11 and PSE10 and the system, peraphs, intercept the call through 'xprotect"process that runs in the background. Thus, Mac OS X blocks the function of PSE11 based on Flash Player as, indeed, the 'Welcome' screen and "Guided" editing function

    S or the problem lies in a starting behavior of PSE that it because of old permissions ACL in the record of the House(because belong to the previous Mac OS X version 10.5 - 10.6). PSE think of having to start the old containded plugin Flash Player in EPAS. This would explain why the PES works well and "guided" PSE mode works if create a new startup account!

    Note! Disk utility does not, correct permission ACL in house by default,! Adobe, then, rather than suggest to create new accounts... must fix PES by deleting any reference to the old Player Flash plugin. otherwise, there is always the risk that Mac OS X prevents proper operation.

    I tried to rename or remove this plug-in and PSE11 still works well, but for the pedantry, I preferred this solution:

    -J' installed the latest version of Flash Player from the Adobe site.

    -J' opened the package to "/ Library / Internet Plug-Ins/Flash of----------------Player.plugin/Contents/PlugIns/FlashPlayer-10.6.plugin/Contents / '.

    -J' copied the four objects (MacOS folder resources and files: file info.plist, version.plist, and)

    and

    stuck in ' Adobe/APE/3.101/adbeapecore.framework/Versions/A/Resources/Flash Player.plugin / summary / "overwhelming existing.

    I have a doubt over left: I have not yet activated the iCloud for Photo Streaming and iTunes sync option to Match; This functionality has been enabled in my old account when PSE did not work... I hope PSE11 works well, even when I activate these features to synchronize with my Apple accounts...

    See the blacklist plugin for Mac OS X

    Post edited by: Dottor Vincenzo 2012 / 12 / 07-9:38:00

Maybe you are looking for