webMethods

webMethods

Join this online group to communicate across IBM product users and experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

MWS 10.5 Kerberos Authentication does not work

  • 1.  MWS 10.5 Kerberos Authentication does not work

    Posted Mon August 01, 2022 12:29 AM

    What product/components do you use and which version/fix level?

    MWS 10.5 , latest fixes

    Are you using a free trial or a product with a customer license?

    Licensed

    What are trying to achieve? Please describe in detail.

    I have configured the LDAP Kerberos configuration in my MWS. Have done all the steps mentioned in the SAG documentation but looks like it’s not working.

    When I am trying to login through browser it shows blank page and in the MWS log I can see the message like trying to login as guest user and authentication fails

    Do you get any error messages? Please provide a full error message screenshot and log file.

    2022-07-29 09:42:06 UTC (c.s.c.t.e.s.i.NervTaskEnablementManager:INFO) [Timer-15][] [] - Adding ITaskChangedEvent listener
    2022-07-29 09:42:24 UTC (c.w.p.f.i.PortalServlet:INFO) [qtp459201738-121][ [RID:1]] [ [RID:1]] - Request [1xrllh02fkihj10eyc1yv8gt40:null] https://aws-bpmdev.customer.com/ (GET) 
    2022-07-29 09:42:24 UTC (c.w.p.f.s.h.Validate:INFO) [qtp459201738-121][ [RID:1]] [ [RID:1]] - Trying to authenticate user: guest
    2022-07-29 09:42:24 UTC (c.w.p.f.s.h.Validate:INFO) [qtp459201738-121][ [RID:1]] [ [RID:1]] - user Guest authenticated = true
    2022-07-29 09:42:42 UTC (d.AccessCache:INFO) [MWS Cache Policy Timer: AccessCachePolicy][] [] - setMaxSizeLocalCache: AccessCache things: 0 entries: 0
    2022-07-29 09:43:10 UTC (c.w.c.m.t.MemoryMonitorServiceTimer:WARN) [MemoryMonitorTimer][] [] - WARN threshold breached!  Current Memory: 143MB , Threshold Memory: 150MB
    2022-07-29 09:43:10 UTC (c.w.c.m.MemoryMonitor:WARN) [MemoryMonitorTimer][] [] - Memory Monitor email configuration is empty. Cannot send notification email.
    2022-07-29 09:43:14 UTC (/SolvayCommonUserDetails:INFO) [qtp459201738-115][] [] - ZenbotServlet: Begin fo Zenbot....
    2022-07-29 09:43:14 UTC (c.w.p.m.d.i.DirSystemMechanics:WARN) [qtp459201738-115][] [] - null
    java.lang.NullPointerException: null
    at com.webmethods.caf.common.StringTools.removeChars(StringTools.java:2023) [com.webmethods.caf.shared.common_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at com.webmethods.portal.mech.dir.impl.DirMechanicsUtils.generateIDQuery(DirMechanicsUtils.java:64) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at com.webmethods.portal.portlet.wm_xt_ldapdirsvc.LdapTools.generateIDQuery(LdapTools.java:253) [?:?]
    at com.webmethods.portal.portlet.wm_xt_ldapdirsvc.service.LdapDirQueryProvider.lookupByID(LdapDirQueryProvider.java:199) [?:?]
    at com.webmethods.portal.mech.dir.impl.DirSystemMechanics$1.visit(DirSystemMechanics.java:347) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at com.webmethods.portal.mech.dir.impl.DirSystemMechanics.visitDirServices(DirSystemMechanics.java:802) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at com.webmethods.portal.mech.dir.impl.DirSystemMechanics.lookupPrincipalByID(DirSystemMechanics.java:344) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at com.webmethods.portal.bizPolicy.impl.ContextProvider.acquireContext(ContextProvider.java:700) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at com.webmethods.portal.bizPolicy.impl.ContextProvider.acquireContext(ContextProvider.java:694) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at com.webmethods.portal.bizPolicy.impl.ContextProvider.acquireContext(ContextProvider.java:677) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at com.webmethods.portal.bizPolicy.impl.ContextFactory.acquireContext(ContextFactory.java:110) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at zenbotMWS.ZenbotServlet.getCurrentContext(ZenbotServlet.java:109) [SolvayCommonUserDetails.jar:?]
    at zenbotMWS.ZenbotServlet.getCurrentUserURI(ZenbotServlet.java:105) [SolvayCommonUserDetails.jar:?]
    at zenbotMWS.ZenbotServlet._doGet(ZenbotServlet.java:38) [SolvayCommonUserDetails.jar:?]
    at zenbotMWS.ZenbotServlet._doPost(ZenbotServlet.java:101) [SolvayCommonUserDetails.jar:?]
    at zenbotMWS.ZenbotServlet.doPost(ZenbotServlet.java:32) [SolvayCommonUserDetails.jar:?]
    at zenbotMWS.ZenbotServlet.service(ZenbotServlet.java:24) [SolvayCommonUserDetails.jar:?]
    at javax.servlet.http.HttpServlet.service(HttpServlet.java:790) [javax.servlet-api_3.1.0.jar:3.1.0]
    at org.eclipse.jetty.servlet.ServletHolder.handle(ServletHolder.java:808) [org.eclipse.jetty.servlet_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.servlet.ServletHandler$CachedChain.doFilter(ServletHandler.java:1669) [org.eclipse.jetty.servlet_9.2.9.v20150224.jar:9.2.9.v20150224]
    at com.webmethods.portal.framework.impl.SpnegoFilterWrapper.callFilterChain(SpnegoFilterWrapper.java:118) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at com.webmethods.portal.framework.impl.SpnegoFilterWrapper.doFilter(SpnegoFilterWrapper.java:98) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at zenbotMWS.userDetails.doFilter(userDetails.java:26) [SolvayCommonUserDetails.jar:?]
    at org.eclipse.jetty.servlet.ServletHandler$CachedChain.doFilter(ServletHandler.java:1652) [org.eclipse.jetty.servlet_9.2.9.v20150224.jar:9.2.9.v20150224]
    at com.webmethods.caf.faces.servlet.MultipartFilter.doFilter(MultipartFilter.java:69) [com.webmethods.caf.shared.jsf_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at org.eclipse.jetty.servlet.ServletHandler$CachedChain.doFilter(ServletHandler.java:1652) [org.eclipse.jetty.servlet_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.servlet.ServletHandler.doHandle(ServletHandler.java:585) [org.eclipse.jetty.servlet_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:143) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.security.SecurityHandler.handle(SecurityHandler.java:553) [org.eclipse.jetty.security_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.session.SessionHandler.doHandle(SessionHandler.java:223) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.ContextHandler.doHandle(ContextHandler.java:1127) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.servlet.ServletHandler.doScope(ServletHandler.java:515) [org.eclipse.jetty.servlet_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.session.SessionHandler.doScope(SessionHandler.java:185) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.ContextHandler.doScope(ContextHandler.java:1061) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:141) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.ContextHandlerCollection.handle(ContextHandlerCollection.java:215) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.HandlerCollection.handle(HandlerCollection.java:110) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.HandlerWrapper.handle(HandlerWrapper.java:97) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at com.webmethods.portal.webapp.jetty7.MwsServer.handle(MwsServer.java:100) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at org.eclipse.jetty.server.Server.handle(Server.java:497) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.HttpChannel.handle(HttpChannel.java:310) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.HttpConnection.onFillable(HttpConnection.java:257) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.io.AbstractConnection$2.run(AbstractConnection.java:540) [org.eclipse.jetty.io_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.util.thread.QueuedThreadPool.runJob(QueuedThreadPool.java:635) [org.eclipse.jetty.util_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.util.thread.QueuedThreadPool$3.run(QueuedThreadPool.java:555) [org.eclipse.jetty.util_9.2.9.v20150224.jar:9.2.9.v20150224]
    at java.lang.Thread.run(Thread.java:748) [?:1.8.0_222]
    2022-07-29 09:43:14 UTC (/SolvayCommonUserDetails:INFO) [qtp459201738-115][] [] - ZenbotServlet: Got zenbot in Exception....
    2022-07-29 09:43:14 UTC (/SolvayCommonUserDetails:INFO) [qtp459201738-115][] [] - ZenbotServlet: com.webmethods.portal.PortalException: [POP.002.0108] User UID can not be found in MWS directories: null
    2022-07-29 09:43:15 UTC (c.w.c.m.MemoryMonitor:WARN) [MemoryMonitorTimer][] [] - Memory Monitor email configuration is empty. Cannot send notification email.
    2022-07-29 09:43:23 UTC (c.w.p.f.i.PortalServlet:INFO) [qtp459201738-120][ [RID:2]] [ [RID:2]] - Request [1xrllh02fkihj10eyc1yv8gt40:Guest] https://aws-bpmdev.customer.com/ (GET) 
    2022-07-29 09:44:23 UTC (SpnegoHttpFilter:ERROR) [qtp459201738-115][] [] - HTTP Authorization Header=Negotiate YIIJMwYGKwYBBQUCoIIJJzCCCSOgMDAuBgkqhkiC9xIBAgIGCSqGSIb3EgECAgYKKwYBBAGCNwICHgYKKwYBBAGCNwICCqKCCO0EggjpYIII5QYJKoZIhvcSAQICAQBuggjUMIII0KADAgEFoQMCAQ6iBwMFACAAAACjggbpYYIG5TCCBuGgAwIBBaEQGw5FVUEuU09MVkFZLkNPTaIxMC+gAwIBAqEoMCYbBEhUVFAbHmFjZXcxZHdtdGRicG0wMS5ldWEuc29sdmF5LmNvbaOCBpMwggaPoAMCARKhAwIBBaKCBoEEggZ98pJagdlv+UgYCgzLeyNNq87XtKaL9JjHaE61UdjSBJ/wKzfnlTIw1bLlAetM2m9XAZhcYgqrpyLlMesauleLLQ/HeXpw3Rn+3yA0ZCmwa0rO+9dOX225g6OwXmKLM9CAqoD5OXKkU7gVDPouJmYQB5DJKrqtt2GBf6wgEgvUT+SkCeds8qLXQ3aTf8c/H3z9stBVsLvsU5INiz3z7mrtMawGdsdtv4HdiLfd02oo1i+d3IDtt4KTT3g4As2gUv9yjTh+268OJReDPF4ISfYykLwxtinvLlxcvKBk+6eYCM4ytgWTG6xODc7CW8jzH0BJ++AbU6Pym2sdnkd0QLu0DppaiF7/2XJM+uQTQXji/MSNYL1p2oQWLINzb9UjWkMPxg7AokVmg+ihv4DDeMmPtTItsyUm+YHf1cb/3rTDl3eAUXEXneYoROfO252HRHCvbXzt9QxNlYP0LpGEFyvTKjRuDBF15RUkZopTyn7piHXPzqwqALyGU2FG4aFFeZoOzbQ98RdneluBF+3xqt0GvRP5C6Hi6E/x/7kke3EwREDNNTZq+vIcQoFQ4xsP9iV/6nEj4sEXrbKgxYuUlF9nCFdfC3/+cxURbhyitWJad9YRlwCP7yORHUxfEfL9fuOOOCH5/sKnX2Z4GtxF1EmOTPMf8ftGWRFWellpWSE8R59u91cTAqiqRDbC+gOeGtDQQ6cHYLWe651XJSn8spa8+VfzFj3X1BNT191c+F14qpLYBGqBA8MfUBk28YF8MOlN3J++f/Jqm3N1ZjFQctLUtDC5HAenjTiC594nL7cDi3E4w0z9ieBg7Ycd/kgCBQ8za9vm80+71d108ZmyusMHe1DOD+Six3DQKQtMUN6Pwt1zS/aJayAGqU+Ervz7sSO2cO3k1aPpXr7wE1iTxWsMpTWlCVCinicGgVL5cfugjXMEOx09riaI7Rp+NKxrVMmxgAx6lqPK/PKG3vIXN6nvrfn1p8IgCJH1Zp/MoITr4rxLDtzCIQ5mIXwFXGn/Uu96yeQvyX7bINjefc9urLyX5cV6RO1GirvGZFP+/4xs0vLSkVPLFY1Dzz5YN7ByK3vNxRXbBU+2w+gc326M3sDueFrfW6kxmdjSNgfijx4Z416fBRs9Kfb0fTAyrSuibqWdHsWW5zhkBgfLJSKSS61Dl5HuAMH4HMhgK0vyT8VtioK2knhFnbsD53pr4nfTJkd1lJoyq3ZHS9mt7PJg/KZcSsdmQm7RExet8rCGGtnCa5lHci+zWK4xsFNEX+eVbWBoXTd5oMcCJZpnZAORQKAuoZVqak5f0eBb8KrHPObQ9GfACPsb8wmy0dKBl+TrkEQoheHwuTWBLzmF192TBk9omDRwbgGAk5wjsBwfLIKq5t0eGejPja1adRlCZM9QGaIDLQ6J5RnnnumIkU0gRTJHQwa67qUGGw2Bg3IOEuXtkO1XI4JNUl43H+qqMPdWhv/x+7wcxa3sLaFNlTphBGGoBOle27zoPDfqFM4V1sEgXImiuwoIQDeCyhUHPhtxWNmCYUOZzWGiCQaGCcc0lmcFShs/UFBSrPS7a3EZOP7GfDz5MQ+BiCdi2k28URbgZDtis7VrHC6oRbUZakqwjEhrY5O5RH0sBDRSvL44943k9tsfD30XBRUDLVasQUhPNoDEMFjhaR8c5ZqIUZj73PyuSvXc6cCfnswraHz5ijm7jKRDlbKq+DXG/5+u297cvBhE0AHj+iO4Xs9S+P5jnyNhozVO0wPwubMIVhXyJbCvGOuUn2cTvNcUXtqfmRzryaeDk53DcUaupbGAwa4WB4eo/0TQUcpWSnV0WHm9mCw9oKunYMX/m+uubFDK7sHLJS3lOrDuW40F7XZ7L+u2F1mxdSvxxFK8k4AYvaI66C5UqGhomH0So0H1yS8/AHGSWR0SKfYoMesNtt0LoiTVJ12Id6LBeG5jItHLGdhxWli3sjNJtpDrRuPhz20vjg2CS5u34AFgemxX9vc7ButBe0CQjZSsllsU7h4bGmmilMbuc9YO/qSnwBpRzqcqk++kbcnYEoEWfDKMUXCZTLbOt2tcLD9GK5rSP8G/n1W+kbZh6gUNNpK3ieNwLVe6UxgVa9l9zgwYG15aN4uTgfJYTepTwqKuqj3kT+4faNyMB1C5/L7sFsyBSWXe9al3rNty2wI+jGleQygjla1LTFoYu4DWsypfly/kvqnDwqQ4FgWkggHMMIIByKADAgESooIBvwSCAbsl6PZyWy0q5bJqKdw7+7TL+cxjeJsQjHBJ5NnuJPPmNYie1PbgTMVf7NL3PBEc9cEtxcWi57OOlI9mXftrKc4klKNpAEWROiM+V3vTILS3cHKmncD2rkRe7yPzxpSo8YCjAMBZ6kWp3OLQil+V2NmqZei3EcE/jaieIZZjUTmMnKwCnUBwcPxfTzfNPivtutZdPT9kZYTUT0XOo7stQJWKDcaJXenuETar8f1Ytqa5evfCx1qqj09IzsAcdEd4vR1YBWhpYITAtZIYCrwVdFhkWUmTXDlWox90ehZT3ClOjst9FQKYgW2CI/sgjdPUDgJWlg8Yep+vnXwwEgUuKzScLFGiaIXMXXj7Odp56aAHvKura7vZ5OyXDMltihRPSZJd6hdVp2ABmy3dLPCvH/sEQI6Iu+lyI2/EY8P2D9Iu0rOKY/46AfiOn3uq2FZzuQ5rRhum8GhDERQX8Hn/0azWc1IAYOi/wgFxgfioUJpjL8YdlqGhHs5wrxugEsH57ud2Go0pPxJa72Q+ZojgSdj/FyZwMduThTaXNey3i6q5Kszly0MPiJOJoZygfPi3DOUtV9tHqSJtvOgWZg==
    2022-07-29 09:44:23 UTC (c.w.p.f.i.SpnegoFilterWrapper:INFO) [qtp459201738-115][] [] - Error while processing Kerberos tokenGSSException: Failure unspecified at GSS-API level (Mechanism level: Checksum failed)
    2022-07-29 09:44:23 UTC (c.w.p.f.i.SpnegoFilterWrapper:WARN) [qtp459201738-115][] [] - Error in Kerberos authentication:
    javax.servlet.ServletException: GSSException: Failure unspecified at GSS-API level (Mechanism level: Checksum failed)
    at net.sourceforge.spnego.SpnegoHttpFilter.doFilter(SpnegoHttpFilter.java:228) [com.softwareag.net.sourceforge.spnego_0.0.0.0000-0003.jar:0.0.0.0000-0003]
    at com.webmethods.portal.framework.impl.SpnegoFilterWrapper.doFilter(SpnegoFilterWrapper.java:95) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at org.eclipse.jetty.servlet.ServletHandler$CachedChain.doFilter(ServletHandler.java:1652) [org.eclipse.jetty.servlet_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.servlet.ServletHandler.doHandle(ServletHandler.java:585) [org.eclipse.jetty.servlet_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:143) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.security.SecurityHandler.handle(SecurityHandler.java:577) [org.eclipse.jetty.security_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.session.SessionHandler.doHandle(SessionHandler.java:223) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.ContextHandler.doHandle(ContextHandler.java:1127) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.servlet.ServletHandler.doScope(ServletHandler.java:515) [org.eclipse.jetty.servlet_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.session.SessionHandler.doScope(SessionHandler.java:185) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.ContextHandler.doScope(ContextHandler.java:1061) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.ScopedHandler.handle(ScopedHandler.java:141) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.ContextHandlerCollection.handle(ContextHandlerCollection.java:215) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.HandlerCollection.handle(HandlerCollection.java:110) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.handler.HandlerWrapper.handle(HandlerWrapper.java:97) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at com.webmethods.portal.webapp.jetty7.MwsServer.handle(MwsServer.java:100) [com.webmethods.caf.server_10.5.0.0013-0277.jar:10.5.0.0013-0277]
    at org.eclipse.jetty.server.Server.handle(Server.java:497) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.HttpChannel.handle(HttpChannel.java:310) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.server.HttpConnection.onFillable(HttpConnection.java:257) [org.eclipse.jetty.server_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.io.AbstractConnection$2.run(AbstractConnection.java:540) [org.eclipse.jetty.io_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.util.thread.QueuedThreadPool.runJob(QueuedThreadPool.java:635) [org.eclipse.jetty.util_9.2.9.v20150224.jar:9.2.9.v20150224]
    at org.eclipse.jetty.util.thread.QueuedThreadPool$3.run(QueuedThreadPool.java:555) [org.eclipse.jetty.util_9.2.9.v20150224.jar:9.2.9.v20150224]
    at java.lang.Thread.run(Thread.java:748) [?:1.8.0_222]
    Caused by: org.ietf.jgss.GSSException: Failure unspecified at GSS-API level (Mechanism level: Checksum failed)
    at sun.security.jgss.krb5.Krb5Context.acceptSecContext(Krb5Context.java:856) [?:1.8.0_222]
    at sun.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:342) [?:1.8.0_222]
    at sun.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:285) [?:1.8.0_222]
    at sun.security.jgss.spnego.SpNegoContext.GSS_acceptSecContext(SpNegoContext.java:906) [?:1.8.0_222]
    at sun.security.jgss.spnego.SpNegoContext.acceptSecContext(SpNegoContext.java:556) [?:1.8.0_222]
    at sun.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:342) [?:1.8.0_222]
    at sun.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:285) [?:1.8.0_222]
    at net.sourceforge.spnego.SpnegoAuthenticator.doSpnegoAuth(SpnegoAuthenticator.java:440) [com.softwareag.net.sourceforge.spnego_0.0.0.0000-0003.jar:0.0.0.0000-0003]
    at net.sourceforge.spnego.SpnegoAuthenticator.authenticate(SpnegoAuthenticator.java:290) [com.softwareag.net.sourceforge.spnego_0.0.0.0000-0003.jar:0.0.0.0000-0003]
    at net.sourceforge.spnego.SpnegoHttpFilter.doFilter(SpnegoHttpFilter.java:224) [com.softwareag.net.sourceforge.spnego_0.0.0.0000-0003.jar:0.0.0.0000-0003]
    ... 22 more
    Caused by: sun.security.krb5.KrbCryptoException: Checksum failed
    at sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType.decrypt(Aes256CtsHmacSha1EType.java:102) [?:1.8.0_222]
    at sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType.decrypt(Aes256CtsHmacSha1EType.java:94) [?:1.8.0_222]
    at sun.security.krb5.EncryptedData.decrypt(EncryptedData.java:175) [?:1.8.0_222]
    at sun.security.krb5.KrbApReq.authenticate(KrbApReq.java:281) [?:1.8.0_222]
    at sun.security.krb5.KrbApReq.<init>(KrbApReq.java:149) [?:1.8.0_222]
    at sun.security.jgss.krb5.InitSecContextToken.<init>(InitSecContextToken.java:108) [?:1.8.0_222]
    at sun.security.jgss.krb5.Krb5Context.acceptSecContext(Krb5Context.java:829) [?:1.8.0_222]
    at sun.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:342) [?:1.8.0_222]
    at sun.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:285) [?:1.8.0_222]
    at sun.security.jgss.spnego.SpNegoContext.GSS_acceptSecContext(SpNegoContext.java:906) [?:1.8.0_222]
    at sun.security.jgss.spnego.SpNegoContext.acceptSecContext(SpNegoContext.java:556) [?:1.8.0_222]
    at sun.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:342) [?:1.8.0_222]
    at sun.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:285) [?:1.8.0_222]
    at net.sourceforge.spnego.SpnegoAuthenticator.doSpnegoAuth(SpnegoAuthenticator.java:440) [com.softwareag.net.sourceforge.spnego_0.0.0.0000-0003.jar:0.0.0.0000-0003]
    at net.sourceforge.spnego.SpnegoAuthenticator.authenticate(SpnegoAuthenticator.java:290) [com.softwareag.net.sourceforge.spnego_0.0.0.0000-0003.jar:0.0.0.0000-0003]
    at net.sourceforge.spnego.SpnegoHttpFilter.doFilter(SpnegoHttpFilter.java:224) [com.softwareag.net.sourceforge.spnego_0.0.0.0000-0003.jar:0.0.0.0000-0003]
    ... 22 more
    Caused by: java.security.GeneralSecurityException: Checksum failed
    at sun.security.krb5.internal.crypto.dk.AesDkCrypto.decryptCTS(AesDkCrypto.java:451) [?:1.8.0_222]
    at sun.security.krb5.internal.crypto.dk.AesDkCrypto.decrypt(AesDkCrypto.java:272) [?:1.8.0_222]
    at sun.security.krb5.internal.crypto.Aes256.decrypt(Aes256.java:76) [?:1.8.0_222]
    at sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType.decrypt(Aes256CtsHmacSha1EType.java:100) [?:1.8.0_222]
    at sun.security.krb5.internal.crypto.Aes256CtsHmacSha1EType.decrypt(Aes256CtsHmacSha1EType.java:94) [?:1.8.0_222]
    at sun.security.krb5.EncryptedData.decrypt(EncryptedData.java:175) [?:1.8.0_222]
    at sun.security.krb5.KrbApReq.authenticate(KrbApReq.java:281) [?:1.8.0_222]
    at sun.security.krb5.KrbApReq.<init>(KrbApReq.java:149) [?:1.8.0_222]
    at sun.security.jgss.krb5.InitSecContextToken.<init>(InitSecContextToken.java:108) [?:1.8.0_222]
    at sun.security.jgss.krb5.Krb5Context.acceptSecContext(Krb5Context.java:829) [?:1.8.0_222]
    at sun.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:342) [?:1.8.0_222]
    at sun.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:285) [?:1.8.0_222]
    at sun.security.jgss.spnego.SpNegoContext.GSS_acceptSecContext(SpNegoContext.java:906) [?:1.8.0_222]
    at sun.security.jgss.spnego.SpNegoContext.acceptSecContext(SpNegoContext.java:556) [?:1.8.0_222]
    at sun.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:342) [?:1.8.0_222]
    at sun.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:285) [?:1.8.0_222]
    at net.sourceforge.spnego.SpnegoAuthenticator.doSpnegoAuth(SpnegoAuthenticator.java:440) [com.softwareag.net.sourceforge.spnego_0.0.0.0000-0003.jar:0.0.0.0000-0003]
    at net.sourceforge.spnego.SpnegoAuthenticator.authenticate(SpnegoAuthenticator.java:290) [com.softwareag.net.sourceforge.spnego_0.0.0.0000-0003.jar:0.0.0.0000-0003]
    at net.sourceforge.spnego.SpnegoHttpFilter.doFilter(SpnegoHttpFilter.java:224) [com.softwareag.net.sourceforge.spnego_0.0.0.0000-0003.jar:0.0.0.0000-0003]
    

    Have you installed latest fixes for the products

    Yes


    #BPM
    #webMethods
    #MWS-CAF-Task-Engine


  • 2.  RE: MWS 10.5 Kerberos Authentication does not work

    Posted Thu October 20, 2022 04:35 AM

    Similar issue was resolved in the past by disabling the encryption keys which were configured at Active directory for the service principal account. See:
    Untitled (softwareag.com)
    page 267


    #webMethods
    #BPM
    #MWS-CAF-Task-Engine