Power

 View Only
Expand all | Collapse all

Help Needed: SSO Issue with EIM - NAV_307002 and Kerberos Credential Mapping Errors

  • 1.  Help Needed: SSO Issue with EIM - NAV_307002 and Kerberos Credential Mapping Errors

    Posted Fri August 02, 2024 03:23 AM

    Hello Everyone,

    We are experiencing an issue with our Single Sign-On (SSO) configured on Enterprise Identity Mapping (EIM). When attempting to connect to EIM from iNavigator, we encounter the following error:

    "Error: NAV_307002: Failed to retrieve the domain list Details: Communication error with EIM domain controller. The server may be down, or the server name or port number may be incorrect."

    Additionally, we receive the following messages on the 5250 emulator:

    MSGSY1018 - Kerberos credentials could not be mapped to user on system *KERBEROS rc=59

    CPD3E3F - Network Authentication Service error X'00000003' occurred.

    We have verified the server status, server name, and port number, but the issue persists. Any insights or suggestions on how to resolve this would be greatly appreciated.

    Thank you!



    ------------------------------
    Suresh Gudelli
    ------------------------------


  • 2.  RE: Help Needed: SSO Issue with EIM - NAV_307002 and Kerberos Credential Mapping Errors

    Posted Mon August 05, 2024 02:40 AM

    Hello, 

    According this note you must check "mismatch between the LDAP and EIM cn=Administrator passwords."

    https://www.ibm.com/support/pages/how-resolve-msgsy1018-when-connecting-ibm-i-using-single-sign



    ------------------------------
    Fernando Plaza
    IBM i System Administrator
    CD INVEST
    MADRID
    ------------------------------



  • 3.  RE: Help Needed: SSO Issue with EIM - NAV_307002 and Kerberos Credential Mapping Errors

    Posted Mon August 05, 2024 07:25 AM

    Hello Fernando,

    I have changed the password with the instructions provided in the link but I still see the same issue. When I try to verify the connection, I am getting the Communication Error with EIM domain controller. The server may be down, or the server name or port number is incorrect. Attached the screen print for your reference.

    Also I don't see anything under the column status for the controller whether it is running or stopped. And when I click on it to start or stop I see both the option available one should be in greyed out right. Attached the screen print for the same.



    ------------------------------
    Suresh Gudelli
    ------------------------------



  • 4.  RE: Help Needed: SSO Issue with EIM - NAV_307002 and Kerberos Credential Mapping Errors

    Posted Mon August 05, 2024 08:34 AM

    Hello Shured ...

    I can't recreate your environment th e

    but MSGSY1018 point to password problems

    https://www.volubis.fr/news/liens/courshtm/EIMV7.htm

    Or DNS problems ...

    https://archive.midrange.com/midrange-l/202104/msg00373.html



    ------------------------------
    Fernando Plaza
    IBM i System Administrator
    CD INVEST
    MADRID
    ------------------------------