cancel
Showing results for 
Search instead for 
Did you mean: 

Active Directory authentication. NTLM and Kerebos.

Former Member
0 Kudos

I've been trying to setup Active Directory authentication on SAP Crystal Server 2011 for several days now. I followed the steps in the security guide. I created the needed service accounts and granted permissions as directed. I mapped active directory groups, and the users in those groups were imported into the system. I enabled the AD plugin. When I attempt to connect to the CMC using Kerebos I recieve the following error

"u2022Account Information Not Recognized: Active Directory Authentication failed to log you on. Please contact your system administrator to make sure you are a member of a valid mapped group and try again. If you are not a member of the default domain, enter your user name as UserName@DNS_DomainName, and then try again. (FWM 00006)"

When I try NTLM authentication I recieve the following error

"u2022Account Information Not Recognized: The Windows AD plug-in does not support Java in NTLM mode. Please use Kerberos. (FWM 02100)

Enter your user information and click Log On.

(If you are unsure of your account information, contact your system administrator.) "

We could live without AD authentication to the CMC but need it for users to be able to log into the system to view reports. I'm thinking NTLM authentication would be fine for that, but I'm not really sure what the URL is for the report view interface is on this version of the software.

Accepted Solutions (0)

Answers (1)

Answers (1)

BasicTek
Advisor
Advisor
0 Kudos

I didn't here you mention creating SPN's, krb5.ini, or bsclogin.conf.

Also is this for WACS or tomcat? [use this KB |http://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/com.sap.km.cm.docs/oss_notes_boj/sdn_oss_boj_bi/sap(bD1lbiZjPTAwMQ==)/bc/bsp/spn/scn_bosap/notes%7B6163636573733d36393736354636443646363436353344333933393338323636393736354637333631373036453646373436353733354636453735364436323635373233443330333033303331333433383333333733363332%7D.do] for full steps to get kerberos working.

Regards,

Tim

Former Member
0 Kudos

Actually yes I created an SPN and I also created the files you mentioned. I assigned the SPN the login as a service right and made it admin.

BasicTek
Advisor
Advisor
0 Kudos

ok so you need to verify the client tools work, instead of logging into the web/app login to a client tool (deski/designer/business views/CCM/etc) on the server for the best test. If client tools work then the problem is with the krb5.ini and bsclogin, if not then the service account isn't working properly

Let us know...

Regards,

Tim