Quantcast
Channel: SCN: Message List
Viewing all articles
Browse latest Browse all 8944

Manual AD not working for users in Non-Default Domain

$
0
0

Hi Experts,

 

Users in the Default domain (D.CHILD1.PARENT.COM) are able to login manually using Windows AD.

But users in others domains (eg : A.CHILD1.PARENT.COM) are not able to login using manual AD. They are getting the below error :

 

Error.PNG

 

I see the below error in tomcat logs (stdout.log)

 

TC Logs.PNG

 

User Entered name : xyz@A.CHILD1.PARENT.COM

[Krb5LoginModule] authentication failed 111.A.CHILD1.PARENT.COM

Strange thing is : "111" kdc server belongs to PARENT.COM, but in the error it is showing "A.CHILD1.PARENT.COM"


Forest structure :

PARENT.COM

-CHILD1.PARENT.COM

    -A.CHILD1.PARENT.COM (trying to make it work for user in this domain first)

    -B.CHILD1.PARENT.COM

    -C.CHILD1.PARENT.COM

    -D.CHILD1.PARENT.COM (Default)

-CHILD2.PARENT.COM

-CHILD3.PARENT.COM

    -E.CHILD3.PARENT.COM

    -F.CHILD3.PARENT.COM

 

krb5.ini (trying to make it work for users of A.CHILD1.PARENT.COM & D.CHILD1.PARENT.COM)

 

 


dummykrb5.PNG

 

So, when a user of domain D.CHILD1.PARENT.COM logs in manually, it works

When a user of domain A.CHILD1.PARENT.COM logs in, it gives above error message. Tomcat logs are also attached above.

 

NOTE : Service account is also from the default domain : D.CHILD1.PARENT.COM

 

Kindly help us in fixing this issue. Thanks.

 

Regards,

Monish


Viewing all articles
Browse latest Browse all 8944

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>