SAP Community Network Forums » Business Objects » BusinessObjects Enterprise Administration

Thread: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos

This question is not answered.


Permlink Replies: 29 - Pages: 2 [ 1 2 | Next ] - Last Post: Nov 17, 2009 5:18 PM Last Post By: Tim Ziemba
Sidney Fernandes

Posts: 5
Registered: 10/15/09
Forum Points: 0
 
Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 15, 2009 8:35 PM
Click to report abuse...   Click to reply to this thread Reply
Are we the only group that has Vintela SSO configured with Kerberos encryption on Windows servers and whose client PCs using Internet Explorer have started to display HTTP Status 500...Channel binding mismatch? We see NOTHING on the web or in any of the forums on this. Client PCs effected have the Microsoft Updates of 10/13/09 applied (especially KB974455).

We have:

- Business Objects Enterprise XI 3.1 with FixPack 1_7

- Windows 2003 Servers for the Vintela and Business Objects Enterprise installation and authentication. On the client side, any version of IE (6, 7, 8) is impacted as soon as the Microsoft Updates are applied (removing KB974455 seems to clear up the problem, but it is a combination of updates that need to be in place for it to occur).

Manual login is not impacted (thank goodness), but we'd much prefer SSO. Suggestions?

Tim Ziemba  Moderator  SAP Employee

Posts: 2,576
Registered: 5/6/08
Forum Points: 4,830
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 16, 2009 7:15 AM   in response to: Sidney Fernandes in response to: Sidney Fernandes
Click to report abuse...   Click to reply to this thread Reply
I would need tracing information to verify the issue, when updates cause the issue it could be DES which we used to use in XIR2 as Microsoft may be preventing it due to security liability. To trace look at the admin forum sticky post where I have my vintela 3.1 doc. The tracing instructions for vintela (djcsi) are at the end. Also if you upgraded to 2008 DC's there is an SAP note on how this could cause an issue and link to Microsoft patch.

Regards,

Tim

Yoshihiko Sugim...

Posts: 1
Registered: 1/5/05
Forum Points: 0
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 16, 2009 9:05 AM   in response to: Sidney Fernandes in response to: Sidney Fernandes
Click to report abuse...   Click to reply to this thread Reply
A similar phenomenon is caused in the our environment .
We use EP of the SAP.
I realized SSO which used kerberos between AD and EP.
However, I was not able to use SSO when I applied Microsoft update KB974455.
The version of the OS of our client PC is windows XP Professional SP3.
Because Microsoft update KB974455 is a patch preventing serious security, I want to apply it.
However, I am troubled with SSO because I want to continue using it.
If there is a solution, please show me it.
Tim Ziemba  Moderator  SAP Employee

Posts: 2,576
Registered: 5/6/08
Forum Points: 4,830
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 16, 2009 12:36 PM   in response to: Yoshihiko Sugim... in response to: Yoshihiko Sugim...
Click to report abuse...   Click to reply to this thread Reply
I will also try to test that patch on some of my kerberos enabled VM's I'll be interested to see what is happening.

Regards,

Tim

Sidney Fernandes

Posts: 5
Registered: 10/15/09
Forum Points: 0
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 16, 2009 4:06 PM   in response to: Tim Ziemba in response to: Tim Ziemba
Click to report abuse...   Click to reply to this thread Reply
Since the system is in-use, I would prefer not to switch from using the keytab to a straight password to enable tracing -- at least not until the weekend (when there are less users). I assure you that we are not using DES -- I configured it for RC4. We also have not upgraded our DCs to 2008 yet, and the SSO continues to work perfectly for any client PC which has not applied the recent Microsoft patches. If necessary, I will come in this weekend and get a trace for you. Thanks a bunch!
K Joyner

Posts: 7
Registered: 10/5/09
Forum Points: 0
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 16, 2009 4:50 PM   in response to: Sidney Fernandes in response to: Sidney Fernandes
Click to report abuse...   Click to reply to this thread Reply
We also have the same issue. Running BO 3.1 with kerberos SSO. After applying KB974455 getting http status 500. Have opened case with support as this is our production envionment. We went live on Monday, patch came out Tueday. Great timing eh?

Any help would be appreciated.
Mark Richardson

Posts: 153
Registered: 6/8/08
Forum Points: 127
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 16, 2009 7:11 PM   in response to: Sidney Fernandes in response to: Sidney Fernandes
Click to report abuse...   Click to reply to this thread Reply
We haven't applied the 10/13/2009 patches yet (but intend to do so this weekend) - and have a couple of questions...

1.) Does this effect all the "flavours" of Enterprise 3.1 (eg. Crystal Report 2008 Server, Business Objects Edge 3.1) - or is it Enterprise 3.1 specific...?

2.) Does it effect WinAD SSO into both the Java (Tomcat) and .Net (IIS) InfoView applications - or is it specific to a certain web-platform....?

Thanks in advance!
K Joyner

Posts: 7
Registered: 10/5/09
Forum Points: 0
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 16, 2009 7:35 PM   in response to: Mark Richardson in response to: Mark Richardson
Click to report abuse...   Click to reply to this thread Reply
I can say for certainty so far that it does not affect Firefox :-) Java SSO still works there...
We do not have SSO enabled for .NET so I can't say. We are running 3.1 Enterprise.
Sidney Fernandes

Posts: 5
Registered: 10/15/09
Forum Points: 0
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 16, 2009 8:06 PM   in response to: Mark Richardson in response to: Mark Richardson
Click to report abuse...   Click to reply to this thread Reply
Mark,

1.) We do not have Crystal Report 2008 Server, nor Business Objects Edge 3.1 -- we can only attest to the impact on Enterprise 3.1 logins.

2.) We only use the Java (Tomcat) portion since the .NET/IIS stuff is being phased out.

So, basically, I can't answer either of your questions. Sorry.
Mark Richardson

Posts: 153
Registered: 6/8/08
Forum Points: 127
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 16, 2009 8:10 PM   in response to: Sidney Fernandes in response to: Sidney Fernandes
Click to report abuse...   Click to reply to this thread Reply
QUOTE : "....since the .NET/IIS stuff is being phased out."

The .NET/IIS components for InfoView were just re-introduced by SAP BOBJ for XI-3.1 after XI-3.0 being Java-only.

Where did you hear that "the .NET/IIS stuff is being phased out."...?
Sidney Fernandes

Posts: 5
Registered: 10/15/09
Forum Points: 0
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 16, 2009 10:53 PM   in response to: Mark Richardson in response to: Mark Richardson
Click to report abuse...   Click to reply to this thread Reply
Mark,

My apologies. I downloaded the documentation for 3.0 long before I downloaded/installed 3.1. My information is old regarding the IIS stuff. We never used the IIS portion even back with XI R2, so my attention was focused elsewhere.
Sidney Fernandes

Posts: 5
Registered: 10/15/09
Forum Points: 0
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 16, 2009 10:57 PM   in response to: Tim Ziemba in response to: Tim Ziemba
Click to report abuse...   Click to reply to this thread Reply
...from the following forum thread, it looks like perhaps the next update for Java might help:

http://groups.google.com/group/comp.protocols.kerberos/browse_thread/thread/77d23b537e917d6a

...but I don't suggest disabling the Microsoft patch through the registry key edit -- kinda defeats the purpose, eh?
Tim Ziemba  Moderator  SAP Employee

Posts: 2,576
Registered: 5/6/08
Forum Points: 4,830
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 16, 2009 11:24 PM   in response to: Sidney Fernandes in response to: Sidney Fernandes
Click to report abuse...   Click to reply to this thread Reply
looking at the patch details I can't see what's happening. My guess is that it's either changing IE settings or IE SSO behavior (since the patch seems to refer to only IE stuff). It is very likely that at least kerberos SSO will also be affected as they both use spnego. NTLM may be ok but who knows.

I did not get a chance to test this today so we'll have to see next week. It sounds like this could be a serious issue so create cases if you can.

Also see the following SAP notes 1379894 for IE rules for configuration or 1245342 for manual logon instructions or 1263764 for firefox (kerberos) SSO instructions.

Looking at the initial findings it looks like this may need to be escalated to Microsoft

Regards,

Tim

K Joyner

Posts: 7
Registered: 10/5/09
Forum Points: 0
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 17, 2009 2:06 AM   in response to: Tim Ziemba in response to: Tim Ziemba
Click to report abuse...   Click to reply to this thread Reply
The update in Microsoft Knowledge Base Article 968389 modifies the SSPI in order to enhance the way Windows authentication works so that credentials are not easily forwarded when Integrated Windows Authentication (IWA) is enabled.

When Extended Protection for Authentication is enabled, authentication requests are bound to both the Service Principal Names (SPN) of the server the client attempts to connect to and to the outer Transport Layer Security (TLS) channel over which the IWA authentication takes place. This is a base update which enables applications to opt in to the new feature.

Future updates will modify individual system components that perform IWA authentication so the components use this protection mechanism. Customers must install both the Microsoft Knowledge Base Article 968389 update and the respective application-specific updates for the client applications and servers on which Extended Protection for Authentication needs to be activated. Upon installation, Extended Protection for Authentication is controlled on the client through the use of registry keys. On the server, configuration is specific to the application.

This is probably red-herring material. I could not find the reg keys and MS says they'd be disabled on default anyways.

Edited by: K Joyner on Oct 19, 2009 8:49 PM
Golo Maichel

Posts: 22
Registered: 1/23/08
Forum Points: 2
 
Re: Microsoft Updates 10/13/09 Kill Vintela SSO w/ Kerberos  
Posted: Oct 19, 2009 9:19 AM   in response to: Sidney Fernandes in response to: Sidney Fernandes
Click to report abuse...   Click to reply to this thread Reply
Hi,

we have the same problem: we have realized SSO between EP and AD. Before installing KB974455 the integrated Window Authentification worked fine. Now, with KB974455 we get the following exception:

org.ietf.jgss.GSSException, major code: 1, minor code: 0
major string: Channel binding mismatch
minor string: ChannelBinding checksum failed verification
at com.ibm.security.jgss.i18n.I18NException.throwGSSException(I18NException.java:34)
at com.ibm.security.jgss.mech.krb5.k.a(k.java:409)
at com.ibm.security.jgss.mech.krb5.k.b(k.java:207)
at com.ibm.security.jgss.mech.krb5.k.acceptSecContext(k.java:76)
at com.ibm.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:353)
at com.ibm.security.jgss.GSSContextImpl.acceptSecContext(GSSContextImpl.java:79)
at com.sap.security.core.server.jaas.SPNegoLoginModule.doHandshake(SPNegoLoginModule.java:749)
at com.sap.security.core.server.jaas.SPNegoLoginModule.login(SPNegoLoginModule.java:365)
at com.sap.engine.services.security.login.LoginModuleLoggingWrapperImpl.login(LoginModuleLoggingWrapperImpl.java:185)
at com.sap.engine.services.security.login.ModulesProcessAction.run(ModulesProcessAction.java:70)
at java.security.AccessController.doPrivileged(AccessController.java:231)
at com.sap.engine.services.security.login.FastLoginContext.login(FastLoginContext.java:181)
at com.sap.engine.system.SystemLoginModule.login(SystemLoginModule.java:90)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
...

Our System:
Client: Windows XP SP2, IE 7.0.5730.13
Server OS: Linux (amd64) 2.6.16.60-0.33-smp
ADS LDAP: Windows 2003 Server
SAP Version: NetWeaver 7.0 SP18
JDK: j2sdk1.4.2_16-x64, IBM

With Firefox the IWA works still fine.
What can we do to fix the problem with IE?


Point your RSS reader here for a feed of the latest messages in all forums