Reputation: 432521
We have a new 3rd party app, IBM WebSphere on Linux with SPNEGO enabled for SSO to our Windows AD. This works as expected, except for one case.
WebSphere calls an existing Windows Web Service that uses pass-through authentication, so the end user credentials are presented to SQL Server. This Windows setup also works.
What doesn't work: WebSphere credentials do not multi-hop to SQL Server
Summary
The failure:
Error Code: 0x24 KRB_AP_ERR_BADMATCH
Server Realm: XXX.CH.OURDOMAIN.COM
Server Name: MSSQLSvc/oursqlserver.xxx.ch.ourdomain.com:50025
Target Name: MSSQLSvc/oursqlserver.xxx.ch.ourdomain.com:[email protected]
Other info
What are we missing for that pass-through hop to SQL Server from IBM WebSphere?
Upvotes: 5
Views: 367
Reputation: 432521
It was a very long Kerberos caching. Rebooted the server, fixed it.
The Linux admins had said "No need to reboot: it isn't Windows"
Upvotes: 1