gbn
gbn

Reputation: 432521

WebSphere Kerberos multi-hop failing

We have a new 3rd party app, IBM WebSphere on Linux with SPNEGO enabled for SSO to our Windows AD. This works as expected, except for one case.

WebSphere calls an existing Windows Web Service that uses pass-through authentication, so the end user credentials are presented to SQL Server. This Windows setup also works.

What doesn't work: WebSphere credentials do not multi-hop to SQL Server

Summary

The failure:

Error Code: 0x24 KRB_AP_ERR_BADMATCH
Server Realm: XXX.CH.OURDOMAIN.COM
Server Name: MSSQLSvc/oursqlserver.xxx.ch.ourdomain.com:50025
Target Name: MSSQLSvc/oursqlserver.xxx.ch.ourdomain.com:[email protected]

Other info

What are we missing for that pass-through hop to SQL Server from IBM WebSphere?

Upvotes: 5

Views: 367

Answers (1)

gbn
gbn

Reputation: 432521

It was a very long Kerberos caching. Rebooted the server, fixed it.

The Linux admins had said "No need to reboot: it isn't Windows"

Upvotes: 1

Related Questions