Forum Discussion
Help me troubleshoot sso issue for ntlm
Hello I have tried to configure a ntlm2 sso for a webapplication, it dont seem to work. Here is from a debug log. http://pastebin.com/0q01Vh71
8 Replies
- kunjan
Nimbostratus
Is the backend configured with NTLM as the authentication provider?
Should see the 401 response in apm log. When SSO fails do you see the logon prompt window?
- supportrsd_1762
Nimbostratus
Yes, the customer sent a wireshark log and there you see clearly its a ntlm authentication.
Well this is also strange, i just did a new check. I did clear my settings and did a logon. This time i got this (it still dont work)
Thre you can see the ntlm stuff.
Then i did a new check, then the logs just look like this.
Yes i do see a 401 page when i try to logon
- kunjan
Nimbostratus
Try enabling "Split domain from full Username" in the logon page
- supportrsd_1762
Nimbostratus
I have it already, i also do a variable assign that looks like this session.logon.last.username = expr { " sheep\[mcget {session.logon.last.username}]" } Before the sso credential mapping Since i also trying to be able to get sso to a webapplication to work (sheep is the domain). I need to specify sheep\username when i log on to that.
- kunjan
Nimbostratus
For SSO, username got to be without domain.
- supportrsd_1762
Nimbostratus
Hmm, but if the webapplication in this case needs to have the domain\username how do i solve it then?
- supportrsd_1762
Nimbostratus
Also, i noticed that after i try to browse the ntlm webapplication, i get this session variable. Then the other sso Resources stops working.
session.sso.token.last.username.sso.state 1 1
- Ibrahim_Kadiri
Nimbostratus
HI,
were you able to solve the issue? If Yes, can you please provide the steps taken.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com