Forum Discussion
Help me troubleshoot sso issue for ntlm
Hello I have tried to configure a ntlm2 sso for a webapplication, it dont seem to work. Here is from a debug log. http://pastebin.com/0q01Vh71
8 Replies
- kunjan
Nimbostratus
Is the backend configured with NTLM as the authentication provider?
Should see the 401 response in apm log. When SSO fails do you see the logon prompt window?
- supportrsd_1762
Nimbostratus
Yes, the customer sent a wireshark log and there you see clearly its a ntlm authentication.
Well this is also strange, i just did a new check. I did clear my settings and did a logon. This time i got this (it still dont work)
Thre you can see the ntlm stuff.
Then i did a new check, then the logs just look like this.
Yes i do see a 401 page when i try to logon
- kunjan
Nimbostratus
Try enabling "Split domain from full Username" in the logon page
- supportrsd_1762
Nimbostratus
I have it already, i also do a variable assign that looks like this session.logon.last.username = expr { " sheep\[mcget {session.logon.last.username}]" } Before the sso credential mapping Since i also trying to be able to get sso to a webapplication to work (sheep is the domain). I need to specify sheep\username when i log on to that.
- kunjan
Nimbostratus
For SSO, username got to be without domain.
- supportrsd_1762
Nimbostratus
Hmm, but if the webapplication in this case needs to have the domain\username how do i solve it then?
- supportrsd_1762
Nimbostratus
Also, i noticed that after i try to browse the ntlm webapplication, i get this session variable. Then the other sso Resources stops working.
session.sso.token.last.username.sso.state 1 1
- Ibrahim_Kadiri
Nimbostratus
HI,
were you able to solve the issue? If Yes, can you please provide the steps taken.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com