Forum Discussion

Talassa_90150's avatar
Talassa_90150
Icon for Nimbostratus rankNimbostratus
Dec 21, 2015

sso problem with ntlm2

Hello guys Im newbie to F5 APM i use f5 ver 12.00 im trying to set SSO via NTLMV2 i can access the website but

 

when looking at the /var/log/apm i see "Could not find SSO username, check SSO credential mapping agent setting" The ntlm2 sso is configured USERNAME SOURCE "session.sso.token.last.username" PASSWORD SOURCE "session.sso.token.last.password"DOMAIN SOURCE "session.logon.last.domain" THE ACCESS PROFILE POLICY IS ASSOCIATED WITH SSO NTLM2 AS WELL AS THE PORTAL RESOURCE ITEM when i use curl -i https://x.abc.com -k i see that the site is working with ntlm

 

HTTP/1.1 401 Unauthorized Server: Microsoft-IIS/7.5 WWW-Authenticate: NTLM MicrosoftSharePointTeamServices: 14.0.0.7015 X-MS-InvokeApp: 1; RequireReadOnly Date: Mon, 21 Dec 2015 16:56:51 GMT

 

any help will be appriciate Tia Tal

 

6 Replies

  • you must create a box "SSO Credential mapping" in VPE to store in "session.so.token.last.username" and "session.so.token.last.password" username and password from logon page.

     

  • HI i almost have the same config but i use reverse proxy "Portal" with "AD reosurce Assign" my ntlm2 sso is the same as u posted and The sso "Credentiol Mapping" is session.sso.token.last.username session.sso.token.last.password

     

    the portal config has

     

    Match Cae for paths is [yes] applicaton uri https://abc.com

     

    resource item paths /* hostname https://abc.com sso configuration is "ntlm2"

     

    • THi's avatar
      THi
      Icon for Nimbostratus rankNimbostratus
      No probs, did you figure out what was the problem?
  • The F5 log reported "Invalid NTLM type 2 message received for SSO configuration" and this is causing the f5 to cancel the authentication !! in other word the sharepoint/IIS web site is sending two 401 header "WWW-Authenticate:NTLM" At the moment there is nothing i can do in the F5 i openned a ticket to the sharepoint webmaster to fond out why m i getting 2 401 header's

     

    im going to install zap/owsap to get more details The case was documented in SOL17417