Symptom
- Users prompted for username and password when accessing Identity Authentication from corporate network even though Kerberos/SPNEGO SSO is configured based on 'Configure Kerberos Authentication' SAP Help documentation.
- Error visible in the Troubleshooting Log:
- Could not validate SPNEGO token: Could not decrypt the encrypted data
- Single Sign-On (SSO) via Kerberos does not complete; authentication falls back to form-based login
- Issue occurs after initial Kerberos configuration or after changes in Active Directory (password reset, new keytab, domain policy update)
Read more...
Environment
SAP Cloud Platform Identity Authentication Service
Product
Identity Authentication 1.0
Keywords
IAS, Kerberos, SPNEGO, SPNego, ktab, ktpass, keytab, keytab file, SPN, Service Principal Name, AES, RC4, AES256, AES128, encryption, decrypt, fails, error, SSO, Single Sign-On, login, username and password, password prompt, corporate network, Active Directory, AD, UserPrincipalName, UPN, klist, klist purge, Could not validate SPNEGO token, Could not decrypt the encrypted data, cloud identity services, identity authentication, BC-IAM-IDS
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview