SAP Knowledge Base Article - Preview

2958786 - Kerberos/SPNEGO login fails with "Could not decrypt the encrypted data" error

Symptom

  1. Users prompted for username and password when accessing Identity Authentication from corporate network even though Kerberos/SPNEGO SSO is configured based on 'Configure Kerberos Authentication' SAP Help documentation.
  2. Error visible in the Troubleshooting Log:
  3. Could not validate SPNEGO token: Could not decrypt the encrypted data
  4. Single Sign-On (SSO) via Kerberos does not complete; authentication falls back to form-based login
  5. Issue occurs after initial Kerberos configuration or after changes in Active Directory (password reset, new keytab, domain policy update)


Read more...

Environment

SAP Cloud Platform Identity Authentication Service

Product

Identity Authentication 1.0

Keywords

IAS, Kerberos, SPNEGO, SPNego, ktab, ktpass, keytab, keytab file, SPN, Service Principal Name, AES, RC4, AES256, AES128, encryption, decrypt, fails, error, SSO, Single Sign-On, login, username and password, password prompt, corporate network, Active Directory, AD, UserPrincipalName, UPN, klist, klist purge, Could not validate SPNEGO token, Could not decrypt the encrypted data, cloud identity services, identity authentication, BC-IAM-IDS
, KBA , BC-IAM-IDS , Identity Authentication Service , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.