Symptom
- Users get "HTTP 500 - Internal Server Error" when accessing BI launchpad
- CMC page works fine
- Manual AD authentication is working
- In the stderr.log users may get an error similar to:
"[DEBUG] Fri Mar 03 17:27:44 EST 2023 jcsi.kerberos: GSS: Acceptor supports: KRB5[DEBUG] Fri Mar 03 17:27:44 EST 2023 jcsi.kerberos: Ticket service name is: HTTP/<hostname>.<realm>@<REALM>
[DEBUG] Fri Mar 03 17:27:44 EST 2023 jcsi.kerberos: GSS name is: <ServiceAccount>@<REALM>
[DEBUG] Fri Mar 03 17:27:44 EST 2023 jcsi.kerberos: Using keytab entry for: <ServiceAccount>@<REALM>
[DEBUG] Fri Mar 03 17:27:44 EST 2023 jcsi.kerberos: ** decrypting ticket .. **
with keyPrincipal: <ServiceAccount>@<REALM>
Type: 1
TimeStamp: Fri Mar 03 17:09:32 EST 2023
KVNO: -1
Key: [18, f7 b7 61 ce f6 57 e2 3e 67 55 5f 64 18 93 4b ef f0 60 d9 f2 75 a1 58 58 47 9a 89 66 61 52 5f 16 ][DEBUG] Fri Mar 03 17:27:44 EST 2023 jcsi.kerberos: Could not decrypt service ticket with Key type 18, KVNO 8, Principal "HTTP/<Hostname>.<realm>@<REALM>" using key:
Principal: [1] <ServiceAccount>@<REALM>
TimeStamp: Fri Mar 03 17:09:32 EST 2023
KVNO: -1
EncType: 18
Key: 32 bytes, fingerprint = [d4 73 3a 11 69 14 dc 61 ea 55 71 55 13 60 5b e9]
Exception for this key was: com.dstc.security.kerberos.CryptoException: Integrity check failure[Note: principal names are different; this may or may not be a problem]
[Note: KVNO used wildcard match, not exact match; perhaps the password used to generate this key is not the most recent password?]
Read more...
Environment
Windows
Windows Active Directory
BI 4.x
Product
Keywords
HTTP 500, windowsAD, Windows active directory, winAD, authentication, auth, aut, bi launchpad, display, bilp, fiori, launchpad, internal server error, login, logon, sso, kerberos, exception,princ, principal, realm, AES, encryption, keytab, idm.realm, idm.password, global.properties, KVNO, wild, card, match, could not decrypt, ticket , KBA , BI-BIP-AUT , Authentication, ActiveDirectory, LDAP, SSO, Vintela , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.