1 2 Previous Next 21 Replies Latest reply: Mar 27, 2012 12:10 AM by Vijay Chaudhery Go to original post RSS
  • 15. Re: Unable to Login in the BDSSA web portal Login v8.2
    Vijay Chaudhery

    I successfully update the intial ETL , but still not able to login in  http://localhost:80/BMCSAReports/cgi-bin/cognos.cgi url for my users even some of the domain users are having Global Reprots rights.

     

    C:\Program Files\BMC Software\BladeLogic\Reports\etl\bin>nsh run_etl.nsh -s 1 -v 82
    Starting run_etl.
    Parameter verification:
        Site Id:  1
        OM Version:  82
        Log Level:  3
        Level of Parallelism:  20
        Override Flag for Cognos Update:  0
        Properties Filename:  RunETL.properties
    Navigating to ETL path...
    Completed.
    Proceeding with ETL ...
    ETL has completed succesfully.

    C:\Program Files\BMC Software\BladeLogic\Reports\etl\bin>

  • 16. Re: Unable to Login in the BDSSA web portal Login v8.2
    Bill Robinson

    You can get to the login page, but you cannot authenticate?  What message do you get when you try to authenticate?

  • 17. Re: Unable to Login in the BDSSA web portal Login v8.2
    Vijay Chaudhery

    Now i can login to Reprot web portal page via BLAdmin user , but have to configure AD authentication service for Domain users. So i followed the steps been given by Komal  http://confluence.bmc.com:8080/display/BCAS/SSO+Kerberos  , but i am facing issue while testing blauthsvc.keytab file and showing below error message , kindly suggest. Due to this error i am not able to start the BBSA app service.

     

     

    C:\Program Files\BMC Software\BladeLogic\8.0\NSH>jre\bin\kinit.exe -k -t br\blauthsvc.keytab "blauthsvc/server1@EXAMPLE.

    COM"

    Exception: krb_error 0 Could not load configuration file C:\Windows\krb5.ini (The system cannot find the file specified)

    No error

    KrbException: Could not load configuration file C:\Windows\krb5.ini (The system cannot find the file specified)

            at sun.security.krb5.PrincipalName.<init>(PrincipalName.java:363)

            at sun.security.krb5.PrincipalName.<init>(PrincipalName.java:421)

            at sun.security.krb5.internal.tools.Kinit.<init>(Kinit.java:207)

            at sun.security.krb5.internal.tools.Kinit.main(Kinit.java:107)

    Caused by: KrbException: Could not load configuration file C:\Windows\krb5.ini (The system cannot find the file specifie

    d)

            at sun.security.krb5.Config.<init>(Config.java:142)

            at sun.security.krb5.Config.getInstance(Config.java:83)

            at sun.security.krb5.PrincipalName.<init>(PrincipalName.java:360)

            ... 3 more

    Caused by: java.io.FileNotFoundException: C:\Windows\krb5.ini (The system cannot find the file specified)

            at java.io.FileInputStream.open(Native Method)

     

     

    ============================

     

    appserver.log

     

    [22 Mar 2012 15:45:50,344] [Support-Thread-1] [INFO] [::] [] Support data thread started.

    [22 Mar 2012 15:45:50,531] [main] [WARN] [::] [] Authentication method in use is Active Directory/Kerberos.

    [22 Mar 2012 15:45:50,531] [main] [WARN] [::] [] Actual error from ADK authentication: No valid credentials provided (Me

    chanism level: Attempt to obtain new ACCEPT credentials failed!)

    [22 Mar 2012 15:45:50,531] [main] [ERROR] [::] [] ADKerberos authentication is enabled but it is not configured correctl

    y. If you are not using kerberos authentication, please turn it off in blasadmin by running the blasadmin command "set a

    uthserver isadkauthenabled false". If you are using it, please check the configuration files to ensure it is configured

    correctly

    [22 Mar 2012 15:45:50,531] [main] [ERROR] [::] [] Error installing to Start: name=bladelogic.service.AuthenticationServi

    ce state=Create

    com.bladelogic.om.infra.app.service.ServiceInitializationException: com.bladelogic.om.infra.mfw.util.BlException: com.bl

    adelogic.om.infra.mfw.util.BlException: Error creating credentials: No valid credentials provided (Mechanism level: Atte

    mpt to obtain new ACCEPT credentials failed!)

            at com.bladelogic.om.infra.auth.service.AuthenticationServiceImpl.start(AuthenticationServiceImpl.java:139)

            at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)

  • 18. Re: Unable to Login in the BDSSA web portal Login v8.2
    Amit Gupta
    1. To verify the keytab file, copy blappserv_krb5.conf to C:\WINNT\krb5.ini on Windows or /etc/krb5.conf on UNIX is the first step listed in the confluence page you mentioned, which is missed.
    2. It also appears that you have enabled the ADK authentication instead of the domain authentication for the auth server (The instruction on that page was for BSA ADK authentication). Do the following and try again, it should hopefully fix this problem:
      1. Cd to .../Reports/bin
      2. run "blasadmin set AuthServer IsADKAuthEnabled false"
      3. run "blasadmin set AuthServer isDomainAuthEnabled true"
      4. Restart BDSSA Authentication Service
  • 19. Re: Unable to Login in the BDSSA web portal Login v8.2
    Vijay Chaudhery

    Thanks for reply, i revet the settings to Domain Auth to AD , now i can restart the app server and Domain users are able to login via Domain a/cs ,but at Report url only BLAdmin with SRP enabled can login , no other domain users can login.

  • 20. Re: Unable to Login in the BDSSA web portal Login v8.2
    Komal Padmawar

    Hi Vijay, You reverted Domain auth to AD or AD to Domain. As per Amit, you should enable Domain authentication and it should be enable on report server as well. Again restating the steps 1. Cd to .../Reports/bin 2. run "blasadmin set AuthServer IsADKAuthEnabled false" 3. run "blasadmin set AuthServer isDomainAuthEnabled true" 4. Restart BDSSA Authentication Service.

  • 21. Re: Unable to Login in the BDSSA web portal Login v8.2
    Vijay Chaudhery

    There is a twist in the BDSS ADK Authentication ,

     

    Irrespective of what anyone said or what you understood, the fact is that BDSSA supports only Domain authentication. ADK authentication is not supported by BDSSA. You can confirm that in BDSSA user guide. So, in other words, Kerberos authentication is implemented via domain authentication in BDSSA. So, you better stop wasting time in trying to configure something that is not going to work.

     

     

    I copied blapp_*.conf files from working BBSA to BDSS br directory and set the below:

    1. Cd to .../Reports/bin
    2. run "blasadmin set AuthServer IsADKAuthEnabled false"
    3. run "blasadmin set AuthServer isDomainAuthEnabled true"
    4. Restart BDSSA Authentication Service

     

     

    Please find my working blapp_*.conf files and modify accordingly. It's been working for me should work for others too.

     

    Enviornment :

    1. Domain Win 2008 Ent Edition

    2. BBSA v82 on Win 2008 Ent Edition

    3. MSSQL 2008 Server ( BBSA / BDSSA database )

    4. BDSSA v82 win 2008 Ent Edition

1 2 Previous Next