10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

v<br />

When<br />

a<br />

problem<br />

occurs,<br />

consider<br />

enabling<br />

trace<br />

<strong>for</strong><br />

SPNEGO.<br />

Add<br />

an<br />

entry<br />

to<br />

the<br />

routing<br />

file.<br />

The<br />

routing<br />

file<br />

is<br />

located<br />

under<br />

the<br />

installation<br />

directory,<br />

in<br />

etc/routing.<br />

Example<br />

entry:<br />

bst:*.9:TEXTFILE:<strong>WebSEAL</strong>_installation_directory/log/spnegotrace.log<br />

On<br />

UNIX,<br />

the<br />

default<br />

<strong>WebSEAL</strong><br />

installation<br />

directory<br />

is<br />

/opt/pdweb.<br />

Substitute<br />

the<br />

path<br />

<strong>for</strong><br />

your<br />

installation<br />

directory.<br />

Stop<br />

and<br />

restart<br />

<strong>WebSEAL</strong>.<br />

Look<br />

<strong>for</strong><br />

error<br />

messages<br />

in<br />

the<br />

trace<br />

file.<br />

v<br />

Problem:<br />

The<br />

<strong>WebSEAL</strong><br />

server<br />

will<br />

not<br />

start.<br />

The<br />

log<br />

file<br />

contains<br />

an<br />

error<br />

saying<br />

″Authentication<br />

method<br />

(kerberosv5)<br />

is<br />

not<br />

configured.″<br />

Solution:<br />

Enable<br />

the<br />

kerberosv5<br />

authentication<br />

method<br />

in<br />

the<br />

[authentication-mechanisms]<br />

stanza<br />

in<br />

the<br />

<strong>WebSEAL</strong><br />

configuration<br />

file.<br />

v<br />

Problem:<br />

The<br />

<strong>WebSEAL</strong><br />

server<br />

will<br />

not<br />

start.<br />

The<br />

error<br />

message<br />

is<br />

″The<br />

security<br />

service<br />

function<br />

gss_import_name<br />

returned<br />

major<br />

error<br />

code<br />

131072<br />

and<br />

minor<br />

error<br />

code<br />

-1765328168.″<br />

Solution:<br />

The<br />

principal<br />

name<br />

specified<br />

in<br />

the<br />

configuration<br />

file<br />

was<br />

invalid.<br />

It<br />

should<br />

have<br />

the<br />

<strong>for</strong>m<br />

″HTTP@host_name″<br />

where<br />

host_name<br />

is<br />

the<br />

fully<br />

qualified<br />

DNS<br />

name<br />

of<br />

a<br />

computer<br />

which<br />

is<br />

configured<br />

into<br />

the<br />

Kerberos<br />

realm.<br />

v<br />

Problem:<br />

The<br />

<strong>WebSEAL</strong><br />

server<br />

does<br />

not<br />

start.<br />

The<br />

error<br />

message<br />

is:<br />

″The<br />

security<br />

service<br />

function<br />

gss_acquire_cred<br />

returned<br />

major<br />

error<br />

code<br />

851968<br />

and<br />

minor<br />

error<br />

code<br />

39756033″.<br />

Solution:<br />

The<br />

principal<br />

name<br />

in<br />

the<br />

configuration<br />

file<br />

does<br />

not<br />

match<br />

any<br />

of<br />

the<br />

keys<br />

in<br />

the<br />

specified<br />

keytab<br />

file.<br />

The<br />

keys<br />

in<br />

the<br />

keytab<br />

file<br />

have<br />

names<br />

like<br />

HTTP/host_name<br />

@REALM.<br />

The<br />

principal<br />

name<br />

should<br />

have<br />

the<br />

<strong>for</strong>mat<br />

HTTP@host_name<br />

v<br />

Problem:<br />

The<br />

<strong>WebSEAL</strong><br />

server<br />

does<br />

not<br />

start.<br />

The<br />

error<br />

message<br />

is<br />

″HPDST0129E<br />

The<br />

security<br />

service<br />

function<br />

gss_acquire_cred<br />

returned<br />

major<br />

error<br />

code<br />

851968<br />

and<br />

minor<br />

error<br />

code<br />

486484225.<br />

(pd<br />

/<br />

bst)″<br />

or<br />

″HPDST0129E<br />

The<br />

security<br />

service<br />

function<br />

gss_acquire_cred<br />

returned<br />

major<br />

error<br />

code<br />

851968<br />

and<br />

minor<br />

error<br />

code<br />

39756033.<br />

(pd<br />

/<br />

bst)″<br />

Solution:<br />

These<br />

errors<br />

are<br />

caused<br />

by<br />

DNS<br />

reverse<br />

lookup<br />

problems.<br />

Verify<br />

that<br />

your<br />

reverse<br />

lookup<br />

works<br />

properly.<br />

v<br />

Problem:<br />

When<br />

a<br />

user<br />

attempts<br />

to<br />

access<br />

<strong>WebSEAL</strong><br />

they<br />

receive<br />

an<br />

error<br />

saying<br />

″HPDIA0100E<br />

An<br />

internal<br />

error<br />

has<br />

occurred.″<br />

The<br />

<strong>WebSEAL</strong><br />

trace<br />

log<br />

file<br />

contains<br />

a<br />

message<br />

saying<br />

″The<br />

security<br />

service<br />

function<br />

gss_accept_sec_context<br />

returned<br />

major<br />

error<br />

code<br />

851968<br />

and<br />

minor<br />

error<br />

code<br />

-1765328347.″<br />

Solution:<br />

the<br />

system<br />

clock<br />

on<br />

the<br />

client<br />

machine<br />

is<br />

out<br />

of<br />

sync<br />

with<br />

the<br />

system<br />

clock<br />

on<br />

the<br />

<strong>WebSEAL</strong><br />

server.<br />

You<br />

must<br />

keep<br />

clocks<br />

synchronized<br />

when<br />

using<br />

Kerberos.<br />

For<br />

a<br />

permanent<br />

solution,<br />

deploy<br />

some<br />

kind<br />

of<br />

time<br />

synchronization<br />

service<br />

on<br />

your<br />

machines.<br />

For<br />

a<br />

temporary<br />

solution,<br />

adjust<br />

the<br />

clocks<br />

on<br />

the<br />

machines<br />

so<br />

they<br />

are<br />

within<br />

one<br />

minute<br />

of<br />

each<br />

other.<br />

244<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!