Return-Path: Delivered-To: apmail-tomcat-users-archive@www.apache.org Received: (qmail 7059 invoked from network); 16 Aug 2010 14:18:27 -0000 Received: from unknown (HELO mail.apache.org) (140.211.11.3) by 140.211.11.9 with SMTP; 16 Aug 2010 14:18:27 -0000 Received: (qmail 39695 invoked by uid 500); 16 Aug 2010 14:18:23 -0000 Delivered-To: apmail-tomcat-users-archive@tomcat.apache.org Received: (qmail 39317 invoked by uid 500); 16 Aug 2010 14:18:19 -0000 Mailing-List: contact users-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Tomcat Users List" Delivered-To: mailing list users@tomcat.apache.org Received: (qmail 39308 invoked by uid 99); 16 Aug 2010 14:18:18 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 16 Aug 2010 14:18:18 +0000 X-ASF-Spam-Status: No, hits=-0.0 required=10.0 tests=SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (nike.apache.org: local policy) Received: from [168.215.186.14] (HELO exchange2003.advocacyinc.org) (168.215.186.14) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 16 Aug 2010 14:18:08 +0000 X-MimeOLE: Produced By Microsoft Exchange V6.5 Content-class: urn:content-classes:message MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Subject: RE: Single Sign-On problems Date: Mon, 16 Aug 2010 09:16:20 -0500 Message-ID: In-Reply-To: <4C68EC0E.30701@ice-sa.com> X-MS-Has-Attach: X-MS-TNEF-Correlator: Thread-Topic: Single Sign-On problems Thread-Index: Acs9FubbKWqOCKamSQqYFxY6S+w54AAMF65g References: <4C681991.3030105@ice-sa.com> <4C68EC0E.30701@ice-sa.com> From: "Carlton Whitmore" To: "Tomcat Users List" X-Virus-Checked: Checked by ClamAV on apache.org Andre, These are the settings that our vendor suggested adding to the web.xml = came with Tomcat. If NtlmHttpFilter isn't recommended are there setup = files for Waffle or Jespa that I could use? I'm a newbie to Tomcat. BTW - Someone asked what the guest OS was. It's Windows 2008 R2. Our users get intermittent SSO errors (looks to happen when we have over = 20 users online), when they try to drag and drop from Word or Outlook = plug-in the vendor developed. This is the error message "Invalid Domain = acquired for SSO! Please Login Manually ". We also have issues trying to = access the SSO logon page. Instead of the SSO error we get an error that = the page cannot be displayed. It's like the app is trying to open the = page before the authentication can take place. I did notice that the Max = Ports setting is 150 on the server.xml. Is that number of users or total = ports open? I have as many as 30-40 users on at a time. Here is my full web.xml and server.xml: Web.xml file: default = org.apache.catalina.servlets.DefaultServlet debug 0 listings false 1 =20 jsp = org.apache.jasper.servlet.JspServlet fork false xpoweredBy false 3 default / jsp *.jsp jsp *.jspx 30 abs audio/x-mpeg ai application/postscript aif audio/x-aiff aifc audio/x-aiff aiff audio/x-aiff aim application/x-aim art image/x-jg asf video/x-ms-asf asx video/x-ms-asf au audio/basic avi video/x-msvideo avx video/x-rad-screenplay bcpio application/x-bcpio bin application/octet-stream bmp image/bmp body text/html cdf application/x-cdf cer application/x-x509-ca-cert class application/java cpio application/x-cpio csh application/x-csh css text/css dib image/bmp doc application/msword dtd application/xml-dtd dv video/x-dv dvi application/x-dvi eps application/postscript etx text/x-setext exe application/octet-stream gif image/gif gtar application/x-gtar gz application/x-gzip hdf application/x-hdf hqx application/mac-binhex40 htc text/x-component htm text/html html text/html hqx application/mac-binhex40 ief image/ief jad text/vnd.sun.j2me.app-descriptor jar application/java-archive java text/plain jnlp application/x-java-jnlp-file jpe image/jpeg jpeg image/jpeg jpg image/jpeg js text/javascript jsf text/plain jspf text/plain kar audio/x-midi latex application/x-latex m3u audio/x-mpegurl mac image/x-macpaint man application/x-troff-man mathml application/mathml+xml=20 me application/x-troff-me mid audio/x-midi midi audio/x-midi mif application/x-mif mov video/quicktime movie video/x-sgi-movie mp1 audio/x-mpeg mp2 audio/x-mpeg mp3 audio/x-mpeg mp4 video/mp4 mpa audio/x-mpeg mpe video/mpeg mpeg video/mpeg mpega audio/x-mpeg mpg video/mpeg mpv2 video/mpeg2 ms application/x-wais-source nc application/x-netcdf oda application/oda odb = application/vnd.oasis.opendocument.database odc application/vnd.oasis.opendocument.chart odf = application/vnd.oasis.opendocument.formula odg = application/vnd.oasis.opendocument.graphics odi application/vnd.oasis.opendocument.image odm = application/vnd.oasis.opendocument.text-master odp = application/vnd.oasis.opendocument.presentation ods = application/vnd.oasis.opendocument.spreadsheet odt application/vnd.oasis.opendocument.text ogg application/ogg otg = application/vnd.oasis.opendocument.graphics-template oth = application/vnd.oasis.opendocument.text-web otp = application/vnd.oasis.opendocument.presentation-template ots = application/vnd.oasis.opendocument.spreadsheet-template = ott = application/vnd.oasis.opendocument.text-template pbm image/x-portable-bitmap pct image/pict pdf application/pdf pgm image/x-portable-graymap pic image/pict pict image/pict pls audio/x-scpls png image/png pnm image/x-portable-anymap pnt image/x-macpaint ppm image/x-portable-pixmap ppt application/powerpoint ps application/postscript psd image/x-photoshop qt video/quicktime qti image/x-quicktime qtif image/x-quicktime ras image/x-cmu-raster rdf application/rdf+xml rgb image/x-rgb rm application/vnd.rn-realmedia roff application/x-troff rtf application/rtf rtx text/richtext sh application/x-sh shar application/x-shar smf audio/x-midi sit application/x-stuffit snd audio/basic src application/x-wais-source sv4cpio application/x-sv4cpio sv4crc application/x-sv4crc swf application/x-shockwave-flash t application/x-troff tar application/x-tar tcl application/x-tcl tex application/x-tex texi application/x-texinfo texinfo application/x-texinfo tif image/tiff tiff image/tiff tr application/x-troff tsv text/tab-separated-values txt text/plain ulw audio/basic ustar application/x-ustar vxml application/voicexml+xml xbm image/x-xbitmap xht application/xhtml+xml xhtml application/xhtml+xml xml application/xml xpm image/x-xpixmap xsl application/xml xslt application/xslt+xml xul application/vnd.mozilla.xul+xml xwd image/x-xwindowdump wav audio/x-wav svg image/svg+xml svgz image/svg+xml vsd application/x-visio wbmp image/vnd.wap.wbmp wml text/vnd.wap.wml wmlc application/vnd.wap.wmlc wmls text/vnd.wap.wmlscript wmlscriptc application/vnd.wap.wmlscriptc wmv video/x-ms-wmv wrl x-world/x-vrml Z application/x-compress z application/x-compress zip application/zip xls application/vnd.ms-excel doc application/vnd.ms-word ppt application/vnd.ms-powerpoint index.html index.htm index.jsp =09 NtlmHttpFilter jcifs.http.NtlmHttpFilter jcifs.http.domainController 192.168.100.6 jcifs.smb.client.domain advocacyinc jcifs.smb.client.username SQL_LegalFiles jcifs.smb.client.password >******* jcifs.smb.lmCompatibility 3 NtlmHttpFilter /* Server.xml file: =20 =20 =20 =20 =20 =20 -----Original Message----- From: Andr=E9 Warnier [mailto:aw@ice-sa.com]=20 Sent: Monday, August 16, 2010 2:43 AM To: Tomcat Users List Subject: Re: Single Sign-On problems Carlton Whitmore wrote: > Andre, > The only reason I think it's Tomcat because when we change the Tomcat = version it seems to affect the speed of the application (Tomcat 7 runs = very slow, but no SSO errors; Tomcat 6 runs fast, but SSO errors). We're = using Active Directory to authenticate. I guess it could be SSL as well. = I've change the domain controller, but that didn't affect the issue. = Here is the code we changed in the conf\web.xml file: > =20 > > index.html > index.htm > index.jsp > > =20 > > NtlmHttpFilter > jcifs.http.NtlmHttpFilter > > jcifs.http.domainController > 192.168.100.6 > > > jcifs.smb.client.domain > advocacyinc > > > jcifs.smb.client.username > SQL_LegalFiles > > > jcifs.smb.client.password > >password > > > jcifs.smb.lmCompatibility > 3 > > > > > NtlmHttpFilter > /* > >=20 > =20 1) you do know that this NtlmHttpFilter is no longer developed or = supported, and that it=20 will never support NTLM v2 (as is standard with Windows Vista, 7 and = later), right ? You should be thinking about switching to Jespa or Waffle. 2) anyway, the jCIFS filter can do quite extensive logs of what it does = (see=20 jcifs.util.loglevel). You could try using that and check what it is = telling you about the=20 failures. 3) when you mention "SSO failures", what do you mean exactly ? the = browser popping up a=20 builtin authentication dialog ? or something else ? And is the above your standard operational configuration, or a = simplified one you are just=20 using for this test ? --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org For additional commands, e-mail: users-help@tomcat.apache.org --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org For additional commands, e-mail: users-help@tomcat.apache.org