We have a new 3rd party app, IBM WebSphere on Linux with SPNEGO enabled for SSO to our Windows AD. This works as expected, except for one case.
WebSphere calls an existing Windows Web Service that uses pass-through authentication, so the end user credentials are presented to SQL Server. This Windows setup also works.
What doesn't work: WebSphere credentials do not multi-hop to SQL Server
Summary
The failure:
Error Code: 0x24 KRB_AP_ERR_BADMATCH
Server Realm: XXX.CH.OURDOMAIN.COM
Server Name: MSSQLSvc/oursqlserver.xxx.ch.ourdomain.com:50025
Target Name: MSSQLSvc/oursqlserver.xxx.ch.ourdomain.com:[email protected]
Other info
What are we missing for that pass-through hop to SQL Server from IBM WebSphere?
It was a very long Kerberos caching. Rebooted the server, fixed it.
The Linux admins had said "No need to reboot: it isn't Windows"
If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!
Donate Us With