<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Improved SPNEGO or Kerberos support with LoadRunner</title>
	<atom:link href="http://altentee.com/2009/improved-spnego-or-kerberos-support-with-loadrunner/feed/" rel="self" type="application/rss+xml" />
	<link>http://altentee.com/2009/improved-spnego-or-kerberos-support-with-loadrunner/</link>
	<description>Performance and Test Automation Experts</description>
	<lastBuildDate>Tue, 02 Mar 2010 14:15:20 +1100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Tim</title>
		<link>http://altentee.com/2009/improved-spnego-or-kerberos-support-with-loadrunner/comment-page-1/#comment-314</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Tue, 20 Oct 2009 07:23:10 +0000</pubDate>
		<guid isPermaLink="false">http://90kts.com/blog/2009/improved-spnego-or-kerberos-support-with-loadrunner/#comment-314</guid>
		<description>OK good to know that. Didn&#039;t realise you could get help on the web_set_sockets_option. There&#039;s lots of resources out there about setting up krb5 config files and generating keytabs (although I didn&#039;t have to for our setup which was IBM WebSEAL / SSO/ AD)

Good luck with it!

Tim</description>
		<content:encoded><![CDATA[<p>OK good to know that. Didn&#8217;t realise you could get help on the web_set_sockets_option. There&#8217;s lots of resources out there about setting up krb5 config files and generating keytabs (although I didn&#8217;t have to for our setup which was IBM WebSEAL / SSO/ AD)</p>
<p>Good luck with it!</p>
<p>Tim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://altentee.com/2009/improved-spnego-or-kerberos-support-with-loadrunner/comment-page-1/#comment-313</link>
		<dc:creator>John</dc:creator>
		<pubDate>Tue, 20 Oct 2009 03:25:05 +0000</pubDate>
		<guid isPermaLink="false">http://90kts.com/blog/2009/improved-spnego-or-kerberos-support-with-loadrunner/#comment-313</guid>
		<description>Tim,

thanks. The F1 help for 8.1 has no mention of the Ã¢â‚¬Å“INITIAL_BASIC_AUTHÃ¢â‚¬Â however when i run the

web_set_sockets_option(&quot;HELP&quot;,&quot;&quot;);

i can see the Ã¢â‚¬Å“INITIAL_BASIC_AUTHÃ¢â‚¬Â option.

web_set_sockets_option parameters =================================
INITIAL_BASIC_AUTH           : Send basic authentithication to server before receiving HTTP error

etc etc


The error i&#039;m receiving is the one mentioned previously above &quot;Warning -26000: can&#039;t get initial credentials for username/password userxxxxx/Password1&quot;


I am looking into the krb5.ini file setup. Thought i had set it up right but getting it looked into.

Cheers
John</description>
		<content:encoded><![CDATA[<p>Tim,</p>
<p>thanks. The F1 help for 8.1 has no mention of the Ã¢â‚¬Å“INITIAL_BASIC_AUTHÃ¢â‚¬Â however when i run the</p>
<p>web_set_sockets_option(&#8220;HELP&#8221;,&#8221;");</p>
<p>i can see the Ã¢â‚¬Å“INITIAL_BASIC_AUTHÃ¢â‚¬Â option.</p>
<p>web_set_sockets_option parameters =================================<br />
INITIAL_BASIC_AUTH           : Send basic authentithication to server before receiving HTTP error</p>
<p>etc etc</p>
<p>The error i&#8217;m receiving is the one mentioned previously above &#8220;Warning -26000: can&#8217;t get initial credentials for username/password userxxxxx/Password1&#8243;</p>
<p>I am looking into the krb5.ini file setup. Thought i had set it up right but getting it looked into.</p>
<p>Cheers<br />
John</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://altentee.com/2009/improved-spnego-or-kerberos-support-with-loadrunner/comment-page-1/#comment-312</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Mon, 19 Oct 2009 08:11:13 +0000</pubDate>
		<guid isPermaLink="false">http://90kts.com/blog/2009/improved-spnego-or-kerberos-support-with-loadrunner/#comment-312</guid>
		<description>Not sure mate would have to go to HP on that one. As it stands this flag is not documented anywhere AFAIK. I was testing on 9+. Have a crack and post any error messages you get here.

Regards,
Tim</description>
		<content:encoded><![CDATA[<p>Not sure mate would have to go to HP on that one. As it stands this flag is not documented anywhere AFAIK. I was testing on 9+. Have a crack and post any error messages you get here.</p>
<p>Regards,<br />
Tim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://altentee.com/2009/improved-spnego-or-kerberos-support-with-loadrunner/comment-page-1/#comment-311</link>
		<dc:creator>John</dc:creator>
		<pubDate>Mon, 19 Oct 2009 07:40:05 +0000</pubDate>
		<guid isPermaLink="false">http://90kts.com/blog/2009/improved-spnego-or-kerberos-support-with-loadrunner/#comment-311</guid>
		<description>Hey Tim,

do you know if the &quot;INITIAL_BASIC_AUTH&quot; is supported by LR8.1 ?

Cheers</description>
		<content:encoded><![CDATA[<p>Hey Tim,</p>
<p>do you know if the &#8220;INITIAL_BASIC_AUTH&#8221; is supported by LR8.1 ?</p>
<p>Cheers</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://altentee.com/2009/improved-spnego-or-kerberos-support-with-loadrunner/comment-page-1/#comment-310</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Fri, 09 Oct 2009 09:42:34 +0000</pubDate>
		<guid isPermaLink="false">http://90kts.com/blog/2009/improved-spnego-or-kerberos-support-with-loadrunner/#comment-310</guid>
		<description>Mate you&#039;re missing the point! Don&#039;t put your webservers in there!! You need to put your domain controllers in there, the servers that look after your kerberos domain! If you don&#039;t know what I&#039;m talking about I suggest you read here first or ask a sysadmin to help explain your security setup to you... Get familar with wireshark, observe a manual test case and watch how your authentication happens in your domain. Fiddler is also useful from a client point of view.

http://en.wikipedia.org/wiki/Kerberos_(protocol)</description>
		<content:encoded><![CDATA[<p>Mate you&#8217;re missing the point! Don&#8217;t put your webservers in there!! You need to put your domain controllers in there, the servers that look after your kerberos domain! If you don&#8217;t know what I&#8217;m talking about I suggest you read here first or ask a sysadmin to help explain your security setup to you&#8230; Get familar with wireshark, observe a manual test case and watch how your authentication happens in your domain. Fiddler is also useful from a client point of view.</p>
<p><a href="http://en.wikipedia.org/wiki/Kerberos_(protocol)" rel="nofollow">http://en.wikipedia.org/wiki/Kerberos_(protocol)</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: karan</title>
		<link>http://altentee.com/2009/improved-spnego-or-kerberos-support-with-loadrunner/comment-page-1/#comment-309</link>
		<dc:creator>karan</dc:creator>
		<pubDate>Fri, 09 Oct 2009 09:26:08 +0000</pubDate>
		<guid isPermaLink="false">http://90kts.com/blog/2009/improved-spnego-or-kerberos-support-with-loadrunner/#comment-309</guid>
		<description>Hi Tim, I&#039;ve updated the Krb5.ini file but getting different error message now &quot;Miscellaneous failure Server not found in Kerberos database  [MsgId: MERR-27734]&quot;

I&#039;m seeing Domain name as &quot;YYYY&quot;, Server Name as &quot;Webserver1&quot;, Domain DNS Name as &quot;yyyy.asd.as.com&quot; and Server DNS Name as &quot;Webserver1.yyyy.asd.as.com&quot; in the Wireshark.

-----------------
Krb5.ini file is

[libdefaults]
default_realm = YYYY.ASD.AS.COM
default_keytab_name = c:\winnt\krb5.keytab
default_tkt_enctypes = des-cbc-md5 rc4-hmac
default_tgs_enctypes = des-cbc-md5 rc4-hmac
[realms]
Webserver1.yyyy.asd.as.com = {
kdc = Webserver1.yyyy.asd.as.com
default_domain = yyyy.asd.as.com
}
Webserver.yyyy.asd.as.com = {
kdc = Webserver2.yyyy.asd.as.com
default_domain = yyyy.asd.as.com
}
Webserver3.yyyy.asd.as.com = {
kdc = Webserver3.yyyy.asd.as.com
default_domain = yyyy.asd.as.com
}
[domain_realm]
.yyyy.asd.as.com = Webserver1.yyyy.asd.as.com
.yyyy.asd.as.com = Webserver2.yyyy.asd.as.com
.yyyy.asd.as.com = Webserver3.yyyy.asd.as.com

---------------

Did I create the ini file in the right way?

Thanks alot for your time &amp; help.

Karan</description>
		<content:encoded><![CDATA[<p>Hi Tim, I&#8217;ve updated the Krb5.ini file but getting different error message now &#8220;Miscellaneous failure Server not found in Kerberos database  [MsgId: MERR-27734]&#8221;</p>
<p>I&#8217;m seeing Domain name as &#8220;YYYY&#8221;, Server Name as &#8220;Webserver1&#8243;, Domain DNS Name as &#8220;yyyy.asd.as.com&#8221; and Server DNS Name as &#8220;Webserver1.yyyy.asd.as.com&#8221; in the Wireshark.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
Krb5.ini file is</p>
<p>[libdefaults]<br />
default_realm = YYYY.ASD.AS.COM<br />
default_keytab_name = c:\winnt\krb5.keytab<br />
default_tkt_enctypes = des-cbc-md5 rc4-hmac<br />
default_tgs_enctypes = des-cbc-md5 rc4-hmac<br />
[realms]<br />
Webserver1.yyyy.asd.as.com = {<br />
kdc = Webserver1.yyyy.asd.as.com<br />
default_domain = yyyy.asd.as.com<br />
}<br />
Webserver.yyyy.asd.as.com = {<br />
kdc = Webserver2.yyyy.asd.as.com<br />
default_domain = yyyy.asd.as.com<br />
}<br />
Webserver3.yyyy.asd.as.com = {<br />
kdc = Webserver3.yyyy.asd.as.com<br />
default_domain = yyyy.asd.as.com<br />
}<br />
[domain_realm]<br />
.yyyy.asd.as.com = Webserver1.yyyy.asd.as.com<br />
.yyyy.asd.as.com = Webserver2.yyyy.asd.as.com<br />
.yyyy.asd.as.com = Webserver3.yyyy.asd.as.com</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Did I create the ini file in the right way?</p>
<p>Thanks alot for your time &amp; help.</p>
<p>Karan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karan</title>
		<link>http://altentee.com/2009/improved-spnego-or-kerberos-support-with-loadrunner/comment-page-1/#comment-308</link>
		<dc:creator>Karan</dc:creator>
		<pubDate>Fri, 09 Oct 2009 07:37:11 +0000</pubDate>
		<guid isPermaLink="false">http://90kts.com/blog/2009/improved-spnego-or-kerberos-support-with-loadrunner/#comment-308</guid>
		<description>Hi Tim, I&#039;ve updated the Krb5.ini file but getting different error message now &quot;Miscellaneous failure Server not found in Kerberos database  [MsgId: MERR-27734]&quot;

I&#039;m seeing Domain name as &quot;YYYY&quot;, Server Name as &quot;Webserver1&quot;, Domain DNS Name as &quot;yyyy.asd.as.com&quot; and Server DNS Name as &quot;Webserver1.yyyy.asd.as.com&quot; in the Wireshark.

-----------------
Krb5.ini file is

[libdefaults]
default_realm = YYYY.ASD.AS.COM
default_keytab_name = c:\winnt\krb5.keytab
default_tkt_enctypes = des-cbc-md5 rc4-hmac
default_tgs_enctypes = des-cbc-md5 rc4-hmac
[realms]
Webserver1.yyyy.asd.as.com = {
kdc = Webserver1.yyyy.asd.as.com
default_domain = yyyy.asd.as.com
}
Webserver2.yyyy.asd.as.com = {
kdc = Webserver2.yyyy.asd.as.com
default_domain = yyyy.asd.as.com
}
Webserver3.yyyy.asd.as.com = {
kdc = Webserver3.yyyy.asd.as.com
default_domain = yyyy.asd.as.com
}
[domain_realm]
.yyyy.asd.as.com = Webserver1.yyyy.asd.as.com
.yyyy.asd.as.com = Webserver2.yyyy.asd.as.com
.yyyy.asd.as.com = Webserver3.yyyy.asd.as.com

---------------

There are 3 web servers in the test bed.

Did i create the ini file in the right way?

Thanks alot for your help.

Karan</description>
		<content:encoded><![CDATA[<p>Hi Tim, I&#8217;ve updated the Krb5.ini file but getting different error message now &#8220;Miscellaneous failure Server not found in Kerberos database  [MsgId: MERR-27734]&#8221;</p>
<p>I&#8217;m seeing Domain name as &#8220;YYYY&#8221;, Server Name as &#8220;Webserver1&#8243;, Domain DNS Name as &#8220;yyyy.asd.as.com&#8221; and Server DNS Name as &#8220;Webserver1.yyyy.asd.as.com&#8221; in the Wireshark.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
Krb5.ini file is</p>
<p>[libdefaults]<br />
default_realm = YYYY.ASD.AS.COM<br />
default_keytab_name = c:\winnt\krb5.keytab<br />
default_tkt_enctypes = des-cbc-md5 rc4-hmac<br />
default_tgs_enctypes = des-cbc-md5 rc4-hmac<br />
[realms]<br />
Webserver1.yyyy.asd.as.com = {<br />
kdc = Webserver1.yyyy.asd.as.com<br />
default_domain = yyyy.asd.as.com<br />
}<br />
Webserver2.yyyy.asd.as.com = {<br />
kdc = Webserver2.yyyy.asd.as.com<br />
default_domain = yyyy.asd.as.com<br />
}<br />
Webserver3.yyyy.asd.as.com = {<br />
kdc = Webserver3.yyyy.asd.as.com<br />
default_domain = yyyy.asd.as.com<br />
}<br />
[domain_realm]<br />
.yyyy.asd.as.com = Webserver1.yyyy.asd.as.com<br />
.yyyy.asd.as.com = Webserver2.yyyy.asd.as.com<br />
.yyyy.asd.as.com = Webserver3.yyyy.asd.as.com</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>There are 3 web servers in the test bed.</p>
<p>Did i create the ini file in the right way?</p>
<p>Thanks alot for your help.</p>
<p>Karan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://altentee.com/2009/improved-spnego-or-kerberos-support-with-loadrunner/comment-page-1/#comment-307</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Fri, 09 Oct 2009 06:18:07 +0000</pubDate>
		<guid isPermaLink="false">http://90kts.com/blog/2009/improved-spnego-or-kerberos-support-with-loadrunner/#comment-307</guid>
		<description>The problem is you haven&#039;t updated the domain controllers in your [realms] to point to real DCs. You&#039;re just using my example file i.e. dc01.domain.local. You need to find out what the names are of your DCs and update accordingly. You can normally figure this out with a wireshark trace, or just ask your system admin type people. The error message is basically telling you this, i.e. it can&#039;t get the username/password for rmatte/Merrill1009

Cheers,
Tim</description>
		<content:encoded><![CDATA[<p>The problem is you haven&#8217;t updated the domain controllers in your [realms] to point to real DCs. You&#8217;re just using my example file i.e. dc01.domain.local. You need to find out what the names are of your DCs and update accordingly. You can normally figure this out with a wireshark trace, or just ask your system admin type people. The error message is basically telling you this, i.e. it can&#8217;t get the username/password for rmatte/Merrill1009</p>
<p>Cheers,<br />
Tim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karan</title>
		<link>http://altentee.com/2009/improved-spnego-or-kerberos-support-with-loadrunner/comment-page-1/#comment-306</link>
		<dc:creator>Karan</dc:creator>
		<pubDate>Fri, 09 Oct 2009 05:48:49 +0000</pubDate>
		<guid isPermaLink="false">http://90kts.com/blog/2009/improved-spnego-or-kerberos-support-with-loadrunner/#comment-306</guid>
		<description>Hi Tim, Thanks a lot for your help.
Here are the details. currently we are using 9.5 version.
----------
Script
web_set_sockets_option(&quot;INITIAL_BASIC_AUTH&quot;,&quot;1&quot;);

web_set_user(&quot;yyyy\\userid&quot;, &quot;pwd&quot;, &quot;app.com:80&quot;);

web_url(&quot;HomePage&quot;,
&quot;URL=http://app.com/&quot;,
&quot;TargetFrame=&quot;,
&quot;Resource=0&quot;,
&quot;RecContentType=text/html&quot;,
&quot;Referer=&quot;,
&quot;Snapshot=t1.inf&quot;,
&quot;Mode=HTML&quot;,
LAST);
-----------------------

-------------
Error message
Action.c(27): Continuing after Error -27734: Internal Error - can&#039;t get initial credentials for username/password rmatte/Merrill1009  [MsgId: MERR-27734]

-----------------

-------------
Krb5.ini
[libdefaults]
default_realm = DOMAIN.LOCAL
default_keytab_name = FILE:c:\winnt\krb5.keytab
default_tkt_enctypes = des-cbc-md5 rc4-hmac
default_tgs_enctypes = des-cbc-md5 rc4-hmac
[realms]
dc01.domain.local = {
kdc = dc01.domain.local
default_domain = domain.local
}
[domain_realm]
.domain.local = dc01.domain.local
-------------

Did I create the Krb5.ini file in the right format?

Thanks &amp; Regards
Karan</description>
		<content:encoded><![CDATA[<p>Hi Tim, Thanks a lot for your help.<br />
Here are the details. currently we are using 9.5 version.<br />
&#8212;&#8212;&#8212;-<br />
Script<br />
web_set_sockets_option(&#8220;INITIAL_BASIC_AUTH&#8221;,&#8221;1&#8243;);</p>
<p>web_set_user(&#8220;yyyy\\userid&#8221;, &#8220;pwd&#8221;, &#8220;app.com:80&#8243;);</p>
<p>web_url(&#8220;HomePage&#8221;,<br />
&#8220;URL=http://app.com/&#8221;,<br />
&#8220;TargetFrame=&#8221;,<br />
&#8220;Resource=0&#8243;,<br />
&#8220;RecContentType=text/html&#8221;,<br />
&#8220;Referer=&#8221;,<br />
&#8220;Snapshot=t1.inf&#8221;,<br />
&#8220;Mode=HTML&#8221;,<br />
LAST);<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>&#8212;&#8212;&#8212;&#8212;-<br />
Error message<br />
Action.c(27): Continuing after Error -27734: Internal Error &#8211; can&#8217;t get initial credentials for username/password rmatte/Merrill1009  [MsgId: MERR-27734]</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>&#8212;&#8212;&#8212;&#8212;-<br />
Krb5.ini<br />
[libdefaults]<br />
default_realm = DOMAIN.LOCAL<br />
default_keytab_name = FILE:c:\winnt\krb5.keytab<br />
default_tkt_enctypes = des-cbc-md5 rc4-hmac<br />
default_tgs_enctypes = des-cbc-md5 rc4-hmac<br />
[realms]<br />
dc01.domain.local = {<br />
kdc = dc01.domain.local<br />
default_domain = domain.local<br />
}<br />
[domain_realm]<br />
.domain.local = dc01.domain.local<br />
&#8212;&#8212;&#8212;&#8212;-</p>
<p>Did I create the Krb5.ini file in the right format?</p>
<p>Thanks &amp; Regards<br />
Karan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim</title>
		<link>http://altentee.com/2009/improved-spnego-or-kerberos-support-with-loadrunner/comment-page-1/#comment-305</link>
		<dc:creator>Tim</dc:creator>
		<pubDate>Fri, 09 Oct 2009 05:23:21 +0000</pubDate>
		<guid isPermaLink="false">http://90kts.com/blog/2009/improved-spnego-or-kerberos-support-with-loadrunner/#comment-305</guid>
		<description>In the end I didn&#039;t have a keytab file. Can you post the error here?</description>
		<content:encoded><![CDATA[<p>In the end I didn&#8217;t have a keytab file. Can you post the error here?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
