BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 07-30-2008, 02:57 PM   #61
rst
New Member
 
Join Date: Jul 2008
Model: 8830
PIN: N/A
Carrier: Bell
Posts: 5
Default

Please Login to Remove!

So I was able to fix the login issue but I am getting the login/krb5.conf error.

I have checked to make sure Windows AUTH is on and I have modified my .conf file so it has my domain info and DC info.

Is there another place to see where it might be failing or something I am missing.
Offline  
Old 07-30-2008, 05:08 PM   #62
jsdc
Knows Where the Search Button Is
 
Join Date: Dec 2004
Model: 8800
Carrier: O2 UK
Posts: 28
Default

Quote:
Originally Posted by rst View Post
So I was able to fix the login issue but I am getting the login/krb5.conf error.

I have checked to make sure Windows AUTH is on and I have modified my .conf file so it has my domain info and DC info.

Is there another place to see where it might be failing or something I am missing.
How did you fix the login issue? I think I have exactly the same issue.
Offline  
Old 07-30-2008, 05:31 PM   #63
JavaJunkee
Thumbs Must Hurt
 
JavaJunkee's Avatar
 
Join Date: Jan 2007
Location: Seattle, WA
Model: 9780
Carrier: T-Mobile
Posts: 156
Talking

Now . . . the "Client for OCS2007" is available.

BlackBerry - BlackBerry Enterprise Instant Messaging

Have at it boys!
Offline  
Old 07-31-2008, 02:20 AM   #64
georgedavid
New Member
 
Join Date: May 2008
Model: 8320
PIN: N/A
Carrier: T-Mobile
Posts: 2
Default

I am also having an issue with authentication. =/
I have OCS 2007 with BES 4.1.6 and bb client 2.1.10

I have tried anonymous access enabled on the IIS site, no good
I have tried all sorts of different options on krb5.conf, no good

an additional difficulty i have is that my internal domain is different than the external and i want users to be able to login with their emails, not an internal suffix.

anyway, everything works via the web access portal and office communicator 2007.

i have changed the kerb5.conf to be .com and .lan. no success. same errors.

--------- kerb5.conf ---------
[libdefaults]
default_tkt_enctypes = des-cbc-md5 ; or des-cbc-crc
default_tgs_enctypes = des-cbc-md5 ; or des-cbc-crc

[realms]
# change COMPANY.COM to your Kerberos realm
# change KDC:88 to the hostname:port of KDC
company.lan = {
kdc = DomainController:88
}
--------- kerb5.conf ---------

---------- BBIM_01 ---------
SIP URI = myusername[at]company.com>
Account = company.lan\myusername>
Integrated Authentication fails due to invalid username/password or incorrect config/krb5.conf. ocs.company.lan:443/iwa/logon.html>
CWA Server -> IM Proxy failure response = CwaRequestFailedResponseType, rid = null>
CWA signon exception for ocs.company.lan:443/iwa/logon.html = CWA server did not return a cwaTicket in signon response>
---------- BBIM_01 ---------

-------BBIM Settings -------
Blackberry Collaboration Services Version: 4.1.6.26
Default Domain Name: company.lan
Host: ocs.company.lan
Port:443
Transport protocol: 1
-------BBIM Settings -------

--- OCS Server IIS logs with Anonymous Authentication Enabled ---
2008-07-31 06:48:45 W3SVC OCS_SERVER_IP POST /iwa/logon.html - 443 - BES_SERVER_IP MDS_4.1.6.26+(MSIE) 200 5 0
2008-07-31 06:48:45 W3SVC OCS_SERVER_IP POST /forms/logon.html - 443 - BES_SERVER_IP MDS_4.1.6.26+(MSIE) 200 0 0
--- OCS Server IIS logs with Anonymous Authentication Enabled ---

--- OCS Server IIS logs with Anonymous Authentication Disabled ---
2008-07-31 06:13:28 W3SVC OCS_SERVER_IP POST /iwa/logon.html - 443 - BES_SERVER_IP MDS_4.1.6.26+(MSIE) 401 2 2148074254
2008-07-31 06:13:28 W3SVC OCS_SERVER_IP POST /forms/logon.html - 443 - BES_SERVER_IP MDS_4.1.6.26+(MSIE) 200 0 0
--- OCS Server IIS logs with Anonymous Authentication Disabled ---

for those who are getting errors on /forms/logon.html. i think it tries both iwa (Integrated Windows authentication) and Form-based authentication. however i believe the bb client cannot use forms based authentication and you need to disable this in OCS 2007.

if i go to the /iwa/logon.html via a web browser on the network i get prompted for a username and password. i enter the same info as my bb client and it works fine. i get the success ticket.

note: i had to remove https:// because i dont have enough posts to insert links =/
any ideas?
Offline  
Old 07-31-2008, 03:47 PM   #65
homeroarg
Knows Where the Search Button Is
 
Join Date: Aug 2006
Model: 8100
Carrier: Telecom Personal
Posts: 46
Default

Isn't required to enable the server's AD account for Kerberos delegation ?!?
No SPNs required ?!?
Offline  
Old 08-01-2008, 02:31 PM   #66
jsdc
Knows Where the Search Button Is
 
Join Date: Dec 2004
Model: 8800
Carrier: O2 UK
Posts: 28
Default

I have been getting authentication issues in IIS logs etc similar to some of the posts in this thread, but have just discovered that users with older firmware (4.1,4.2) work OK. However my curve on 4.5 does not.

Does anyone have a 4.5 curve working against OCS 2007?
Offline  
Old 08-01-2008, 04:03 PM   #67
kjarrodc
Thumbs Must Hurt
 
Join Date: Jan 2008
Model: 8830
PIN: N/A
Carrier: verizon
Posts: 82
Default

Quote:
Originally Posted by jsdc View Post
I have been getting authentication issues in IIS logs etc similar to some of the posts in this thread, but have just discovered that users with older firmware (4.1,4.2) work OK. However my curve on 4.5 does not.

Does anyone have a 4.5 curve working against OCS 2007?

Yes sir - my 8330 with 4.5 is working.
Offline  
Old 08-02-2008, 01:43 AM   #68
send2brian
New Member
 
Join Date: Aug 2008
Model: 3210
PIN: N/A
Carrier: ATT
Posts: 1
Default

Was any able to resolve this issue:

Integrated Authentication fails due to invalid username/password or incorrect config/krb5.conf. URL = https://cwa.company.com:443/iwa/logon.html>

Authentication works fine if I access the URL from the BES server.

-------------
OCS 2007
CWA 2007
BES 4.1.6.10
Enterprise Messenger 2.1.10 for OC 2007
Offline  
Old 08-02-2008, 03:01 PM   #69
danedel
Talking BlackBerry Encyclopedia
 
danedel's Avatar
 
Join Date: Aug 2006
Location: Denver, Co
Model: 9000
Carrier: The "new" at&t
Posts: 210
Default

Yeaaa for me, upgraded my BES's and setup the enterprise messenger. Only took five uninterupted hours this morning. Thanks for all the tips...You guys are great!

I think I am getting the hang of how the BES works....its all about the services.
__________________
Crackberry 9000 (4.6.0.190) New at&t
BES 4.1.6 Exchange 2007 08.01.0240

Last edited by danedel; 08-02-2008 at 03:04 PM..
Offline  
Old 08-03-2008, 08:53 AM   #70
Dirky
Talking BlackBerry Encyclopedia
 
Dirky's Avatar
 
Join Date: Jul 2006
Location: Up North - UK
Model: 8320
Carrier: T-Mobile UK
Posts: 265
Default

Is it possible to configure OCS 2007 to allow communications with MSN messenger clients, via the BB OCS client??

D
__________________
http://www.ubertechs.co.uk
Personal Blog - http://www.g6phf.co.uk
Offline  
Old 08-03-2008, 10:54 AM   #71
danedel
Talking BlackBerry Encyclopedia
 
danedel's Avatar
 
Join Date: Aug 2006
Location: Denver, Co
Model: 9000
Carrier: The "new" at&t
Posts: 210
Default

Quote:
Originally Posted by Dirky View Post
Is it possible to configure OCS 2007 to allow communications with MSN messenger clients, via the BB OCS client??

D


Like external to your network? Messenger clients that are not on the enterprise? I am thinking you could, but all you would really need to do it create some tunnel to a public messaging server on the net. This would essentially be a "back door" to people trying to get into your intranet from the extranet.

Of course my SOX compliance people would freak the heck out if I did this!! I see it being a huge vulnerability. I run gtalk on my device, it allows you to have "buddies" from aim and I believe msn. This is much safer than making your enterprise messaging open, but you will need the appropriate IT policy to allow this type of connection
__________________
Crackberry 9000 (4.6.0.190) New at&t
BES 4.1.6 Exchange 2007 08.01.0240
Offline  
Old 08-03-2008, 01:53 PM   #72
Dirky
Talking BlackBerry Encyclopedia
 
Dirky's Avatar
 
Join Date: Jul 2006
Location: Up North - UK
Model: 8320
Carrier: T-Mobile UK
Posts: 265
Default

Quote:
Originally Posted by danedel View Post
Like external to your network? Messenger clients that are not on the enterprise? I am thinking you could, but all you would really need to do it create some tunnel to a public messaging server on the net. This would essentially be a "back door" to people trying to get into your intranet from the extranet.

Of course my SOX compliance people would freak the heck out if I did this!! I see it being a huge vulnerability. I run gtalk on my device, it allows you to have "buddies" from aim and I believe msn. This is much safer than making your enterprise messaging open, but you will need the appropriate IT policy to allow this type of connection
Well it seems you can configure OCS 2007 to communicate with external IM server at hotmail.com, so I guess you can use the BB OCS 2007 client to talk to external contacts.

However i see OCS 2007 needs Exchange 2007 and this is not supported by RIM.

A nice setup would be Server 2008 env with OCS 2007 and Exchange 2007 but I guess thats not possible.
__________________
http://www.ubertechs.co.uk
Personal Blog - http://www.g6phf.co.uk
Offline  
Old 08-03-2008, 02:39 PM   #73
Dirky
Talking BlackBerry Encyclopedia
 
Dirky's Avatar
 
Join Date: Jul 2006
Location: Up North - UK
Model: 8320
Carrier: T-Mobile UK
Posts: 265
Default

Do you think this scenario would work:-

Box A
Server 2008
Exchange 2007
File server

Box B
Server 2003
OCS 2007
BES 4.1.6

?
D
__________________
http://www.ubertechs.co.uk
Personal Blog - http://www.g6phf.co.uk
Offline  
Old 08-03-2008, 03:57 PM   #74
danedel
Talking BlackBerry Encyclopedia
 
danedel's Avatar
 
Join Date: Aug 2006
Location: Denver, Co
Model: 9000
Carrier: The "new" at&t
Posts: 210
Default

I think you could get that to work, but like I said, it would be an exposure to your enterprise, from a sox perspective.
__________________
Crackberry 9000 (4.6.0.190) New at&t
BES 4.1.6 Exchange 2007 08.01.0240
Offline  
Old 08-03-2008, 06:08 PM   #75
scorp508
Knows Where the Search Button Is
 
Join Date: Aug 2005
Location: Boston, MA
Model: 0000
Carrier: VZW
Posts: 43
Default

Quote:
Originally Posted by Dirky View Post
Well it seems you can configure OCS 2007 to communicate with external IM server at hotmail.com, so I guess you can use the BB OCS 2007 client to talk to external contacts.

However i see OCS 2007 needs Exchange 2007 and this is not supported by RIM.
OCS 2007 does not require Exchange to work, but can integrate with it and give you some hella-awesome presence features. OCS 2007 can also integrate with Exchange 2007 Unified Messaging services. We have OCS 2007 running with Exchange 2003.

External Federation to MSN/AOL/Yahoo requires pricey licenses to work. Otherwise everyone and their brother would be connecting to those company's chat servers with their own.
Offline  
Old 08-03-2008, 06:10 PM   #76
scorp508
Knows Where the Search Button Is
 
Join Date: Aug 2005
Location: Boston, MA
Model: 0000
Carrier: VZW
Posts: 43
Default

Quote:
Originally Posted by danedel View Post
Like external to your network? Messenger clients that are not on the enterprise? I am thinking you could, but all you would really need to do it create some tunnel to a public messaging server on the net. This would essentially be a "back door" to people trying to get into your intranet from the extranet.

Of course my SOX compliance people would freak the heck out if I did this!! I see it being a huge vulnerability. I run gtalk on my device, it allows you to have "buddies" from aim and I believe msn. This is much safer than making your enterprise messaging open, but you will need the appropriate IT policy to allow this type of connection
You need a special federation license to connect to those other services. You can use polcies within OCS to lock out who can and cannot talk to external chat servers too. You can have say 10,000 people on a system with 7,000 only allowed to do internal IM and then another 3,000 who are allowed to talk to AOL/Yahoo/MSN, whatever license you purchased.
Offline  
Old 08-04-2008, 06:49 AM   #77
Dirky
Talking BlackBerry Encyclopedia
 
Dirky's Avatar
 
Join Date: Jul 2006
Location: Up North - UK
Model: 8320
Carrier: T-Mobile UK
Posts: 265
Default

Quote:
Originally Posted by scorp508 View Post
OCS 2007 does not require Exchange to work, but can integrate with it and give you some hella-awesome presence features. OCS 2007 can also integrate with Exchange 2007 Unified Messaging services. We have OCS 2007 running with Exchange 2003.

External Federation to MSN/AOL/Yahoo requires pricey licenses to work. Otherwise everyone and their brother would be connecting to those company's chat servers with their own.
Thanks for info.
I assume these licenses are not included in the MS Action pack subsrciption?

Also I understood that OCS 2007 would only work with Exchange 2007 but perhaps this is microsoft pushing us to upgrade?

D
__________________
http://www.ubertechs.co.uk
Personal Blog - http://www.g6phf.co.uk
Offline  
Old 08-04-2008, 11:15 AM   #78
scorp508
Knows Where the Search Button Is
 
Join Date: Aug 2005
Location: Boston, MA
Model: 0000
Carrier: VZW
Posts: 43
Default

Quote:
Originally Posted by Dirky View Post
Thanks for info.
I assume these licenses are not included in the MS Action pack subsrciption?
Definitely not. Not with a TechNet subscription either.

Quote:
Also I understood that OCS 2007 would only work with Exchange 2007 but perhaps this is microsoft pushing us to upgrade?
Well it depends on what you want it to do. Sure there are some features which only Exchange 2007 allows, but it most certainly doesn't require E2K7 to work. It works quite wonderfully for most things (No UM-integration) with Exchange 2003.
Offline  
Old 08-05-2008, 04:12 AM   #79
mattigan
New Member
 
Join Date: Aug 2008
Model: 8310
PIN: N/A
Carrier: O2 (UK)
Posts: 4
Default

Quote:
Originally Posted by send2brian View Post
Was any able to resolve this issue:

Integrated Authentication fails due to invalid username/password or incorrect config/krb5.conf. URL = https://cwa.company.com:443/iwa/logon.html>

Authentication works fine if I access the URL from the BES server.

-------------
OCS 2007
CWA 2007
BES 4.1.6.10
Enterprise Messenger 2.1.10 for OC 2007
I am having the exact same problem , and can't for the life of me figure out where it's falling over, any suggestions?
Offline  
Old 08-05-2008, 06:22 PM   #80
danedel
Talking BlackBerry Encyclopedia
 
danedel's Avatar
 
Join Date: Aug 2006
Location: Denver, Co
Model: 9000
Carrier: The "new" at&t
Posts: 210
Default

Quote:
Originally Posted by mattigan View Post
I am having the exact same problem , and can't for the life of me figure out where it's falling over, any suggestions?
Have you guys looked at your server certs on the cwa site created when you install the web access component?
__________________
Crackberry 9000 (4.6.0.190) New at&t
BES 4.1.6 Exchange 2007 08.01.0240
Offline  
Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


42

42" Modern Crystal Ceiling Fan Light Fandelier Chandelier Lamp 4 Blades W/Remote

$166.75



20

20" AQM FROSTED QUARTZ CRUCIBLE BOWL CG2-0045D mono crystalline silicon

$350.00



Crystal Clear Epoxy Resin Bar & Table Top, Crafts,Coating,Casting, 2 Gallon Kit picture

Crystal Clear Epoxy Resin Bar & Table Top, Crafts,Coating,Casting, 2 Gallon Kit

$124.99



Crystal Business Card Holder picture

Crystal Business Card Holder

$10.00



Orthodontic Self Ligating Brackets Ceramic Sapphire brace RothMBT 022''3/345Hook picture

Orthodontic Self Ligating Brackets Ceramic Sapphire brace RothMBT 022''3/345Hook

$126.00



RALCAM Endoscope Camera Articulating Borescope 2-Way 180° Industrial Inspection picture

RALCAM Endoscope Camera Articulating Borescope 2-Way 180° Industrial Inspection

$118.99







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.