I have the following test code to try and run a simple query using my kerberos credentials based on (poor) example from the guides
We are using Documentum 6.7 and Apache Tomcat 6.0 running dfs web services
I suspect the problem is somewhere in the code below. I can find no good examples on what to do. I can tell you that the InitializeContext command is supposed to get kerberos ticket from client but it also sets the value ContinueNeeded to TRUE. What does this mean? If True, are there additional steps that must be taken? I found some reference about having to send something to server and then calling initializecontext again with the returned ticket...
void testQueryServiceKerberos(string repository, string module,string server)
{
KerberosTokenHandler handler = new KerberosTokenHandler();
String servicePrincipalName = "DFS/xxxxx.xxxxx.com:8080@XXXXX.COM"; // this is the service principal name for your DFS service account in Active Directory.
using (KerberosClientContext kerberosClientContext = new KerberosClientContext(servicePrincipalName, true, ImpersonationLevel.Delegation))
{
KerberosBinarySecurityToken token = new KerberosBinarySecurityToken(kerberosClientContext.InitializeContext(), KerberosValueType.KERBEROSV5_AP_REQ);
handler.SetBinarySecurityToken(token);
List<IEndpointBehavior> handlers = new List<IEndpointBehavior>();
handlers.Add(handler);
//create service with ticket
IServiceContext serviceContext = ContextFactory.Instance.NewContext();
ContentTransferProfile contentTransferProfile = new ContentTransferProfile();
serviceContext.SetProfile(contentTransferProfile);
RepositoryIdentity repIdent = new RepositoryIdentity();
repIdent.RepositoryName = repository;
serviceContext.AddIdentity(repIdent);
IQueryService queryService = ServiceFactory.Instance.GetRemoteService<IQueryService>(serviceContext, module, server,handlers);
List<string> reps = new List<string>();
reps.Add(repository);
PassthroughQuery query = new PassthroughQuery(reps, "select DATE(now) as systime from dm_server_config");
QueryExecution queryEx = new QueryExecution(0, 30, 30);
List<DataObject> dataObjects = queryService.Execute(query, queryEx, null).DataPackage.DataObjects;
Console.WriteLine(dataObjects[0].Properties.Properties[0].GetValueAsString());
}
}
The error it generates as seen in server log is as follows:
7:33:15,657 DEBUG [DFS] com.emc.documentum.fs.rt.handlers.KerberosTokenServerHandler - Kerberos authentication processing enabled on the server side!
17:33:15,657 DEBUG [DFS] com.emc.documentum.fs.rt.handlers.KerberosTokenServerHandler - Found Kerberos ticket in SOAP header: 1cb73937632237b9d7d2f2ce5b329db498f51736
17:33:15,672 INFO [DFS] com.emc.documentum.fs.rt.context.impl.SessionManagerFactory - I_SET_UP_ALLOW_TRUSTED_LOGIN
17:33:15,672 DEBUG [DFS] com.emc.documentum.fs.rt.context.impl.SessionManagerProxy - Calling method: setIdentity
17:33:15,672 DEBUG [DFS] com.emc.documentum.fs.rt.context.impl.SessionManagerProxy - Calling method: setIdentity
17:33:15,672 DEBUG [DFS] com.emc.documentum.fs.rt.context.impl.SessionManagerProxy - Calling method: toString
17:33:15,672 DEBUG [DFS] com.emc.documentum.fs.rt.context.impl.SessionManagerFactory - Created new session manager: com.documentum.fc.client.impl.session.SessionManager@14f865e for token: temporary/127.0.0.1-1376501593256-1544050884
17:33:15,672 DEBUG [DFS] com.emc.documentum.fs.rt.context.impl.SessionManagerProxy - Calling method: getSession
17:33:15,688 INFO [DFS] com.emc.documentum.fs.rt.context.impl.SessionManagerFactory - I_SET_UP_ALLOW_TRUSTED_LOGIN
17:33:15,688 DEBUG [DFS] com.emc.documentum.fs.rt.context.impl.SessionManagerProxy - Calling method: setIdentity
17:33:15,688 DEBUG [DFS] com.emc.documentum.fs.rt.context.impl.SessionManagerProxy - Calling method: setIdentity
17:33:15,688 DEBUG [DFS] com.emc.documentum.fs.rt.context.impl.SessionManagerProxy - Calling method: toString
17:33:15,688 DEBUG [DFS] com.emc.documentum.fs.rt.context.impl.SessionManagerFactory - Created new session manager: com.documentum.fc.client.impl.session.SessionManager@70a917 for token: dfs-sso-temp-token-for-6.7-temporary/127.0.0.1-1376501593256-1544050884-com.emc.documentum.kerberos.utility.GSSCredentialWrapper@1
17:33:15,688 DEBUG [DFS] com.emc.documentum.fs.services.core.impl.execution.QueryAction - execute: query object->DfPassthroughQuery: [select DATE(now) as systime from dm_server_config]
17:33:15,688 DEBUG [DFS] com.emc.documentum.fs.services.core.impl.execution.QueryAction - execute: query string ->select DATE(now) as systime from dm_server_config
17:33:15,688 DEBUG [DFS] com.emc.documentum.fs.services.core.impl.execution.QueryAction - execute: query id ->null
17:33:15,688 DEBUG [DFS] com.emc.documentum.fs.services.core.impl.execution.QueryAction - execute: query starting index->0
17:33:15,688 DEBUG [DFS] com.emc.documentum.fs.services.core.impl.execution.QueryAction - execute: query max m_result->30
17:33:15,688 DEBUG [DFS] com.emc.documentum.fs.services.core.impl.execution.QueryAction - execute: query docbase names->REP1DEV
17:33:15,688 DEBUG [DFS] com.emc.documentum.fs.services.core.impl.execution.QueryAction - execute: query cache strategy->DEFAULT_CACHE_STRATEGY
17:33:15,688 DEBUG [DFS] com.emc.documentum.fs.rt.context.impl.SessionManagerProxy - Calling method: getSession
17:33:15,719 ERROR [DFS] com.emc.documentum.fs.services.core.QueryServiceWebService - "QUERY" action failed. java.lang.NullPointerException
com.emc.documentum.fs.services.core.CoreServiceException: "QUERY" action failed. java.lang.NullPointerException
at com.emc.documentum.fs.services.core.impl.execution.QueryAction.process(QueryAction.java:129)
at com.emc.documentum.fs.services.core.impl.payload.FailOnExceptionPayloadPolicy.process(FailOnExceptionPayloadPolicy.java:23)
at com.emc.documentum.fs.services.core.impl.execution.ExecutionStrategy.process(ExecutionStrategy.java:43)
at com.emc.documentum.fs.services.core.impl.QueryService.execute(QueryService.java:93)
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at sun.reflect.NativeMethodAccessorImpl.invoke(Unknown Source)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
at java.lang.reflect.Method.invoke(Unknown Source)
at com.emc.documentum.fs.rt.context.impl.ReflectionServiceInvoker.invoke(ReflectionServiceInvoker.java:40)
at com.emc.documentum.fs.rt.impl.tx.TxInvocationHandler.invoke(TxInvocationHandler.java:29)
at com.emc.documentum.fs.rt.context.impl.SoapServiceInvocationHandler.invoke(SoapServiceInvocationHandler.java:50)
at com.emc.documentum.fs.rt.context.impl.ContextCacheCleanupHandler.invoke(ContextCacheCleanupHandler.java:28)
at com.emc.documentum.fs.rt.context.impl.ServiceContextCleanupHandler.invoke(ServiceContextCleanupHandler.java:31)
at com.emc.documentum.fs.rt.context.impl.HandlerChainExceptionInvocationHandler.invoke(HandlerChainExceptionInvocationHandler.java:35)
Caused by: java.lang.NullPointerException
at com.documentum.fc.common.UnifiedLoginHelper.isULSupportedByClient(UnifiedLoginHelper.java:41)
at com.documentum.fc.client.impl.connection.docbase.DocbaseConnection.checkForUnifiedLogin(DocbaseConnection.java:1590)
at com.documentum.fc.client.impl.connection.docbase.DocbaseConnection.authenticate(DocbaseConnection.java:408)
at com.documentum.fc.client.impl.connection.docbase.DocbaseConnection.open(DocbaseConnection.java:128)
at com.documentum.fc.client.impl.connection.docbase.DocbaseConnection.<init>(DocbaseConnection.java:97)
at com.documentum.fc.client.impl.connection.docbase.DocbaseConnection.<init>(DocbaseConnection.java:60)
at com.documentum.fc.client.impl.connection.docbase.DocbaseConnectionFactory.newDocbaseConnection(DocbaseConnectionFactory.java:26)
at com.documentum.fc.client.impl.connection.docbase.DocbaseConnectionManager.getDocbaseConnection(DocbaseConnectionManager.java:85)
at com.documentum.fc.client.impl.session.SessionFactory.newSession(SessionFactory.java:29)
at com.documentum.fc.client.impl.session.PrincipalAwareSessionFactory.newSession(PrincipalAwareSessionFactory.java:42)
at com.documentum.fc.client.impl.session.PooledSessionFactory.newSession(PooledSessionFactory.java:47)
at com.documentum.fc.client.impl.session.SessionManager.getSessionFromFactory(SessionManager.java:111)
at com.documentum.fc.client.impl.session.SessionManager.newSession(SessionManager.java:64)
at com.documentum.fc.client.impl.session.SessionManager.getSession(SessionManager.java:168)
at com.emc.documentum.fs.rt.context.impl.SessionManagerProxy$SMInvocationHandler.getSessionInternal(SessionManagerProxy.java:127)
at com.emc.documentum.fs.rt.context.impl.SessionManagerProxy$SMInvocationHandler.invoke(SessionManagerProxy.java:63)
at com.sun.proxy.$Proxy52.getSession(Unknown Source)
at com.emc.documentum.fs.services.core.impl.query.lowlevel.DfQueryService.getSession(DfQueryService.java:90)
at com.emc.documentum.fs.services.core.impl.query.lowlevel.DfQueryService.execute(DfQueryService.java:37)
at com.emc.documentum.fs.services.core.impl.execution.QueryAction.process(QueryAction.java:99)
... 51 more
I don't know why it has nullpointerexception.
I disguised the SPN in the code but it is registered correctly in our domain. I did it the same way as with the WDK aps and I am able to log into Webtop using Kerberos ticket without problems. I created a new username for DFS called DFS/servername.abc.com:8080@ABC.COM for DFS services.
I have tracing turned on Content Server too and now get no errors while trying to authenticate. Only error is on app server.