My Oracle Support Banner

WebLogic Server Fails to Authenticate a Client Via Kerberos Protocol When Authentication Is Delegated to Citrix Netscaler (Doc ID 1933634.1)

Last updated on DECEMBER 16, 2023

Applies to:

Oracle WebLogic Server - Version 10.3.6 to 12.1.3.0.0
Information in this document applies to any platform.

Symptoms

In this scenario, a Negotiate Identity provider has been configured in WebLogic Server as per the doc "Configuring Single Sign-On with Microsoft Clients".

Everything works fine when using MS Internet explorer, or other browsers on client computers in Microsoft domain. The problem came when one tries to configure Citrix Netscaler appliance to delegate the Kerberos authentication, typically for external users connecting from Internet from computers which are not in Microsoft domain. The Netscaler correctly authenticates the user, then sends a Kerberos ticket to WebLogic Server, but WebLogic Server is unable to parse it.

These are the entries in WebLogic Server logs showing the issue:

 

Cause

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Symptoms
Cause
Solution
References


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.