When customers upgrade their hosted/on-premises (HOPS) instances to Jive 9.1 and above, they may face an error logging in with Kerberos Single Sign-On (SSO). The error message in sbs.log says
GSSException: Unsupported mechanism requested. The users will be asked to log in with usernames and passwords, despite Kerberos being configured.
This article walks you through the solution for this error.
In Jive HOPS 9.1, we moved from Oracle JDK 8.0 to Amazon Corretto 8.0 JDK. The Amazon Corretto 8 JDK has a different out of the box configuration of their crypto providers when comparing it to the one found in Oracle JDK 8.0
You need to edit the file:
- Existing security.provider.X entries need to be deleted or commented out. For example:
These entries need to be enabled
The users who were previously not able to log in using Kerberos SSO should now be able to log in successfully, without needing to enter a username and password.