<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intel SCS Kerberos Issue in Intel vPro® Platform</title>
    <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-SCS-Kerberos-Issue/m-p/316024#M3696</link>
    <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue has been identified and resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Root cause was Token Bloat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The maximum Kerberos token size allowable by vPro / AMT is located here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://software.intel.com/en-us/node/631441"&gt;https://software.intel.com/en-us/node/631441&lt;/A&gt; &lt;A href="https://software.intel.com/en-us/node/631441"&gt;https://software.intel.com/en-us/node/631441&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When testing the above setup using an account with a token size within the allowable limits, the issue has been resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I confirmed that Kerberos is now working as expected, along with Kerberos with TLS &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 05 Sep 2017 15:31:24 GMT</pubDate>
    <dc:creator>MFish6</dc:creator>
    <dc:date>2017-09-05T15:31:24Z</dc:date>
    <item>
      <title>Intel SCS Kerberos Issue</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-SCS-Kerberos-Issue/m-p/316023#M3695</link>
      <description>&lt;P&gt;Hello All!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------&lt;/P&gt;&lt;P&gt;First off, Digest Authentication works without ANY issue&lt;/P&gt;&lt;P&gt;----------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im running into an issue with Kerberos Authentication. I was hoping someone could provide some insight as to whats going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;Below is the environment im working with&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Intel SCS Server v11.1 (Windows Server 2012)&lt;/P&gt;&lt;P&gt;2) Lenovo X1 Carbon Gen 4  (Windows 10 1703)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using the most basic Profile possible for AD Integration with ACL Groups&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No other options are being selected as of now (NO TLS, NO Home Domains, NO Remote, NO Network, etc)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the AD Integration piece, i performed the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) I created the OU in our active directory&lt;/P&gt;&lt;P&gt;2) I gave the SCS Admin user FULL CONTROL to the OU&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the ACL piece, i performed the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) I created a SCS Admin Domain Local Group in Active Directory and added the SCS Admin user to the group&lt;/P&gt;&lt;P&gt;2) I added the SCS Admin Group to the ACL in the profile (Permissions are EVERYTHING except Access Monitor)&lt;/P&gt;&lt;P&gt;2) I added the SCS Admin User itself to the ACL in the profile (Permissions are EVERYTHING except Access Monitor)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The profile has 2 entries, 1 is the SCS admin, and the other is the group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I remote_configure the X1 Carbon Laptop, everything succeeds and the system is Configured in Admin Control Mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the system report to the SCS server, and I am able to hit the AMT Web UI @  &lt;A href="http://laptop.domain.com:16992"&gt;http://laptop.domain.com:16992&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Furthermore, I am able to access ALL AMT functions including KVM using the Intel Manageability Commander (Mesh Edition)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BUT....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ONLY with the DIGEST authentication (admin / ******)&lt;/P&gt;&lt;P&gt;----------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kerberos is NOT working....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have performed the following troubleshooting steps for Kerberos&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) I verified the computer account is being created in the OU (samAccountName = LAPTOP$iME)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) I verified the servicePrincipalName on the above object contains the following SPN's&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTTP/&lt;A href="http://LAPTOP.DOMAIN.COM"&gt;LAPTOP.DOMAIN.COM&lt;/A&gt;:664&lt;/P&gt;&lt;P&gt;HTTP/&lt;A href="http://LAPTOP.DOMAIN.COM"&gt;LAPTOP.DOMAIN.COM&lt;/A&gt;:623 &lt;/P&gt;&lt;P&gt;HTTP/&lt;A href="http://LAPTOP.DOMAIN.COM"&gt;LAPTOP.DOMAIN.COM&lt;/A&gt;:16995&lt;/P&gt;&lt;P&gt;HTTP/&lt;A href="http://LAPTOP.DOMAIN.COM"&gt;LAPTOP.DOMAIN.COM&lt;/A&gt;:16994&lt;/P&gt;&lt;P&gt;HTTP/&lt;A href="http://LAPTOP.DOMAIN.COM"&gt;LAPTOP.DOMAIN.COM&lt;/A&gt;:16993&lt;/P&gt;&lt;P&gt;HTTP/&lt;A href="http://LAPTOP.DOMAIN.COM"&gt;LAPTOP.DOMAIN.COM&lt;/A&gt;:16992&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) I verified there are NO duplicate SPN's in our environment (setspn -X)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I can tell, that is all that's required to get AD / Kerberos up and running&lt;/P&gt;&lt;P&gt;----------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to hit the AMT Web UI using Internet Explorer or Chrome, I get a challenge for Username / Password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i type incorrect domain credentials, it goes to the Intel Login page and says (Incorrect Password)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i type correct domain credentials, I get a HTTP 400 - Bad Request&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i use the Intel Manageability Commander (Kerberos NO TLS), I get "Error # 400"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i use the Intel Manageability Commander (Digest), It works perfectly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im not sure whats going on here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the environment stripped down to the very minimum required to get a system provisioned via SCS with AD intefgration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am i missing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;Any assistance is much appreciated!&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2017 15:46:46 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-SCS-Kerberos-Issue/m-p/316023#M3695</guid>
      <dc:creator>MFish6</dc:creator>
      <dc:date>2017-09-01T15:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Intel SCS Kerberos Issue</title>
      <link>https://community.intel.com/t5/Intel-vPro-Platform/Intel-SCS-Kerberos-Issue/m-p/316024#M3696</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue has been identified and resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Root cause was Token Bloat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The maximum Kerberos token size allowable by vPro / AMT is located here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://software.intel.com/en-us/node/631441"&gt;https://software.intel.com/en-us/node/631441&lt;/A&gt; &lt;A href="https://software.intel.com/en-us/node/631441"&gt;https://software.intel.com/en-us/node/631441&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When testing the above setup using an account with a token size within the allowable limits, the issue has been resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I confirmed that Kerberos is now working as expected, along with Kerberos with TLS &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2017 15:31:24 GMT</pubDate>
      <guid>https://community.intel.com/t5/Intel-vPro-Platform/Intel-SCS-Kerberos-Issue/m-p/316024#M3696</guid>
      <dc:creator>MFish6</dc:creator>
      <dc:date>2017-09-05T15:31:24Z</dc:date>
    </item>
  </channel>
</rss>

