Users Are Unable To Login When Restricted to Kerberos Authentication
search cancel

Users Are Unable To Login When Restricted to Kerberos Authentication

book

Article ID: 407156

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

  • When restricting authentication to Kerberos (disabling NTLM), authorized users are no longer able to login to the Carbon Black App Control console
  • All AD Users are locked out after reboot installing Windows Updates

Environment

  • App Control Server: 8.11.0 and lower

Cause

Issue with Kerberos handling (CRE-20286)

Resolution

Upgrade to App Control server version 8.11.2 or Higher which can be downloaded here

Additional Information

Workaround (revert after upgrading).

  1. Login using local admin user
  2. Navigate to https://<AppControlServerName>/shepherd_config.php
    • Select the Property: AllowADScript
    • Change the Value to true.
  3. Restart the App Control Server & Reporter services.
  4. Verify the AD accounts are able to log in correctly.

Note: Windows Updates may also make changes to Kerberos and NTLM Authentication which may require using the workaround until it's possible to upgrade the App Control server to a version that includes the fix.