Kerberos SSO在Chrome更新后不工作
我们将Kerberos SSO用于我们的SAP业务对象应用程序,并在上周的Chrome升级到版本101.0.4951.54之后,SSO停止在Chrome上工作,但在IE11中仍然可以正常工作。还有其他人经历过并找到了解决方案吗?
PS-我看到另一个用户在其他应用程序中发布了同样的问题,但是我无法问他是否找到了解决方案,因为我是这个论坛的新手,并且没有赢得特权来对其他问题发表评论。
We use Kerberos SSO for our SAP Business Objects Application and after the last week's Chrome upgrade to version 101.0.4951.54, the SSO stopped working on chrome, but it still works fine in IE11. Has anyone else experienced and found solution?
P.S - I see another user posted the same question with different application but I couldn't ask the user if he/she found the solution becuase I am new to this forum and haven't earned privilege to comment on others questions.
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
问题已解决。
这是由于安全策略参数名称在新的Chrome浏览器中更改。 https://support.google.com/chrome.com/chrome/a/a/a/a/an/a/answer/76794088# nononincl
Chrome版本101已删除了策略名称“ AuthnegotiatedElegateWhitelist”,并替换为“ AuthnegotiatedElegatelegateAllowlist”。
通过注册表编辑器下的“ authnegotiatedelegateallowlist”替换“ authnegotiatedElegateWhitelist”来修复问题
:
元素类型:string(reg_sz)元素名称:authnegotiatedElegateAllowList元素值:.mycompany.com,.trustedCompany.com
Issue is resolved.
It is because of Security Policy parameter name change in new Chrome browser. https://support.google.com/chrome/a/answer/7679408#noNonIncl
Chrome version 101 has removed the policy name "AuthNegotiateDelegateWhitelist" and replaced with "AuthNegotiateDelegateAllowlist".
Fixed the issue by replacing "AuthNegotiateDelegateWhitelist" with "AuthNegotiateDelegateAllowlist" under registry Editor
Example: Key: \Software\Policies\Google\Chrome
Element Type: String (REG_SZ) Element Name: AuthNegotiateDelegateAllowlist Element Value: .mycompany.com,.trustedcompany.com