You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WebLogic集成Windows AD Kerberos SSO重复请求TGT问题咨询

WebLogic + Windows AD Kerberos SSO 疑问解答

问题分析与解答

1. 为何WebLogic每次请求都向KDC请求带SPN的TGT?

从你提供的WebLogic控制台日志里能看到几个核心线索,直接指向问题根源:

  • ticketCache is null:WebLogic的Kerberos配置中没有指定有效的票据缓存路径,导致每次请求时无法从本地缓存读取已生成的TGT,只能重复向KDC发起申请。
  • LSA contains TGT for ayadav@DOMAIN.COM not HTTP/APPDEV2011.domain.com@DOMAIN.COM:系统缓存里只有用户ayadav的TGT,完全没有WebLogic服务对应的SPN(HTTP/APPDEV2011.domain.com)的TGT,这说明WebLogic根本没成功缓存过自己的服务端TGT。

正常情况下,WebLogic作为服务端,应该是验证客户端(浏览器)传递过来的服务票据,而不是自己主动去请求TGT。出现这种异常流程的常见原因:

  • 前端Apache配置缺失:Apache没有正确完成Kerberos认证流程,既没有验证客户端的票据,也没有将有效的服务票据传递给WebLogic,导致WebLogic不得不以“发起方”身份去KDC重新申请TGT。
  • WebLogic缓存配置错误:要么没配置ticketCache参数,要么缓存路径的权限不足(WebLogic进程没有读写权限),导致TGT无法被持久化缓存。
  • KeyTab有效性问题:虽然指定了KeyTab,但文件权限不对、或者KeyTab中没有包含对应SPN的有效密钥,导致WebLogic无法通过KeyTab自动获取并缓存TGT。

2. 关于会话密钥与KDC交互的理解是否正确?

你的理解完全正确!正常Kerberos流程中:

  • 客户端和服务端协商出会话密钥后,在会话密钥的有效期内,双方可以直接用该密钥加密通信,不需要再联系KDC。
  • 只有当会话密钥过期需要续期、或者客户端的TGT过期需要重新申请时,才会再次与KDC交互。

但当前你的场景中,WebLogic每次都在请求TGT,说明流程根本没走到“使用会话密钥通信”这一步——要么是WebLogic没收到客户端的服务票据,要么是WebLogic自身无法缓存TGT,导致每次请求都要从头发起AS-REQ(申请TGT的请求)。

关键日志片段

Found ticket for HTTP/APPDEV2011.domain.com@DOMAIN.COM to go to krbtgt/DOMAIN.COM@DOMAIN.COM expiring on Fri May 11 21:06:46 CDT 2018 
Debug is true storeKey true useTicketCache true useKeyTab true doNotPrompt true ticketCache is null isInitiator true 
KeyTab is http_weblogic_test.keytab refreshKrb5Config is false principal is HTTP/APPDEV2011.domain.com@DOMAIN.COM 
tryFirstPass is false useFirstPass is false storePass is false clearPass is false 
Acquire TGT from Cache 
KinitOptions cache name is D:\Users\ayadav.DOMAIN.000\krb5cc_ayadav 
Acquire default native Credentials 
default etypes for default_tkt_enctypes: 17 23. 
LSA contains TGT for ayadav@DOMAIN.COM not HTTP/APPDEV2011.domain.com@DOMAIN.COM 
Principal is HTTP/APPDEV2011.domain.com@DOMAIN.COM 
null credentials from Ticket Cache 
Looking for keys for: HTTP/APPDEV2011.domain.com@DOMAIN.COM 
Added key: 17version: 14 
Added key: 18version: 14 
Added key: 23version: 14 
Found unsupported keytype (3) for HTTP/APPDEV2011.domain.com@DOMAIN.COM 
Found unsupported keytype (1) for HTTP/APPDEV2011.domain.com@DOMAIN.COM 
Looking for keys for: HTTP/APPDEV2011.domain.com@DOMAIN.COM 
Added key: 17version: 14 
Added key: 18version: 14 
Added key: 23version: 14 
Found unsupported keytype (3) for HTTP/APPDEV2011.domain.com@DOMAIN.COM 
Found unsupported keytype (1) for HTTP/APPDEV2011.domain.com@DOMAIN.COM 
default etypes for default_tkt_enctypes: 17 23. 
KrbAsReq creating message 
KrbKdcReq send: kdc=wcosp-dc01.domain.com UDP:88, timeout=30000, number of retries =3, #bytes=163 
KDCCommunication: kdc=wcosp-dc01.domain.com UDP:88, timeout=30000,Attempt =1, #bytes=163 
KrbKdcReq send: #bytes read=207 
Pre-Authentication Data: PA-DATA type = 19 
PA-ETYPE-INFO2 etype = 17, salt = DOMAIN.COMHTTPAPPDEV2011.domain.com, s2kparams = null 
PA-ETYPE-INFO2 etype = 23, salt = null, s2kparams = null 
Pre-Authentication Data: PA-DATA type = 2 
PA-ENC-TIMESTAMP 
Pre-Authentication Data: PA-DATA type = 16 
Pre-Authentication Data: PA-DATA type = 15 
KdcAccessibility: remove wcosp-dc01.domain.com 
KDCRep: init() encoding tag is 126 req type is 11 
KRBError: sTime is Fri May 11 11:06:46 CDT 2018 1526054806000 suSec is 633784 
error code is 25 error Message is Additional pre-authentication required 
sname is krbtgt/DOMAIN.COM@DOMAIN.COM eData provided. msgType is 30 
Pre-Authentication Data: PA-DATA type = 19 
PA-ETYPE-INFO2 etype = 17, salt = DOMAIN.COMHTTPAPPDEV2011.domain.com, s2kparams = null 
PA-ETYPE-INFO2 etype = 23, salt = null, s2kparams = null 
Pre-Authentication Data: PA-DATA type = 2 
PA-ENC-TIMESTAMP 
Pre-Authentication Data: PA-DATA type = 16 
Pre-Authentication Data: PA-DATA type = 15 
KrbAsReqBuilder: PREAUTH FAILED/REQ, re-send AS-REQ 
default etypes for default_tkt_enctypes: 17 23. 
Looking for keys for: HTTP/APPDEV2011.domain.com@DOMAIN.COM 
Added key: 17version: 14 
Added key: 18version: 14 
Added key: 23version: 14 
Found unsupported keytype (3) for HTTP/APPDEV2011.domain.com@DOMAIN.COM 
Found unsupported keytype (1) for HTTP/APPDEV2011.domain.com@DOMAIN.COM 
Looking for keys for: HTTP/APPDEV2011.domain.com@DOMAIN.COM 
Added key: 17version: 14 
Added key: 18version: 14 
Added key: 23version: 14 
Found unsupported keytype (3) for HTTP/APPDEV2011.domain.com@DOMAIN.COM 
Found unsupported keytype (1) for HTTP/APPDEV2011.domain.com@DOMAIN.COM 
default etypes for default_tkt_enctypes: 17 23. 
EType: sun.security.krb5.internal.crypto.Aes128CtsHmacSha1EType 
KrbAsReq creating message 
KrbKdcReq send: kdc=wcosp-dc01.domain.com UDP:88, timeout=30000, number of retries =3, #bytes=250 
KDCCommunication: kdc=wcosp-dc01.domain.com UDP:88, timeout=30000,Attempt =1, #bytes=250 
KrbKdcReq send: #bytes read=96 
KrbKdcReq send: kdc=wcosp-dc01.domain.com TCP:88, timeout=30000, number of retries =3, #bytes=250 
KDCCommunication: kdc=wcosp-dc01.domain.com TCP:88, timeout=30000,Attempt =1, #bytes=250 
DEBUG: TCPClient reading 1602 bytes 
KrbKdcReq send: #bytes read=1602 
KdcAccessibility: remove wcosp-dc01.domain.com 
Looking for keys for: HTTP/APPDEV2011.domain.com@DOMAIN.COM 
Added key: 17version:

建议排查步骤

  • 补全WebLogic缓存配置:在WebLogic安全领域的Kerberos配置中,指定ticketCache路径(比如D:\weblogic_krb_cache\krb5cc_weblogic),并确保WebLogic进程对该路径有读写权限。
  • 验证Apache Kerberos配置:确认Apache的mod_auth_kerb已正确配置,开启了Kerberos认证,并且通过ProxyPass传递请求时,将认证后的票据或用户信息(比如Authorization头)转发给WebLogic。
  • 重新生成KeyTab:使用ktpass命令重新生成KeyTab,确保包含正确的SPN(HTTP/APPDEV2011.domain.com@DOMAIN.COM),并检查WebLogic进程对KeyTab文件的读取权限。
  • 开启详细调试日志:在WebLogic中启用更细致的Kerberos调试日志,跟踪TGT的获取、缓存和验证流程,进一步定位异常点。

内容的提问来源于stack exchange,提问作者Abhishek Yadav

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 07:29:45