> Source: [sk116246](https://support.checkpoint.com/results/sk/sk116246)

# sk116246 - Single Sign On with Kerberos Constrained Delegation does not work for Mobile Access users from the same domain with different UPN Suffixes

| Property | Value |
|----------|-------|
| Solution ID | sk116246 |
| Date Created | 2017-03-21 |
| Last Modified | 2021-05-17 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * *$CVPNDIR/log/httpd.log* file on the Mobile Access Gateway shows:

  `[KERBEROS] [CVPN_ERROR] comErrHook: Cvpn::KerberosComponent::initCredentials : Cannot find KDC for requested realm : when doing krb5_get_init_creds_password()`
* Single Sign On for Kerberos Constrained Delegation does not work for Mobile Access users.

## Cause

Kerberos Constrained Delegation does not work for Mobile Access users from the same domain with different UPN Suffixes:

AD domain, with which Mobile Access Gateway should perform Kerberos Constrained Delegation, is taken from the UPN suffix of the user, who logged in to Mobile Access Gateway.  
However, UPN suffix is not necessarily the user's domain (for example, different UPNs are needed for different applications).  
In such cases, the Kerberos Delegator would not be found.

## Solution

This problem was fixed. The fix is included in:

* [Check Point R80.10](http://supportcontent.checkpoint.com/solutions?id=sk111841)

Check Point recommends to always [upgrade to the most recent version](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=184)

For **other [supported](http://www.checkpoint.com/support-services/support-life-cycle-policy/index.html) versions** , Check Point can supply a **Hotfix** . [Contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Code was improved:**

* Kerberos realm will be the domain configured in the application object properties in the "Single Sign On" settings (fallback to UPN suffix, if no domain is configured).

**Hotfix installation instructions:**

1. Hotfix has to be installed on ***Mobile Access Gateway***.

   **Note:** In cluster environment, this procedure must be performed on *all* members of the cluster.
2. Procedure:

   * Using CPUSE - On Mobile Access Gateway running Gaia OS R75.40 and above:

     Make sure to install the [latest build of the CPUSE Agent](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest build of CPUSE and What's New).

     Refer to [sk92449: CPUSE - Gaia Software Updates (including Gaia Software Updates Agent)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE):
     * Section "[(4-A-c)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE - How to download and import a CPUSE package - Import instructions for Offline procedure - Gaia Portal)" / "[(4-A-d)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE - How to download and import a CPUSE package - Import instructions for Offline procedure - Gaia Clish)" - refer to import instructions for *Offline procedure*
     * Section "[(4-B-a)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE - How to install a CPUSE package - Installing a Hotfix package / Minor Version package)" - refer to installation instructions for *Hotfixes*

     You can also use the [sk111158 - Central Deployment Tool (CDT)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111158) to install this hotfix on Security Gateways.

     **Note:** Reboot is required.
   * Using Legacy CLI - On VSX Gateway running Gaia OS R75.40VS and above; On Mobile Access Gateway running SecurePlatform/XOS OS:

     Note: On these versions of VSX, the CPUSE does not support installation of hotfixes (refer to [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#System requirements and limitations) - section "(2)" - "VSX Gateways").
     1. Transfer the hotfix package to the machine (into some directory, e.g., */some_path_to_fix/*).

     2. Unpack and install the hotfix package:

        ***\[Expert@HostName\]# cd /some_path_to_fix/***   
        ***\[Expert@HostName\]# tar -zxvf cvpn_\<HOTFIX_NAME\>.tgz***   
        ***\[Expert@HostName\]# ./cvpn_\<HOTFIX_NAME\>***
        **Note:** The script will stop all of Check Point services (*cpstop*) - read the output on the screen.
     3. Reboot the machine.

3. Follow the relevant configuration instructions below.

**Configuration instructions:**

Note: It is assumed that Kerberos and Kerberos Constrained Delegation (KCD) are already configured. Just need to configure the SSO for KCD in the relevant Mobile Access application objects.

|-------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Where                         | How                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Web Application objects       | 1. In SmartDashboard, go to the ***Mobile Access*** tab 2. In the left upper tree, expand the ***Applications*** - select the object of the relevant Web Application - click on the ***Edit...*** button *Example* : [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Web_Application_1.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Web_Application_1.png "Click the image to see it in full size in a new tab/window") 3. In the object's properties, expand the ***Additional Settings*** - click on the ***Single Sign On*** pane 4. Check the box ***Tune on Single Sign On for this application*** 5. In the ***Application Single Sign On Method*** section, select the option ***Advanced*** - click on the ***Edit...*** button *Example* : [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Web_Application_2.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Web_Application_2.png "Click the image to see it in full size in a new tab/window") 6. Select the option ***This application reuses the portal credentials. Users are not prompted*** - click on OK *Example* : [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Web_Application_3.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Web_Application_3.png "Click the image to see it in full size in a new tab/window") 7. In the ***Logon Settings*** section, click on the ***Edit...*** button *Example* : [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Web_Application_4.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Web_Application_4.png "Click the image to see it in full size in a new tab/window") 8. In the Windows Domain section, check the box ***The user of this application belongs to the following Windows domain*** - specify the real domain of the users (e.g., *xyz.com*) - click OK *Example* : [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Web_Application_5.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Web_Application_5.png "Click the image to see it in full size in a new tab/window") Notes: * This domain has to be the same domain as configured in the LDAP Account Unit / Kerberos configuration file. * "Credential Formats" are irrelevant for KCD (whatever is currently checked, will be ignored). In case UPN is used user username, else SSO will fail. 9. Click on OK 10. Install the security policy |
| Capsule Workspace Mail object | 1. In SmartDashboard, go to the ***Mobile Access*** tab 2. In the left upper tree, expand the ***Applications*** - click on the ***Capsule Workspace Mail*** 3. Select the object of the relevant ***Capsule Workspace Mail*** application - click on the ***Edit...*** button *Example* : [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Capsule_Workspace_Mail_1.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Capsule_Workspace_Mail_1.png "Click the image to see it in full size in a new tab/window") 4. In the left tree, go to the ***Exchange Access*** pane - check the box ***Use specific domain*** - specify the real domain of the users (e.g., *xyz.com*) *Example* : [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Capsule_Workspace_Mail_2.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Capsule_Workspace_Mail_2.png "Click the image to see it in full size in a new tab/window") 5. In the left tree, go to the ***Single Sign On*** pane - select the option ***Login to exchange with the application credentials*** *Example* : [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Capsule_Workspace_Mail_3.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk116246/Capsule_Workspace_Mail_3.png "Click the image to see it in full size in a new tab/window") Note: "Credential Formats" are irrelevant for KCD. In case UPN is used user username, else SSO will fail. 6. Click on OK 7. Install the security policy                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
