Consideration
When FME Flow is configured for Active Directory authentication using a preauth service account, users with valid accounts and correct permissions may be unable to view the list of resources in FME Flow Web UI > Manage > Resources. This occurs even after reviewing Safe Software's Troubleshooting Authentication Services documentation.
The following entry appears in <FME Flow System Share>\resources\logs\core\current\fmesharedresource.log:
(Active Directory) Authenticating user "FMESERVICE@SAFE.COM" using SASL mechanism "GSSAPI" with KDC address "DNS.SAFE.COM" and realm "SAFE.COM"...
(Active Directory) Successfully established a new connection to DNS.SAFE.COM.
(Single Sign-On) Disabled single sign-on authentication.
(Login Module) Authenticating token "23b385c617625eefb4f7ea8d91746aa572b889a9" clientAddress "".
(Active Directory) Successfully established a new connection to DNS.SAFE.COM.Failed login by user 23b385c617625eefb4f7ea8d91746aa572b889a9 due to insufficient credentials.
Why This Happens
This behavior is caused by a setting on the Active Directory service account used for preauthentication:
- The Windows Active Directory account can be configured with the "Do not require Kerberos preauthentication" option enabled.
- When this option is enabled on the account specified as
SECURITY_AD_PREAUTH_USERNAME(for example,FMESERVICE), FME Flow cannot complete the GSSAPI SASL authentication handshake with the domain controller. - As a result, users are treated as having insufficient credentials, even though their own account and permissions are correct.
How to Resolve It
- Open Active Directory Users and Computers (or the equivalent Active Directory management tool) on the domain controller.
- Locate the service account specified as
SECURITY_AD_PREAUTH_USERNAMEin fmeCommonConfig.txt (for example,FMESERVICE). - Open the Properties dialog for the account and click the Account tab.
- Under Account options, ensure "Do not require Kerberos preauthentication" is unchecked.
- Click OK to save the changes.
If this does not resolve the issue, search the FME Community for similar topics or submit a support ticket.