<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with kerberos authentication in QlikView</title>
    <link>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2541227#M1242983</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/13651"&gt;@Chip_Matejowsky&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I will ask the IT department which trust relationship exists between the "legacy" domains and the new domains.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But why is everything working as expected if I use NTLM and not if I use "Negotiate"? That's the point I don't understand. All four domains are configured within the DSC config (see attached screenshot). The ones without a password are the "legacy" domains, the last one is the new domain.&lt;/P&gt;&lt;P&gt;I forgot to mention we use QlikView May 2024SR1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jan 2026 05:57:59 GMT</pubDate>
    <dc:creator>peterwh</dc:creator>
    <dc:date>2026-01-21T05:57:59Z</dc:date>
    <item>
      <title>Problem with kerberos authentication</title>
      <link>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2430263#M1242976</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I've tried to activate kerberos in our QlikView-Environment. I used this documentation: &lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Kerberos-support-using-QlikView-Webserver/ta-p/1710991" target="_self"&gt;https://community.qlik.com/t5/Official-Support-Articles/Kerberos-support-using-QlikView-Webserver/ta-p/1710991&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I changed the config.xml and "setspn" was executed. But if I try to open the AccessPoint I get "Login failed". I've used Edge und Firefox and both show the same error message.&lt;/P&gt;
&lt;P&gt;Does anyone have an idea what could be wrong? Which log-files could be relevant (unfortunately I didn't find one that shows me more details)?&lt;/P&gt;
&lt;P&gt;I know I ask where unspecific, but I didn't find a startingpoint yet for further investigation.&lt;/P&gt;
&lt;P&gt;Our server are Windows 2016 and we're using QlikView May 2023SR1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards&lt;/P&gt;
&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jan 2026 18:19:17 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2430263#M1242976</guid>
      <dc:creator>peterwh</dc:creator>
      <dc:date>2026-01-26T18:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with kerberos authentication</title>
      <link>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2431019#M1242979</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/22008"&gt;@peterwh&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;See if you can reproduce issue while recording a .HAR file as described in article&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Save-network-web-traffic-HAR-XML-file-and-console-logs-from-the/ta-p/1714049" target="_self"&gt;&lt;STRONG&gt;Save network web traffic (HAR/XML file) and console logs from the browser's developer tools&lt;/STRONG&gt;&lt;/A&gt;. It may help in determining what the issue is.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best Regards&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 21:40:12 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2431019#M1242979</guid>
      <dc:creator>Chip_Matejowsky</dc:creator>
      <dc:date>2024-03-14T21:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with kerberos authentication</title>
      <link>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2433134#M1242980</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;thanks for your answer. Due to my current workload I couldn't test it. If I have new insights I will post them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards&lt;/P&gt;
&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 06:56:25 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2433134#M1242980</guid>
      <dc:creator>peterwh</dc:creator>
      <dc:date>2024-03-21T06:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with kerberos authentication</title>
      <link>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2541199#M1242981</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry for the late response, but now I've had the chance to investigate my problem further. This is what I've found:&lt;/P&gt;&lt;P&gt;We have three (legacy) domains which trust each other. There is a forth domain which doesn't have a full trust. Which trust exactly, I don't know.&lt;/P&gt;&lt;P&gt;The four domains are configured in DSC via "Active Directory" and "LDAP://&amp;lt;domain&amp;gt;".&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I use NTLM users from every domain can logon to the AccessPoint and use QlikView-dashboards.&lt;/P&gt;&lt;P&gt;If I switch to "Negotiate" only user from the three "legacy"-domains can logon successfully. The users of the forth domain get "Login failed".&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone have a glue, what could be the problem and how to solve it?&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 15:11:43 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2541199#M1242981</guid>
      <dc:creator>peterwh</dc:creator>
      <dc:date>2026-01-20T15:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with kerberos authentication</title>
      <link>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2541214#M1242982</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/22008"&gt;@peterwh&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I believe a domain trust with the fourth domain would be a requirement. Have a look at the following articles:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Is-it-possible-to-set-up-multiple-Active-Directory-domains/ta-p/1929703" target="_self"&gt;&lt;STRONG&gt;Is it possible to set up multiple Active Directory domains within one QlikView Server?&lt;/STRONG&gt;&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/Users-from-AD-DomainB-can-t-connect-to-QlikView-server-that/ta-p/1929695" target="_self"&gt;&lt;STRONG&gt;Users from AD DomainB can't connect to QlikView server that resides in AD DomainA&lt;/STRONG&gt;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 19:56:55 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2541214#M1242982</guid>
      <dc:creator>Chip_Matejowsky</dc:creator>
      <dc:date>2026-01-20T19:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with kerberos authentication</title>
      <link>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2541227#M1242983</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/13651"&gt;@Chip_Matejowsky&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I will ask the IT department which trust relationship exists between the "legacy" domains and the new domains.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But why is everything working as expected if I use NTLM and not if I use "Negotiate"? That's the point I don't understand. All four domains are configured within the DSC config (see attached screenshot). The ones without a password are the "legacy" domains, the last one is the new domain.&lt;/P&gt;&lt;P&gt;I forgot to mention we use QlikView May 2024SR1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Peter&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 05:57:59 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2541227#M1242983</guid>
      <dc:creator>peterwh</dc:creator>
      <dc:date>2026-01-21T05:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with kerberos authentication</title>
      <link>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2541397#M1242984</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.qlik.com/t5/user/viewprofilepage/user-id/13651"&gt;@Chip_Matejowsky&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I talked to our IT department and they said there is a "selective" trust between the domains. So not all users or service can communicate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;They modified a configuration so that our service user has the right to use kerberos and now I can access the QVWebserver from all four domains.&lt;/P&gt;&lt;P&gt;Thank you for your time investment.&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Peter&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jan 2026 11:25:01 GMT</pubDate>
      <guid>https://community.qlik.com/t5/QlikView/Problem-with-kerberos-authentication/m-p/2541397#M1242984</guid>
      <dc:creator>peterwh</dc:creator>
      <dc:date>2026-01-23T11:25:01Z</dc:date>
    </item>
  </channel>
</rss>

