A fix is available
APAR status
Closed as fixed if next.
Error description
The inbound userID from Kerberos service ticket has the following format: userid@company.com@XYZ.NET.COM Note the two '@' symbols in the fully qualified Kerberos principal. It has to be interpreted as follows: - userid@company.com is the Windows AD user principal name - @XYZ.NET.COM is the Windows AD domain realm However, when viewing the probe of this Kerberos service ticket, Datapower is parsing the fully qualified domain name as: userid\@company.com@XYZ.NET.COM
Local fix
Use custom stylesheet in the map credential step to remove the backslash from the userid.
Problem summary
A principle identity that contains an '@' character many not be completely parsed from a Kerberos service ticket.
Problem conclusion
Temporary fix
Comments
APAR Information
APAR number
IT09124
Reported component name
DATAPOWER
Reported component ID
DP1234567
Reported release
710
Status
CLOSED FIN
PE
NoPE
HIPER
NoHIPER
Special Attention
NoSpecatt
Submitted date
2015-05-27
Closed date
2015-08-20
Last modified date
2015-08-20
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
DATAPOWER
Fixed component ID
DP1234567
Applicable component levels
R720 PSY
UP
[{"Line of Business":{"code":"LOB45","label":"Automation"},"Business Unit":{"code":"BU053","label":"Cloud & Data Platform"},"Product":{"code":"SS9H2Y","label":"IBM DataPower Gateways"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.1"}]
Document Information
Modified date:
25 September 2021