IBM Support

Change in Kerberos Windows Authentication Registry Settings for Chrome and Edge SSO

Troubleshooting


Problem

  • Mode 3 Windows Authentication with SSO is not working in new versions of Chrome and Edge Chromium.
  • When users click "Login", they see a "Login failed" error message

Cause

  • New version of Chrome and Edge have updated their policy settings
  • Looking at the documentation from the following Chrome website: https://support.google.com/chrome/a/answer/7679408?hl=en
  • Version 86 and above for Chrome has the parameters AuthNegotiateDelegateallowlist, AuthSchemes, and AuthServerallowlist changed to: AuthNegotiateDelegateAllowlist, AuthSchemes, and AuthServerAllowlist.
  • The newer Edge Chromium versions make use of these new parameters as well - AuthNegotiateDelegateAllowlist, AuthSchemes, and AuthServerAllowlist.

Resolving The Problem

  • Open up the Registry Editor
  • Go to "\HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome"
  • Change AuthNegotiateDelegateallowlist to AuthNegotiateDelegateAllowlist, and AuthServerallowlist to AuthServerAllowlist
  • Add the AuthSchemes key if it does not exist.
  • The above keys should have values based on your SSO configuration. For more information check the following documentation that explains the policy in detail: https://docs.microsoft.com/en-us/deployedge/microsoft-edge-policies

Document Location

Worldwide

[{"Line of Business":{"code":"LOB10","label":"Data and AI"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSD29G","label":"IBM Planning Analytics"},"ARM Category":[{"code":"a8m0z000000GozKAAS","label":"Troubleshooting->TM1Web->Configuration"}],"ARM Case Number":"","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"All Version(s)"}]

Document Information

Modified date:
20 April 2021

UID

ibm16438931