IBM Support

How to enable Kerberos Debugging for Navigator for i

How To


Summary

Troubleshooting Kerberos/SSO issues with Navigator for i can be time consuming. Enabling Kerberos Debugging may assist with finding the issue(s).

Objective

Aide in troubleshooting Kerberos/SSO issues with Navigator for i. 

Steps

Navigate to the jvm.options file located in '/qibm/userdata/os/ADMININST/admin1/wlp/usr/servers/admin1' and add the commands to enable Kerberos Debugging. 
1. wrklnk '/qibm/userdata/os/ADMININST/admin1/wlp/usr/servers/admin1'
2. Take option 5 to display admin2
3. Locate the jvm.options stream file and take option 2 to Edit
4. Add in the following two lines:
-Dcom.ibm.security.jgss.debug=all
-Dcom.ibm.security.krb5.Krb5Debug=all
5. Hit F3 to Save/Exit
6. Restart the HTTP Admin Server for Navigator for i to pick up the changes and gather the Kerberos Debug details
This will add a lot of details and events to the messages.log file, causing it grow fairly large. It is suggested to remove the two lines from jvm.options when no longer needed. 

Document Location

Worldwide

[{"Line of Business":{"code":"LOB68","label":"Power HW"},"Business Unit":{"code":"BU070","label":"IBM Infrastructure"},"Product":{"code":"SWG60","label":"IBM i"},"ARM Category":[{"code":"a8m0z0000000CH1AAM","label":"IBM Navigator for i"},{"code":"a8m0z0000000CGqAAM","label":"IBM i HTTP Server"}],"ARM Case Number":"","Platform":[{"code":"PF012","label":"IBM i"}],"Version":"All Version(s)"}]

Document Information

Modified date:
29 January 2025

UID

ibm16376028