When system is configured with SSO with SSO LDAP Then Internal, Configurator uses a compound authenticator. A regression was introduced in 11.6.1 where the parsing of AE authenticator throws a NullPointerException (NPE) and prevents the IdP from being initialized properly. No workaround can be provided besides turning off SSO .
The error message will be different, but issue has to do with expired SBM SSO certificates. When trying to login to SBM, the login page will show the following error. For those using CAC or Third Party authentication that have enable forms authentication turned off , you will see the same message in the SSO -STS.LOG.
When using SSO, the IIS server will talk to Tomcat/JBoss and Tomcat/JBoss will authenticate the user. Try turning off SSO (using the SBM Configurator). If the login works correctly, the IIS server is having problems communicating with Tomcat/JBoss.
ALF Event Failed.: Error obtaining security token: Failed to resolve user In versions of SBM prior to 10.1 the workaround is to turn off SSO on the SBM server. In versions of SBM after 10.1 do the following.