Forum Discussion
APM + Active Directory Trusts
Try this:
-
Add a session variable for session.logon.last.domain and set it to CHILD.DOMAIN.COM.
-
Enable cross domain support in the AD auth (split domain shouldn't matter for this test).
-
Run a WireShark from the DC and capture the Kerberos and DNS traffic from APM.
-
Test with just the username and password for a CHILD domain member (no domain association).
The split domain function is supposed to separate the domain portion of a username (domain\user or user@domain) and set that in the session.logon.last.domain variable. The above bypasses that to test just the Kerberos and DNS transactions. You want to APM contact its local KDC, get a referral for the CHILD domain, and then request a ticket from the CHILD domain.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com