Forum Discussion
APM : Multiple servers for Kerberos SSO
Hi,
In Kerberos SSO, there are 3 solutions to define KDC server
- left blank : use DNS to find kerberos server with SRV record : not recommended by F5, requires change of /etc/krb5.conf
- KDC hostname : use DNS to resolve kerberos IP from provided name : a little better
- KDC IP : recommended by F5
When configuring hostname or IP, I did not find how to configure more than one server.
The only solution I found was to create a VS listening on all ports (to allow LDAP and Kerberos ports, UDP and TCP)
Is it the solution? is there a solution to configure more than one server? can we configure a pool like in AD Auth?
1 Reply
- Seth_Cooper
Employee
Yes, You would need to use a separate VS to accomplish this. Just point the KDC to the VIP and the pool members to the KDCs.
-Seth
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com