Forum Discussion
Wand_97484
Sep 13, 2013Nimbostratus
APM ClientCert to Kerberos Transition - parsing SubjectAlternateName in Variable assign
Hi,
I'm currently setting up different APM profiles to test Kerberos Protocol Transition.
LDAP Auth to Kerberos works
RSA SecurID to Kerberos works
Client Certificate to Kerberos - does not work...
Kevin_Stewart
Oct 08, 2013Employee
It looks like the Kerberos Client Principal is build by sAMAccountName@REALM
I think it's safer to say that Windows will accept both userPrincipalName AND sAMAccountName for identity assertion. Either can usually be in name@domain or domain\name format.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects