Forum Discussion
Roman_178798
Nimbostratus
Apr 11, 2016APM is not forwarding authentication token to ADFS
Hello experts,
we configured ADFS on F5, in deployment guide, the name is Securing AD FS with the BIG-IP APM.
Customer had another demmand, to authenticat with UPN only, not with SAMACCOUNTNAME....
Stanislas_Piro2
Cumulonimbus
Apr 21, 2016Hi,
If you configured SSO with Kerberos, requirements are:
- SSO username must be the sAMAccountName user attribute
- session.logon.last.domain must be configured with domain FQDN
to authenticate with UPN with AD Auth, you can configure a AD query first with:
- UserPrincipalName=%{session.logon.last.username}
-
attributes :
- samaccountname
- memberof
Then Configure a variable assign to :
- assign session.logon.last.username with AD attribute sAMAccountName.
- assign session.logon.last.domain with variable session.ad.last.actualdomain
After this box, you can authenticate user based on the new username variable, and Kerberos is configured with expected variables.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
