Forum Discussion
APM KCD SSO - Requesting ticket can't get forwardable tickets (-1765328163) but works eventually
Just my 2c, might not be relevant to your situation.
I experienced something similar when I was trying to set up an office online server and attach it to our SharePoint VIP with smart card auth. Turns out I didn't need to mess with SPNs/configure Kerberos or anything. SharePoint ACLs were handling the access to the files and the IIS site used anonymous authentication.
Hmm.
Can you also look at the clear text traffic to the server? I’m assuming, but it’d be good to validate that on every attempt APM actually does pass a Kerberos AP_REQ ticket to the app, and that for some reason the app doesn’t accept it. If you can get a wireshark view of the APM-server traffic you should be able to see the full Kerberos details. And if that’s true, it might imply that the server is at fault, the KDC is issuing a ticket to the wrong service, or there’s something wrong with the ticket.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com