Forum Discussion
APM Kerberos authentication
How APM authenticates a client is completely dependent on how you define authentication in an access policy. For AD, those options can include:
-
401 and 407-based Kerberos authentication - where there client requests a Kerberos service ticket from the AD for access to a service. Here the client contacts the AD (via Kerberos negotiation).
-
401 and 407-based NTLM authentication - where APM presents an NTLM challenge-response to the client, and verifies the client's response against the AD. Here APM contacts the AD via NTLM/RPC negotiation.
-
401 and 407-based Basic authentication - where APM queries the AD via AD query (Kerberos) or LDAP query to validate a user.
-
Forms-based authentication - where APM queries the AD via AD query (Kerberos) or LDAP query to validate the user.
There is no "default" method. You would choose which method(s) you want to use with clients.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
