Forum Discussion
Wand_97484
Nimbostratus
Jan 13, 2011ASM - Kereberos protocol transition
Hi everyone, just want to share my experience with the kerberos delegation / protocol transition feature in 10.2. Kerberos Delegation works fine for me (was stuck first with reverse lookup), but works fine now. Kerberos protocol transition doesn't work yet for me, I added some logging lines to the default iRule and can see that the LTM receives the User Certificate.
15:05:16 CET 2011 info local/tmm3 tmm3[5695] Rule iRule_krbdelegate_logging : Protocol Transition with CERT: 3005218020 0?¦0?? qèØs????=0 *?H?÷ ??01!0UOnline CA0 110111160632Z 120111160632Z010UTest.User0?"0 *?H?÷ ?????0? ???¿¯Wçwçå@Ä`,z?îY¯ÓùêÀ¾è[îÀ�½B?ä�Êxé¸ù??`ïÒM*?`2SoÊÙm?§???¿gW?©Pk³¿¬??R|Ã?�áX8Õ05ÈoÐkPm^¹ÍÁ5OC*?o¥?I?3ùÊ*?{¬p[ß,+Õõ¢Ô�>?½1Ô¦ ÂÕË5Lð¦sÛÈ[?4yÔ:RWØûPÊ{2A~CgékH@?ä?R¤¯Ëï??H�´Ê´R2@m÷?å¿í?ÏèøSÉ?BÞMaí?ÈÈ)GqÅnÜÑ?VæRÏ£¼ók{°ÉîRYI?]G;hæ1S±Öva ???£?ã0?ß0 U 0D *?H?÷ 7050*?H?÷ ???0*?H?÷ ???0+0 *?H?÷ 0U¦µ¤9 6mÚ?,ö{XUÐ?F0> +?710/'+?7?ô�G?ó?7?Õ?-?ÿ�$?ÓÓ�"�?Ñ ?Ëúd 0U0?Éú_[u½Õµ?T%?b¿â[M0?,U?0?0? ? ??�Èldap:/
At the network I see that the LTM sends out a AS-REQ, but receives a KRB_ERROR: KRB5KDC_ERR_PREAUTH_REQUIRED, followed by another AS-RQ failing with a KRB_ERROR: KRB5KDC_ERR_PREAUTH_FAILED. In addition to the F5 config Guide, I added "DONT_REQ_PREAUTH" (http://support.microsoft.com/kb/305144) to the computer accounts useraccountcontroll attribute.
With this settings I receive a different Kerberos error AS-REP NT Status: unknown error code 0x2e465341.
So I'm pretty much stuck with the protocol transition feature.
Any Tips which trick I'm missing?
BTW: Since the krbdelegate iRule has the Certificate Authentication hardcoded, does someone replaced Certificate Auth by another one?
BR
Jens
2 Replies
Sort By
- Kevin_Stewart
Employee
Jens, - Wand_97484
Nimbostratus
Hi Kevin,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects