Forum Discussion
Steve_Lyons
Jul 31, 2018Ret. Employee
Cross Domain / Cross Forest Kerberos SSO
Does anyone have a how to or gotcha's when deploying cross domain or cross forest Kerberos SSO? I am currently working on a how to but curious if anyone has anything already and would like to share ...
Steve_Lyons
Jul 31, 2018Ret. Employee
More requirements.
- The delegation account must be in service principal name (SPN) format “host/name”.
- In the active directory, the delegation account must use this SPN value for both its servicePrincipalName and userPrincipalName attributes.
- This same SPN value must also be used in the Account Name field in the Kerberos SSO config.
- Kerberos only mode enables the “Kerberos Protocol Transition” protocol option, which is required for APM Kerberos SSO to work.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects