Forum Discussion
Steve_Lyons
Jul 31, 2018Ret. Employee
Cross Domain / Cross Forest Kerberos SSO
Does anyone have a how to or gotcha's when deploying cross domain or cross forest Kerberos SSO? I am currently working on a how to but curious if anyone has anything already and would like to share ...
Steve_Lyons
Jul 31, 2018Ret. Employee
More requirements.
- The delegation account must be in service principal name (SPN) format “host/name”.
- In the active directory, the delegation account must use this SPN value for both its servicePrincipalName and userPrincipalName attributes.
- This same SPN value must also be used in the Account Name field in the Kerberos SSO config.
- Kerberos only mode enables the “Kerberos Protocol Transition” protocol option, which is required for APM Kerberos SSO to work.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
