Forum Discussion
F5 APM SAML with Safenet and SharePoint
Hello,
The SAML assertion is consumed by the SP. In you situation I'd rather perform a Kerberos authentication via SSO Kerberos Profile on the Sharepoint at the backend.
I thing this is the easies approach unless there is a technical constraint in your environment.
Let me know
Yoann
Hi Yoann
How can we achieve Kerberos SSO between F5 and Sharepoint in this case ? Do we need to configure Kerberos on Safenet (the external IDP) as well or no ?On F5 APM, there are few details required like SPN, account name, password, kerberos realm, KDC, these details should be retrieved IDP through SAML Assertion or how ? Is there a document explains this ?
- Dave_WFeb 17, 2020
Employee
Hello,
Kerberos SSO is Constrained Delegation. Here is a guide on configuring it:
https://www.f5.com/pdf/deployment-guides/kerberos-constrained-delegation-dg.pdf
- SASA1Feb 17, 2020
Nimbostratus
Hi Dave
In the document, the integration is between F5 and AD which is KDC server. In our scenario, there is no AD. It is F5 as SAML SP and Safenet/Gamealto as SAML IDP. Does it mean in this case, the safenet will be the KDC server ?
- Dave_WFeb 25, 2020
Employee
Hello, that depends, but if the site supports Kerberos I would assume there is a KDC that supports it somewhere in this environment. Keep in mind that the Kerberos SSO in APM was designed with MS AD in mind so whatever KDC is present may work, but will need to mimic the AD Kerberos implementation.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
