Forum Discussion
KCD SmartCard Two Domains Same Forest Users in both
You're actually talking about a Kerberos "extension" referred to as "Canonical Referral". It's like a CNAME process for Kerberos. In any case, APM Kerberos doesn't follow these referrals today, so you have to tell it exactly which domain the user belongs to. This is complicated by the fact that your smartcard UPN doesn't match any single domain. So basically what you need to do is this:
-
Insert an LDAP Query in the VPE that queries the domain(s) or GC. You need to extract the user's real domain and their sAMAccountName.
-
Use the sAMAccountName and user's real domain as the Kerberos SSO input username and domain session values.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com