Forum Discussion
kerberos and ntlm authentication using APM
The orginal question submitter is confused about the role of the APM. He implies that he is not seeking a F5 APM managed KPT but just wants kerberos SSO to carry on working with a F5 LTM load balancing virtual server in the path. Easy - forget about the APM - it's not required for this scenario - the F5 can just pass through the SPNEGO portion of the header from the client. While I can't vouch for the specifics of Sharepoint portal, the reason why he is struggling I suspect is due to DNS lookup part of the Kerberos protocol. It is a common mistake to make an application SPN based on the DNS cname of the F5 virtual server instead of using the FQDN of DNS a-record for the VIP that the F5 pool is using.
hth. David.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com