Forum Discussion
Kerberos: can't get S4U2Self ticket for user Exch2016@MYDOMAIN.COM - Server not found in Kerberos database (-1765328377)
Example: ABC/exch2016 or exchange2016@mydomain.com
I'm probably splitting hairs here, but you seem to be using "mydomain.com" and "ABC" interchangeably. My point is, if the domain name is "ABC.NET", is the user principal name for that account @abc.net, or is it @mydomain.net (as in not the same as the domain name)?
I ask because using a UPN realm alias requires an extension to the Kerberos protocol that APM Kerberos SSO currently does not have. If the UPN realm and domain name are different, you have to inject the user's sAMAccountName as the SSO username source and the real domain name (ABC.NET) as the SSO domain realm source.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com