Forum Discussion
Kerberos: can't get TGT for HOST/abc@abc.com - Realm not local to KDC
Hi There,
I am trying to get the Kerberos constrained delegation to work, where the client authentication is done via certficate with the BIGIP. The BIGIP uses the further via Kerberos SSO to authenticate to the backend servers. I have tried the options as per the links below http://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-sso-config-11-1-0/3.html https://devcentral.f5.com/articles/single-sign-on-mit-kerberos-constrained-delegation.UxhzSs4e_DM https://devcentral.f5.com/articles/single-sign-on-mit-kerberos-constrained-delegation-teil-2-debugging.UxhzXc4e_DM(for Troubleshooting
Any hints ?
Thanks
22 Replies
- Kevin_Stewart
Employee
For MS i still get a logon prompt
Can you clarify? Is this for an IIS-based application?
- MS
Nimbostratus
this is sharepoint that always throws the prompt
- Kevin_Stewart
Employee
At this point, looking at it with WireShark, you should probably see an HTTP request going to SharePoint from APM with a Kerberos ticket in it (an Authorization header). If so, that would indicate that SharePoint is rejecting the ticket.
- Kevin_Stewart
Employee
At this point, looking at it with WireShark, you should probably see an HTTP request going to SharePoint from APM with a Kerberos ticket in it (an Authorization header). If so, that would indicate that SharePoint is rejecting the ticket.
- MS
Nimbostratus
here is the debug for the GSSAPI
adding item to WorkQueue
sid: ctx:0x8d1b978 server address = ::ffff:10.10.10.10
sid: ctx:0x8d1b978 SPN = HTTP/portal.abc.com@ABC:COM
Kerberos: realm for user someone is not set, using server's realm ABC.COM
S4U ======> ctx: , sid: 0x8d1b978, user: someone@ABC.COM, SPN: HTTP/portal.abc.com@ABC:COM
metadata len 409
Could not find SSO domain, check variable assign agent setting
Websso Kerberos authentication for user 'someone' using config '/Common/kerberos:sso_401'
adding item to WorkQueue
- Kevin_Stewart
Employee
Did you set Authorization back to Always?
- MS
Nimbostratus
Yes That is with the Authorization to always
- MS
Nimbostratus
when authorization turned to 401 there is nothing in the debug and the same for the MS-SPS. That makes it difficult
- Kevin_Stewart
Employee
The debug you're showing is actually normal. You said earlier that you were getting S4U -> OK in the log. If that's still true, can you determine if an HTTP request is being sent to SharePoint with an Authorization header?
- MS
Nimbostratus
Just rebuilt the SSO and SPS works Thanks for your constant inputs
- Kevin_Stewart
Employee
Did you use the same settings as before, with the SPN-formatted username? If so, that should have had the same effect as doing this in the shell:
bigstart restart webssoAdmittedly I forgot to mention that command.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
