Forum Discussion
John_K_01_16461
Nimbostratus
Sep 23, 2016Kerberos multi-hop supported in APM
We currently have a virtual server set up with APM and we are using it to extract UPN from client certificate and pass along a Kerberos ticket to the back-end server for authentication. This part is...
Kevin_Stewart
Employee
Sep 23, 2016The trick for multi-hop constrained delegation (what APM does) is to enable constrained delegation at every hop. So in your case you have an account in AD that is allowed (and constrained) to delegate to a specific service (presumably a web server). The account that owns that service must then be given (constrained) delegation rights to the downstream service.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects