Forum Discussion
Kerberos SSO across External trust
That's an interesting read, but it doesn't once mention Protocol Transition (S4U2Self), which is what I believe is the limiting factor here. I applied the recommended settings and got the same errors. Moreover, here's something from Microsoft:
http://technet.microsoft.com/en-us/library/cc772683%28v=ws.10%29.aspx
When you use protocol transition across Active Directory forests, both forests must be operating at the Windows Server 2003 forest functional level and two-way forest trust must be established between the forests
That seems to imply that a forest trust is indeed required. I'm still testing this, but all roads seem to be leading to the same conclusion.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com