Forum Discussion
Kerberos SSO across External trust
That's an interesting read, but it doesn't once mention Protocol Transition (S4U2Self), which is what I believe is the limiting factor here. I applied the recommended settings and got the same errors. Moreover, here's something from Microsoft:
http://technet.microsoft.com/en-us/library/cc772683%28v=ws.10%29.aspx
When you use protocol transition across Active Directory forests, both forests must be operating at the Windows Server 2003 forest functional level and two-way forest trust must be established between the forests
That seems to imply that a forest trust is indeed required. I'm still testing this, but all roads seem to be leading to the same conclusion.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com