Forum Discussion
Kerberos SSO issues
Hello F5 Community
I'm the appointed admin of our new F5 BIG-IP appliances (11.2.1) at our company. I'm trying to get Kerberos SSO to work but some things I just can't get right. I've read a lot of the documentation on the web (F5 official only) about the APM in general, the Kerberos configuration, SSO credential mapping and so on.
I have a configuration in place which looks correct but doesn't work as it should. There are messages in the session log that indicate errors.
Before I get to the problem, a bit of information:
- The SSO shall be used for MS SharePoint 2010 servers (LB of two web frontend servers)
- The configuration for MSSP is done via the F5 iApp
- I've got an AccessPolicy attached to the HTTPS virtual server of the iApp
- I've got a SSO configuration for Kerberos with a delegation account as documented by F5
- I've got a AAA Server (Kerberos) with a keytab file for this service
- My access policy looks like this: http://i.imgur.com/9ISpZ.png
Now, the following entries in the session log bug me:
Kerberos: realm for user 12345@ZHAW.CH is not set, using server's realm ZHAW.CH
Kerberos: Failed to get ticket for user 12345@ZHAW.CH@ZHAW.CH
\N: failure occurred when processing the work item
We do have the following in the logs:
\N: Username used for SSO contains domain information. Please enable 'Split domain from full Username' option in Logon Page if domain info should be separated from username for SSO to work properly
\N: Could not find SSO domain
In our case the "Logon Page" is the HTTP 401 Response part on the AP. And the option to split the domain from the full username is set. It does not make a difference, though. The log says the same with or without the option enabled.
When I try to access the site, the first thing I get is a popup window to enter my credentials (Basic Auth), I hit ESC and try to access the URL again which then works. oO
I'll gladly send/upload the session log to anyone who's willing to help. It would be much aprechiated.
Thanks in advance,
Stefan
6 Replies
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com