Forum Discussion
Kerberos SSO resource and account not in the same domain
- Nov 04, 2017
Changed -> Dns_lookup_kdc = true Analaysing packet capture answer was found.
USERDOMAIN.INTERNAL was child domain of INTERNAL and INTERNAL KCD was not allowed on firewall. after allowing INTERNAL KCD, stuff started to work.
Hi jban,
When using the classic Kerberos Constrained Delegation mode (>=Win2003) you have to create the service account which performs the Kerberos Constrained Delegation in the same AD domain as the service account of the ressource service. But the user could be stored in any trusted domain.
When using the Resource-based Kerberos Constrained Delegation mode (>=Win2012) the service account which performs the Kerberos Constrained Delegation, the service account of the ressource service and the user account can be all stored in different domains.
https://blog.kloud.com.au/2013/07/11/kerberos-constrained-delegation/
Cheers, Kai
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
