Forum Discussion
East_Coast_1151
Nimbostratus
Mar 19, 2013Kerberos SSO with two realms
I am working on a solution depicted in the attached file.
Clients are expected to authenticate with a Form-Based front-end provided by F5 APM and using a back-end Active Directory forest ...
Lloyd_56248
Mar 19, 2013Historic F5 Account
Hi, in my experience DNS has to be rock solid for Kerberos Constrained Delegation to work. I would have Kerberos working for one domain, then introduce the second. You might want to add a final SSO Credential Mapping to the policy also.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects