Forum Discussion
East_Coast_1151
Nimbostratus
Mar 18, 2013Kerberos SSO with two realms
I am working on a solution depicted in the attached file.
Clients are expected to authenticate with a Form-Based front-end provided by F5 APM and using a back-end Active Directory forest ...
Kevin_Stewart
Employee
Mar 22, 2013East Coast, you may already know this, but for the larger audience, your suspicions were correct. Kerberos S4U does in fact require a two-way trust between domains/forests.
http://support.microsoft.com/?kbid=954739
http://msdn.microsoft.com/en-us/magazine/cc188757.aspx
Thanks to some internal F5 folks for finding these articles. I wasn't sure either.
That said, I see a potential alternative. Given that you're authenticating the user via form logon, you have the credentials (and I assume the domain) to perform an HTTP Basic or NTLM authentication to the web server.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects