Forum Discussion
Kerberos SSO without APM
If you want Client request Kerberos ticket for the server SPN, you must configure reverse DNS name of VIP with SPN known by application server.
I configured for one customer APM Kerberos Constraint Delegation for Exchange Servers load balanced by LTM in a dedicated appliance
I had following flow: APM --> LTM --> Exchange
Kerberos ticket needed to be created for LTM VIP and known by Exchange
The LTM VIP was define with PTR exch.company.local in DNS IIS Exchange services were started as user with SPN HOST/exch.company.local
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com