Forum Discussion
mixing SSO methods, i.e. ntlm, basic http and kerberos
im not quite getting there:
Websso Kerberos authentication for user 'user' using config '/DMZ/sso-kerberos'
adding item to WorkQueue
sid: ctx:0x92384d8 server address = ::ffff:192.168.8.21
sid: ctx:0x92384d8 SPN = HTTP/ext-hostname.domain.uk@DOMAIN.UK
S4U ======> ctx: , sid: 0x92384d8, user: user@DOMAIN.UK, SPN: HTTP/ext-hostname.domain.uk@DOMAIN.UK
Kerberos: Failed to get ticket for user user@DOMAIN.UK
failure occurred when processing the work item
as im not quite sure were to check id like to double check some things:
on the SSO profile should be user be in the format host\delegation_user.domain ? or just delegation_user
should on AD side be HTTP/ext-hostname.domain.uk@DOMAIN.UK allowed as service? or is HTTP/ext-hostname enough?
although the SPN appears to be HTTP/ext-hostname.domain.uk@DOMAIN.UK the actual website is hostname.domain.uk, is that an issue?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com