Forum Discussion
Multi-Domain - Multi-SSO
A few things to consider:
- You'd use the WEBSSO::select command to switch between SSO profiles:
https://devcentral.f5.com/wiki/iRules.WEBSSO__select.ashx
-
Which SSO profile you use depends on how you derive user membership. It could be as simple as a drop down box in the logon page, or gleaned from a client side Kerberos token.
-
Assuming you mean Kerberos SSO (from previous posts), you're no doubt aware that there's an issue with using multiple Kerberos SSO profiles in 11.3 and 11.4. There is an open case for this, and 11.2 does work.
-
Per Kerberos Protocol Transition and Constrained Delegation protocol requirements (not an APM limitation), a full two-way trust is required for KPT to work across domains. You're attempting to switch SSO profiles based on user membership, so that shouldn't be an issue, but an important consideration nonetheless.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com