Forum Discussion
Multiple Windows Authentication Prompts after F5 Authentication
APM Kerberos SSO will only intercept the 401 if you have the Send Authorization setting in the Kerberos SSO profile set to "On 401 Status Code". The "Always" option will send a preemptive Kerberos ticket. In either case, SSO must know how to retrieve a ticket to a give service, which is where I believe the problem lies. Before digging into the ugly details, let's establish that a service must be associated with a declared by a unique** service principal name (SPN), that SSO must be able to derive/find this SPN, and that the AD delegation account be able to delegate to that SPN. So in your SSO,
- Do you have a SPN pattern defined?
- Does the target service have a defined and unique SPN?
- Does the hostname in that SPN reverse resolve in AD DNS?
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com