Forum Discussion
Multiple Windows Authentication Prompts after F5 Authentication
I assume that the SSO profile is going to create the ticket then for ssrs.example.com, right (http/ssrs.example.com SPN)?
It should, yes.
Is there a way to get APM to use the pool member instead of the VIP's hostname for the service son?
That's actually how it's designed to work. In the absence of an SPN Pattern in the Kerberos SSO profile, APM will reverse resolve the pool member IP and derive the SPN from the returned host name. If there is no reverse record for a given IP, you can also wire up each pool member IP to a local Hosts entry on the BIG-IP and use the %s wildcard in the SPN pattern:
http/%s
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com