Forum Discussion
Multiple Windows Authentication Prompts after F5 Authentication
The AD delegation account (host/kerberos_user) must have the SPN of each and every account that it is allowed to delegate to. You've indicated that the pool members' individual SPNs are assigned, but if you're attempting to request a ticket for http/ssrs.example.com, then that SPN also needs to be in the delegation list. But more important, if Kerberos SSO works when specifying the server SPN (server1.example.com), that's a good indication that the ssrs account is indeed not the owner of the service.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
