Forum Discussion
Doug_Pruiett_24
Nimbostratus
Feb 08, 2016Multiple Windows Authentication Prompts after F5 Authentication
I am not the principle engineer on this issue, nor an F5 expert. I am part of a project that uses F5 and doing a little research to see if I can find help for an issue we are having.
The desire...
Kevin_Stewart
Employee
Feb 09, 2016The AD delegation account (host/kerberos_user) must have the SPN of each and every account that it is allowed to delegate to. You've indicated that the pool members' individual SPNs are assigned, but if you're attempting to request a ticket for http/ssrs.example.com, then that SPN also needs to be in the delegation list. But more important, if Kerberos SSO works when specifying the server SPN (server1.example.com), that's a good indication that the ssrs account is indeed not the owner of the service.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects