Forum Discussion
dp_119903
Cirrostratus
Sep 15, 2015Non local kerberos realm
I have kerberos for server-side (SSO) working just fine.
My kerberos sso config looks like this:
username source: session.sso.token.last.username
username realm source: session.logon.last.domain...
Kevin_Stewart
Employee
Sep 16, 2015You should also be specifying the user's real domain in the session.logon.last.domain variable. APM Kerberos SSO won't chase Kerberos referrals so you have to tell it which domain the user belongs to. Try the short name (bob) and the real domain as SSO inputs.
Also if the UPN you're trying is using a domain alias (ie. doesn't exactly match the real domain name), then you MUST use the sAMAccountName (short) name.
Is this a FULL transitive trust, forest trust, or selective trust?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects