Forum Discussion
dp_119903
Cirrostratus
Sep 15, 2015Non local kerberos realm
I have kerberos for server-side (SSO) working just fine.
My kerberos sso config looks like this:
username source: session.sso.token.last.username
username realm source: session.logon.last.domain...
Kevin_Stewart
Employee
Sep 22, 2015I am being told that it is a two way non-transitive trust with domain wide auth.
I was afraid of that. The base requirement for APM Kerberos SSO is a forest or two-way transitive trust. A selective trust can also work, but requires more configuration in the domain. APM Kerberos SSO performs Kerberos Constrained Delegation and Kerberos Protocol Transition. The latter is what requires the trust.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects