Forum Discussion
Non local kerberos realm
For SSO you don't specifically need to modify the /etc/krb5.conf, except for setting dns_lookup_kdc to true. The most important thing is that APM can resolve the KDCs of all of the domains.
With the proper trusts in place, if from the command line you can nslookup/dig the the domain names and return the KDCs, then:
a. Set APM SSO logging to debug and reply back here with that log
b. Capture the Kerberos traffic between APM and the KDC, either directly with Wireshark on the KDC or with tcpdump and import into Wireshark.
tcpdump -lnni 0.0 -Xs0 -w [write to file] port 88 [and any other filters]
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com