Forum Discussion
Non local kerberos realm
Let's step back a bit. We know that if you very simply do a variable assignment in the visual policy with the correctly formatted names then it works. So the goal should be to take whatever subject value is coming from the SAML assertion and assign that, formatted as required, into the session variables needed for Kerberos SSO. If you're using sAMAccountName and correct domain in the working policy, then that's what you need to convert the SAML subject to. If you can derive any of that information directly from the SAML assertion, great. Otherwise you may need to do a quick AD or LDAP query to get the sAMAccountName of the user.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com