Forum Discussion
Per-App-VPN using Kerberos Constrained Delegation and Protocol Transition...HELP!
The APM SSO process is going to end with the production of a Kerberos service ticket (AP_REQ) embedded in an HTTP request Authorization header, and that header is going to come from the device that performs the rest of the Kerberos negotiation. It's not impossible to do of course, but an SSL VPN generally doesn't perform SSO functions. The initiation of the VPN is the end state. What you'd need to do is to transmit the user's information to a separate access policy, potentially even the internal device, and then let it do the Kerberos SSO.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com