Forum Discussion
Steve_Janetzke_
Nimbostratus
We were able to figure it out. We had to add the "host/apmkerb.svc" as an SPN for apmkerb.svc even though it got a TGT for host/apmkerb.svc@TEST.DOMAIN.COM when it tried to fetch the S4U ticket it first sent a TGS to the domain with that Sname. A packet capture on the DC revealed it and it is now fetching the S4U ticket correctly.
RecontuerSG_258
Dec 19, 2016Historic F5 Account
Thank you for responding, Kees. Is the Kerberos database same as Active Directory database? Is a keytab file required? The Kerberos-F5 guide I am reading did not mention about keytab file and I am using 12.1.1 version of LTM. "davis" is part of Active Directory..