Forum Discussion

Sheetal_43349's avatar
Sheetal_43349
Icon for Nimbostratus rankNimbostratus
Jan 12, 2018

kerberos SSO not working on non company laptops

Hello,

 

I have configured a service with APM ( 2 factor authnetication) and seems to be working fine till we don't enable SSO. User enables Kerberose based authentication and wants me to have sso, so that when the client authneticate to APM, that username and password should be passed on to the AD to get Kerberose ticket.

 

WE are not able to get the kerberose tickets when we use a personal laptop.

 

Please advise if this is possible.

 

The relevant logs are

 

Kerberos: realm for user is not set, using server's realm xxx.com S4U ======> /Extranet/ap_vwikidev.statoil.no_Nov_1:Extranet:4e278373: ctx: 0x850a2c8, user: xxx@xxx.com, SPN: XXX

 

 

I have followed the steps mentioned in https://devcentral.f5.com/articles/apm-cookbook-single-sign-on-sso-using-kerberos

 

Please advise Regards Sheetal

 

1 Reply

  • Hi,

     

    I guess the issue is for all users, not only non company laptops.

     

    When working with kerberos SSO, kerberos authentication request never sent on the client side.

     

    What application are you configuring?

     

    Is the IIS application configured with a dedicated user account?

     

    If yes, Is this account configured with a Service Principal Name?

     

    If yes, Does the Application configured with parameter useAppPoolCredenVals true?