Forum Discussion

senthil147_1421's avatar
senthil147_1421
Icon for Nimbostratus rankNimbostratus
Feb 21, 2018

APM - Kerberos SSO Not working

Hi team,

 

I have configured kerberos SSO for accessing citrix forefront server's . After authentication in F5 getting following error.

 

Followed the config steps as per page : https://www.f5.com/pdf/deployment-guides/kerberos-constrained-delegation-dg.pdf

 

err websso.0[20378]: 014d0056:3: /Common/citrix_kerberos_sso:Common:7db4d953:Kerberos: can't get S4U2Self ticket for user bravo@ABC.COM- Server not found in Kerberos database (-1765328377) err websso.0[20378]: 014d0024:3: /Common/citrix_kerberos_sso:Common:7db4d953: Kerberos: Failed to get ticket for User: 'bravo@ABC.COM' accessing service: 'HTTP/server.abc.com@ABC.COM' err websso.0[20378]: 014d0048:3: /Common/citrix_kerberos_sso:Common:7db4d953: failure occurred when processing the work item

 

APM Policy - Logon page -- AD authentication -- SSO mapping -- Allow

 

Please help me..

 

Thanks, Senthil

 

1 Reply

  • Do you have DNS configured in you big-ip? A simple test is trying to ping abc.com.Check as well in your /etc/krb5.conf if dns_lookup_realm = true and dns_lookup_kdc = true