Forum Discussion

tiwang_122270's avatar
tiwang_122270
Icon for Nimbostratus rankNimbostratus
Dec 18, 2013

Problems with Kerberos and delegation account

Hi out there I need to define a Kerberos AAA service against a MS Win2k8 AD for certificate authentication from external clients - I got stuck at a very basic level - in the F5 documentation it is written:

 

Open the Active Directory Users and Computers administrative tool and create a new user account. The account name must be in this format, host/name.domain, where host is a literal string, name is any arbitrary name, and domain is the DNS FQDN for that realm. Here is an example, host/apm.example.com.

 

ehh - my domain is testdomain.dk - my DC & CA's hostname is Win2k8DC - my webservers hostname is win2k8web1 - the F5 is bigip1 - what do I need to enter as username in the ActiveDirectory ? win2k8web/apm.testdomain.dk or what?

 

best regards /ti

 

22 Replies