Loading...
Loading...
When you configure single sign-on (SSO) using Kerberos, and you do not fill in the KDC field on the configuration page (Access Policy > SSO Configurations > Kerberos) , you may encounter an error. The error may be similar to: <Date> slot2/BIGIP1 err websso.0[29236]: 014d0005:3: Kerberos: can't get TGT for host/svcf5kerberos.corpdev.apdev.local@CORPDEV.APDEV.LOCAL - Cannot contact any KDC for realm 'CORPDEV.APDEV.LOCAL' (-1765328228)
SSO fails
This occurs if you do not specify a value for KDC when configuring SSO with Kerberos.
Has a workaround, administrator should edit /etc/krb5.conf file manually and set option dns_lookup_kdc=true Note that this workaround is: not synced across cluster not backed up not audited not upgrade safe not re-provision safe may revert during other maintenance operations
None
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.