ESP configuration - SSO SharePoint
Information
Summary: |
User configured kcd for their sharepoint service |
|||
Environment: |
Product: Loadmaster Version: Any Platform: Any Application: Sharepoint with KCD |
|||
Question/Problem Description: |
From our deployment guide for KCD: Kerberos Constrained Delegation – Kemp Support (kemptechnologies.com)
The most common scenario is a request for a delegated ticket (unconstrained or constrained delegation). You will typically see this on the middle-tier server trying to access a back-end server. There are several reasons for rejection: |
|||
Steps to Reproduce: | ||||
Error Message: |
2023-04-12T14:50:08+07:00 KEMP-PRD ssomgr: SM: #31727# >>> kcd_get_user_ticket
For more info refer to Kerberos errors in network captures - Microsoft Tech Community |
|||
Defect Number: | ||||
Enhancement Number: | ||||
Cause: | ||||
Resolution: |
Kerberos NOT Working: As far as I can see when it comes to the failed login attempts with test account Sebastian the Destination/Target that is used is either:
The KCD fails with the error 1765328371 - KRB5KDC_ERR_BADOPTION`- KDC cannot fulfill requested option The customer should verify the delegation settings and ensure that the SharePoint server has the correct service account set. |
|||
Workaround: | ||||
Notes: |