I am trying to build a 3 node HA/DR setup with 2 nodes behind an F5 at our main colo and then the 3rd at our DR site...having issues with the SSO for the selfservice...before I put it behind the F5 I am having issues with node 2 working with the shared FQDN...Ideally I would like something like password.domain.local to point to the VIP and then if something should happen, have a short TTL and execute a DNS change to our DR site (till we get F5 GTMs)


oh and if I goto the server by shortname, SSO works...both boxes are trusted for delegation and SPNs are identical excluding ports...

the methods I am testing with is adjusting with HOSTS and the A record, verifying its flushed and TTL has WELL expired


Adaxes uses the Kerberos authentication mechanism for SSO. Take a look at the following article that describes how to set up Kerberos delegation with F5: http://support.f5.com/kb/en-us/products ... ation.html. Make sure that you've completed all the steps listed in the article to enable Kerberos authentication in your F5 farm.

Also, if you performed all the steps as described in the article, but still cannot get SSO working, the reason can be that the Kerberos ticket cache on your computer is full. Try purging the Kerberos ticket cache on the computer, from which you are trying to view the Web Interface. For this purpose, do the following:

  1. On the computer, from which you are trying to access Adaxes Web Interface, start Windows Command Prompt (cmd.exe).
  2. In the Command Prompt console, type:
    klist purge
  3. Press Enter.
  4. Answer Yes (Y) to all confirmations.

