Bug ID 977169: AD Auth agent sends duplicate Kerberos AS-REQ when Cross Domain Support and Split Domain are enabled

Last Modified: Aug 27, 2026

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 14.1.4.1, 14.1.4.2, 14.1.4.3, 14.1.4.4, 14.1.4.5, 14.1.4.6, 14.1.5, 14.1.5.1, 14.1.5.2, 14.1.5.3, 14.1.5.4, 14.1.5.6, 17.5.1.8

Opened: Dec 29, 2020

Severity: 3-Major

Symptoms

When AD Auth has "Cross Domain Support" enabled and the Logon Page has "Split domain from full Username" enabled, each authentication attempt sends two AS-REQ messages to the KDC instead of one. This causes the KDC's failed-login counter to increment twice per attempt, potentially locking out user accounts before the configured AD account lockout threshold is reached.

Impact

Users may be locked out of Active Directory after fewer failed attempts than expected. The "Max Logon Attempts Allowed" setting on the BIG-IP effectively consumes double the KDC lockout budget.

Conditions

AD Auth agent with Cross Domain Support enabled; Logon Page with "Split domain from full Username" enabled; user logs in with domain\username format where domain matches the configured AD domain.

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips