Bug ID 1644457: Kerberos SSO across domains fails for child domain users

Last Modified: Apr 04, 2025

Affected Product(s):
BIG-IP APM(all modules)

Fixed In:
17.5.0

Opened: Sep 10, 2024

Severity: 3-Major

Symptoms

Kerberos usage with multiple domains fails for child domain users. Although a transitive trust is established between user forest and service AD, the child domain user is not able to access the services from service AD after upgrading the krb5 library from 1.14 to 1.18.2.

Impact

Child domain users are not able to access the services from service AD.

Conditions

In a cross-domain Kerberos SSO scenario, child domain users access the services from service AD.

Workaround

Need to create external trust between service AD and the child domain machine.

Fix Information

Upgrade krb5 library to krb5-1.19.1 version.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips