Bug ID 818673: F5 APM modules added capability to pull user group membership information from Kerberos authentication tickets

Last Modified: Apr 28, 2025

Affected Product(s):
BIG-IP APM(all modules)

Fixed In:
16.1.0

Opened: Aug 28, 2019

Severity: 3-Major

Symptoms

F5 APM Kerberos Auth agent is unable to extract the user group membership info from the Kerberos authentication ticket.

Impact

APM is unable to extract user group membership info directly from Kerberos tickets.

Conditions

This is encountered while using the Kerberos Auth agent

Workaround

Use Active Directory query module to query on user group membership info from backend AD server during every request. Impact of workaround: this has a negative performance impact

Fix Information

F5 APM modules added capability in Kerberos Authentication module to pull user group membership IDs from Kerberos authentication tickets, and added new AD Group SID Resolver module to resolve group IDs to memorable group names using group cache.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips