Kerberos Constrained Delegation
Hello,
I have a request from customer to set up SSO via SAML + Kerberos Constrained Delegation. SAML is working but I have problem with the kerberos delegation. The backend server is IIS on Windows 2016 server.
I set everything I found in the admin guide for Fortiweb - KDC server, the SPN's, the account and delegation, application pool in IIS and changed on IIS the useAppPoolCredentials to True + use the service account.
However it seems to me that the fortiweb does not communicate with the KDC. There is no packet sent to KDC to obtain a kerberos ticket on behalf of the user.
Does anyone have an idea where the problem should be? Or maybe a bug?
Fortiweb VM is used with firmware version: FortiWeb-VM 6.01,build0036,180822
