Appliance Configuration
The RapidIdentity Appliance must be able to resolve your domain through DNS. Ideally, your appliance will be configured to use your domain controllers for DNS. Alternatively, you can configure your hosts file to point to your domain, however, your appliance will be limited to using only one domain controller for Kerberos Authentication.
In RapidIdentity Appliance Configuration (idauto-apps), navigate to Core Configuration > Authentication > Kerberos Configuration and configure the following parameters with your values.
Domain: test.local
KDC Address: test.local
Service Principal: HTTP/my.example.com@test.local
Service Principal Password: Configured earlier in step 1 of Active Directory Configuration
In RapidIdentity Appliance Configuration (idauto-apps), navigate to Core Configuration > Authentication and create an authentication policy for Kerberos Authentication
Criteria > Kerberos > Enabled: Checked
Authentication Methods > Kerberos > Required: Checked
Note
Additional authentication methods can be enabled (such as TOTP) to provide additional authentication.