Skip to content
Go back

NetScaler KCD Configuration Guide (Kerberos SSO Step by Step)

3 min read5 topics
Edit page

I use this flow in real customer environments when NetScaler sits in front of web apps or API gateways and we want clean Kerberos SSO to the backend.

This is the practical version, in simple language.

Quick architecture in one minute

For KCD to work, you need to separate two identities in Active Directory:

  1. Delegator (svc_netscaler)
    • The account NetScaler uses to talk to AD and request Kerberos tickets on behalf of users.
  2. Delegatee (svc_backend or server computer account)
    • The identity running the backend service.
    • This is the target service that receives delegated credentials.

If this separation is wrong, SSO usually fails.

Phase 1: Active Directory side

Step 1: Configure backend identity (target service)

First, register the SPN for the backend service.

  1. Identify backend FQDN (example: webapp.example.com).
  2. Identify account running the service:
    • Service account user (svc_backend) or
    • Computer account (TargetServerName$) if service runs as Local System/Network Service.
  3. Register SPN on the correct account:
# Service account
setspn -S HTTP/webapp.example.com svc_backend

# Computer account
setspn -S HTTP/webapp.example.com TargetServerName$
  1. Verify there is only one mapping:
setspn -Q HTTP/webapp.example.com

You should get one result only.

Step 2: Configure NetScaler identity (delegator)

Now allow svc_netscaler to delegate to that backend service.

  1. Open Active Directory Users and Computers.
  2. Open properties of svc_netscaler.
  3. Go to Delegation tab.
  4. Choose:
    • Trust this user for delegation to specified services only
    • Use any authentication protocol (important for protocol transition)
  5. Click Add → find backend account from Step 1.
  6. Select the matching HTTP service entry.
  7. Save.

If the Delegation tab does not appear, add a temporary SPN to svc_netscaler to expose the tab, then continue.

Phase 2: NetScaler side

Step 3: Create KCD Account

Go to: Security → AAA - Application Traffic → KCD Accounts

Create:

Step 4: Create Traffic Profile

Go to: System → Profiles → Traffic Profiles

Create:

Step 5: Create Traffic Policy

Go to: System → Profiles → Traffic Policies

Create:

Step 6: Bind policy to the LB vServer

  1. Open target Load Balancing vServer.
  2. Under Policies, add a Traffic policy.
  3. Bind pol_kcd_sso.
  4. Save.

Pre-flight checklist (don’t skip)

Before testing, validate these three items:

Troubleshooting

When SSO fails, start with NetScaler Kerberos debug:

cat /tmp/nskrb.debug

Common errors:

Final note

KCD is very reliable when identity mapping is clean:

When those three line up, Kerberos SSO usually works smoothly.

Post Actions

Continue exploring, share this post, or jump back to key sections.

Edit page