I use this flow in real customer environments when NetScaler sits in front of web apps or API gateways and we want clean Kerberos SSO to the backend.
This is the practical version, in simple language.
Quick architecture in one minute
For KCD to work, you need to separate two identities in Active Directory:
- Delegator (
svc_netscaler)- The account NetScaler uses to talk to AD and request Kerberos tickets on behalf of users.
- Delegatee (
svc_backendor server computer account)- The identity running the backend service.
- This is the target service that receives delegated credentials.
If this separation is wrong, SSO usually fails.
Phase 1: Active Directory side
Step 1: Configure backend identity (target service)
First, register the SPN for the backend service.
- Identify backend FQDN (example:
webapp.example.com). - Identify account running the service:
- Service account user (
svc_backend) or - Computer account (
TargetServerName$) if service runs as Local System/Network Service.
- Service account user (
- Register SPN on the correct account:
# Service account
setspn -S HTTP/webapp.example.com svc_backend
# Computer account
setspn -S HTTP/webapp.example.com TargetServerName$
- Verify there is only one mapping:
setspn -Q HTTP/webapp.example.com
You should get one result only.
Step 2: Configure NetScaler identity (delegator)
Now allow svc_netscaler to delegate to that backend service.
- Open Active Directory Users and Computers.
- Open properties of
svc_netscaler. - Go to Delegation tab.
- Choose:
- Trust this user for delegation to specified services only
- Use any authentication protocol (important for protocol transition)
- Click Add → find backend account from Step 1.
- Select the matching HTTP service entry.
- Save.
If the Delegation tab does not appear, add a temporary SPN to
svc_netscalerto expose the tab, then continue.
Phase 2: NetScaler side
Step 3: Create KCD Account
Go to: Security → AAA - Application Traffic → KCD Accounts
Create:
- Name:
kcd_webapp_profile - Realm:
EXAMPLE.COM(uppercase) - Delegated User:
svc_netscaler - Password: password of
svc_netscaler - Enterprise Realm/User: leave blank in normal setups
Step 4: Create Traffic Profile
Go to: System → Profiles → Traffic Profiles
Create:
- Name:
prof_kcd_sso - SSO: ON
- S4U2Proxy: ON
- KCD Account:
kcd_webapp_profile
Step 5: Create Traffic Policy
Go to: System → Profiles → Traffic Policies
Create:
- Name:
pol_kcd_sso - Profile:
prof_kcd_sso - Expression:
TRUE(apply to all traffic), orHTTP.REQ.HOSTNAME.EQ("webapp.example.com")(host-specific)
Step 6: Bind policy to the LB vServer
- Open target Load Balancing vServer.
- Under Policies, add a Traffic policy.
- Bind
pol_kcd_sso. - Save.
Pre-flight checklist (don’t skip)
Before testing, validate these three items:
- Time sync (NTP)
- NetScaler, DC, and backend must be synchronized.
- Kerberos usually fails with time skew > 5 minutes.
- DNS resolution
- NetScaler must resolve backend FQDN correctly.
- SPN ownership
HTTP/webapp.example.commust be on backend identity only.- Do not register it on
svc_netscaler.
Troubleshooting
When SSO fails, start with NetScaler Kerberos debug:
cat /tmp/nskrb.debug
Common errors:
PRINCIPAL_UNKNOWN(-1765328371)- SPN missing, duplicated, or registered on wrong account.
PREAUTH_FAILED(-1765328360)- Wrong password configured for
svc_netscalerin KCD profile.
- Wrong password configured for
Final note
KCD is very reliable when identity mapping is clean:
- right SPN on the right account,
- right delegation permissions,
- right profile/policy binding on NetScaler.
When those three line up, Kerberos SSO usually works smoothly.