When trying to do SSO through QSJ using Safari browser, it fails with error 401
1. Enable forwardable tickets in Kerberos configuration (default Kerberos configuration of Mac doesn't do this)
Add the following flag in /Library/Preferences/edu.mit.Kerberos:
forwadable=true
2. Mac client is not configured for cross-realm authentication by default so you will need to add the appropriate [realms] and [capaths] for the cross realm domains in:
/Library/Preferences/edu.mit.Kerberos
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Termini di utilizzo Privacy Cookie Preference Center