Active Directory and Kerberos
You can configure PingFederate to authenticate users through the following identity provider (IdP) adapters or token processors.
Adapter or Token Processor | Description |
---|---|
PingFederate integrated Kerberos Adapter |
Using the built-in Kerberos Adapter with a configured AD domain allows a PingFederate identity provider (IdP) server to perform single sign-on (SSO) to service provider (SP) applications based on Kerberos tickets. |
PingFederate integrated Kerberos Token Processor |
The built-in Kerberos Token Processor accepts and validates Kerberos tokens through a configured Kerberos Realm from a web service client. |
As of version 10.3 and above, PingFederate no longer supports the IWA integration kit. For more information about Migrating from the IWA Integration Kit to the PingFederate Kerberos adapter, see Migrating from the Integrated Windows Authentication Integration Kit to the PingFederate Kerberos adapter in the Ping Identity Support Portal. |