We have configured SPNEGO for Fiori and found that Kerberos SSO works fine when we assign not host name but FQDN or FQDN＋Port as well to service account for HTTP SPN.
What information does Fiori actually sends to AD in order to issue Kerberos Token? Does anyone know why?
Also, we have found that we have to assign via points SPN e.g. load balancer. Could you please tell me why via points SPN is also required?