SteelHeadā„¢ Deployment Guide - Protocols : RiOS Version Compatibility with Domains and Domain Relationships : Legacy Delegate User Configurations
  
Legacy Delegate User Configurations
In versions of RiOS prior to 8.5, certain corner cases required the use of Kerberos Constrained Delegation. This legacy method of authenticating to Active Directory was needed prior to the development of Riverbed Active Directory integrated mode. Active Directory integrated mode enables the server-side SteelHead to use Microsoft pass-through authentication capability transparently without the overhead and administration of Kerberos Constrained Delegation.
Riverbed recommends that you migrate from legacy Kerberos Constrained Delegation when upgrading to RiOS v8.5 and later.
Some very select corner cases, might still require legacy Kerberos Constrained Delegation. These include older versions of RiOS and older versions of Windows server and clients. Riverbed understands that certain applications cannot easily be upgraded or migrated to newer versions of RiOS. For more information about Delegation mode, see Choosing an Authentication Mode for the Server-Side SteelHead.