KRB Error: KRB5KDC_ERR_BADOPTION error occurs when the BIG-IP APM system is unable to obtain a Kerberos service ticket on behalf of the user and Kerberos SSO fails for the user.
When these messages occur, consider the following:
-In the Active Directory delegation account (Account Properties > Delegation), add the requested service to the Services to which this account can present delegated credentials box.
-When using a non-Windows Kerberos KDC environment, ensure that the KDC can support the same options as Active Directory.
The below thread discusses the same issue and you can get some insights from this.
Kerberos error when using a DNS name that doesn't match the Active Directory domain name https://social.technet.microsoft.com/Forums/windowsserver/en-US/736b4f5e-536f-455d-bf73-3c4d147de4b6/kerberos-error-when-using-a-dns-name-that-doesnt-match-the-active-directory-domain-name?forum=winservergen
--If the reply is helpful, please Upvote and Accept it as an answer–