I try to implement multi domain authentication but I have some issue.
The keytab is generated for each domain. It works for each domain, but when I use the merge keytab, I receive the login screen in place.
I use nam 3.1.5, on which version have you tested this solution?
I have a misuderstanding with following:
Make sure that the Kerberos service user account you have set up does not have “Use DES encryption types for this account” selected. If it is already selected, then you must unchecked it and reset the password. It is not possible for the same SPN/service user account to support both DES and RC4-HMAC security. It must be one or the other.
Note: Implementation procedures on Windows 2008 R2 are basically the same as with other Windows versions. However, since DES cipher by default is disabled in Windows 2008 R2. Enable DES cipher support on Windows 2008 R2. See the following tech note from Microsoft: