The KCD seems to be configured properly, the ASA is added to the 2008 Windows AD, but the sso process is failing. A Wireshark capture generates a Kerberos error KRB5KDC_ERR_BADOPTION NT Status: STATUS_NOT_SUPPORTED. I have already disable pre-authentication for the Windows user account I am using as a test. I have also updated the ASA object in AD for Delegation to Trust the specific SPN I am trying to reach. Any thought on where to look next to try to get this working?