Hello, I created a cross-realm between a Kerberos MIT and a AD 2008 R2. That works. I can authenticate a MIT user from a windows workstation. I configured a samba workstation and add it into my Windows domain. I can authenticate a user form my AD but not from MIT Kerberos. How can I do that ? Is it possible ? Thanks