Hello Expert
We want to enable SSO with Kerberos in our AD domain
I already made some test and they work fine, but, I have this questions:
1.- should all user have the canonical name mapped? Because if the server has the snc setting users without canonical name mapped cannot logon to the SAP server

2.- Can I logon in another client (such as 000) if the server has the SNC Settings enable?
3.- what happen with the default users, such as sap* or DDIC?
I am using just the snc settings with AD
The PC users has the SAPSSO.msi installed

Thank you in advance
Romel D.