http://eweiibe6tdjsdprb4px6rqrzzcsi22m4koia44kc5pcjr7nec2rlxyad.onion/help/integration/kerberos.md
For instance, if the Kerberos realm is AD.EXAMPLE.COM , then the LDAP
user's Distinguished Name should end in dc=ad,dc=example,dc=
com .
Taken together, these rules mean that linking only works if your users'
Kerberos usernames are of the form
[email protected] and their
LDAP Distinguished Names look like sAMAccountName=foo,dc=ad,dc=example,dc=
com .