I have a LF 11 installation with the main repository and web client server hosted on a local domain-joined server (LF-Main). We use Windows Authentication to let our users browse the repositories without having to provide domain credentials.
We worked with our vendor to tweak the installation to support multiple Web Client servers (also within our local domain network) to let users login with Windows Authentication (LF-web1 and LF-web2); through a combination of a lot of SPI record work to have the remote web app pools run as a domain account.
We found that this setup worked great for the web client users authenticating to the LF-web1 and LF-web2 servers, but it made auto authentication very unreliable for users hitting LF-Main. Most users had a 50/50 chance of being prompted for credentials, and after selecting "Windows Authentication", would have to hit the sign-on button 10-15 times before it finally let them in.
We've reverted to just having users authenticate to the original LF-Main server, and now the external servers won't use Windows Authentication anymore. Is there a scenario where Windows authentication works seamlessly (without involving an LFDS server)?