Server: Fully-patched 2008 R2, running Certificate Services. The /certsrv virtual directory is using (I believe) default settings. Specifically, this means it's using Windows Authentication, with NTLM ...
RIght now we do kerberos authentication against AD on our Linux boxes, and then create local accounts without passwords on the servers. We have some scripts but this is annoying to maintain. It works ...