1. Kerberos Locality via DNS: Unlike legacy LDAP where client configs hardcode server IP addresses, Kerberos authentication is dynamically discovered. When a Linux client attempts to obtain a Ticket Granting Ticket (TGT) for a cross-realm user, the Kerberos library queries DNS for specific SRV records to locate the Key Distribution Center (KDC). 2. The Missing Service Records: If the Windows AD DNS zone or the FreeIPA BIND9 zone fails to publish authoritative SRV records (``_kerberos._udp``, ``_kerberos._tcp``, ``_kpasswd._udp``, and ``_ldap._tcp.dc._msdcs``), domain controllers cannot discover each other during trust establishment. 3. Kerberos Realm Referral Failures: Without explicit realm referrals configured in SSSD and Kerberos (``/etc/krb5.conf``), Linux clients query their local KDC for external AD realms. The local KDC has no routing path to issue referral tickets, and cross-realm authentication fails completely.