I am working with a Kerberized HDP 2.3 cluster that uses AD with Kerberos for strong authentication via Knox. Does the end user need to have a local Kerberos client installed on their Windows workstations to request the ticket? Or is it possible to enable SSO such that Kerberos ticket is issues as part of Windows domain login?