AFP/Kerberos connection generates Error 32
I've configured an OD master for managing groups and computers and have also bound this computer to Active Directory for User accounts. All the directory service pieces seem to work (can look up and login using accounts in both OD and AD). When users try to connect to the server via AFP, after a longer then normal wait, an Error 32 is generated. I know this has to do with kerberos because if I change the authentication method in Server Admin to just standard rather then Any or Kerberos, the user is presented with a normal login window that works. Users are logged into the computer using AD accounts, I verified that they have a valid ticket and that time is synced appropriately. Additionally, sso for windows users works correctly (e.g. they can connect to the server and aren't prompted to authenticate). Does anybody know how to fix this?