This disclosure pertains generally to client authentication. One aspect of
the disclosure relates to a first server for presenting evidence to a
Domain Controller (DC) of a first authentication context being submitted
from a client to the first server to obtain a delegable credential,
wherein the credential can be used to request a second authentication
context from that client to a second server. Another aspect relates to
the first server providing a pass-thru with evidence to a DC. The
evidence relates to a first authentication context being submitted from a
client to the first server that it obtained a delegable credential. The
pass-thru is used in combination with the credential to request a second
authentication context from the client to a second server.