Hello Mark,
They are separate forests. The domains have no trust between them at all. We connect to the domain using different service credentials and I tested my account by using it to connect to the domain.
To do this, I right clicked the domain and selected "Change logon information"
Thank you for the clarification. The check that you performed does not test Kerberos because the authentication that is performed via the Change Logon Information option uses LDAP.
Following your instructions about didn't work but i think that is because the service is not using that domain but our primary domain.
The logon to the Adaxes service did not work because Kerberos authentication cannot be performed for the accounts of your secondary domain. When Kerberos works, logon to an Adaxes service should be possible using the credentials of any enabled, not expired and not locked account managed by the service.
We need to schedule a call on this one for you to truly understand how we have it set up.
We can schedule a WebEx meeting. If it is suitable, please, specify your time zone and convenient date/time for the meeting. Also, please, confirm that we can use the email address specified in your Q&A profile to send the meeting invitation.