Shaoqun,
Like Tim said for #1, no certs involved.
2) p:CN=YOUR-AD-USER-ID
3) p:CN=USERNAME@DOMAIN.COM
4) p:CN=YOUR-AD-USER-ID
5) snc/gssapi_lib = /usr/sap/SID/INSTANCE/SLL/libsapcrypto.so
We don't set the SNC_LIB variable at the OS level. I don't think that's needed
NICK