From RFC(http://tools.ietf.org/html/rfc4559):
When using the SPNEGO HTTP authentication facility with client- supplied data such as PUT and POST, the authentication should be complete between the client and server before sending the user data. The return status from the gss_init_security_context will indicate that the security context is complete. At this point, the data can be sent to the server.
What does this mean?
This actually means that if you have a loadbalancer/reverse proxy/similar(tmg/cisco-ace/iis/apache/nginx)) that supports
spnego/kerberos running towards a middleware system that doesn't(but replies ok whenever an authentication header is passed - or not) - post requests won't work.
The reverse proxy will send an empty post request with an headers, expecting an authentication negotiation from the server to properly authenticate before sending a new post with the actual data.
Seen in action With Hybris and Microsoft forefront TMG.