Yes, from B2TR on, WSSv3 requires Kerberos authentication to be
enabled before it can consume its own RSS feeds. This was apparently
to resolve a security hole.
For a single server configuration, this is easy to configure in
central administration. For any
multi-server configuration, you also have to enable Kerberos
delegation on the network by
configuring the application pool identity account (or the machine
account if using Network Services) as "trusted for delegation" in
the
directory, and registering an SPN. The database server machine
account
also must have an SPN registered, although it doesn't need to be
trusted for delegation.