Support for Kerberos tickets re-delegation for connections by NX protocol is available since v. 6.12.3 (https://www.nomachine.com/FR07R04008) but it applies only to direct connections with Kerberos authentication.
This functionality needs to be extended to cover the case of non-direct connections with Kerberos authentication and also include Kerberos tickets obtained during password authentication:
Kerberos authentication -> main server -> remote server
Password authentication with pam_krb5.so -> main server
Password authentication with pam_krb5.so -> main server -> remote server