The Webserver name (or the entire domain) has to be in the Local intranet zone. See http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnsecure/html/http-sso-1.asp, ”local intranet sites”. You could add
http://*.yourdomain.com/
to the zone.
Add your domain (or webserver's FQDN) to network.negotiate-auth.trusted-uris, for example add ”.yourdomain.com”.