The SPN should be simply SERVICEACCOUNTNAME@DOMAIN.COM not the actual SPN, use the UPN instead.
Also the service account should be added to the local admin group and the SIA should be running as that user for CCM testing. Afterward let us know if the logins work.
-Josh