On Fri, Jun 01, 2001 at 12:58:29PM +0200, Johan Danielsson wrote: > Of course the best way would be if we could always use (secure) dns to > verify that hosts exist, but that's not likely to happen any time > soon. So add Kerberos principal name canonicalization to the TGS and make the KDCs be authoritative DNS servers for the DNS domains related to its Kerberos realms. > /Johan :^) Cheers, Nico --