>Maybe it would be better to put the principal name in the token >instead of the potentially completely wrong UID? I hate to ask ... why do you care what UID is in there? It was only used by one piece of software that I know of (the Andrew Mail System). Why does aklog put it in there? Because klog did it. Why does afslog put it in there? Probably because klog and aklog put it in there. --Ken