>#klist >Ticket cache: FILE:/tmp/krb5cc_0 >Default principal: bsmith at AFB.LAN > >#ldapsearch -Y GSSAPI -D "uid=bsmith,ou=People,dc=afb,dc=lan" -v No credentials?? or did you just edit out the result of klist? You should see at the very least a ticket-granting ticket >2. Do I need a host principal for every client? > This I am pretty sure is a 'yes you do' -Marty