Whenever a client principle issues a TGS request with an expired TGT, an error is logged in krb5kdc.log. But such entries in my krb5kdc.log do not specify which client principle had an expired TGT (in fact, the log entry says "<unknown client>"). How can I determine which principle was trying to operate with an expired TGT? Thanks for any help. -ian