i'm trying to set up cross-realm authentication between a win domain
and our kerberos realm.  while sniffing the connections from our
windows clients, i see that there is no preauthentication field in the
packets initially being sent to
the kdc, even after receiving an error stating "...preauth required". 
this is both for workstations attempting to join a windows domain as
well as a local user running kinit.  is this something that is
configurable on the workstation?  i don't know where to look on the
windows clients to require them
to do preauthentication.  thanks.

