Hi, is there a way with MIT kerberos to create an "alias" for e.g. service/myhost.priv. at REALM (mind the trailing dot in the SPN) to service/myhost.priv at REALM (without dot), so that a request (with canonicalization flag set) for the former principal returns a ticket for the latter? Best regards, Lorenzo Costanzia