Asking here to make sure I got the mechanism right: I created the principal nfs/china.mytest.org at TEST1.MYTEST.ORG on the KDC machine so that NFSv4 client china.mytest.org can mount a NFSv4 filesystem. How does the client china.mytest.org now get the keys? Wendy