I know I saw something about this in some set of release notes for some version of Windows. How do I install the equivalent of the [domain_realm] section into ADs Kerberos? I have a working cross-realm trust. user at AD can get HOST/machine at MIT tickets, but only if the realm is explicit. Personal email. hbhotz at oxy.edu