...when krb5_get_init_creds_password() is invoked for a prinicpal that requires preauthentication and only supports weak crypto (and allow_weak_crypto is not specified). It should fail, clearly, but probably in some speedier and more comprehensible fashion. -Kevin Wasserman