OK. You don't need krb5_fwd_tgt_creds at all. Also, you must verify the ticket *before* creating the account. If you do not, you will be vulnerable to a user impersonating the ldap server. --Sam