I think the world only cares about authorization, and you need  
something like LDAP to store the necessary information.  In the chaos  
that is currently typical the convenience and security issues that  
Kerberos solves are all secondary and not visible.  Splitting  
"authorization" into two different problems appears to be making the  
problem harder rather than solving it.

Even people who understand the issue may not have the charter to  
address it, because they are only responsible for the one, narrowly  
defined, end capability.
