I mostly don't buy it.  In its white papers, the consortium has taken
the position that Kerberos is part of fairly complex interdependent
systems basically in all the environments that use Kerberos.

I don't think the simple use cases are interesting to anyone

I can think of a couple of specific exceptions.  For example
maintaining credentials for the system account.  If one of those use
cases happens to be the real motivating use case for this work, then
sticking very closely to that use case seems good.

This project runs the real danger of creating a partial solution that
no one really wants that is strictly less useful than k5start.
Whatever can be done to avoid that is good, and if possible locking in
on a specific enough use case would be an example of such a way out.


