Hi, I'm unable to authenticate through Kerberos to a 2008 R2 read only domain controller (RODC) with Samba 3.5.5. I changed the krb5_princ_type field in bld_pr_ext.c krb5_build_principal_ext() to KRB5_NT_SRV_INST from KRB5_NT_UNKNOWN and this solved the problem. Is there a better / safer fix for this bug? Thanks, Bill Fellows