On 9/26/25 06:00, Alexander Bokovoy via krbdev wrote: > So I am thinking on how we can implement this in MIT Kerberos-based > Samba AD DC or FreeIPA domain controllers. Do these requests have to be serviced by the KDC process at all? Could it be a separate daemon with access to the KDB?