We've never used kaserver (we already were using Kerberos when we started on AFS), but it seems to me that the one really advantage of kaserver over a true KDC is that it had real replication instead of a master/slave model. So can somebody in the know comment on why "ka5server" wasn't the answer (for those who use kaserver)? Just curious, john