Personally I can't get -K to work, but it might be due to my PAM configuration. I couldn't get GSSAPIDelegateCredentials to work until I also set GSSAPIAuthentication. I think you also need forwardable=true in krb5.conf. But the biggest problem for me is it only works for a single realm. I wish we still had afs token forwarding in ssh.