One problem more for me:
I've got two cells in different countries, both working for themself.
One has old builtin krb4 and a krb5 auth, the new one hs only krb5 auth.
Just to understand it:
I want to get tokens in cell a for cell b and other way round.
And I want to get krb5 tickets from cell a on b and other way round.
Right now I get a ticket from cell a in cell b, but no ticket from cell b in
cell a, I think thats kinda firewall problem.
But even with a ticket from cell a in cell b, I can't get a token for cell a and
 can't browse the afs of cell a.
Do I have to generate a new key entry for cell a in kerberos of cell b and other
way round?

And another small problem: the root.afs is mounted rl, is there a easy way to
make a new entry under /afs instead of removing all root.cell.readonly and make
the changes, or not?

