> On Thu, Nov 16, 2006 at 09:57:27PM +0100, Måns Nilsson wrote:

>> Both methods have issues; do you want the kdc on Sol10, and can your
>> clients find the kdc through DNS? 
> What is the problem with the first method? As a matter of fact, this is
> exactly what I am doing. I used RBAC to allow a heimdal user access to
> the privileged ports. It seems to be working fine.

I have no big issues with doing that. A lot of sysadmins have isues with
Solaris, mostly from being subjected to, say, 2.3.  That does not wear off
so easily...

