The kerberos code in /usr/src/domestic is not vulnerable to the poor key generation code present in the MIT kerberos distributions. I guess it's a good thing that we got it from somewhere else that had already instituted full use of des_new_random_key(). ==John