What does the krb5PrincipalName attribute really do? My original thought for usage was to use the attribute to map a Kerberos user to an OpenLDAP user, but in my tests that doesn't appear to be the case. Is this implemented but not functioning in 2.0.x? Thanks, Jason