>What does the krb5PrincipalName attribute really do? My original thought for >usage was to use the attribute to map a Kerberos user to an OpenLDAP user, >but in my tests that doesn't appear to be the case. Is this implemented but >not functioning in 2.0.x? Yes, it maps an LDAP object (user?) to a Kerberos V principle. It works here.