I stand by my recommendation. Your advice assumes too many restrictions. What if you do not have KDC, what if you want to store krb tickets in the ldap store using heimdal apps, what if you want ldap and/or berkeley support in sasl, etc...
--Quanah
-- Quanah Gibson-Mount Principal Software Developer ITSS/TSS/Computing Systems ITSS/TSS/Infrastructure Operations Stanford University GnuPG Public Key: http://www.stanford.edu/~quanah/pgp.html