> If you have Kerberos, it won't help with root access, since there is no passwords > in the LDAP database, and the Kerberos database isn't "de-crackable" (?). -- kpasswd.local --- Root access to the DC (be it LDAP, Kerberos, both, whatever...) and your just baked.