Oh, one other thing that may make your life easier. ;)
You can, of course, use completely different entities for the slurpd replication than "host/blah@realm". That is actually what I do. I use "service/ldap@stanford.edu". You can do this by setting environment variables to slurpd about what K5 ticket to use (and then just keep a k5 ticket around for it with something like k5start). So you could technically have two different entities for replication, which would also solve your problem.
-- Derek T. Yarnell UNIX System Administrator Computer Science Deparment University of Maryland