Does slapd or sasl build the kerberos5 service principle? On Solaris, I am getting a service principal without the fully qualified domain name. Like ldap/hostname@MY.REALM, instead of ldap/hostname.openldap.org@MY.REALM Alex --