>>105563272
ok. now you have to have a fully set up and trusted domain, users need to know to kinit or configure their pam stack to do it for them or they're using windows and it's all for naught.
hell some software still can't use kernel keyring for credential cache.