Hi Dan, When I check the Kerberos messages, TGS-REP shows :-
TGS-REP Client realm : SML.CITIZEN.CO.JP Client name (Principal): host/imapsv04.sml.citizen.co.jp Name-type: Principal(1) Name: host Name: imapsv04.sml.citizen.co.jp On the working system (Heimdal 1.0.1 + SASL 2.1.22) , the TGS-REP should be my Kerberos principal :- TGS-REP Client realm : SML.CITIZEN.CO.JP Client name (Principal): john Name-type: Principal(1) Name: john Ticket : ...... Server name (service and host): ldap/tunis.pvd.citizen.co.jp ..... Any idea if it is a Heimdal 1.2 or SASL 2.1.23 problem ? Thanks a lot. John Mok