OK. I have no idea what's going on here. If I were approaching this I'd step through things in the client and server until I found the problem. So, I'm kind of shooting in the dark here. Kerberos 1.9 includes a tracing facility that could help with issues like this, but Kerberos 1.9 is not even in sid yet much less squeeze.
Is the default realm on your ssh server set to the realm in which it has its host keys? Do things change if you add a domain_realm entry to your ssh server mapping it into the realm where its key exists? -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected]

