Try turning off dns_lookup_* in krb5.conf ? Then the client *should* try kdcs in the order they're listed in krb5.conf.
--andy ________________________________________________ Kerberos mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/kerberos
