Ksu should call krb5_verify_init_creds instead of using its own function. This was prompted by a desire for ksu to work without a domain_realm mapping for the local server, but the duplication of code is bad anyway. https://github.com/krb5/krb5/commit/7686b7181e9090e4bd84fbc64ce8980673d03126 Commit By: hartmans Revision: 21714 Changed Files: U trunk/src/clients/ksu/krb_auth_su.c