>>>>> "Lukas" == Lukas Grässlin <lukas.graess...@adfinis.com> writes:
Lukas> We have a scenario where we need to disable reverse lookups for Lukas> canonicalization in Kerberos as the customer's PTR records are not Lukas> consistent and lead to wrongly requested SPNs otherwise (see Lukas> https://web.mit.edu/kerberos/krb5-latest/doc/admin/princ_dns.html#reverse-dns-mismatches) How are you actually triggering the GSS-API authentication? ldapsearch in all cases? And you are confident that libkrb5 is triggering the reverse lookup not your application? (I realize that you may be using the same application on Debian and RH, but there could be differences in the application code).