Hello, Has anyone ever tried citrix client pass through authentication to external MIT KDC instead of to the windows domain where the citrix server actually belongs to ? Let's say that a user uses his/her external MIT realm credential to login to a windows xp machine, which is a citrix metaframe xp presentation server 3.0 client. We would like to make use of pass-through authentication feature when the user wants to access the shared applications so that the user doesn't need to reenter his/her credential in windows AD (we don't want to make use or even store user credentials in AD anyway). In my opinion, it should be possible to authenticate with external MIT realm as long as the server is able to resolve the address of external MIT realm. Through ethereal, i can see that the server is trying to resolve the MIT.REALM.COM (that's the external MIT Realm) using NBNS. I tried to tell the citrix server to use DNS instead, by 'enabling XML service DNS address resolution' in the metaframe xp settings of the farm but it still sends queries using NBNS Is it actually possible to get pass-through authentication to work using external MIT realm tickets ? Thanks, lara ------------------------------------------------------------------------------------ La vie, voyez-vous, ca n'est jamais si bon ni si mauvais qu'on croit - Guy de Maupassant - ------------------------------------------------------------------------------------ --------------------------------- Do you Yahoo!? New and Improved Yahoo! Mail - 100MB free storage!