On 11/05/11 12:17, Mark Andrews wrote: > {ms,krb5}-subdomain allows updates of *.machinename One note - this isn't so handy if you have a disjoint namespace, where: machinename.*.example.com ...is what you want. We are in this boat, and can't use the built in ACLs for this very reason.