our oes11 sp1 dsfw servers stopped populating UserPrincipalName so Kerberos authentication don't work for new users.
I checked and double checked and we have set dnsDomainName in description of domain root container as per
Support | Kerberos authentication for the user without UserPrincipalName (UPN) attribute fails.

I suspect that stopped with some recent updates. Right now we have eDir 8.8 SP7 (novell-NDSbase-

Has anybody else seen that?

