Administrators are advised to consider the following points while deploying Novell Kerberos KDC, because it involves an integration between Kerberos and eDirectory paradigms:
Multiple realms can be configured in a single tree.
Only one Kerberos identity can be stored on the user object. To associate multiple Kerberos identities, a Kerberos principal can be created separately and linked to the user object.
Overall, the need for more than one administrator is avoided. The benefits of having such a single point of management are ease of administration and reduced administrative costs.
If separate eDirectory container administrators are present, each has an additional responsibility of administrating the Kerberos data.