If you would like to use Kerberos and also allow access to service principals in form of service/host@REALM than for these if you use user directory in form of LDAP you mostly need full name, spliting of the realm can be done easily only for users on webserver level so this should be configurable in plugin
If you would like to use Kerberos and also allow access to service principals in form of service/host@REALM than for these if you use user directory in form of LDAP you mostly need full name, spliting of the realm can be done easily only for users on webserver level so this should be configurable in plugin