On Wed, Mar 16, 2005 at 08:30:34AM -0800, Jason Thorpe wrote:
  | kdc provides authentication, potentially for many other services (which=
  | may or may not know they actually need Kerberos [c.f. PAM], so can't=20
  | really have an explicit dependency).  It is my opinion that "kdc"=20
  | should start as early as possible, and have a "BEFORE: ...", probably=
  | SERVERS at this stage.

PAM using services generally require LOGIN.
(What are the exceptions to this?)

What specific services (that start before LOGIN) need
kdc running before they start?
AFAICT, only racoon.

