It looks as if others have successfully built the environment you 
described. As we are using Heimdal instead of MIT it could be that is 
where our problems came from. I will try once more to build SGE with GSS 
enabled and do report my findings.

One thing puzzles me however: Both the "jobs" directory and the files 
therein are readable by ordinary users (at least in my case SGE6u3 
compiled with the -afs flag). In the docs I read
     1. qsub/qmon calls get_cred when a job is submitted to get the
        credentials of the user. The tokenized credentials are sent back
        to qsub and are put into the job request.
Therefore I could easily extract the credentials from an arbitrary user 
and use it in the same way (get_cred/put_cred) as the qmaster does. Did I 
misunderstand something here? To be on the safe side I thought that the 
credentials must be stored separately on the qmaster in a root protected 

If the above mentioned Kerberos integration does also work for us I would 
prefer that solution (as it is integrated into qmaster/execd) instead of 
our "external" solution.

