> So my advice is to use tried and tested public key management. Export

But I want tried and tested Kerberos, Dave!! Many sites use Kerberos now, and 
it's much more important for me to be able to authenticate my local users (who 
already have Kerberos tickets when they login), rather than off-site users. 
While I wouldn't stop local users from using PGP/PEM if they want, I don't 
want to have to put another authentication system in place just to 
authenticate WWW when I have a perfectly good Kerberos set up already.

