With Kerberos, if you're planning on lying to your servers about DNS, you really need to make sure you lie consistently.
(Was having GSSAPI errors, because DNS was sometimes pulling from our workgroup DNS servers with a private network view, and sometimes from the real campus DNS servers, which know nothing about our cluster hosts.)