slurpd with kerberos working config

Can someone send out the relevant lines from slapd.conf 
that make slurpd replication work using GSSAPI and kerberosV.
I've been trying to make this work all weekend without success.
Using simple bind works fine but with kerberos tickets the
mod to the slave database always fails.  I've tried various
permutations of ACLs, the updatedn line on the slave side, and 
many combinations of params for the replica line on the 
master side.  If someone could post working examples I'd
be most appreciative.

Keith Lally

Error on slave side with database perms wide open:
        replace: otherMailbox
        replace: modifiersName
        replace: modifyTimestamp
send_ldap_result: conn=0 op=3 p=3
send_ldap_result: 10::
send_ldap_response: msgid=4 tag=103 err=32