The Kerberos service provides a default mapping of GSS credential names to UNIX user IDs (UIDs) for GSS applications that require this mapping, such as NFS. GSS credential names are equivalent to Kerberos principal names when using the Kerberos service. Also, UNIX users who do not have valid user accounts in the default Kerberos realm can be automatically migrated by using the PAM framework.