Index: server/fedora/config/etc/httpd/conf.d/scripts-special.conf
===================================================================
--- server/fedora/config/etc/httpd/conf.d/scripts-special.conf	(revision 707)
+++ server/fedora/config/etc/httpd/conf.d/scripts-special.conf	(revision 708)
@@ -10,4 +10,10 @@
 <Location /__scripts/needcerts>
     RewriteEngine On
+
+    RewriteCond %{HTTP_HOST} !:444$
+    RewriteCond %{SERVER_NAME} ^(.*\.)?scripts$
+    RewriteCond %{THE_REQUEST} ^[^\ ]*\ (.*)\ .*
+    RewriteRule ^ https://%{SERVER_NAME}.mit.edu:444%1 [L,R]
+
     RewriteCond %{HTTP_HOST} !:444$
     RewriteCond %{SERVER_NAME} !=scripts-cert.mit.edu
Index: server/fedora/config/etc/httpd/conf/httpd.conf
===================================================================
--- server/fedora/config/etc/httpd/conf/httpd.conf	(revision 707)
+++ server/fedora/config/etc/httpd/conf/httpd.conf	(revision 708)
@@ -5,9 +5,22 @@
 MaxKeepAliveRequests 1000
 KeepAliveTimeout 5
-MinSpareServers 5
-MaxSpareServers 20
-StartServers 8
-MaxClients 256
-MaxRequestsPerChild 4000
+
+<IfModule mpm_prefork_module>
+    MinSpareServers 5
+    MaxSpareServers 20
+    StartServers 8
+    MaxClients 256
+    MaxRequestsPerChild 4000
+</IfModule>
+
+<IfModule mpm_worker_module>
+    StartServers 3
+    MinSpareThreads 75
+    MaxSpareThreads 250
+    ServerLimit 16
+    ThreadsPerChild 25
+    MaxClients 400
+    MaxRequestsPerChild 10000
+</IfModule>
 
 LoadModule auth_basic_module modules/mod_auth_basic.so
Index: server/fedora/config/etc/krb5.conf
===================================================================
--- server/fedora/config/etc/krb5.conf	(revision 707)
+++ server/fedora/config/etc/krb5.conf	(revision 708)
@@ -91,4 +91,11 @@
 		admin_server = kerberos.dementia.org
 	}
+	CSAIL.MIT.EDU = {
+		kdc = kerberos-1.csail.mit.edu
+		kdc = kerberos-2.csail.mit.edu
+		admin_server = kerberos.csail.mit.edu
+		default_domain = csail.mit.edu
+		krb524_server = krb524.csail.mit.edu
+	}
 
 [domain_realm]
@@ -99,4 +106,8 @@
 	.whoi.edu = ATHENA.MIT.EDU
 	whoi.edu = ATHENA.MIT.EDU
+	.csail.mit.edu = CSAIL.MIT.EDU
+        csail.mit.edu = CSAIL.MIT.EDU
+        .ai.mit.edu = CSAIL.MIT.EDU
+        ai.mit.edu = CSAIL.MIT.EDU
 	.stanford.edu = stanford.edu
 
Index: server/fedora/config/etc/sudoers
===================================================================
--- server/fedora/config/etc/sudoers	(revision 707)
+++ server/fedora/config/etc/sudoers	(revision 708)
@@ -21,2 +21,3 @@
 
 scripts	ALL=(signup)	NOPASSWD: /usr/local/bin/ldap-backup
+rebecca	ALL=(root)	NOPASSWD: /sbin/service nscd restart
Index: server/fedora/config/etc/sysconfig/openafs
===================================================================
--- server/fedora/config/etc/sysconfig/openafs	(revision 707)
+++ server/fedora/config/etc/sysconfig/openafs	(revision 708)
@@ -2,6 +2,9 @@
 BOSSERVER_ARGS=
 
-/sbin/sysctl -q afs.GCPAGs=0
-/usr/bin/fs setcrypt on
-/usr/bin/fs sysname 'amd64_linux26' 'i386_rhel4' 'i386_rhel3' 'i386_rh9' 'i386_linux24' 'i386_linux22' 'i386_linux3' 'i386_linux2' 'i386_linux1'
-/usr/bin/fs setcell -nosuid -c athena
+postinit () {
+	/sbin/sysctl -q afs.GCPAGs=0
+	/usr/bin/fs setcrypt on
+	/usr/bin/fs sysname 'amd64_linux26' 'i386_rhel4' 'i386_rhel3' 'i386_rh9' 'i386_linux24' 'i386_linux22' 'i386_linux3' 'i386_linux2' 'i386_linux1'
+	/usr/bin/fs setcell -nosuid -c athena
+}
+AFS_POST_INIT=postinit
Index: server/fedora/config/etc/yum.conf
===================================================================
--- server/fedora/config/etc/yum.conf	(revision 707)
+++ server/fedora/config/etc/yum.conf	(revision 708)
@@ -9,4 +9,5 @@
 plugins=1
 metadata_expire=1800
+installonlypkgs=kernel kernel-devel
 
 # PUT YOUR REPOS HERE OR IN separate files named file.repo
