Jeff Hodges blogs about some new work from MIT Kerberos Consortium.
You can look here.
In my view, the span of Kerberos in terms of trust is limited to the footprint of the KDC. But this new proposal highlighted in this picture utilizes various other forms of trust identifiers to go along with Kerberos.