require a realm in EAP names; don't add default Kerberos realm