On 07/10/2012 11:48 PM, Weijun Wang wrote:
> My question is: is this ticket useful for any other purpose? If not, why 
> doesn't krb5_get_credentials_for_user return an error at the beginning?

It can be useful for examining the authorization data in the ticket
(like a PAC), if the KDC is capable of putting one in there.

See also:
http://msdn.microsoft.com/en-us/library/ff634450(v=prot.13)
________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos

Reply via email to