John W. Sopko Jr. wrote:

> The afs/cell.name service principal only belongs to the standard
> "domain users" group, (I think this is standard), and I do not believe
> the afs service principal will need to be in any other groups. Thus
> the PAC data for the service principal should not be growing. And as
> long as it is less then 12k this should not cause a problem,
> sound correct? Thanks.

The PAC doesn't contain the authorization data for the service.
It contains the authorization data for the user.


Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to