RFC 4120 requires that if a subkey is present in the TGS request that authorization data be encrypted in the subkey. Our KDC did not handle this correctly. http://src.mit.edu/fisheye/changelog/krb5/?cs=22168 Commit By: hartmans Revision: 22168 Changed Files: U trunk/src/kdc/kdc_authdata.c