An alternative plan for principal mapping

> It's important that we don't create a situation where services expect
> the KDC to perform authorization checks and fail insecurely if that  
> does not happen.
> PAC like behavior is fine because a service can tell if the PAC is not
> present.  However something where a service expects a KDC only to
> grant tickets to authorized users would be a really bad idea, because
> it would mean the service is only secure with certain KDCs.
That's a very correct technical position to take.  That's why I  
called attention to the issue.

OTOH (at the risk of starting another long thread with Greg W. like I  
did once before) the only thing people really care about is  
authorization.  I already have problems with people believing that  
having a Kerberos ticket is sufficient to access things.  A standard  
way to solve the authorization problem without requiring another  
independent implementation/integration effort would be very nice.

