>The best thing would be to advocate gss_krb5_inquire_sec_context_by_oid w/ >OIDs for the subkey and PAC [1] w/ support in MIT and stock Heimdal. For accessing the PAC, we will probably move to store the authorization data inside a gss_name_t() and provide something like gss_inquire_name_by_oid rather than extracting it from the context. -- Luke --