Put KDB authdata first Windows services, as well as some versions of Samba, may refuse tickets if the PAC is not in the first AD-IF-RELEVANT container. In fetch_kdb_authdata(), change the merge order so that authdata from the KDB module appears first. [ghudson@mit.edu: added comment and clarified commit message] (cherry picked from commit 331fa4bdd34263ea20667a0f51338cb84357fdaa) https://github.com/krb5/krb5/commit/ca0e1e9c663db20823130df5ee9d7b2d3a879fbe Author: Isaac Boukris Committer: Greg Hudson Commit: ca0e1e9c663db20823130df5ee9d7b2d3a879fbe Branch: krb5-1.18 src/kdc/kdc_authdata.c | 9 ++++++--- 1 files changed, 6 insertions(+), 3 deletions(-)