authorized_principal
krb5_boolean authorized_principal
if (!authorized_principal(doit_context, client, etype)) {