The PA-S4U-X509-USER the reply carries: the request's S4UUserID with its checksum, under the TGT session key — key usage 27 when the request asked for it (and said so in the options it echoes), 26 otherwise.
what readS4uX509User() returned
{ etype, key }, the TGT's session key
{ etype, key }
the padata entry { type, value }
{ type, value }
The PA-S4U-X509-USER the reply carries: the request's S4UUserID with its checksum, under the TGT session key — key usage 27 when the request asked for it (and said so in the options it echoes), 26 otherwise.