Derives the session's amr and acr from a ticket's own flags and
authentication indicators: pwd for pre-authent, hwk for hw-authent,
otp for the RFC 8129 indicator from this realm; mfa only for two.
the ticket's flag names
Optionalindicators: any
the ticket's authentication indicators
OptionalownRealm: any
false for a ticket from a foreign realm, whose indicators count for nothing
{ amr, acr, method, password, hardware, otp }
Forwards to
SpnegoAuthn.factorsFor()on the installed instance.