The heimdal KDC announces support for KRB5_PADATA_FX_FAST, KRB5_PADATA_PKINIT_KX and KRB5_PADATA_GSS, even if they are later rejected/ignored. It means in Samba KRB5_PADATA_FX_FAST is announce in the PREAUTH-REQUIRED response, even if 'kdc enable fast = no' is configured.
Created attachment 17714 [details] 4.17 patches (has to go via lorikeet-heimdal and samba master first)
Created attachment 17715 [details] 4.16 patches (has to go via lorikeet-heimdal and samba master first)
This was addressed with updates to Heimdal for Samba 4.19.