/etc/webkdc/token.acl is in libapache2-webkdc 4.0.2-1.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 | # token.acl -- Sample ACL file for the WebKDC.
# If uncommented, this would let anyone with a krb5 webauth/*@example.com
# principal to get an id token (perform basic authentication).
#krb5:webauth/*@example.com id
|