/etc/webkdc/token.acl is in libapache2-mod-webkdc 4.5.5-2.
This file is owned by root:root, with mode 0o644.
The actual contents of the file can be viewed below.
1 2 3 4 5 | # token.acl -- Sample ACL file for the WebKDC.
# If uncommented, this would let anyone with a krb5 webauth/*@example.com
# principal to get an id token (perform basic authentication).
#krb5:webauth/*@example.com id
|