There there should be possibly THREE SAF calls to ACF2 for each use by an application of a PassTicket:
What resource validation calls are used by applications that utilize a PassTicket?
There are two components at play:
GENERATION of passticket will have the following resource validations.
EVALUATION of passticket (at signon time) will NOT cause a validation for IRRPTAUTH with READ access because ACF2 does not use the callable services at signon time. Applications that utilize R_ticketserv or R_GenSec callable service to generate or evaluate a PassTicket will cause validations by resources in the PTKTDATA class:
Operation Resource Name Access Required
Generate PassTicket IRRPTAUTH.application.target-userid UPDATE
Evaluate PassTicket IRRPTAUTH.application.target-userid READ
See following links for documented details.
Details on - Control Applications that Invoke the R_xxxxxxx Callable Services
Details on PTKRESCK / NOPTKRESCK can be found in ACF2 documentation section ACF2 Options Specifications (OPTS)