Since the passticket is system generated it would not be invalid. But if it is passed from one system to another, both systems must be using the same encryption key. If the encrytion is different then the passticket will not appear the same on each system and fail. If both are using the same encryption then the passticket will be accepted. If a user tries to signon multiple times and fails they would be subjected to PTHRESH because the password is checked first. So in this case the user would be suspended after three invalid password attempts whether using passtickets, passwords or passphrases.