Re: Current semantics for channel-bindings in GSSAPI
Isaac Boukris <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.devel |
|---|---|
| Message-ID | <CAC-fF8SOMeOMXubqK-27jhS4fALu-jM4=nue466hHLwmHOGvYQ@mail.gmail.com> |
As discussed last week, we want the following changes. - MIT should match Heimdal behavior and only error if client bindings are not all zeros. - Both Heimdal/MIT should return channel-bound flag if the bindings did match. - Both Heimdal/MIT should take advantage of KERB_AP_OPTIONS_CBT if present if authenticator, in which case if the server passed bindings they must match. - Both Heimdal/MIT should provide a conf option to asset the client system supports channel-bindings, causing KERB_AP_OPTIONS_CBT to be sent in any ap-req. I submitted wip PR #1047 upstream MIT based on the above. @metze, would that satisfy samba's requirements? _______________________________________________ krbdev mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/krbdev