Re: Current semantics for channel-bindings in GSSAPI

Isaac Boukris <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.devel
Message-ID <CAC-fF8SOMeOMXubqK-27jhS4fALu-jM4=nue466hHLwmHOGvYQ@mail.gmail.com>
As discussed last week, we want the following changes.

- MIT should match Heimdal behavior and only error if client bindings
are not all zeros.
- Both Heimdal/MIT should return channel-bound flag if the bindings did match.
- Both Heimdal/MIT should take advantage of KERB_AP_OPTIONS_CBT if
present if authenticator, in which case if the server passed bindings
they must match.
- Both Heimdal/MIT should provide a conf option to asset the client
system supports channel-bindings, causing KERB_AP_OPTIONS_CBT to be
sent in any ap-req.

I submitted wip PR #1047 upstream MIT based on the above.

@metze, would that satisfy samba's requirements?
_______________________________________________
krbdev mailing list             [email protected]
https://mailman.mit.edu/mailman/listinfo/krbdev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.