Re: Current semantics for channel-bindings in GSSAPI
Stefan Metzmacher <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi Issac, > As discussed last week, we want the following changes. > > - MIT should match Heimdal behavior and only error if client bindings > are not all zeros. > - Both Heimdal/MIT should return channel-bound flag if the bindings did match. > - Both Heimdal/MIT should take advantage of KERB_AP_OPTIONS_CBT if > present if authenticator, in which case if the server passed bindings > they must match. > - Both Heimdal/MIT should provide a conf option to asset the client > system supports channel-bindings, causing KERB_AP_OPTIONS_CBT to be > sent in any ap-req. > > I submitted wip PR #1047 upstream MIT based on the above. > > @metze, would that satisfy samba's requirements? I looked briefly and the core changes look good, but (as always :-) I think krb5.conf option alone are unflexible and I'd really like to get rid of autogenerated krb5.conf files and global exporting "KRB5_CONFIG". So APIs to turn this on from the application would be great. metze _______________________________________________ krbdev mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/krbdev
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEfFbGo3YXpfgryIw9DbX1YShpvVYFAl5nsPcACgkQDbX1YShp vVZSVhAAwBsplzPw7T69sdBinHqy8s1m2Dic0fGyVfR7qjsbUsQZCOftx2TGyI2Q grohttlhuR0Y+8VnpbnurrGsRJhZsish90b2POa47QXDdLcB5BCHbbcGtOlfQyEu vpRhjMxYNdLGI8p43IyCHGP03z8bDGi4OXu7EqtiCOOp/yp/Jfzqn6VgPkVYkNdf VbxcDJhL4+1CCki3L8z3iOJE81toby12Ze6iaTzLvlsrWHulisZZImp2XLoY8U6/ SHHj+7e/1HUprE3zRVN8D9AqNvkfbyTMNbiV+FDKleSnGhNK/oJvcVdrup2yWC66 2dSxHAhLWrvSeHAhoxtOBo1Ch65VmYuLDvq3ynUkqZsg0Gu2WJcWuZ4j6aQwMXh7 Kbt57IdDjase3Y8jaa3AeE25LC7w6E/N/WpipPAhDiNzbXE6h8nV0KDFTMiQqfHo /9QAEkkN4ny9Fbd1YqH+K9k8Wh2J4yJp8erBePlhmnLZkny8TP+6hx1SqxCqJDNW Us7E0Ob3cl7z/A3W5rE/wFPQrmYgh2/y6fUQ9IGyPxfg50FGY2D4tZDwP4eWJaaW W82OUTG3NC3N2DIdscCgd6rwwODb2EdgzxxjOcenlUE1pIOCOJ3N85n3iW64o408 zXAhVVVlv9XYTqeI05Yq8eoiCV9AIWwWmoHhR1YHvPkn7fzvAZA= =+Oxy -----END PGP SIGNATURE-----