Re: Current semantics for channel-bindings in GSSAPI

Stefan Metzmacher <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.devel
Message-ID <[email protected]>
Hi Issac,

> As discussed last week, we want the following changes.
> 
> - MIT should match Heimdal behavior and only error if client bindings
> are not all zeros.
> - Both Heimdal/MIT should return channel-bound flag if the bindings did match.
> - Both Heimdal/MIT should take advantage of KERB_AP_OPTIONS_CBT if
> present if authenticator, in which case if the server passed bindings
> they must match.
> - Both Heimdal/MIT should provide a conf option to asset the client
> system supports channel-bindings, causing KERB_AP_OPTIONS_CBT to be
> sent in any ap-req.
> 
> I submitted wip PR #1047 upstream MIT based on the above.
> 
> @metze, would that satisfy samba's requirements?

I looked briefly and the core changes look good,
but (as always :-) I think krb5.conf option alone are unflexible
and I'd really like to get rid of autogenerated krb5.conf files and
global exporting "KRB5_CONFIG". So APIs to turn this on from the
application would be great.

metze

_______________________________________________
krbdev mailing list             [email protected]
https://mailman.mit.edu/mailman/listinfo/krbdev
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEfFbGo3YXpfgryIw9DbX1YShpvVYFAl5nsPcACgkQDbX1YShp
vVZSVhAAwBsplzPw7T69sdBinHqy8s1m2Dic0fGyVfR7qjsbUsQZCOftx2TGyI2Q
grohttlhuR0Y+8VnpbnurrGsRJhZsish90b2POa47QXDdLcB5BCHbbcGtOlfQyEu
vpRhjMxYNdLGI8p43IyCHGP03z8bDGi4OXu7EqtiCOOp/yp/Jfzqn6VgPkVYkNdf
VbxcDJhL4+1CCki3L8z3iOJE81toby12Ze6iaTzLvlsrWHulisZZImp2XLoY8U6/
SHHj+7e/1HUprE3zRVN8D9AqNvkfbyTMNbiV+FDKleSnGhNK/oJvcVdrup2yWC66
2dSxHAhLWrvSeHAhoxtOBo1Ch65VmYuLDvq3ynUkqZsg0Gu2WJcWuZ4j6aQwMXh7
Kbt57IdDjase3Y8jaa3AeE25LC7w6E/N/WpipPAhDiNzbXE6h8nV0KDFTMiQqfHo
/9QAEkkN4ny9Fbd1YqH+K9k8Wh2J4yJp8erBePlhmnLZkny8TP+6hx1SqxCqJDNW
Us7E0Ob3cl7z/A3W5rE/wFPQrmYgh2/y6fUQ9IGyPxfg50FGY2D4tZDwP4eWJaaW
W82OUTG3NC3N2DIdscCgd6rwwODb2EdgzxxjOcenlUE1pIOCOJ3N85n3iW64o408
zXAhVVVlv9XYTqeI05Yq8eoiCV9AIWwWmoHhR1YHvPkn7fzvAZA=
=+Oxy
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.