Re: Current semantics for channel-bindings in GSSAPI
Isaac Boukris <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.devel |
|---|---|
| Message-ID | <CAC-fF8S67=goQP_ccE_fWeiTtZQbzs96ZCBrX=EpMe6AAP1b_Q@mail.gmail.com> |
On Fri, Mar 20, 2020 at 10:19 PM Isaac Boukris <[email protected]> wrote: > > BTW, it looks like both Heimdal/MIT do not handle the bindings in the > DCE style case, so we'd just not return channel-bound in that case. Actually, that seems wrong. I think the bindings are checked in the first leg of authentication, so perhaps we should keep the channel-bound flag on the context and return it by the end (although i'm not sure an outer channel is relevant). _______________________________________________ krbdev mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/krbdev