Re: Current semantics for channel-bindings in GSSAPI

Isaac Boukris <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.devel
Message-ID <CAC-fF8SXt53hoXJfsrPPxmy=TRs-nzhC1KvLWjw3OTaVB4eujw@mail.gmail.com>
On Sat, Mar 21, 2020 at 11:45 AM Isaac Boukris <[email protected]> wrote:
>
> On Fri, Mar 20, 2020 at 10:19 PM Isaac Boukris <[email protected]> wrote:
> >
> > BTW, it looks like both Heimdal/MIT do not handle the bindings in the
> > DCE style case, so we'd just not return channel-bound in that case.
>
> Actually, that seems wrong. I think the bindings are checked in the
> first leg of authentication, so perhaps we should keep the
> channel-bound flag on the context and return it by the end (although
> i'm not sure an outer channel is relevant).

Oh, the MIT code was already doing it, added tests for it.
_______________________________________________
krbdev mailing list             [email protected]
https://mailman.mit.edu/mailman/listinfo/krbdev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.