Re: Current semantics for channel-bindings in GSSAPI
Isaac Boukris <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.devel |
|---|---|
| Message-ID | <CAC-fF8SXt53hoXJfsrPPxmy=TRs-nzhC1KvLWjw3OTaVB4eujw@mail.gmail.com> |
On Sat, Mar 21, 2020 at 11:45 AM Isaac Boukris <[email protected]> wrote: > > On Fri, Mar 20, 2020 at 10:19 PM Isaac Boukris <[email protected]> wrote: > > > > BTW, it looks like both Heimdal/MIT do not handle the bindings in the > > DCE style case, so we'd just not return channel-bound in that case. > > Actually, that seems wrong. I think the bindings are checked in the > first leg of authentication, so perhaps we should keep the > channel-bound flag on the context and return it by the end (although > i'm not sure an outer channel is relevant). Oh, the MIT code was already doing it, added tests for it. _______________________________________________ krbdev mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/krbdev