Constrained Delegation with certificate and GSS API

Puran Chand <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.devel
Message-ID <CAKnEmRK_KdfRVq8WfVH32WDK5iUXrUvO2CpGii1jrBPiea4rsg@mail.gmail.com>
Hi,

I see 'gss_acquire_cred_impersonate_name' should be used to obtain
impersonation token on behalf of user and the API expects
User-Principal-Name 'gss_name_t' as input to identify the user.

I was wondering if there is similar API to perform same with
user-certificate this time instead of UPN.
I hope it should send a AS-REQ with  PA-DATA P4-S4U-X509-USER with
certificate (with my limited knowledge).

If there isn't any API, I would be happy to work upon this.

Let me know where to start.
Thanks

-Puran
_______________________________________________
krbdev mailing list             [email protected]
https://mailman.mit.edu/mailman/listinfo/krbdev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.