Re: Constrained Delegation with certificate and GSS API

Isaac Boukris <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.devel
Message-ID <CAC-fF8R7Y2diyqxDEc_4+rnB3AmVCe2bU-9JMzTCQDJTxDGE9g@mail.gmail.com>
On Wed, May 6, 2020 at 6:46 AM Greg Hudson <[email protected]> wrote:
>
> https://github.com/krb5/krb5/pull/1063
>
> There may be alternative designs for the API; for instance, we could
> perhaps instead define a new name type and use
> gss_acquire_cred_impersonate_name().

Yes, that would solve the authdata problem and we can skip the name+cert case.

@Puran, feel free to develop it on top PR 1063 if you like, it already
got some tests.
_______________________________________________
krbdev mailing list             [email protected]
https://mailman.mit.edu/mailman/listinfo/krbdev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.