Re: Alternative proxy-creds API for constrained-delegation
Isaac Boukris <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.devel |
|---|---|
| Message-ID | <CAC-fF8SUyBG3ZKwtgs51BoDK=F3XdcBe4wysD0XNg0rk9ot=-g@mail.gmail.com> |
On Wed, Jun 3, 2020 at 1:45 PM Isaac Boukris <[email protected]> wrote: > > I think context option would have been more adequate if we had, but > cred-based is fine too. Actually that's wrong, context won't do it because we don't have one in gss_acquire_cred_impersonate_name(), while it may be useful to produce a tgt-less cache with a s4u2self ticket for certificate logon and such. It should be a cred-based option. _______________________________________________ krbdev mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/krbdev