Re: Alternative proxy-creds API for constrained-delegation

Isaac Boukris <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.devel
Message-ID <CAC-fF8SUyBG3ZKwtgs51BoDK=F3XdcBe4wysD0XNg0rk9ot=-g@mail.gmail.com>
On Wed, Jun 3, 2020 at 1:45 PM Isaac Boukris <[email protected]> wrote:
>
> I think context option would have been more adequate if we had, but
> cred-based is fine too.

Actually that's wrong, context won't do it because we don't have one
in gss_acquire_cred_impersonate_name(), while it may be useful to
produce a tgt-less cache with a s4u2self ticket for certificate logon
and such.
It should be a cred-based option.
_______________________________________________
krbdev mailing list             [email protected]
https://mailman.mit.edu/mailman/listinfo/krbdev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.