Re: Session Key through GSS-API

Sam Hartman <[email protected]> Tue, 28 Feb 2023 21:50:56 +0000
Newsgroups gmane.comp.encryption.kerberos.devel
Message-ID <010001869a01d329-16b0eacb-1d10-4a84-b78c-dda122519af2-000000@email.amazonses.com>
>>>>> "Nico" == Nico Williams <[email protected]> writes:

    Nico> Wait, so Oracle uses the _ticket_'s session key as the session
    Nico> key for its security layer??

Yes, or at least this doesn't surprise me.

There's a tag in the old cvs repositories for a version of krb5 (pre
beta5)l that MIT shipped to Oracle.
I think they ended up going with some version of Cybersafe,
but their krb5 was old enough that subsession keys weren't really used.

--Sam
_______________________________________________
krbdev mailing list             [email protected]
https://mailman.mit.edu/mailman/listinfo/krbdev