Re: choosing principal names
Nico Williams <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <CAK3OfOjPozwdLzbpP5E+piCLVx3HCJRhGJ0vaTyvu8xohsqpKQ@mail.gmail.com> |
I hadn't thought of LDAP filtering before. I think that allows one to make a convincing argument here against PACs. There's still other issues, such as how to make it so the server has to show that the user it's inquiring about did, in fact, authenticate. This requires something like S4U2Proxy. Nico --