Re: choosing principal names
Russ Allbery <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Organization | The Eyrie |
| Message-ID | <[email protected]> |
Nico Williams <[email protected]> writes: > I hadn't thought of LDAP filtering before. I think that allows one to > make a convincing argument here against PACs. There's still other > issues, such as how to make it so the server has to show that the user > it's inquiring about did, in fact, authenticate. This requires > something like S4U2Proxy. Yes, indeed. (And you really want that, not straight credential delegation.) I'm very interested in adding something like S4U2Proxy to WebAuth at some point in the next couple of years, since I think it's the direction to go for a lot of interesting use cases. -- Russ Allbery ([email protected]) <http://www.eyrie.org/~eagle/>