Re: Reading MS PAC data

"Markus Moeller" <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.general,gmane.comp.encryption.kerberos.heimdal.general
Message-ID <[email protected]>
"Greg Hudson" <[email protected]> wrote in message 
news:[email protected]...
> On 08/18/2013 03:07 PM, Markus Moeller wrote:
>> says ctx->authdata[i]->ad_type  is 1 and not 128.   Is there a bug in MIT 
>> ?
>
> It looks like Heimdal's
> gsskrb5_extract_authz_data_from_sec_context will look inside
> AD-IF-RELEVANT containers but MIT's will not.  We can correct this
> divergence for future releases (I'm actually not sure how it came
> about), but that probably doesn't solve your problem.
>
> In the mean time, I think using gss_get_name_attribute with urn:mspac:
> is your best bet, when linking against MIT krb5 libraries.  Samba's
> auth/kerberos/gssapi_pac.c has example usage.
>

I was sucessful with gss_map_name_to_any and MIT libraries, but was looking 
for a function both support, but it seems I need to use different functions 
for now

> ________________________________________________
> Kerberos mailing list           [email protected]
> https://mailman.mit.edu/mailman/listinfo/kerberos
>

Thank you
Markus


________________________________________________
Kerberos mailing list           [email protected]
https://mailman.mit.edu/mailman/listinfo/kerberos
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.