Re: Target realm gets overwritten

Alibek Jorajev <[email protected]> Mon, 13 Aug 2018 06:23:44 +0000 (UTC)
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Message-ID <[email protected]>
------=_Part_6733501_1056221764.1534141424415
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

 hi Viktor!
I would be happy to use latest 7.x.but the upgrade will take time (it is on=
 the roadmap).and I need to patch 1.4 for this specific defect.=20

I have the following options (no question about moving to 7.x, that will be=
 separate effort):- do not use realm from "source" in this specific scenari=
o (cross-realm)- remove "source" all together- try to backport portion of c=
ode (if that code is still meaningful for 1.4) from latest 7.x
do you know, why in 1.5.x series, it was needed to use "source" (client pri=
ncipal's realm)?

regards,Alibek

    On Friday, 10 August 2018, 22:17:59 GMT+1, Viktor Dukhovni <heimdal@duk=
hovni.org> wrote: =20
=20
=20

> On Aug 10, 2018, at 4:01 PM, Alibek Jorajev <[email protected]> wrote:
>=20
> I am using KRB5 API to fetch TGT and then GSS API to generate negotiate t=
okens.
> (then I add these tokens into HTTP headers when needed). I am using Heimd=
al v. 1.4.

You really SHOULD NOT be using Heimdal 1.4.=C2=A0 We only support Heimdal 7=
.x.

--=20
=C2=A0=C2=A0=C2=A0 Viktor.
 =20
------=_Part_6733501_1056221764.1534141424415
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit

<html><head></head><body><div style="font-family:courier new, courier, monaco, monospace, sans-serif;font-size:16px;"><div style="font-family:courier new, courier, monaco, monospace, sans-serif;font-size:16px;"><div></div>
        <div>hi Viktor!</div><div><br></div><div>I would be happy to use latest 7.x.</div><div>but the upgrade will take time (it is on the roadmap).</div><div><div>and I need to patch 1.4 for this specific defect. <br><span></span></div><br></div><div>I have the following options (no question about moving to 7.x, that will be separate effort):</div><div>- do not use realm from "source" in this specific scenario (cross-realm)</div><div>- remove "source" all together</div><div>- try to backport portion of code (if that code is still meaningful for 1.4) from latest 7.x</div><div><br></div><div>do you know, why in 1.5.x series, it was needed to use "source" (client principal's realm)?<br></div><div><br></div><div>regards,</div><div>Alibek<br></div><div><br></div>
        
        </div><div id="ydp5ce1e055yahoo_quoted_4870066064" class="ydp5ce1e055yahoo_quoted">
            <div style="font-family:'Helvetica Neue', Helvetica, Arial, sans-serif;font-size:13px;color:#26282a;">
                
                <div>
                    On Friday, 10 August 2018, 22:17:59 GMT+1, Viktor Dukhovni &lt;[email protected]&gt; wrote:
                </div>
                <div><br></div>
                <div><br></div>
                <div><div dir="ltr"><br clear="none"><div class="ydp5ce1e055yqt8666686443" id="ydp5ce1e055yqtfd86414"><br clear="none">&gt; On Aug 10, 2018, at 4:01 PM, Alibek Jorajev &lt;<a shape="rect" href="mailto:[email protected]" rel="nofollow" target="_blank">[email protected]</a>&gt; wrote:<br clear="none">&gt; <br clear="none">&gt; I am using KRB5 API to fetch TGT and then GSS API to generate negotiate tokens.<br clear="none">&gt; (then I add these tokens into HTTP headers when needed). I am using Heimdal v. 1.4.</div><br clear="none"><br clear="none">You really SHOULD NOT be using Heimdal 1.4.&nbsp; We only support Heimdal 7.x.<br clear="none"><br clear="none">-- <br clear="none">&nbsp;&nbsp;&nbsp; Viktor.<div class="ydp5ce1e055yqt8666686443" id="ydp5ce1e055yqtfd87412"><br clear=
 "none"></div></div></div>
            </div>
        </div></div></body></html>
------=_Part_6733501_1056221764.1534141424415--