Re: Target realm gets overwritten
Alibek Jorajev <[email protected]> Mon, 13 Aug 2018 06:23:44 +0000 (UTC)
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <[email protected]> |
------=_Part_6733501_1056221764.1534141424415
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
hi Viktor!
I would be happy to use latest 7.x.but the upgrade will take time (it is on=
the roadmap).and I need to patch 1.4 for this specific defect.=20
I have the following options (no question about moving to 7.x, that will be=
separate effort):- do not use realm from "source" in this specific scenari=
o (cross-realm)- remove "source" all together- try to backport portion of c=
ode (if that code is still meaningful for 1.4) from latest 7.x
do you know, why in 1.5.x series, it was needed to use "source" (client pri=
ncipal's realm)?
regards,Alibek
On Friday, 10 August 2018, 22:17:59 GMT+1, Viktor Dukhovni <heimdal@duk=
hovni.org> wrote: =20
=20
=20
> On Aug 10, 2018, at 4:01 PM, Alibek Jorajev <[email protected]> wrote:
>=20
> I am using KRB5 API to fetch TGT and then GSS API to generate negotiate t=
okens.
> (then I add these tokens into HTTP headers when needed). I am using Heimd=
al v. 1.4.
You really SHOULD NOT be using Heimdal 1.4.=C2=A0 We only support Heimdal 7=
.x.
--=20
=C2=A0=C2=A0=C2=A0 Viktor.
=20
------=_Part_6733501_1056221764.1534141424415
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit
<html><head></head><body><div style="font-family:courier new, courier, monaco, monospace, sans-serif;font-size:16px;"><div style="font-family:courier new, courier, monaco, monospace, sans-serif;font-size:16px;"><div></div>
<div>hi Viktor!</div><div><br></div><div>I would be happy to use latest 7.x.</div><div>but the upgrade will take time (it is on the roadmap).</div><div><div>and I need to patch 1.4 for this specific defect. <br><span></span></div><br></div><div>I have the following options (no question about moving to 7.x, that will be separate effort):</div><div>- do not use realm from "source" in this specific scenario (cross-realm)</div><div>- remove "source" all together</div><div>- try to backport portion of code (if that code is still meaningful for 1.4) from latest 7.x</div><div><br></div><div>do you know, why in 1.5.x series, it was needed to use "source" (client principal's realm)?<br></div><div><br></div><div>regards,</div><div>Alibek<br></div><div><br></div>
</div><div id="ydp5ce1e055yahoo_quoted_4870066064" class="ydp5ce1e055yahoo_quoted">
<div style="font-family:'Helvetica Neue', Helvetica, Arial, sans-serif;font-size:13px;color:#26282a;">
<div>
On Friday, 10 August 2018, 22:17:59 GMT+1, Viktor Dukhovni <[email protected]> wrote:
</div>
<div><br></div>
<div><br></div>
<div><div dir="ltr"><br clear="none"><div class="ydp5ce1e055yqt8666686443" id="ydp5ce1e055yqtfd86414"><br clear="none">> On Aug 10, 2018, at 4:01 PM, Alibek Jorajev <<a shape="rect" href="mailto:[email protected]" rel="nofollow" target="_blank">[email protected]</a>> wrote:<br clear="none">> <br clear="none">> I am using KRB5 API to fetch TGT and then GSS API to generate negotiate tokens.<br clear="none">> (then I add these tokens into HTTP headers when needed). I am using Heimdal v. 1.4.</div><br clear="none"><br clear="none">You really SHOULD NOT be using Heimdal 1.4. We only support Heimdal 7.x.<br clear="none"><br clear="none">-- <br clear="none"> Viktor.<div class="ydp5ce1e055yqt8666686443" id="ydp5ce1e055yqtfd87412"><br clear=
"none"></div></div></div>
</div>
</div></div></body></html>
------=_Part_6733501_1056221764.1534141424415--