Re: Security Factor with GSSAPI (MIT Compat/Cyrus-SASL 2.1.27 compatibility)

Quanah Gibson-Mount <[email protected]> Mon, 20 Aug 2018 13:31:12 -0700
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Message-ID <A57764483435292CC065EE39@[192.168.1.10]>
--On Monday, August 20, 2018 2:12 PM -0700 Quanah Gibson-Mount 
<[email protected]> wrote:

> In the MIT code, this is provided via:
> GSS_C_SEC_CONTEXT_SASL_SSF
>
> Is there something similar in Heimdal that I'm missing, or should I open
> an issue on GitHub for this functionality to be added?

Ok, in reading the code, the issue is deeper than that 
(GSS_C_SEC_CONTEXT_SASL_SSF is set in cyrus-sasl if the implementation is 
Heimdal).  The actual issue is apparently the 
gss_inquire_sec_context_by_oid function returns data with MIT Kerberos 
that's not available with Heimdal.

I'll open a ticket in this regard.

--Quanah




--

Quanah Gibson-Mount
Product Architect
Symas Corporation
Packaged, certified, and supported LDAP solutions powered by OpenLDAP:
<http://www.symas.com>