GSSAPI improvements PR
"carson.gaspar via SASL" <[email protected]> Wed, 17 May 2023 17:19:56 -0400
| Newsgroups | gmane.comp.security.cyrus.sasl |
|---|---|
| Message-ID | <[email protected]> |
--16843583961.89c5f.901182 Date: Wed, 17 May 2023 17:19:56 -0400 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable I just created a new PR on github to allow for multiple service principals = in a single service, and to allow overriding the auto-generated service pri= ncipal name. https://github.com/cyrusimap/cyrus-sasl/pull/763 With the new code, specifying the option=C2=A0accept_any_principal will cau= se the GSSAPI plugin to accept any service principal with a valid entry in = the keytab, per best practice. I kept the existing behaviour the same to avoid backwards compatibility iss= ues, although I'd argue the current behaviour is undesirable in almost all = cases. ------------------------------------------ Cyrus: SASL Permalink: https://cyrus.topicbox.com/groups/sasl/Tee3bf01947b01310-M7fc829= f84cd9180204dbc69f Delivery options: https://cyrus.topicbox.com/groups/sasl/subscription --16843583961.89c5f.901182 Date: Wed, 17 May 2023 17:19:56 -0400 MIME-Version: 1.0 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <!DOCTYPE html> <html><html><html><body><div>I just created a new PR on github to allow for= multiple service principals in a single service, and to allow overriding t= he auto-generated service principal name.<br /></div><div><br /></div><div>= <a href=3D"https://github.com/cyrusimap/cyrus-sasl/pull/763">https://github= .com/cyrusimap/cyrus-sasl/pull/763</a><br /></div><div><br /></div><div>Wit= h the new code, specifying the option <code style=3D"border-radius: 3p= x; border: 1px solid rgb(204, 204, 204); padding: 1px 3px; background: rgb(= 246, 246, 246); font-family: menlo, consolas, monospace; font-size: 90%; --= darkreader-inline-border-top: #3e4446; --darkreader-inline-border-right: #3= e4446; --darkreader-inline-border-bottom: #3e4446; --darkreader-inline-bord= er-left: #3e4446; --darkreader-inline-bgimage: initial; --darkreader-inline= -bgcolor: #1d2021;">accept_any_principal</code> will cause the GSSAPI plugi= n to accept any service principal with a valid entry in the keytab, per bes= t practice.<br /></div><div><br /></div><div>I kept the existing behaviour = the same to avoid backwards compatibility issues, although I'd argue th= e current behaviour is undesirable in almost all cases.<br /></div><div><br= /></div><div id=3D"topicbox-footer" style=3D"margin:10px 0 0;border-top:1p= x solid #ddd;border-color:rgba(0,0,0,.15);padding:7px 0;"> <strong><a href=3D"https://cyrus.topicbox.com/latest" style=3D"color:inheri= t;text-decoration:none">Cyrus</a></strong> / SASL / see <a href=3D"https://cyrus.topicbox.com/groups/sasl">discussions</a> + <a href=3D"https://cyrus.topicbox.com/groups/sasl/members">participants</a> + <a href=3D"https://cyrus.topicbox.com/groups/sasl/subscription">delivery&nb= sp;options</a> <a href=3D"https://cyrus.topicbox.com/groups/sasl/Tee3bf01947b01310-M7fc829= f84cd9180204dbc69f" style=3D"float:right">Permalink</a> </div> </body></html></html></html>= --16843583961.89c5f.901182--