GSSAPI improvements PR

"carson.gaspar via SASL" <[email protected]> Wed, 17 May 2023 17:19:56 -0400
Newsgroups gmane.comp.security.cyrus.sasl
Message-ID <[email protected]>
--16843583961.89c5f.901182
Date: Wed, 17 May 2023 17:19:56 -0400
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

I just created a new PR on github to allow for multiple service principals =
in a single service, and to allow overriding the auto-generated service pri=
ncipal name.

https://github.com/cyrusimap/cyrus-sasl/pull/763

With the new code, specifying the option=C2=A0accept_any_principal will cau=
se the GSSAPI plugin to accept any service principal with a valid entry in =
the keytab, per best practice.

I kept the existing behaviour the same to avoid backwards compatibility iss=
ues, although I'd argue the current behaviour is undesirable in almost all =
cases.

------------------------------------------
Cyrus: SASL
Permalink: https://cyrus.topicbox.com/groups/sasl/Tee3bf01947b01310-M7fc829=
f84cd9180204dbc69f
Delivery options: https://cyrus.topicbox.com/groups/sasl/subscription

--16843583961.89c5f.901182
Date: Wed, 17 May 2023 17:19:56 -0400
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE html>
<html><html><html><body><div>I just created a new PR on github to allow for=
 multiple service principals in a single service, and to allow overriding t=
he auto-generated service principal name.<br /></div><div><br /></div><div>=
<a href=3D"https://github.com/cyrusimap/cyrus-sasl/pull/763">https://github=
.com/cyrusimap/cyrus-sasl/pull/763</a><br /></div><div><br /></div><div>Wit=
h the new code, specifying the option&nbsp;<code style=3D"border-radius: 3p=
x; border: 1px solid rgb(204, 204, 204); padding: 1px 3px; background: rgb(=
246, 246, 246); font-family: menlo, consolas, monospace; font-size: 90%; --=
darkreader-inline-border-top: #3e4446; --darkreader-inline-border-right: #3=
e4446; --darkreader-inline-border-bottom: #3e4446; --darkreader-inline-bord=
er-left: #3e4446; --darkreader-inline-bgimage: initial; --darkreader-inline=
-bgcolor: #1d2021;">accept_any_principal</code> will cause the GSSAPI plugi=
n to accept any service principal with a valid entry in the keytab, per bes=
t practice.<br /></div><div><br /></div><div>I kept the existing behaviour =
the same to avoid backwards compatibility issues, although I&#39;d argue th=
e current behaviour is undesirable in almost all cases.<br /></div><div><br=
 /></div><div id=3D"topicbox-footer" style=3D"margin:10px 0 0;border-top:1p=
x solid #ddd;border-color:rgba(0,0,0,.15);padding:7px 0;">

<strong><a href=3D"https://cyrus.topicbox.com/latest" style=3D"color:inheri=
t;text-decoration:none">Cyrus</a></strong>
  / SASL / see
<a href=3D"https://cyrus.topicbox.com/groups/sasl">discussions</a>
  +
<a href=3D"https://cyrus.topicbox.com/groups/sasl/members">participants</a>
  +
<a href=3D"https://cyrus.topicbox.com/groups/sasl/subscription">delivery&nb=
sp;options</a>
<a href=3D"https://cyrus.topicbox.com/groups/sasl/Tee3bf01947b01310-M7fc829=
f84cd9180204dbc69f" style=3D"float:right">Permalink</a>
</div>
</body></html></html></html>=

--16843583961.89c5f.901182--