[25039] in Kerberos

home help back first fref pref prev next nref lref last post

Delegation using MIT client

daemon@ATHENA.MIT.EDU (ambekar@gmail.com)
Wed Nov 30 16:15:24 2005

From: "ambekar@gmail.com" <ambekar@gmail.com>
Date: 26 Nov 2005 00:08:07 -0800
Message-ID: <1132992487.058931.107890@o13g2000cwo.googlegroups.com>
To: kerberos@mit.edu
Errors-To: kerberos-bounces@mit.edu

I am trying to do delegation using gssapi/MIT client. I am using
Microsoft Kerberos and I have configured my UNIX boxes for the kerberos
realm. I am able to make my application and service work in this
environment. I have a requirement to make client credetials delegated
to server for impersonation.
I have created forwardable and proxiable ticket (I tried ticket for
service as well as tgt). I am trying to call gss_init_sec_context with
GSS_C_DELEG_FLAG flag. gss_init_contect returns with
GSS_S_CONTINUE_NEEDED, but ret_flags does not contain GSS_C_DELEG_FLAG!
Also, with this context, gss_accept_sec_context returns NULL value for
the delegated_cred_handle. Any clues on this?

Thanks in advance.
Ashwin Ambekar

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post