[27534] in Kerberos

home help back first fref pref prev next nref lref last post

RE: Extract Information from Ticket.

daemon@ATHENA.MIT.EDU (Bruce Stewart)
Mon Mar 5 03:19:22 2007

Content-Class: urn:content-classes:message
MIME-Version: 1.0
Date: Mon, 5 Mar 2007 10:18:15 +0200
Message-ID: <A7589312AB39244FA9071CC60A97951EB13C2F@commsbert.nsfas.org.za>
From: "Bruce Stewart" <BruceS@nsfas.org.za>
To: "Michael B Allen" <mba2000@ioplex.com>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Hi Michael,

> Actually only with jcifs-ext and that package is horribly out 
> of date. 

Agreed that it is horribly out of date ;-).  I mentioned "jcifs and jcifs-ext" because jcifs-ext depends on jcifs, and jcifs therefore needs to be included.

> The
> stock jcifs distribution only supports NTLM SSO (but that 
> actually works
> quite well assuming you don't need delegation).

FWIW...the spnego classes accept NTLM aswell as Kerberos tokens - which was  a problem for us - we only wanted Kerberos tokens (because we wanted delegation).  I created our own bare bones version of the jcifs.spnego.Authentication class - removed the jcifs dependencies (i.e. NTLM code), "client" code and reflection based GSS-API code.  Instead of returning a Principal with authentication.getPrincipal(), we return a javax.security.auth.Subject (which contains the KerberosPrincipal and KerberosTicket) with getSubject().  That allows us to use Subject.doAs(subject, ...) etc.

Using the jcifs-ext code as a guide it was pretty easy for us to create exactly what we needed.

Cheers,
Bruce

-- 
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.5.446 / Virus Database: 268.18.7/710 - Release Date: 04/03/2007 13:58
 

This e-mail and any files transmitted with it are confidential and intended solely for the use of the individual or entity to which they are addressed.  If you have received this e-mail in error please notify NSFAS immediately.  Please note that any views or opinions presented in this e-mail are solely those of the author and do not necessarily represent those of the organisation.


________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post