[27680] in Kerberos

home help back first fref pref prev next nref lref last post

Re: GSS-API routine for renewing credentials

daemon@ATHENA.MIT.EDU (Nicolas Williams)
Wed Apr 18 18:17:41 2007

Date: Wed, 18 Apr 2007 17:16:23 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: Robert <rob_krb@xs4all.nl>
Message-ID: <20070418221622.GA4375@Sun.COM>
Mail-Followup-To: Robert <rob_krb@xs4all.nl>, kerberos@mit.edu
Mime-Version: 1.0
Content-Disposition: inline
In-Reply-To: <000f01c78206$56438a30$8ff5fea9@rapido>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

On Thu, Apr 19, 2007 at 12:10:12AM +0200, Robert wrote:
> I do have control over the protocol (That is, in one instance. Another 
> instance will
> probably make use of SASL). Thanks for your elaborate answer. It's much 
> appreciated.
> I 'll go and play around with it a bit.

Even if you're using SASL, if you have control over the application
protocol you may still be able to signal the peer to tear down the SASL
security layers and start over with new SASL authentication and security
layers.
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post