[27680] in Kerberos
Re: GSS-API routine for renewing credentials
daemon@ATHENA.MIT.EDU (Nicolas Williams)
Wed Apr 18 18:17:41 2007
Date: Wed, 18 Apr 2007 17:16:23 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
To: Robert <rob_krb@xs4all.nl>
Message-ID: <20070418221622.GA4375@Sun.COM>
Mail-Followup-To: Robert <rob_krb@xs4all.nl>, kerberos@mit.edu
Mime-Version: 1.0
Content-Disposition: inline
In-Reply-To: <000f01c78206$56438a30$8ff5fea9@rapido>
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
On Thu, Apr 19, 2007 at 12:10:12AM +0200, Robert wrote:
> I do have control over the protocol (That is, in one instance. Another
> instance will
> probably make use of SASL). Thanks for your elaborate answer. It's much
> appreciated.
> I 'll go and play around with it a bit.
Even if you're using SASL, if you have control over the application
protocol you may still be able to signal the peer to tear down the SASL
security layers and start over with new SASL authentication and security
layers.
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos