[19270] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Questions on gss_verify_mic_iov

daemon@ATHENA.MIT.EDU (Greg Hudson)
Sat Sep 26 11:49:09 2015

To: Natalie Li <natalie.li@oracle.com>
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <5606BE67.9020502@mit.edu>
Date: Sat, 26 Sep 2015 11:48:55 -0400
MIME-Version: 1.0
In-Reply-To: <560306C8.8090402@oracle.com>
Cc: MIT Kerberos Dev List <krbdev@mit.edu>,
        Satish Pudi <satish.pudi@oracle.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On 09/23/2015 04:08 PM, Natalie Li wrote:
> 2) MS version of gss_verify_mic_iov (AKA  [MS-KILE] 3.4.5.7
> GSS_VerifyMICEx()) successfully verify the MIC token even when the MIC
> token w/ the trailing zeros is passed as function argument.
> 
> Can the checksum_iov_v3() be updated as we previously discussed?

Did Luke's reply adequately address this issue?  You can use
gss_get_mic_iov_length() to interrogate the context for the appropriate
length of a MIC token, and truncate the received MS-RPCE token to that
value.
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post