[19271] in Kerberos_V5_Development
Re: Questions on gss_verify_mic_iov
daemon@ATHENA.MIT.EDU (Natalie Li)
Mon Sep 28 17:27:54 2015
Message-ID: <5609B052.7010907@oracle.com>
Date: Mon, 28 Sep 2015 14:25:38 -0700
From: Natalie Li <natalie.li@oracle.com>
MIME-Version: 1.0
To: Greg Hudson <ghudson@mit.edu>
In-Reply-To: <5606BE67.9020502@mit.edu>
Cc: MIT Kerberos Dev List <krbdev@mit.edu>,
Satish Pudi <satish.pudi@oracle.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
On 9/26/2015 8:48 AM, Greg Hudson wrote:
> On 09/23/2015 04:08 PM, Natalie Li wrote:
>> 2) MS version of gss_verify_mic_iov (AKA [MS-KILE] 3.4.5.7
>> GSS_VerifyMICEx()) successfully verify the MIC token even when the MIC
>> token w/ the trailing zeros is passed as function argument.
>>
>> Can the checksum_iov_v3() be updated as we previously discussed?
> Did Luke's reply adequately address this issue? You can use
> gss_get_mic_iov_length() to interrogate the context for the appropriate
> length of a MIC token, and truncate the received MS-RPCE token to that
> value.
Yes, it does. Thanks!
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev