[19460] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: any way to get user's ldap dn (or part of it) as part of the

daemon@ATHENA.MIT.EDU (Greg Hudson)
Fri Aug 26 02:32:17 2016

To: Chris Hecker <checker@d6.com>, krbdev@mit.edu
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <57BFE26A.1040900@mit.edu>
Date: Fri, 26 Aug 2016 02:32:10 -0400
MIME-Version: 1.0
In-Reply-To: <57BFE1DD.5070602@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On 08/26/2016 02:29 AM, Greg Hudson wrote:
> Microsoft's PAC is visible to the server, not the client.

Oops, I misread your question.  You want this information in the server,
so yes, you want authdata.  Ignore everything I said about using padata.

We do have an authdata plugin interface, but unfortunately it's
unfinished and not public.  Still, it's probably better than modifying
the code.

Authdata is encrypted in the AS-REP, so you don't have to worry about
protecting the value.  Negative authdata types are reserved for
unregistered use (RFC 4120 section 5.2.6).
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post