[19479] in Kerberos_V5_Development
Re: Accepting security contexts,
daemon@ATHENA.MIT.EDU (Robbie Harwood)
Fri Sep 2 15:53:13 2016
From: Robbie Harwood <rharwood@redhat.com>
To: Dylan Klomparens <dylan.klomparens@gmail.com>
In-Reply-To: <CANy6xUekDyfSrVavc44y2zmVuKjkU2MA67+QLY9-GfPPKnPR5A@mail.gmail.com>
Date: Fri, 02 Sep 2016 15:50:51 -0400
Message-ID: <jlgzinq13ok.fsf@thriss.redhat.com>
MIME-Version: 1.0
Cc: krbdev@mit.edu
Content-Type: multipart/mixed; boundary="===============4265875935691166085=="
Errors-To: krbdev-bounces@mit.edu
--===============4265875935691166085==
Content-Type: multipart/signed; boundary="=-=-=";
micalg=pgp-sha1; protocol="application/pgp-signature"
--=-=-=
Content-Type: text/plain
Dylan Klomparens <dylan.klomparens@gmail.com> writes:
> I am writing a module for Apache HTTPD. The prototype module code is on
> GitHub:
>
> https://github.com/dylan-klomparens/mod_kerberos/blob/master/mod_kerberos.c
If this is for anything other than your own learning, you may wish to
use the (already packaged in all distros) mod_auth_gssapi instead:
https://github.com/modauthgssapi/mod_auth_gssapi
> I have a test setup to compare with, running mod_auth_kerb. Using that
> testbed, Kerberized access to the test web page works properly. This
> leaves me relatively certain that my keytab is valid and my browser is
> sending credentials properly.
I'd check that you're decoding the tokens properly and passing them in
to accept_sec_context in the expected way.
--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBAgAGBQJXydiaAAoJECUy+RdqlaRCFIkP/2YeeUNoryQHv9RL3upEzxax
HaKx+f0g6R8fOdqSSfOMAuKnjBqqutlwA4k3LbVZO9nHdIouFtSivewE4dAuMpE8
hd8CxXhFbUw9qW4Mu+ngtB5L47fD7WBpXyPH2xwTM3ZPt/EdvLn/APj6gRix9Vp9
BHp05qk+UmtLjQCGKdCRu23FKcyZlNrm0+NtIVMJMzfsjv65ZkBP0+OR5N85Beb6
UeFN7o3jVRVyGMynrjiNEVAKEEYev3+MVFvBFaKxXF2AYxSsIZ8XO7NlrzJJczd4
g22zCtEFXbl/4ZFNfMbPqwk7lsVScAzGqMkJ6yXCAWjhOYChyKobr9wN8f41QM8h
7AQYkB0SYd7M04v9MEZ00yrkXRYGN9+11WMnMBikKDvdJ6jeC6Eh0UTxZz3XLOR5
xGj5N9zVLaICNj6aqYnIqDvYc9xZSkDtu/lCvxMr5iV9oogdkKczfbH91FRP1eF1
StNgKl0tnE7guxIzPvuGzoyCCC0//G6ghhhXTUuFyWH30/G//AMKLCujXSF3O6oC
A1mJgmVreBE+eK8Q0XfdxHh00oXLddxsSdWxw0vHjL26wSv6cKySUKIZaEPrUnOd
kwju20CByVGku9CYAa28Lcnt7UDcs+6LIEwy7eN2xYjdho79OnAWvj7WgwBLilMq
kNwkLgVfJJdxNBZ4ZUbE
=hDiY
-----END PGP SIGNATURE-----
--=-=-=--
--===============4265875935691166085==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev
--===============4265875935691166085==--