[19538] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Writing gss mechanism - Kerberos user2user

daemon@ATHENA.MIT.EDU (Greg Hudson)
Sun Feb 5 11:28:02 2017

To: Idan Freiberg <speidy@gmail.com>, krbdev@mit.edu
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <0eaf4b0a-6709-ec01-1c48-98acfe1aa96a@mit.edu>
Date: Sun, 5 Feb 2017 11:27:48 -0500
MIME-Version: 1.0
In-Reply-To: <CAOWMy3n+vFCF5-ajK5Ji-jaYx67KLnSTX04EWaZpK-u6TEHouQ@mail.gmail.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On 02/05/2017 01:21 AM, Idan Freiberg wrote:
> While it is possible, i'm not sure its the right way. One reason for that
> is because MS doesn't specify user2user mech as a seperate mech in
> MechTypes (NegoTokenInit).
> They actually ask for official krb5 or mskrb5 oids, then they include the
> user2user token as the MechToken of the request.

That's a little surprising.  Is there any Microsoft documentation on
this u2u mechanism?  I wasn't able to find any.
draft-ietf-cat-user2user-02 (which is ancient) gives a different OID for
use with SPNEGO.


_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post