[19994] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: [kitten] Checking the transited list of a kerberos ticket in a

daemon@ATHENA.MIT.EDU (Nico Williams)
Fri Nov 22 17:46:16 2019

Date: Fri, 22 Nov 2019 16:45:28 -0600
From: Nico Williams <nico@cryptonector.com>
To: Stefan Metzmacher <metze@samba.org>
Message-ID: <20191122224526.GA28614@localhost>
MIME-Version: 1.0
Content-Disposition: inline
In-Reply-To: <22f96c93-0217-0b2b-d7e1-684f9269fba4@samba.org>
Cc: "heimdal-discuss@sics.se" <heimdal-discuss@sics.se>,
        Viktor Dukhovni <viktor1dane@dukhovni.org>,
        Samba Technical <samba-technical@lists.samba.org>,
        "krbdev@mit.edu Dev List" <krbdev@mit.edu>, kitten@ietf.org
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Fri, Nov 22, 2019 at 11:24:44AM +0100, Stefan Metzmacher wrote:
> > Correspondingly and symmetrically, the right way to request some
> > behavior on the side where the credential is available, is to associate
> > that request with the desired_name for which the credential is acquired.
> 
> So you mean we need to pass an explicit desired_name to
> gss_acquire_cred_from() and use gss_set_name_attribute() calls
> (for no_transit_check and iterate_acceptor_keytab) on that desired_name
> before?

Oh, wait, right.  That's not going to work when you want a default
credential.

Alright.  I've got a nasty cold and can't think straight, and deadlines
to meet to boot too.  I'll respond more thoughtfully some time next
week.

Nico
-- 
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post