[38191] in Kerberos

home help back first fref pref prev next nref lref last post

RE: Different realms

daemon@ATHENA.MIT.EDU (Robbie Harwood)
Sun Jan 28 07:41:39 2018

From: Robbie Harwood <rharwood@redhat.com>
To: Imanuel Greenfeld <imanuel.greenfeld1@ntlworld.com>, kerberos@mit.edu
In-Reply-To: <001601d39829$a0f099c0$e2d1cd40$@ntlworld.com>
Date: Sun, 28 Jan 2018 13:41:02 +0100
Message-ID: <jlgvafmma01.fsf@redhat.com>
MIME-Version: 1.0
Cc: "'Simo Sorce'" <simo@redhat.com>
Content-Type: multipart/mixed; boundary="===============5382683317597282842=="
Errors-To: kerberos-bounces@mit.edu

--===============5382683317597282842==
Content-Type: multipart/signed; boundary="=-=-=";
	micalg=pgp-sha512; protocol="application/pgp-signature"

--=-=-=
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

"Imanuel Greenfeld" <imanuel.greenfeld1@ntlworld.com> writes:

> public void doWithKeytabFile() {
>     KerberosRestTemplate restTemplate =3D
>             new KerberosRestTemplate("/tmp/user2.keytab",
> "user2@EXAMPLE.ORG");
>     restTemplate.getForObject("http://neo.example.org:8080/hello",
> String.class);
> }
>
> As you can see the HTTP request just has one "endpoint" so the keytab nee=
ds
> to be part of it.
>
> But in C++ I cannot find a way how to achieve the same - in other words,
> once I have the keytab in the code, and I separately build the HTTP reque=
st,
> how do I incorporate that keytab to that HTTP request ?=20=20

The keytab isn't part of the request.  The *credential*, which is
derived from the keytab, is part of the request.

> I can only change the client code - the server code is not available to m=
e.
>
> Once again, I'm trying to find C/C++ good example.

You'll most likely need to write it yourself, which is why I linked you
the requests-gssapi version.  I'm not sure anyone's done the client side
of this from C, other than curl [1].  I don't find that easier to read
than the python, but I'm of course biased.

Thanks,
=2D-Robbie

1: https://github.com/curl/curl

--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEA5qc6hnelQjDaHWqJTL5F2qVpEIFAlptxN4ACgkQJTL5F2qV
pEI1gw/6A7gc7puSnkV68uTZEel1rHks7+dX+YCo/MoJABi6Tukkha/4TJjRO4mm
2M1G0xgJjXLYssfZrWvU2wiPX05YGmxhFkC6dOyoxbtzxDzGRt9XiKNt6h1lXJlU
aDan/wHL5GZbAxfyB6x1VVmzbDmsjPydpfYRCnu1HUDFeCn7uCIU++JO6DeFftTp
gW62JrE5zE2NKsjipHnfc+2HbUSEVwu+m4QJHHmkCltY/49GC88RQ1aJ7QGroM2O
ipT0O0qpJ2OF0zrXHVcA/hElC4Uz9mnIAWBLjzulevxfYngCSHNvQmcdfhPgFFhq
zQG3wllgo2VPgkkyuVvlqmVCaw9+jtM8hF30CKAEYtoDTqJSRAMaRBQIKO6KiOiz
ipUIZlkRCB1W6DbVw423tXbKRGuF34Z7hAHHD45niigkJKtDuwEVR7TJmAfc/wdk
lI71ww/geA1Dho+htPoGyP/R+qJdTPTqudx6NweV51D1MGLzCkhOkjVcu1xxjp+A
3iWh6isUzvUCvg5b3hJKGdqT04PUdwb44x3BcbJsq5rk12PMDLnjlMRXf1hlsgJA
8SXUe6fBr2TDtBqA6/7QGLB1LyjH6nbO4Vn3ByrUi8bBfa4jtqMlUKMO2e/JbWPw
2um+AWx2bPmr621d4WAdfyT0jimteCHUiOHxqBNmBFr/z3o+5IE=
=pOMM
-----END PGP SIGNATURE-----
--=-=-=--

--===============5382683317597282842==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

--===============5382683317597282842==--

home help back first fref pref prev next nref lref last post