[3943] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

[krbdev.mit.edu #1352] Cannot return prot_ready without unwrap

daemon@ATHENA.MIT.EDU (Sam Hartman via RT)
Thu Feb 20 20:16:37 2003

Date: Thu, 20 Feb 2003 20:16:11 -0500 (EST)
Mail-Followup-To: rt@krbdev.mit.edu
Message-Id: <rt-1352-4605.14.1910658821412@krbdev.mit.edu>
In-Reply-To: <rt-1352@krbdev.mit.edu>
From: "Sam Hartman via RT" <rt-comment@krbdev.mit.edu>
Mail-Copies-To: never
To: wyllys.ingersoll@sun.com
cc: krb5-prs@mit.edu
Reply-To: rt-comment@krbdev.mit.edu
Errors-To: krb5-bugs-bounces@mit.edu



Hi.  I actually think our implementation is wrong to set the
prot_ready flag before context establishment is complete.  If it sets
that flag then both gss_wrap and gss_unwrap need to work.  However
gss_unwrap cannot work because the sequence state is not yet
initialized.


I'm also not sure that RFC 1964 allows this behavior; I don't think
having inconsistent support for prot_ready between implementations is
a good idea.


Why do you need this for SPNEGO?  You don't have to generate the
meclistmic until after the underlying mechanism has returned complete.


_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
http://mailman.mit.edu/mailman/listinfo/krb5-bugs

home help back first fref pref prev next nref lref last post