[3952] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

[krbdev.mit.edu #1352] kg_seal should check GSS_C_PROT_READY_FLAG

daemon@ATHENA.MIT.EDU (via RT)
Fri Feb 21 15:33:25 2003

Date: Fri, 21 Feb 2003 15:32:23 -0500 (EST)
Mail-Followup-To: rt@krbdev.mit.edu
Message-Id: <rt-1352-4613.12.8050574259299@krbdev.mit.edu>
In-Reply-To: <rt-1352@krbdev.mit.edu>
From: " via RT" <rt-comment@krbdev.mit.edu>
Mail-Copies-To: never
To: wyllys.ingersoll@sun.com
cc: krb5-prs@mit.edu
Reply-To: rt-comment@krbdev.mit.edu
Errors-To: krb5-bugs-bounces@mit.edu

[hartmans - Fri Feb 21 15:24:02 2003]:

> >>>>> "Nicolas" == Nicolas Williams via RT <rt-comment@krbdev.mit.edu>
> writes:
> 
> 
>     Nicolas> But even so, I think it makes plenty of sense to allow
>     Nicolas> the client to send the MIC as soon as the mech it picks
>     Nicolas> to negotiate for optimistically is ready to do so.
> 
> I'd agree with you except that this is fairly clearly prohibited by
> section 3.2.2 of the RFC.  I suspect SPNEGO predates prot-ready.

Sam, you are correct, I had not noticed that.  HOWEVER, the MIT code
seems to want to support PROT_READY, but the support is not complete
and that is what this bug report is about.  Regardless of the SPNEGO
issue, the fact is that the MIT krb5 does not support PROT_READY
correctly.

Nico


_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
http://mailman.mit.edu/mailman/listinfo/krb5-bugs

home help back first fref pref prev next nref lref last post