[4126] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

Re: [krbdev.mit.edu #1415] subkeys fubar

daemon@ATHENA.MIT.EDU (Sam Hartman)
Sun Apr 20 00:59:17 2003

To: rt-comment@krbdev.mit.edu
From: Sam Hartman <hartmans@MIT.EDU>
Date: Sun, 20 Apr 2003 00:59:07 -0400
In-Reply-To: <rt-1415-5776.7.83886159285387@krbdev.mit.edu> (Tom Yu via's
 message of "Fri, 18 Apr 2003 20:04:06 -0400 (EDT)")
Message-ID: <tslr87x3gtg.fsf@konishi-polis.mit.edu>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
cc: krb5-prs@mit.edu
Errors-To: krb5-bugs-bounces@mit.edu

>>>>> "Tom" == Tom Yu via RT <rt-comment@krbdev.mit.edu> writes:


    Tom> If we change client code to additionally smash the local
    Tom> subkey if it receives a subkey from the server, then the
    Tom> semantic of "server subkey wins" will be accomplished.  This
    Tom> change to the client code won't break against servers with
    Tom> the old behavior of merely sending back in the AP-REP the
    Tom> client subkey as received in the AP-REQ.

I think this is probably wrong to do though.  I think this discussion
is best handled in person than through the bug system.

_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
http://mailman.mit.edu/mailman/listinfo/krb5-bugs

home help back first fref pref prev next nref lref last post