[16457] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: inspecting krb5 ticket in GSSAPI

daemon@ATHENA.MIT.EDU (Luke Howard)
Tue Nov 9 16:30:32 2010

Mime-Version: 1.0 (Apple Message framework v1081)
From: Luke Howard <lukeh@padl.com>
In-Reply-To: <3C3C22DA02DF9F4FFB3FFB76@dhcp-172-19-76-254.mtv.corp.google.com>
Date: Wed, 10 Nov 2010 08:29:57 +1100
Message-Id: <BA2373AB-FCD6-439B-9296-26E0AA6FF2CD@padl.com>
To: Frank Cusack <frank+krb@linetwo.net>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu


On 10/11/2010, at 6:50 AM, Frank Cusack wrote:

> If I want my GSSAPI server application to inspect the kerberos
> ticket flags, is there a way to do this?

gss_krb5_get_tkt_flags()

> It looks like I would just take the token the client sent, verify
> the mechanism and then *do something* to extract the krb5 ticket.
> Then I could create a krb5 context and look at the flags.

There's no way to get the raw ticket.

-- Luke
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post