[18932] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: [PATCH] Fix SPNEGO interoperability with servers implementing

daemon@ATHENA.MIT.EDU (Nico Williams)
Mon Aug 4 15:27:52 2014

Date: Mon, 4 Aug 2014 14:27:42 -0500
From: Nico Williams <nico@cryptonector.com>
To: David Woodhouse <dwmw2@infradead.org>
Message-ID: <20140804192741.GY3579@localhost>
MIME-Version: 1.0
Content-Disposition: inline
In-Reply-To: <1407180008.28796.11.camel@infradead.org>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Mon, Aug 04, 2014 at 08:20:08PM +0100, David Woodhouse wrote:
> On Mon, 2014-08-04 at 14:01 -0500, Nico Williams wrote:
> > You should be able to 
> 
> ... patch every application in the system, including third party apps
> like Google Chrome, to ...
> 
> > gss_set_neg_mechs() to disable offering mechanisms you can't / don't
> > want to use.
> 
> :(

Yeah, we have a problem :(

One option might be to require calling gss_set_neg_mechs() to enable
offering mechanisms other than Kerberos and NTLM.  Greg?

Nico
-- 
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post