[18960] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: requesting MS-PAC in AS-REQ

daemon@ATHENA.MIT.EDU (Greg Hudson)
Thu Aug 7 15:21:40 2014

Message-ID: <53E3D1B5.70802@mit.edu>
Date: Thu, 07 Aug 2014 15:21:25 -0400
From: Greg Hudson <ghudson@mit.edu>
MIME-Version: 1.0
To: Nate Rosenblum <nater@maginatics.com>, krbdev@mit.edu
In-Reply-To: <CACK7m--k3afKZPOVu-OWgLSyqhXvdNyqEjsfttLP+tkk+knaxA@mail.gmail.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On 08/06/2014 06:12 PM, Nate Rosenblum wrote:
> When requesting a TGT from a Microsoft KDC, I'd like to request a PAC by
> adding a KRB5_PADATA_PAC_REQUEST to the PADATA. I looked through the public
> headers and no method for doing this jumps out at me; is this something for
> which I'd need to add a client preauth module for?

I think you are right for now.  I will open a ticket that we should add
krb5_get_init_creds_opt_set_pac_request like Heimdal does.
Unfortunately there isn't time to get it into 1.13.

Under what circumstances does AD use this padata element?  I thought
that it normally included a PAC by default, unless the service principal
is configured not to require it.
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post