[18961] in Kerberos_V5_Development
Re: requesting MS-PAC in AS-REQ
daemon@ATHENA.MIT.EDU (Nate Rosenblum)
Thu Aug 7 15:37:51 2014
MIME-Version: 1.0
In-Reply-To: <53E3D1B5.70802@mit.edu>
Date: Thu, 7 Aug 2014 12:37:44 -0700
Message-ID: <CACK7m--BCU2UQ_oTywdt6WCYWhhGb9375s=qMwcgLKLfjWRhkw@mail.gmail.com>
From: Nate Rosenblum <nater@maginatics.com>
To: Greg Hudson <ghudson@mit.edu>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
>
> I think you are right for now. I will open a ticket that we should add
> krb5_get_init_creds_opt_set_pac_request like Heimdal does.
> Unfortunately there isn't time to get it into 1.13.
>
> Under what circumstances does AD use this padata element? I thought
> that it normally included a PAC by default, unless the service principal
> is configured not to require it.
>
I believe that Windows servers will only return a PAC in the AS-REP and
TGS-REP messages if requested; that's my reading of MS-KILE, Sec. 3.3.5.3 (
http://msdn.microsoft.com/en-us/library/cc233897.aspx). I could be wrong;
let me double-check.
--nate
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev