[19144] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

S4U2self and S4U2proxy don't honor Canonicalize option

daemon@ATHENA.MIT.EDU (Srinivas Cheruku)
Tue Mar 24 05:44:50 2015

From: "Srinivas Cheruku" <srinivas.cheruku@gmail.com>
To: "'krbdev@mit.edu'" <krbdev@mit.edu>
Date: Tue, 24 Mar 2015 15:14:35 +0530
Message-ID: <003101d06617$25322a70$6f967f50$@gmail.com>
MIME-Version: 1.0
Content-Language: en-in
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

Hello,

 

I am sending S4U2self and S4U2proxy requests to MS AD (2003/2008/2012) and
found that the client name in these tickets is not canonicalized even though
KDC option Canonicalize is set.

 

Any idea why MS AD is not canonicalizing the client name in these tickets? 

Is there any other option that needs to be set to get the canonicalized
client name in the S4U2self and S4U2proxy tickets? 

 

I found an heimdal thread
http://comments.gmane.org/gmane.comp.encryption.kerberos.heimdal.general/611
1 which also talks about this issue.

 

Thanks,
Srini

_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post