[19185] in Kerberos_V5_Development
Re: Suppressing conf/integ flags in krb5 GSS tokens
daemon@ATHENA.MIT.EDU (Nico Williams)
Mon Jun 1 00:42:41 2015
Date: Sun, 31 May 2015 23:37:23 -0500
From: Nico Williams <nico@cryptonector.com>
To: heimdal-discuss@sics.se, Greg Hudson <ghudson@mit.edu>
Message-ID: <20150601043722.GB600@localhost>
MIME-Version: 1.0
Content-Disposition: inline
In-Reply-To: <20150601040317.GA600@localhost>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
Greg objects to SPNEGO not requesting GSS_C_INTEG_FLAG, and I tend to
agree (since it's possible to design a mechanism that uses -say- bearer
tokens for authentication but does no key exchange unless requested).
To make that work we'd have to change GSS_KRB5_CRED_NO_CI_FLAGS_X to
unset the CI flags rather than not set them by default.
Nico
--
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev