[19185] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Suppressing conf/integ flags in krb5 GSS tokens

daemon@ATHENA.MIT.EDU (Nico Williams)
Mon Jun 1 00:42:41 2015

Date: Sun, 31 May 2015 23:37:23 -0500
From: Nico Williams <nico@cryptonector.com>
To: heimdal-discuss@sics.se, Greg Hudson <ghudson@mit.edu>
Message-ID: <20150601043722.GB600@localhost>
MIME-Version: 1.0
Content-Disposition: inline
In-Reply-To: <20150601040317.GA600@localhost>
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu


Greg objects to SPNEGO not requesting GSS_C_INTEG_FLAG, and I tend to
agree (since it's possible to design a mechanism that uses -say- bearer
tokens for authentication but does no key exchange unless requested).

To make that work we'd have to change GSS_KRB5_CRED_NO_CI_FLAGS_X to
unset the CI flags rather than not set them by default.

Nico
-- 
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post