[19191] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Suppressing conf/integ flags in krb5 GSS tokens

daemon@ATHENA.MIT.EDU (Nico Williams)
Mon Jun 1 15:16:05 2015

Date: Mon, 1 Jun 2015 14:15:45 -0500
From: Nico Williams <nico@cryptonector.com>
To: Benjamin Kaduk <kaduk@mit.edu>
Message-ID: <20150601191544.GH600@localhost>
MIME-Version: 1.0
Content-Disposition: inline
In-Reply-To: <alpine.GSO.1.10.1506011257160.22210@multics.mit.edu>
Cc: heimdal-discuss@sics.se, krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Mon, Jun 01, 2015 at 01:04:22PM -0400, Benjamin Kaduk wrote:
> That seems correct.  Section 1.2.2:
> 
>    GSS-API callers desiring per-message security services should check
>    the values of these flags at context establishment time, and must be
>    aware that a returned FALSE value for integ_avail means that
>    invocation of GSS_GetMIC() or GSS_Wrap() primitives on the associated
>    context will apply no cryptographic protection to user data messages.
> 
> Note that this seems to imply that you can generate a MIC which provides
> no integrity benefit, calling the above assumption into question.

Ugh.  That's like the GSS_Add_cred() text: broken and unmatched by
reality.

As to MIT Kerberos, you *of course* know what *it* does.

Nico
-- 
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post