[cifs-protocol] RE: How to validate the PAC in NETLOGON
rguthrie at microsoft.com
Wed Dec 3 19:42:33 GMT 2008
We have reviewed your proposed change and have updated the documentation (see attached document) in section 18.104.22.168 of MS-APDS. Please let us know if you have further questions.
Open Protocols Support Team
Support Escalation Engineer, US-CSS DSC PROTOCOL TEAM
Tel: +1 (469) 775-7794
E-mail: rguthrie at microsoft.com
From: Andrew Bartlett [mailto:abartlet at samba.org]
Sent: Thursday, November 13, 2008 2:37 PM
To: Richard Guthrie
Cc: pfif at tridgell.net; cifs-protocol at samba.org
Subject: RE: How to validate the PAC in NETLOGON SRX080918600905
On Thu, 2008-11-13 at 06:23 -0800, Richard Guthrie wrote:
> We have revised the MS-PAC documentation to more accurately reflect
> signature verification requirements in section 2.8 as well as made
> several updates to clarify the relationship between MS-PAC and
> MS-KILE. I have attached those three documents for your review. The
> changes in each document are highlighted in yellow.
> Please let us know if you have any further questions.
In MS-APDS 22.214.171.124 Processing a KERB_VERIFY_PAC_REQUEST Message You really need to say:
The server MUST verify the signature over the server checksum ([MS-PAC]section 2.8.2) and compare the result against the KDC checksum passed in the request.
As you should not say 'signature' without indicating what it is over, and 2.8.2 is a better reference.
Authentication Developer, Samba Team http://samba.org
Samba Developer, Red Hat Inc.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 60154 bytes
Url : http://lists.samba.org/archive/cifs-protocol/attachments/20081203/b9990e9f/SRX081118600177-0001.bin
More information about the cifs-protocol