Heimdal rc-hmac and gss_wrap_iov

Andreas Schneider asn at samba.org
Mon Jul 28 06:32:59 MDT 2014


Hi Love,

Günther and I are currently working on MIT Kerberos support for the Samba AD 
DC.

We would like to always use the gss_(un)wrap_iov*() functions but it isn't 
possible with Heimdal codebase right now.

a) gss_wrap_iov doesn't work with rc4-hmac
b) gss_wrap_iov doesn't support GSS_IOV_BUFFER_TYPE_STREAM


Metze already started to hack on this and I took over. The current changes are 
currently here:

https://git.samba.org/?p=asn/samba.git;a=shortlog;h=refs/heads/master-gss_wrap_iov


Could you please take a look if you're fine with the approach. I'm a total 
GSSAPI newbie so I have a hard time finding the right functions to call and 
split up the blob. So advice and help is very welcome.


Best regards,


	-- andreas

-- 
Andreas Schneider                   GPG-ID: CC014E3D
Samba Team                             asn at samba.org
www.samba.org



More information about the samba-technical mailing list