[kitten] Checking the transited list of a kerberos ticket in a transitive cross-realm trust situation...
metze at samba.org
Thu Aug 24 13:11:16 UTC 2017
>> I guess the proposed credential option is necessary, in that case.
> I think in this case ignoring the flag should probably be conditional
> to whether a PAC is present.
We should enforce a PAC always to be present, as we don't support
trusted domains with LSA_TRUST_TYPE_MIT anyway.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 836 bytes
Desc: OpenPGP digital signature
More information about the samba-technical