credentials_krb5: use gss_acquire_cred for client-side GSSAPI use case

Stefan Metzmacher metze at samba.org
Mon Mar 6 06:03:39 UTC 2017


Hi Alexander,

>>> ACK. Will do that.
>> I pushed current patchset to
>> https://git.samba.org/?p=ab/samba.git/.git;a=shortlog;h=refs/heads/master-gss_acquire_cred_from
>>
>> I'm running tests right now. Will submit final patch once they pass.
> Final patch is attached.

I think we should also handle the keytab_principal argument
(or drop it from the argument list of the wrapper).

And please also add the fallback logic for broken
of gse_init_server() to handle the broken gss_krb5_import_cred()
for the acceptor into the wrapper. And/or reseach if the fallback
logic is still needed with our requirement for MIT 1.9.

Thanks!
metze


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: OpenPGP digital signature
URL: <http://lists.samba.org/pipermail/samba-technical/attachments/20170306/cf1d563a/signature.sig>


More information about the samba-technical mailing list