Issues bringing 'new SPENGO' to MIT Kerberos 1.8 builds
simo
idra at samba.org
Tue Feb 14 09:56:02 MST 2012
On Tue, 2012-02-14 at 15:50 +1100, Andrew Bartlett wrote:
> On Tue, 2012-02-14 at 13:42 +1100, Luke Howard wrote:
> > What do you need gss_krb5_export_lucid_sec_context for? Can you use GSS_C_INQ_SSPI_SESSION_KEY?
>
> We used it to determine if CFX was used, and therefore that the new
> (returning the mechListMic) SPENGO should be used, as we implement
> SPNEGO outside GSSAPI.
I meant to ask for a while, why don't we drop our own SPENGO and simply
use the one in GSSAPI ? Are there deficiencies in it ?
Simo.
--
Simo Sorce
Samba Team GPL Compliance Officer <simo at samba.org>
Principal Software Engineer at Red Hat, Inc. <simo at redhat.com>
More information about the samba-technical
mailing list