Commit graph

5 commits

Author SHA1 Message Date
Olga Kornievskaia
4222bd6f2b [sspi] passing gss seq# to sspi privacy api 2011-03-24 14:41:31 -04:00
U-ultimate\aglo
332f9331a2 [sspi] removing size constraints on contest tokens
MIT KDC don't issue tickets that are better than 1K.

Windows KDC carry authorization payloads with their service tickets
and thus much bigger than MIT's tickets.
2011-03-24 11:38:51 -04:00
Olga Kornievskaia
5e5d1d21d5 fixing compile warnings and funciton name typos 2011-03-22 14:49:27 -04:00
Olga Kornievskaia
4411d3d807 first stab at integrity and privacy
note: privacy will not work when we have more than 1 outstanding rpcs which generates out of order replies which sspi does not allow when privacy is enabled.

adding auth_wrap() and auth_unwrap() to per-message gss token protection required adding these methods to auth_sys and auth_non.

linux server doesnt support v2 kerberos tokens that have rotated data. sspi will always produce such tokens for aes. thus thus code was only tested for v1 kerberos tokens (ie des).
2011-01-27 13:52:08 -05:00
Olga Kornievskaia
b9494c3ccc first stab at SSPI leaving gss calls in 2010-12-02 14:22:04 -05:00