Files
heimdal/kdc
Luke Howard 2087e07c1e kdc: update PAC hooks for Samba
Samba includes the user's long-term credentials (encrypted in the AS reply key)
to allow legacy authentication protocols such as NTLM to work even if the
pre-authentication mechanism replaced the reply key (as PKINIT does).

Samba also needs to know whether the client explicitly requested a PAC be
included (or excluded), in order to defer PAC exclusion until a service ticket
is issued (thereby avoiding a name binding attack if the user is renamed
between TGT and service ticket issuance).

References:

https://bugzilla.samba.org/show_bug.cgi?id=11441
https://bugzilla.samba.org/show_bug.cgi?id=14561

Closes: #864

Original authors:
 - Joseph Sutton <josephsutton@catalyst.net.nz>
 - Andrew Bartlett <abartlet@samba.org>
 - Stefan Metzmacher <metze@samba.org>
2021-12-14 13:51:53 +11:00
..
2011-07-24 13:07:07 -07:00
2019-10-03 13:09:18 -05:00
2021-12-14 13:24:02 +11:00
2011-05-21 11:57:31 -07:00
2021-12-14 13:51:53 +11:00
2021-12-14 13:51:53 +11:00
2021-12-14 13:51:53 +11:00
2011-05-21 11:57:31 -07:00
2019-12-09 21:39:30 -06:00
2008-09-13 09:21:03 +00:00
2011-05-21 11:57:31 -07:00
2019-12-04 21:34:44 -06:00
2021-12-14 13:51:53 +11:00
2021-12-14 13:51:53 +11:00