Files
heimdal/tests/kdc
Nicolas Williams dc74e9d00c kdc: Add Heimdal cert ext for ticket max_life
This adds support for using a Heimdal-specific PKIX extension to derive
a maximum Kerberos ticket lifetime from a client's PKINIT certificate.

KDC configuration parameters:

 - pkinit_max_life_from_cert_extension
 - pkinit_max_life_bound

If `pkinit_max_life_from_cert_extension` is set to true then the
certificate extension or EKU will be checked.

If `pkinit_max_life_bound` is set to a positive relative time, then that
will be the upper bound of maximum Kerberos ticket lifetime derived from
these extensions.

The KDC config `pkinit_ticket_max_life_from_cert` that was added earlier
has been renamed to `pkinit_max_life_from_cert`.

See lib/hx509 and lib/krb5/krb5.conf.5.
2021-03-24 19:12:00 -05:00
..
2020-04-25 21:22:32 -05:00
2020-04-25 21:22:32 -05:00
2020-09-08 00:25:24 -05:00
2017-03-10 15:47:43 -05:00
2017-03-10 15:47:43 -05:00
2017-03-10 15:47:43 -05:00
2017-03-10 15:47:43 -05:00
2017-03-10 15:47:43 -05:00
2017-03-10 15:47:43 -05:00
2009-09-21 10:36:37 -07:00
2017-03-10 15:47:43 -05:00
2017-03-10 15:47:43 -05:00
2017-03-10 15:47:43 -05:00
2017-03-10 15:47:43 -05:00
2017-03-10 15:47:43 -05:00
2007-07-28 19:57:50 +00:00
2020-09-08 14:34:08 -05:00
2012-01-10 22:54:16 +01:00
2011-11-23 09:43:56 -08:00
2016-11-14 21:29:47 -06:00
2016-11-14 21:29:47 -06:00
2016-11-14 21:29:47 -06:00
2020-09-08 14:34:08 -05:00
2020-09-18 14:31:43 -05:00
2016-11-14 21:29:47 -06:00
2009-09-21 10:36:37 -07:00
2009-09-21 10:36:37 -07:00
2007-01-10 20:14:59 +00:00
2018-12-18 06:21:07 +13:00