Kerberos Digest, Vol 9, Issue 25

Sam Hartman hartmans at MIT.EDU
Thu Sep 25 16:34:44 EDT 2003


>>>>> "Kumaresh" == Kumaresh  <kumaresh_ind at gmx.net> writes:

    Kumaresh> Passing GSS_C_NO_NAME will NOT compare the name in
    Kumaresh> server and client credentials, if I am correct. If so,
    Kumaresh> is this not bad in security point of view?

It will accept any valid server credential.  I.E. for Kerberos,
anything in the keytab



More information about the Kerberos mailing list