Why do "strict acceptor checking"?

Russ Allbery eagle at eyrie.org
Tue Oct 8 21:19:01 EDT 2024


Ken Hornstein via Kerberos <kerberos at mit.edu> writes:

>> Me too. We've been recommending calling gss_accept_sec_context with
>> GSS_C_NO_CREDENTIAL for a long time, and almost no one does that.  it's
>> very annoying.

> It's comforting to know that at least I'm not the only old, grizzled
> Kerberos user that feels that way.

You definitely are not.  I don't know how many times I've tried to explain
this to people.

-- 
Russ Allbery (eagle at eyrie.org)             <https://www.eyrie.org/~eagle/>


More information about the Kerberos mailing list