[krbdev.mit.edu #7044] gss_init_sec_context misbehaves on mismatched credentials

Greg Hudson via RT rt-comment at krbdev.mit.edu
Wed Dec 7 11:54:13 EST 2011


Another reasonable behavior would be to see if the requested mechanism 
supports some kind of credential import.  SPNEGO would implement this SPI; 
other mechansms probably wouldn't.  That's a lot more work than failing 
out with GSS_S_BAD_MECH, of course.


More information about the krb5-bugs mailing list