Samba and MIT Kerberos

Jeffrey Altman jaltman at MIT.EDU
Sat Apr 16 00:12:42 EDT 2005

Andrew Bartlett wrote:
> On Fri, 2005-04-15 at 22:13 -0400, Jeffrey Altman wrote:
>>Please advise me of any functions you require that MIT currently
>>does not support in addition to the gss_krb5_get_subkey and
>>gsskrb5_extract_authz_data_from_sec_context functions.
> We also require the DCE_STYLE GSSAPI encryption, (metze has a modified
> version of heimdal in a branch of our lorikeet SVN repository that
> implements this, but has been dragged back into studies and not cleaned
> it up for submission).

Can you provide me a reference?

> On the KDC server-side, we are yet to fully determine what we need - we
> have a hdb module for Heimdal, but it's a kludge in places and by the
> time we finish all this we expect to have futher and more bizarre
> requirements in this area.


> None of this is helped by the fact that I really don't know what I'm
> doing when it comes to kerberos stuff ;-)

That's ok.  We can help you figure it out.

> Andrew Bartlett

