[kitten] Checking the transited list of a kerberos ticket in a transitive cross-realm trust situation...
metze at samba.org
Thu Aug 24 09:11:16 EDT 2017
>> I guess the proposed credential option is necessary, in that case.
> I think in this case ignoring the flag should probably be conditional
> to whether a PAC is present.
We should enforce a PAC always to be present, as we don't support
trusted domains with LSA_TRUST_TYPE_MIT anyway.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 836 bytes
Desc: OpenPGP digital signature
Url : http://mailman.mit.edu/pipermail/krbdev/attachments/20170824/de808e15/attachment-0001.bin
More information about the krbdev