Current semantics for channel-bindings in GSSAPI

Isaac Boukris iboukris at
Mon Mar 2 09:12:28 EST 2020

On Fri, Feb 28, 2020 at 6:00 PM Greg Hudson <ghudson at> wrote:
> On 2/27/20 8:27 PM, Isaac Boukris wrote:
> > Following the discussion on  IRC, there is currently a difference in
> > between Heimdal and MIT, when the client does not send bindings, and
> > the server does pass bindings to accept(), in MIT it fails, in Heimdal
> > it succeeds.
> There are a few reasons why I think Heimdal's behavior is better:

Taking a closer look at MIT accept() code, it looks like there is a
case where no checksum is provided at all, where MIT would skip
channel-bindings even if the server provided ones. It sounds like
Windows also supports this.

More information about the krbdev mailing list