Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

I do not fear computers. I fear the lack of them. -- Isaac Asimov


devel / comp.protocols.kerberos / Re: heimdal http proxy

SubjectAuthor
o Re: heimdal http proxyBenjamin Kaduk

1
Re: heimdal http proxy

<mailman.3.1631466079.19450.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=140&group=comp.protocols.kerberos#140

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!tncsrv06.tnetconsulting.net!.POSTED.pch.mit.edu!not-for-mail
From: kad...@mit.edu (Benjamin Kaduk)
Newsgroups: comp.protocols.kerberos
Subject: Re: heimdal http proxy
Date: Sun, 12 Sep 2021 10:01:07 -0700
Organization: TNet Consulting
Lines: 13
Message-ID: <mailman.3.1631466079.19450.kerberos@mit.edu>
References: <87sfyq9qtg.fsf@hope.eyrie.org>
<58C9CD4B-C68A-4480-BFD8-29DC38D8C22A@cs.rutgers.edu>
<6589bffb-75be-62f3-5e3e-6c0b315dd865@secure-endpoints.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="pch.mit.edu:18.7.21.50";
logging-data="31417"; mail-complaints-to="newsmaster@tnetconsulting.net"
Cc: "kerberos@mit.edu" <kerberos@mit.edu>
To: Jeffrey Altman <jaltman@secure-endpoints.com>
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=J7G9t25848D82iYpa7vlE54gBLGvBP7I+aIAXZJUESJV23CVSeBeKrzgv7FnRtUUMrdWSDjSvWNVVhmYGTdNBIye/VapFHFzfNDPTv+PN9zcccNVurdOJ9aJcVS2vdAhebbjw9SGrPbgV81683eeiIcCxm/W8zGujR2Oq4u+iVUMog8tBfd+cRIr5yMlgemlcRO4sdTwfZMBDocr6nS4jxldrnLZmT/uoJMnL/XJZV9YxI35Ue574s7pP/vl1iBbnSE1M4IRu7vekMChY0S/ll8xD0sdCjfluPtPkZ6OSimGCoNdJUtNJJLPU+waqHuj4febrwSOkhqN1QigzBSHXw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version;
bh=KJPccw5/+ydIUJN2rN4XDhxp18UffcSfKbYf3oQxIQA=;
b=iWLXpbKgKVtSCnjjJRrvCrQdO5T0Jik7W8uFI5RlY+Qf7C7V5fsFQnav/lNwGiu2mKvTHTHx2Fzb74Tdw0jwp0ope/vgrGN96/d5CPTlOJt+xhpET1qaEGZm4+7B81ScRptyisTRaGbxamMEu2LoaF2KIhNb0pC9gSFhGTimQlIRx+I5NcAi7SMx3mCxXKhz9DR/JzuGuBh8dVIuGOLvs+ojfrqYgBIh6ib7T7mmh8geRZLxoXMXYxOB2afJ/njRGA78AFd1dJNZ9zK5YXLbG16dlFAikIaxkB8fdLuQ0mFbyA0KUyP+G7g5dSHB9hCMhcTbsTIfKUau2vaS3Bhkxw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none;
dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mit.edu; s=selector2;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=KJPccw5/+ydIUJN2rN4XDhxp18UffcSfKbYf3oQxIQA=;
b=Y+jXMcE5VcQZ9lJKJEFiXXlx/tWfFCpXCshuBkeQeoYBQQl2ok+anWZdY+oEy3hzmueDWA6y0Vt4ImJYVsTCqdc9YX4ORpznGb0je8lXDFZLky20p8p1AOfJl7Vulqb29SNkPR6wlin8l1pwkO4EUzij83ycyubhrlBsHRC+t0g=
Authentication-Results: spf=pass (sender IP is 18.9.28.11)
smtp.mailfrom=mit.edu; mit.edu; dkim=none (message not signed)
header.d=none; mit.edu;
dmarc=bestguesspass action=none header.from=mit.edu;
Received-SPF: Pass (protection.outlook.com: domain of mit.edu designates
18.9.28.11 as permitted sender) receiver=protection.outlook.com;
client-ip=18.9.28.11; helo=outgoing.mit.edu;
Content-Disposition: inline
In-Reply-To: <6589bffb-75be-62f3-5e3e-6c0b315dd865@secure-endpoints.com>
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-Office365-Filtering-Correlation-Id: 4a667093-7a30-4f9e-f565-08d9760eee47
X-MS-TrafficTypeDiagnostic: CH2PR01MB5653:
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-Microsoft-Antispam-PRVS: <CH2PR01MB5653EC0A08A072A6F5DE9D19A0D89@CH2PR01MB5653.prod.exchangelabs.com>
X-MS-Oob-TLC-OOBClassifiers: OLM:5516;
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: 5vNAg1YqOI4v5PEWOgrbKqsGw+FbMuhUQFyVsp0q/H4q+3n82Xtl/hrPeNlZbUsnyqPFqA+W0VAoNbPqoKKoM2cA88nkX09i/682n5kLxhhZY8UH0DnlBEH+CeBvutI3pX74S4UCBqCmlbaj/jW2HOGYN0NbAXUdkKhQed5AWFfKBNiANzqcMqNlDTwWtKymnw7vhPcUyBXiE0Ah5BBvyaNc9jeqHTC3pTUQH9+1lAMdHdyq0BkCG+zxaqXXJLqAv1SdTLp6GvRgSj7zU3pXcIZIBDIWkGGphLN5WKvbPKOj83yPEzND2vUaHA+KFw6K3Fws47AVpUoeI24+knisuVEwNlQdMdoU89DIgGyW+e6kdor8lIYeiFatn9ajNZFpfIol8mNc/Ln1OhFGBN+lhXvx9xY80+4/jBKry6GOvcIQIx1zwq67ajqNTMEGHGUzP70y1V77pVDlf43tuOlQJAbj7KBXcYF2GDd1a9fagBqeEoW1ztaxdEqCw5mOvl2+ABuv1NNRgY0wGdmdl9aF7cQcniGXpK1DzZIbMisIrfGRSeD/6EhVH38EecgLqnZlttf/ObFHMLPxlrWsKQDF1UfkT9nVo6DaIJPsTaRb8ywFVZIIem5QSkTRFrS7GQezyjZqpuS3L3vfGDbmIUzoA/C/oOUOO4RQLGf4dQlXLNF63CH2CGdbshXI35GzXNAeIGRpq3kmFAeNOmG4eKWPzA==
X-Forefront-Antispam-Report: CIP:18.9.28.11; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:CAL; SFV:NSPM; H:outgoing.mit.edu;
PTR:outgoing-auth-1.mit.edu; CAT:NONE;
SFS:(4636009)(39860400002)(346002)(136003)(396003)(376002)(55016002)(66574015)(45080400002)(8676002)(4326008)(4744005)(53546011)(5660300002)(75432002)(336012)(70586007)(26005)(68406010)(426003)(3480700007)(86362001)(966005)(956004)(6862004)(316002)(7696005)(7116003)(478600001)(1076003)(54906003)(6666004)(356005)(2906002)(33656002);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-Transport-Forked: True
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 12 Sep 2021 17:01:14.5770 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 4a667093-7a30-4f9e-f565-08d9760eee47
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: CO1NAM11FT044.eop-nam11.prod.protection.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CH2PR01MB5653
X-OriginatorOrg: mit.edu
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.6
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
 by: Benjamin Kaduk - Sun, 12 Sep 2021 17:01 UTC

On Sun, Sep 12, 2021 at 07:49:57AM -0400, Jeffrey Altman wrote:
> On 9/11/2021 11:22 AM, Charles Hedrick (hedrick@rutgers.edu) wrote:
> > We don’t currently explore our Kerberos servers to the Internet, but we do have an https proxy for MIT kerberos. Heimal apparently has its own HTTP proxy. Does anyone know of software to implement the proxy?
> I believe the question that should be asked is
>
>   "Can an https proxy client compatible with MIT Kerberos be implemented
> for Heidmal?"

My understanding is that MIT Kerberos just implemented compatibility for
Microsoft's MS-KKDCP protocol,
https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-kkdcp/5bcebb8d-b747-4ee5-9453-428aec1c5c38

-Ben

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor