Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

'Course, I haven't weighed in yet. :-) -- Larry Wall in <199710281816.KAA29614@wall.org>


devel / comp.protocols.kerberos / Re: How to get Kerberos token for proxy authentication

SubjectAuthor
o Re: How to get Kerberos token for proxy authenticationKen Hornstein

1
Re: How to get Kerberos token for proxy authentication

<mailman.74.1711036206.2322.kerberos@mit.edu>

  copy mid

https://www.novabbs.com/devel/article-flat.php?id=526&group=comp.protocols.kerberos#526

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!news.quux.org!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: ken...@cmf.nrl.navy.mil (Ken Hornstein)
Newsgroups: comp.protocols.kerberos
Subject: Re: How to get Kerberos token for proxy authentication
Date: Thu, 21 Mar 2024 11:49:54 -0400
Organization: TNet Consulting
Lines: 15
Message-ID: <mailman.74.1711036206.2322.kerberos@mit.edu>
References: <1182031369.5745575.1710653866918.ref@mail.yahoo.com>
<1182031369.5745575.1710653866918@mail.yahoo.com>
<202403180011.42I0Bfq8004419@hedwig.cmf.nrl.navy.mil>
<1971540388.4984456.1710851301228@mail.yahoo.com>
<202403200124.42K1Ogwb031014@hedwig.cmf.nrl.navy.mil>
<1607837619.5406090.1710931234295@mail.yahoo.com>
<202403201533.42KFXFYr006534@hedwig.cmf.nrl.navy.mil>
<ZfxRGUGVIIXJ42x+@gozer.tproa.net>
<202403211549.42LFnrb3019859@hedwig.cmf.nrl.navy.mil>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="3239"; mail-complaints-to="newsmaster@tnetconsulting.net"
Cc: kerberos@mit.edu
To: Thomas Kula <kula@tproa.net>
DKIM-Filter: OpenDKIM Filter v2.11.0 unknown-host (unknown-jobid)
Authentication-Results: mailman.mit.edu;
dkim=pass (1024-bit key, unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=Vzcgtot9;
dkim=pass (2048-bit key,
unprotected) header.d=nrl.navy.mil header.i=@nrl.navy.mil header.a=rsa-sha256
header.s=s2.dkim header.b=C5uRn94Z
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=avxg7Mf1n4LD+VGTsfUz0GySIcErCOnN6UI1IcM9DFUVoe/HP4bebQ/GWFlq1/tDI6GTR7esEYRnY8jmDahY0n81J8r+W4QzQePtm69gmNu6kMmYMx2nP1sDrEhTEz2/oYUtSrVDoOl3S4K6suSuu7uCFvkVk0Nh8fVQHWgPCLoh9ktrgs2im39S7MVpgogZNbiUV6ZEpb1oTLE/IJJ32SpxfRCMTvhI8X9VdfIoeL4Y/S8xUCEGU/5p+ZPERlwOWxS5Hvtj+vWN0I9IbL6DYiez6jjY2g8Q2fwliU+8llT5agEjPWI+h2eYuCUFRQiWd10WoiGWvfw/vrfH6Q6UGw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=4/6wp1Lort7brOhEsaiaD0unVdlV0PccPxUScpLHa5s=;
b=GZO1kHJFV4CNM0TNXMWYE7wz0gUNXpgJozW8qufallLyXGcBxfHscVrdIkP1YnmIL1ruLPaDMZlbA8UVHKsBlnkWIGwVxg2ZYdecmD1L+AnXQ9rGBLNBcytLQ+InK8x/I6BWHQiq9mPIL4EwNgGfTsnpKoqvosCHKKk/mikQEGz9HXVN3V/j+EhSzvTue/6qVjNfqIU54X3//8C63wU5PcUmbFgeOOP8rfDQDTqbenIyX5UA+8XvkVGtpb8NmXa5/cZQGitPS2L3d1yZn/Rgpi51aTLv7MNJ3OdLvbzOmNsI0aG8aeyLbuJUFAyYZn8Hcb0oHK3ocRycYrrxr+CsXA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
140.32.59.234) smtp.rcpttodomain=mit.edu smtp.mailfrom=cmf.nrl.navy.mil;
dmarc=pass (p=reject sp=reject pct=100) action=none
header.from=cmf.nrl.navy.mil; dkim=pass (signature was verified)
header.d=nrl.navy.mil; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=4/6wp1Lort7brOhEsaiaD0unVdlV0PccPxUScpLHa5s=;
b=Vzcgtot9N7f1csNTUclogl1G7b3XYbHxKmb/RmBTPXuQxBZ1p0nP2C3J5BbEjGWOw66yiX+eefVzDnrAFRBAGJLjiI4ffQ85R+kxVvlZXTs5zpy0+x2NKDcE8+1O0ZHw8ATjCu2FIiuLKuO8frt5jwr9gTESVJ3AmDcYUfecihM=
Authentication-Results: spf=pass (sender IP is 140.32.59.234)
smtp.mailfrom=cmf.nrl.navy.mil; dkim=pass (signature was verified)
header.d=nrl.navy.mil;dmarc=pass action=none header.from=cmf.nrl.navy.mil;
Received-SPF: Pass (protection.outlook.com: domain of cmf.nrl.navy.mil
designates 140.32.59.234 as permitted sender)
receiver=protection.outlook.com; client-ip=140.32.59.234; helo=mf.dren.mil;
pr=C
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nrl.navy.mil;
h=message-id : from :
to : cc : subject : in-reply-to : references : mime-version : content-type
: date; s=s2.dkim; bh=4/6wp1Lort7brOhEsaiaD0unVdlV0PccPxUScpLHa5s=;
b=C5uRn94ZH5Bl7W6oVhfAlbBLmvuheaPqCQKREhLBXWatDkbZeQb2jX06e/j1MfxWUmWr
Ek2nVo3BDbqSHH/+Rq+ylc6lXuhsxyfRo18u+PW0BKbctj0Id4o38Bt+Dmo/nQz0C6Pg
FWRk1kzsyEon8Cs+YH8pitYMINMA7GnJ4nfQnc/gcaHDTVAcvzUe06lpF5ehl7OMXGrj
UvBH+VK6Jy+NzP+eWCLHAnswNbmRIlH6nEYQQVVZ47lt6EyU5BYAL1DwMpV7JkECIrl6
iRElVzcJFA1Mff35xRvVfeOKGlBhUeBbpJLrUIPynhMRde5eF89HCVDba+cLC6+ePNOt XA==
In-Reply-To: <ZfxRGUGVIIXJ42x+@gozer.tproa.net>
X-Face: "Evs"_GpJ]],xS)b$T2#V&{KfP_i2`TlPrY$Iv9+TQ!6+`~+l)#7I)0xr1>4hfd{#0B4
WIn3jU;bql;{2Uq%zw5bF4?%F&&j8@KaT?#vBGk}u07<+6/`.F-3_GA@6Bq5gN9\+s;_d
gD\SW #]iN_U0 KUmOR.P<|um5yP<ea#^"SJK;C*}fMI;Mv(aiO2z~9n.w?@\>kEpSD@*e`
X-NRLCMF-Spam-Score: () hits=0 User Authenticated
X-NRLCMF-Virus-Scanned:
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: MN1PEPF0000F0E1:EE_|SA1PR01MB8250:EE_
X-MS-Office365-Filtering-Correlation-Id: 69ae636e-618a-4d78-af18-08dc49be8ecb
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: k14X/bd2kqUlAOAPD1KzNvzelz2Xyt3tFnbV/HSLFXbrYZNU+0cUze+GM1680tXQH3HXlhRAhF+vK02oWjGwXbP1ofFjTQD1U56xiShclNYmm/9rurJihAQR7ByN/eAbFyhCdnRMW6mfb3JBH1ATnrmC8yJcFkVHkqu3M5ehCqJIBD0w9NlwwruXVK60I1j4OLGjGljqgk/HbRdAk79XEAYK5jOJ+70pDziOAwQM8IA6nkJTDKhSEHpv5ylJuXiYNlr9GDEI0oO/rAHA5GsAboq5CyJpt36xt/ZemzUv2SOyZqzi72ExUfHXjS6xt/YSdNgvg+QrpgBg7AUT8juQg48nq/vNRfYv6d4nvF0teXJl900rW+Q5I9S6LSY8l8jSMfjCjD79qP5jLWw+UOpDrkZOZOdP2iHGlfDxKtXvWYslz/Y3hWoXaGKgbIFUEmdHL9u9iMcMGoOD19pJEZnZtyI5jnGJkHQJY/sX4CRSU7ypol5PfkmUrgXDj6UE2QvMXFhqz9PpdBhYDbERXQLcHmz1TZZp1FZJa+oO46JdEKBPyBGUacH7v7fCPjh4u2dktJBmattNGbJjyc3AHm3niADUJHzbxmLinu5iSGCrquq5nGo5+xWTcG5l11KLgX7vG2rK6+MSlpZsD9oL0hJKvmKrl7fy0mXyTw3vD7EWUuiSqyynP6AxG2vVc04ON8yh
X-Forefront-Antispam-Report: CIP:140.32.59.234; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:mf.dren.mil; PTR:mfe.dren.mil; CAT:NONE;
SFS:(13230031)(376005)(61400799018)(48200799009); DIR:OUT; SFP:1102;
X-ExternalRecipientOutboundConnectors: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-OriginatorOrg: mitprod.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 21 Mar 2024 15:49:56.6688 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 69ae636e-618a-4d78-af18-08dc49be8ecb
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: MN1PEPF0000F0E1.namprd04.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA1PR01MB8250
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <202403211549.42LFnrb3019859@hedwig.cmf.nrl.navy.mil>
X-Mailman-Original-References: <1182031369.5745575.1710653866918.ref@mail.yahoo.com>
<1182031369.5745575.1710653866918@mail.yahoo.com>
<202403180011.42I0Bfq8004419@hedwig.cmf.nrl.navy.mil>
<1971540388.4984456.1710851301228@mail.yahoo.com>
<202403200124.42K1Ogwb031014@hedwig.cmf.nrl.navy.mil>
<1607837619.5406090.1710931234295@mail.yahoo.com>
<202403201533.42KFXFYr006534@hedwig.cmf.nrl.navy.mil>
<ZfxRGUGVIIXJ42x+@gozer.tproa.net>
 by: Ken Hornstein - Thu, 21 Mar 2024 15:49 UTC

>Are you familiar with https://github.com/jcmturner/gokrb5? I've used it
>in the past with some experiments in some Go code I was working on, I
>wasn't touching GSSAPI but there's at least some GSSAPI code in there.
>Might be worth checking out as it's native Go code, no cgo wrapping.

I would caution you that if you are targeting MacOS X as a platform, one
of the most important things is integration with the native credential
cache format (especially if you are assuming your credentials are being
acquired as part of the single signon process). On MacOS X the default
credential cache uses a RPC mechanism to talk to a daemon process (and
that has actually changed to a DIFFERENT RPC service in more recent
versions of MacOS X). My brief look at gokrb5 suggests that it only
supports the FILE credential cache type.

--Ken

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor