• Open Menu Close Menu
  • Apple
  • Shopping Bag
  • Apple
  • Mac
  • iPad
  • iPhone
  • Watch
  • TV
  • Music
  • Support
  • Search apple.com
  • Shopping Bag

Lists

Open Menu Close Menu
  • Terms and Conditions
  • Lists hosted on this site
  • Email the Postmaster
  • Tips for posting to public mailing lists
Re: GSS-SPNEGO exposed as a GSSAPI library?
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: GSS-SPNEGO exposed as a GSSAPI library?


  • Subject: Re: GSS-SPNEGO exposed as a GSSAPI library?
  • From: Simon Spero <email@hidden>
  • Date: Wed, 10 Aug 2005 15:02:43 -0400

There is a bug in the currently shipping SPNEGO implementation (which is in CFNetwork). This bug makes SPNEGO use the wrong case in part of the server principal name. Well, it uses the right server principal name, but some silly company in WA accidentally made canonical SPNEGO use HTTP/<host> instead of http/<host>. It would not surprise me if this bug had already been fixed for the next Tiger update.

 CFNetwork is open sourced, so you can check there.

The CFNetwork SPNEGO doesn't pretend to be a pseudomechanism; I wouldn't recommend trying to do that until the KITTEN working group has finished the GSSAPI revisions, as there are a lot of places where its not clear what a pseudo-mechanism should do (I tried wrapping up some java SPNEGO stuff with the GSSAPI, and it got quite messy figuring out what credentials and name types to ask for or report).

See also: CFHTTPAuthentication.

Simon


On Aug 9, 2005, at 4:38 PM, Nathan Herring wrote:

Given that Tiger's Safari supports the Negotiate authentication
mechanism with at least support for Kerberos (although I also expect it
supports NTLM), is it using some system library that exports the GSSAPI
supporting Negotiate?


I'm thinking here of a library that is a thin wrapper to other
GSSAPI-exported libraries (e.g., Kerberos.framework), which might load
them as plugins (if possible?).

_______________________________________________
Do not post admin requests to the list. They will be ignored.
Macnetworkprog mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden


References: 
 >GSS-SPNEGO exposed as a GSSAPI library? (From: "Nathan Herring" <email@hidden>)

  • Prev by Date: Re: How to detect Wifi device?
  • Next by Date: Re: WPAC configuration in Tiger (and beyond)
  • Previous by thread: GSS-SPNEGO exposed as a GSSAPI library?
  • Next by thread: Re: How to detect Wifi device?
  • Index(es):
    • Date
    • Thread