GSS-API - Kerberos Ticket - Kerberos

This is a discussion on GSS-API - Kerberos Ticket - Kerberos ; Hello, Is there any method of "extracting" the Kerberos key from a GSS ticket? Microsoft sends the Kerberos ticket (SPNEGO over http) using the GSS methods. If one attempts to handle the internal Kerberos ticket information (such as the case ...

+ Reply to Thread
Results 1 to 3 of 3

Thread: GSS-API - Kerberos Ticket

  1. GSS-API - Kerberos Ticket

    Hello,

    Is there any method of "extracting" the Kerberos key from a GSS ticket?

    Microsoft sends the Kerberos ticket (SPNEGO over http) using the GSS
    methods. If one attempts to handle the internal Kerberos ticket
    information (such as the case of the PAC data) he will have to use the
    Kerberos ticket.

    Any idea?
    Any explicit function I've missed ? such as
    gss_extract_krb5_ticket()..?

    Eitan.


  2. Re: GSS-API - Kerberos Ticket

    > Hello,
    >
    > Is there any method of "extracting" the Kerberos key from a GSS ticket?
    >
    > Microsoft sends the Kerberos ticket (SPNEGO over http) using the GSS
    > methods. If one attempts to handle the internal Kerberos ticket
    > information (such as the case of the PAC data) he will have to use the
    > Kerberos ticket.
    >
    > Any idea?
    > Any explicit function I've missed ? such as
    > gss_extract_krb5_ticket()..?


    In 1.4 MIT added gss_krb5_export_lucid_sec_context() to obtain
    information from the negotiated context. (This is a mechanism-
    specific routine currently available only in the MIT distribution
    AFAIK.) Is this close to what you are looking for?

    K.C.

    ________________________________________________
    Kerberos mailing list Kerberos@mit.edu
    https://mailman.mit.edu/mailman/listinfo/kerberos


  3. Re: GSS-API - Kerberos Ticket


    have a look at gss_krb5_copy_ccache()


    On Tue, 2005-09-27 at 03:24 -0700, Eitan wrote:
    > Hello,
    >
    > Is there any method of "extracting" the Kerberos key from a GSS ticket?
    >
    > Microsoft sends the Kerberos ticket (SPNEGO over http) using the GSS
    > methods. If one attempts to handle the internal Kerberos ticket
    > information (such as the case of the PAC data) he will have to use the
    > Kerberos ticket.
    >
    > Any idea?
    > Any explicit function I've missed ? such as
    > gss_extract_krb5_ticket()..?
    >
    > Eitan.


    ________________________________________________
    Kerberos mailing list Kerberos@mit.edu
    https://mailman.mit.edu/mailman/listinfo/kerberos

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.1 (GNU/Linux)

    iD8DBQBDOo/5hjEylB2OKukRAu3/AJ9KPcCPaNpvnY6BtByzrn25/e23FACcDmOu
    7CtJAcm5nVqwazMMTsdKcCw=
    =ASHt
    -----END PGP SIGNATURE-----


+ Reply to Thread