Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

/usr/news/gotcha


devel / comp.protocols.kerberos / Re: Kerberos PAC decoding support

SubjectAuthor
o Re: Kerberos PAC decoding supportGreg Hudson

1
Re: Kerberos PAC decoding support

<mailman.91.1692897380.1964.kerberos@mit.edu>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=374&group=comp.protocols.kerberos#374

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: ghudson@mit.edu (Greg Hudson)
Newsgroups: comp.protocols.kerberos
Subject: Re: Kerberos PAC decoding support
Date: Thu, 24 Aug 2023 13:15:32 -0400
Organization: TNet Consulting
Lines: 16
Message-ID: <mailman.91.1692897380.1964.kerberos@mit.edu>
References: <TYCPR01MB118471D443B42094302C80091D91DA@TYCPR01MB11847.jpnprd01.prod.outlook.com>
<c563996f-d8f2-9bbb-6238-b5d1d6b55485@mit.edu>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="7914"; mail-complaints-to="newsmaster@tnetconsulting.net"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.13.0
To: Ondrej Valousek <ondrej.valousek.xm@renesas.com>, "kerberos@mit.edu"
<kerberos@mit.edu>
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mit.edu; s=outgoing;
t=1692897379; bh=uMzDEGhyhzEfTVv6TrBgqStQwDNpiKPfxISm+T3OG1U=;
h=Message-ID:Date:MIME-Version:Subject:From:Content-Type;
b=eyWTavTAic3gofGUBUiAwb3KuADRcSzDZdUP1CqQut+VCmxaQAzCaY247dGEfXnks
g1rZhvl/OiTTn4iBY7pkFU6L2GRh4nCvGElPqw+m2Faj1qkJISpbKrfFv/THkPzy5z
cKxxkhQ1rOIfhMXcHgzpb1L+zWW8C1ywmFTrTZkmVBx8D2i+MrPD9dBqzQ6oTpZwVT
1dpFO6nF6MatUl6ddHido3at8iN3QhSGCAogvC5vAYbDVx0HBygep5s25+wNorIQAN
CeBCsrPO1wE439QTMaHKVE7VG9MWF7IXDY30X1HsOIHFlQAy1b3eX69B7ZP+AKFVp+
0TQcn6ykg4PJw==
Authentication-Results: spf=pass (sender IP is 18.9.28.11)
smtp.mailfrom=mit.edu; dkim=pass (signature was verified)
header.d=mit.edu;dmarc=pass action=none header.from=mit.edu;
Received-SPF: Pass (protection.outlook.com: domain of mit.edu designates
18.9.28.11 as permitted sender) receiver=protection.outlook.com;
client-ip=18.9.28.11; helo=outgoing.mit.edu; pr=C
Content-Language: en-US
In-Reply-To: <TYCPR01MB118471D443B42094302C80091D91DA@TYCPR01MB11847.jpnprd01.prod.outlook.com>
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: SN1PEPF0002636D:EE_|MW6PR01MB8343:EE_
X-MS-Office365-Filtering-Correlation-Id: 253e2d1e-c2b9-4b1f-6390-08dba4c5bb30
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: eTniEFTdbh97oS+9PIKJDezl2JM1La//o2dkQ3sOcntnPAFgEGDHAXUMjiFMyLx56zLQAZD1ad6RLF4B7wrnwl51xJx/41dCryDbUIOVjvDSYswVC2e7ecPhzN8fjWNQNN/F9NpTfmQGkntbTQAknai3uY6Pve37N+gq/WY4vFv7WcAhZaeXr3PNWI4qN7RQhDUV8cJQrkH9PfYvdobtc1IrGg0TExZfuK3RIpse/5bM/eKw7NPDZ2v16JZxhPeonUgdJGKV0B/P5rQH5MljWFSNjCBPL6dXh2BsosuZUw3HB0aTltdoswDcFhzxnOhRD11oX9Qt5kGvjbkJ+8qX4ZF82mMgm9JWNxNmBZox7C4qIoV3v8YIIaeGqU3wFNxVdMBzVbvC+l0QS7pukwRtWGQbwWo4VpIQBdMN7cJh6KKcEOEUaE2326Nhls1WpAtRAitM2Udh0dWPGzYE+lQn9bRGwyZFe1Hwg9a6bKXCmO+Xp+qeqUQND7szdlTrAKp7EtBijU42ocIc6krjXRO5SZZTDG+nXfN9TC6+V/WDizSnXXKXLJBhH3v+nK9hnaAv4jIiIvcwwJPx4Qxwh3IIc0AbpuuE/rO2nqQA4VGia5sxvbySnfP+i8sgZlw+tKPkgBg0h36ulRkfXRIeDwrtQnAuEHPVQIEx1fcDwdUxjwtZ8ILwPw6eFdMgY1VWSZHh846+07XgegxRaB6WhqDpK+8Wf+LcGmt0zQRX0w9oU6YmymWXc/RKxg0fO4/deMT53vU1RtFWnxOrDO2baJS0WA==
X-Forefront-Antispam-Report: CIP:18.9.28.11; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:CAL; SFV:NSPM; H:outgoing.mit.edu; PTR:outgoing-auth-1.mit.edu; CAT:NONE;
SFS:(13230031)(4636009)(136003)(346002)(376002)(396003)(39860400002)(451199024)(1800799009)(68406010)(70586007)(6636002)(316002)(786003)(478600001)(110136005)(26005)(356005)(53546011)(7696005)(86362001)(31696002)(2906002)(31686004)(8676002)(956004)(2616005)(75432002)(5660300002)(83380400001)(3480700007)(4744005)(36756003)(336012)(426003)(43740500002);
DIR:OUT; SFP:1102;
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 24 Aug 2023 17:15:35.5799 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 253e2d1e-c2b9-4b1f-6390-08dba4c5bb30
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: SN1PEPF0002636D.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MW6PR01MB8343
X-OriginatorOrg: mit.edu
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <c563996f-d8f2-9bbb-6238-b5d1d6b55485@mit.edu>
X-Mailman-Original-References: <TYCPR01MB118471D443B42094302C80091D91DA@TYCPR01MB11847.jpnprd01.prod.outlook.com>
 by: Greg Hudson - Thu, 24 Aug 2023 17:15 UTC

On 8/24/23 02:18, Ondrej Valousek wrote:
> I am wondering if it is reasonable to request the MIT library to support PAC decoding (possibly in form of Named Attributes) so that the information there could be used in calling application, I.e.:

PAC buffers are available via these name attributes:

urn:mspac: (for the whole PAC)
urn:mspac:logon-info
urn:mspac:credentials-info
urn:mspac:server-checksum
urn:mspac:privsvr-checksum
urn:mspac:client-info
urn:mspac:delegation-info
urn:mspac:upn-dns-info

libkrb5 doesn't do any NDR decoding, so that part has to be done by the
application.

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor