Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

May all your PUSHes be POPped.


devel / comp.protocols.kerberos / Re: How to get Kerberos token for proxy authentication

SubjectAuthor
o Re: How to get Kerberos token for proxy authenticationKen Hornstein

1
Re: How to get Kerberos token for proxy authentication

<mailman.69.1710897889.2322.kerberos@mit.edu>

  copy mid

https://www.rocksolidbbs.com/devel/article-flat.php?id=521&group=comp.protocols.kerberos#521

  copy link   Newsgroups: comp.protocols.kerberos
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!tncsrv06.tnetconsulting.net!.POSTED.mailman.mit.edu!not-for-mail
From: kenh@cmf.nrl.navy.mil (Ken Hornstein)
Newsgroups: comp.protocols.kerberos
Subject: Re: How to get Kerberos token for proxy authentication
Date: Tue, 19 Mar 2024 21:24:43 -0400
Organization: TNet Consulting
Lines: 13
Message-ID: <mailman.69.1710897889.2322.kerberos@mit.edu>
References: <1182031369.5745575.1710653866918.ref@mail.yahoo.com>
<1182031369.5745575.1710653866918@mail.yahoo.com>
<202403180011.42I0Bfq8004419@hedwig.cmf.nrl.navy.mil>
<1971540388.4984456.1710851301228@mail.yahoo.com>
<202403200124.42K1Ogwb031014@hedwig.cmf.nrl.navy.mil>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Injection-Info: tncsrv06.tnetconsulting.net; posting-host="mailman.mit.edu:18.7.21.50";
logging-data="16871"; mail-complaints-to="newsmaster@tnetconsulting.net"
Cc: "kerberos@mit.edu" <kerberos@mit.edu>
To: "m_a_n_j_u_s_k@yahoo.com" <m_a_n_j_u_s_k@yahoo.com>
DKIM-Filter: OpenDKIM Filter v2.11.0 unknown-host (unknown-jobid)
Authentication-Results: mailman.mit.edu;
dkim=pass (1024-bit key, unprotected) header.d=mitprod.onmicrosoft.com
header.i=@mitprod.onmicrosoft.com header.a=rsa-sha256
header.s=selector2-mitprod-onmicrosoft-com header.b=W9WS/FAF;
dkim=pass (2048-bit key,
unprotected) header.d=nrl.navy.mil header.i=@nrl.navy.mil header.a=rsa-sha256
header.s=s2.dkim header.b=X3B0FaBp
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;
b=Gtgcw7G9LeM4kWwABlTxeJNbKxVw6Q13j4vEn3fKW9g4mpxyptLdGN6KRUF4m84qZwME5up0dUWQrZqcnoIlEpvJjb+qIptBNY7/MinQOUJXB2IFIRUrXL1Bqw//b11MifWuVsP5Vzt8oBXjEIV/uyBgxLI+j7sFm13QrxZvLS2bWYhyCF5IsKQtt+oZCeLRI9RPznbgLv2kl+eUtJxi3MDM5glBWFAGniWNUGn0I2hstqkE2OYELJR1tBX1gjr6Lwiq8qFAz0KUBOqkzittj/B0dgVjaYGek0EcCg8oPuiMyF+41NUIRfQ9sJ2m93EOf2oWKZETQNW4jhJr49ETjQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
s=arcselector9901;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
bh=imrWTsxHTrQeLc31gdx4lPrwCkxc2iQRM1Q5+MrvEsk=;
b=SN47htJ9cVm4oKChWHUocsx3lWSCJSTPcL1OWJGon1BozRjBVWJ0TQ63bYqSMb+5THSRQoHIhjvStwuOOLshSyOGNboz7lNq3tZgGU/+e7/B2rrLvL+hqa+fA1HEGo2YsvStjdPQebj/dQt/wDSRAzu9jpCZUa2oJUhAk2lxABhnJd8tDViucnQOu31JVLx4kY7Qf1ysk3h1ue/ZfLeaybiVGbhAH4FwrYugbm5YbnNNGPz6jhLIlx2pXFHF6OoM2rWsnFUcQIp564HKB43SKxf16i7xIJK0IA7jzi3suRL9vQcPjGY9q7P3lxxyHz+TMgN7a3mJKO3wkwHrfiaKhA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
140.32.59.234) smtp.rcpttodomain=mit.edu smtp.mailfrom=cmf.nrl.navy.mil;
dmarc=pass (p=reject sp=reject pct=100) action=none
header.from=cmf.nrl.navy.mil; dkim=pass (signature was verified)
header.d=nrl.navy.mil; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=mitprod.onmicrosoft.com; s=selector2-mitprod-onmicrosoft-com;
h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
bh=imrWTsxHTrQeLc31gdx4lPrwCkxc2iQRM1Q5+MrvEsk=;
b=W9WS/FAFn4r+i9NEZs73afd19MXk2L3RWJe20Cx23CwdwOtg01FOUi+9/yaupUms+hmkYgAIZJaM2eTlAjQZ5PvXiQuJNpb27vPtwyy7lTA3bhEsqXto0u+bP71KAttEGflRp4weh9pGdHVFWwPwOzqUkQZgv+y12a61AH7MW0Y=
Authentication-Results: spf=pass (sender IP is 140.32.59.234)
smtp.mailfrom=cmf.nrl.navy.mil; dkim=pass (signature was verified)
header.d=nrl.navy.mil;dmarc=pass action=none header.from=cmf.nrl.navy.mil;
Received-SPF: Pass (protection.outlook.com: domain of cmf.nrl.navy.mil
designates 140.32.59.234 as permitted sender)
receiver=protection.outlook.com; client-ip=140.32.59.234; helo=mf.dren.mil;
pr=C
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nrl.navy.mil;
h=message-id : from :
to : cc : subject : in-reply-to : references : mime-version : content-type
: date; s=s2.dkim; bh=imrWTsxHTrQeLc31gdx4lPrwCkxc2iQRM1Q5+MrvEsk=;
b=X3B0FaBpv70ao/Um/gaKG0vAQ3rMQml1PN/kJ0HUTlxRI7J2fo7HLXoYacuHLDwtjHbn
6JHvReWQsFygzSHuEPkVq0u7shpmY6mpCpZ+2CeGV588SMjr0ymvSo850QnDuy4pFtpl
TYqYeQ5NosEjqJUeoRI5mTse5+ZD+YMZ1lyZuz2F7M5iSh7ByJx1bUdaaw7PCX8oxSbS
EdhQbTeCvmUsTc0F2SguDFBIfVfOFwdEJWFlt4z2MWVQHXH8rtUdJnU+qxkAfvazcUEd
F9cf2UdCDYBrut+anq8wqvNo88MhBvuhcgfLnEJtufy2//LxyC9lwAnJ/6rMhFFCLG59 rw==
In-Reply-To: <1971540388.4984456.1710851301228@mail.yahoo.com>
X-Face: "Evs"_GpJ]],xS)b$T2#V&{KfP_i2`TlPrY$Iv9+TQ!6+`~+l)#7I)0xr1>4hfd{#0B4
WIn3jU;bql;{2Uq%zw5bF4?%F&&j8@KaT?#vBGk}u07<+6/`.F-3_GA@6Bq5gN9\+s;_d
gD\SW #]iN_U0 KUmOR.P<|um5yP<ea#^"SJK;C*}fMI;Mv(aiO2z~9n.w?@\>kEpSD@*e`
X-NRLCMF-Spam-Score: () hits=0 User Authenticated
X-NRLCMF-Virus-Scanned:
X-EOPAttributedMessage: 0
X-EOPTenantAttributedMessage: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b:0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: MN1PEPF0000F0E5:EE_|SN4PR01MB7519:EE_
X-MS-Office365-Filtering-Correlation-Id: 7a806f33-cbc4-477e-0733-08dc487c8713
X-LD-Processed: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b,ExtAddr
X-MS-Exchange-AtpMessageProperties: SA
X-MS-Exchange-SenderADCheck: 0
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: /+0jyJH0abN4dH93hcibTfBftpHu5NMD/7UH5NJMd6G6n0an1kEpHhXjPehWXfsaTV0ZZAaHComZ8YFJw4kfp9W6G23/JI3HNfnelxZ/u0kng/4Up3n6Oz4klfIC04fKwzaWmjKLsMNKQLnUDlZsrISKKEtndrZG5kYZKcYLa0Cc/Dw2B9VT2c6kjjZmoXy9ufa+NrJ/+9MdBvaD0I23ZSxv2Xb6yyjPnoZ4OBtjojnH0J32dtNFODJFBP0fEsk+8NPS10mMjBdzcYgD8KVm36I+cpEvAiQoIO3Ioxc/zG00rfwz8WeVIEWJ/XxfdZ1Mu5jaDIrfT+SDzJ8QiSXKnq+EaXGGhXUnI2hqinqzjnQeofp4WdHPNlhs/vAq7oIp9IDo0U3TUamy5iM07PxJXsEUEQtfEnKLH8e3dXz6YVLiDhKUZ0JjbBJZiXLL4vmTiOLInELnL3uoIdP3/qn7m2p33pWis3c4FkBGM+zM8z2qqiwO8lqWbUSALz+Kl1yOH3KwcgI4iIprIxh+1mriKI9GXzcIOYuJH/jxcVKQIsbXTFgaaKTOcOmc955zYIy+ZX6QdZqP7RK7aZB51v/a9ui1QblDYaOW84qu972YwQ7HSPyVpLI2UTJDF7CN3AxoDNbsRlE1NlXVt5LaaB03giBlnLsZ+nmASdi3aDurxKFjQfaRSpAYh4x8O3wi72HCzXY2/Z34eXqZxi4omTOsw0fB1lVI8l/pwg8Z53B4c9IudaHODog0PKrOZvENONPg
X-Forefront-Antispam-Report: CIP:140.32.59.234; CTRY:US; LANG:en; SCL:1; SRV:;
IPV:NLI; SFV:NSPM; H:mf.dren.mil; PTR:mfe.dren.mil; CAT:NONE;
SFS:(13230031)(48200799009)(376005)(61400799018); DIR:OUT; SFP:1102;
X-ExternalRecipientOutboundConnectors: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-OriginatorOrg: mitprod.onmicrosoft.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Mar 2024 01:24:45.6583 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 7a806f33-cbc4-477e-0733-08dc487c8713
X-MS-Exchange-CrossTenant-Id: 64afd9ba-0ecf-4acf-bc36-935f6235ba8b
X-MS-Exchange-CrossTenant-AuthSource: MN1PEPF0000F0E5.namprd04.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Anonymous
X-MS-Exchange-CrossTenant-FromEntityHeader: Internet
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN4PR01MB7519
X-BeenThere: kerberos@mit.edu
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: The Kerberos Authentication System Mailing List <kerberos.mit.edu>
List-Unsubscribe: <https://mailman.mit.edu/mailman/options/kerberos>,
<mailto:kerberos-request@mit.edu?subject=unsubscribe>
List-Archive: <http://mailman.mit.edu/pipermail/kerberos/>
List-Post: <mailto:kerberos@mit.edu>
List-Help: <mailto:kerberos-request@mit.edu?subject=help>
List-Subscribe: <https://mailman.mit.edu/mailman/listinfo/kerberos>,
<mailto:kerberos-request@mit.edu?subject=subscribe>
X-Mailman-Original-Message-ID: <202403200124.42K1Ogwb031014@hedwig.cmf.nrl.navy.mil>
X-Mailman-Original-References: <1182031369.5745575.1710653866918.ref@mail.yahoo.com>
<1182031369.5745575.1710653866918@mail.yahoo.com>
<202403180011.42I0Bfq8004419@hedwig.cmf.nrl.navy.mil>
<1971540388.4984456.1710851301228@mail.yahoo.com>
 by: Ken Hornstein - Wed, 20 Mar 2024 01:24 UTC

>Thanks Ken,I understand I need to use GSSAPI for Linux/MacOS
>platforms. I was wondering if I can use MIT Kerberos GSSAPI for the
>same. Does libcurl use MIT Kerberos gssapi ? Yes my proxy header would
>look exactly like you mentioned. Thank-you.

You should be able to use the MIT Kerberos GSSAPI implementation fine
for this (but I think either MIT Kerberos or Heimdal would work; on
MacOS X it might be easier to use the native GSSAPI implementation which
would be Heimdal). My understanding is that libcurl can link against
either Heimdal or MIT Kerberos, but you should probably investigate that
yourself.

--Ken

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor