[PATCH 8/9] kerberos: Don't include GSS_C_DCE_STYLE in default gss_init_sec_context() flags.

Hans Leidekker hans at codeweavers.com
Mon Feb 5 03:17:32 CST 2018


On Mon, 2018-02-05 at 11:27 +0800, Dmitry Timoshkov wrote:
> Dmitry Timoshkov <dmitry at baikal.ru> wrote:
> 
> > Otherwise the returned ticket won't be accepted by WWW server when wrapped
> > in an HTTP request.
> > 
> > Original Rob's patch doesn't have this flag either.
> > 
> > This patch is one of the fixes to make Kerberos Authentication Tester work.
> 
> This patch is marked as 'Superseded' in the patch tracker, but my testing
> shows that (after applying "[PATCH 13/13] secur32: Add support for switching
> between Kerberos and NTLM in Negotiate provider.") both my test program and
> Kerberos Authentication Tester still fail to authenticate without removing
> GSS_C_DCE_STYLE when creating initial Kerberos context.
> 
> Thus, I believe that 'Superseded' state was assigned by mistake. If that's
> not the case please point out to a patch that was supposed to obsolete this
> one.

I showed you how simply removing GSS_C_DCE_STYLE failed my tests, so
the patch should have been marked as rejected. Note that Kerberos
Authentication Tester only tests initializing a Negotiate security 
context whereas my tests work directly against the Kerberos provider,
and they include tests for signing and sealing.

I have submitted a patch that should fix your problem.




More information about the wine-devel mailing list