gss-api negotiation termination (was Re: [AFS3-std] rxgk implementation notes)

Simon Wilkinson simon@sxw.org.uk
Fri, 1 Mar 2013 04:39:59 +0000


On 1 Mar 2013, at 02:13, Benjamin Kaduk wrote:

> It's also worth noting that the standard GSS-API negotiation loop does =
not provide the major/minor status from gss_accept_sec_context() to the =
initiator as we do.  So maybe our case is more confusing than the =
standard case, after all.

Is that not just the equivalent of the OpenSSH error packet though? =
Letting the initiator know why the acceptor failed is really handy for =
debugging problems.

S.