Re: [Freeipa-devel] Anonymous PKINIT and kdcproxy

2016-12-12 Thread Simo Sorce
On Mon, 2016-12-12 at 09:42 +0100, Christian Heimes wrote: > Hi Simo, > > I'm wondering if we need to change kdcproxy for anon pkinit. What kind > of Kerberos requests are performed by anon pkinit and to establish a > FAST tunnel? python-kdcproxy allows only request types AS-REQ, TGS-REQ > and AP-

Re: [Freeipa-devel] Anonymous PKINIT and kdcproxy

2016-12-12 Thread Christian Heimes
On 2016-12-12 10:37, Alexander Bokovoy wrote: > On ma, 12 joulu 2016, Alexander Bokovoy wrote: >> On ma, 12 joulu 2016, Christian Heimes wrote: >>> On 2016-12-12 09:54, Alexander Bokovoy wrote: On ma, 12 joulu 2016, Christian Heimes wrote: > Hi Simo, > > I'm wondering if we need to

Re: [Freeipa-devel] Anonymous PKINIT and kdcproxy

2016-12-12 Thread Alexander Bokovoy
On ma, 12 joulu 2016, Alexander Bokovoy wrote: On ma, 12 joulu 2016, Christian Heimes wrote: On 2016-12-12 09:54, Alexander Bokovoy wrote: On ma, 12 joulu 2016, Christian Heimes wrote: Hi Simo, I'm wondering if we need to change kdcproxy for anon pkinit. What kind of Kerberos requests are per

Re: [Freeipa-devel] Anonymous PKINIT and kdcproxy

2016-12-12 Thread Alexander Bokovoy
On ma, 12 joulu 2016, Christian Heimes wrote: On 2016-12-12 09:54, Alexander Bokovoy wrote: On ma, 12 joulu 2016, Christian Heimes wrote: Hi Simo, I'm wondering if we need to change kdcproxy for anon pkinit. What kind of Kerberos requests are performed by anon pkinit and to establish a FAST tu

Re: [Freeipa-devel] Anonymous PKINIT and kdcproxy

2016-12-12 Thread Christian Heimes
On 2016-12-12 09:54, Alexander Bokovoy wrote: > On ma, 12 joulu 2016, Christian Heimes wrote: >> Hi Simo, >> >> I'm wondering if we need to change kdcproxy for anon pkinit. What kind >> of Kerberos requests are performed by anon pkinit and to establish a >> FAST tunnel? python-kdcproxy allows only

Re: [Freeipa-devel] Anonymous PKINIT and kdcproxy

2016-12-12 Thread Alexander Bokovoy
On ma, 12 joulu 2016, Christian Heimes wrote: Hi Simo, I'm wondering if we need to change kdcproxy for anon pkinit. What kind of Kerberos requests are performed by anon pkinit and to establish a FAST tunnel? python-kdcproxy allows only request types AS-REQ, TGS-REQ and AP-REQ+KRB-PRV. Responses

[Freeipa-devel] Anonymous PKINIT and kdcproxy

2016-12-12 Thread Christian Heimes
Hi Simo, I'm wondering if we need to change kdcproxy for anon pkinit. What kind of Kerberos requests are performed by anon pkinit and to establish a FAST tunnel? python-kdcproxy allows only request types AS-REQ, TGS-REQ and AP-REQ+KRB-PRV. Responses are not filtered. Regards, Christian signatu