Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-6851973

ignore incoming channel binding if acceptor does not set one

    Details

    • Type: Enhancement
    • Status: Resolved
    • Priority: P4
    • Resolution: Fixed
    • Affects Version/s: 1.4.2, 1.4.2_22-rev, 7
    • Fix Version/s: 7
    • Component/s: security-libs
    • Subcomponent:
    • Resolved In Build:
      b64
    • CPU:
      generic, x86
    • OS:
      generic, linux_redhat_5.0, windows_xp

      Backports

        Description

        JSS/krb5 should ignore remote channel binding info when not requested at local side (RFC 4121 4.1.1.2: the acceptor MAY ignore...).

        All major krb5 implementors implement this "MAY", and some applications depend on it as a workaround for not having a way to negotiate the use of channel binding -- the initiator application always uses CB and hopes the acceptor will ignore the CB if the acceptor doesn't support CB.

          Attachments

            Issue Links

              Activity

                People

                • Assignee:
                  weijun Weijun Wang
                  Reporter:
                  weijun Weijun Wang
                • Votes:
                  0 Vote for this issue
                  Watchers:
                  1 Start watching this issue

                  Dates

                  • Created:
                    Updated:
                    Resolved:
                    Imported:
                    Indexed: