projects
/
mech_eap.git
/ commitdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
| commitdiff |
tree
raw
|
patch
| inline |
side by side
(parent:
2f0adc9
)
Temporary: set mutual in flags token
author
Sam Hartman
<hartmans@debian.org>
Mon, 28 Oct 2013 17:31:54 +0000
(13:31 -0400)
committer
Sam Hartman
<hartmans@debian.org>
Mon, 28 Oct 2013 17:31:54 +0000
(13:31 -0400)
Force mutual flag on the context prior to sending the flags token until channel binding is better deployed.
mech_eap/init_sec_context.c
patch
|
blob
|
history
diff --git
a/mech_eap/init_sec_context.c
b/mech_eap/init_sec_context.c
index
fb2f6c8
..
29465be
100644
(file)
--- a/
mech_eap/init_sec_context.c
+++ b/
mech_eap/init_sec_context.c
@@
-964,6
+964,11
@@
eapGssSmInitGssFlags(OM_uint32 *minor,
unsigned char wireFlags[4];
gss_buffer_desc flagsBuf;
+ /*
+ * As a temporary measure, force mutual authentication until channel binding is
+ * more widely deployed.
+ */
+ ctx->gssFlags |= GSS_C_MUTUAL_FLAG;
store_uint32_be(ctx->gssFlags & GSSEAP_WIRE_FLAGS_MASK, wireFlags);
flagsBuf.length = sizeof(wireFlags);