[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: SPNEGO, gssapi examples, keytab, cracking passwords, ...

On 10/8/05, Michael B Allen <mba2000@ioplex.com> wrote:
5) What is the difference between Kerberos 5 (1.2.840.113554.1.2.2) and
Microsoft Kerberos 5 ( 1.2.840.48018.1.2.2)? Is it just the authorization
data (PAC)?

This was a bug in early windows implementations. Their ASN library were limited so that it could only use 16 bit oid componnets.

So  the real value(113554) was truncated to 16 bits and became  48018.

The old buggy value is still accepted by ms as to provide compatibility with hosts that are not patched yet.

I.e.   they are the same.