patches to make bind9 with TKEY/GSS updates easier to configure

tridge at samba.org tridge at samba.org
Fri Dec 3 10:22:46 UTC 2010


Hi Love,

 > An alternative is to use the GSS_C_DELEG_POLICY_FLAG which only
 > delegates if the admin of the domain have said its ok to delegate
 > to that host.

Would you recommend that we add it?

With my current patches the flags we're passing are:

 GSS_C_REPLAY_FLAG | GSS_C_MUTUAL_FLAG | GSS_C_INTEG_FLAG

is that a good choice?

Cheers, Tridge



More information about the bind-workers mailing list