mirror of
https://github.com/curl/curl.git
synced 2026-08-24 23:33:33 +03:00
spnego: block NTLM fallback in SPNEGO negotiation
- Switch the Windows SSPI identity struct to SEC_WINNT_AUTH_IDENTITY_EX to use !ntlm in PackageList to prevent NTLM from being offered. - For GSS filter out NTLMSSP OID, and restrict via gss_set_neg_mechs() to prevent NTLM from being offered. - Extend the GSS-API debug stub layer to support the NTLM blocking logic without a real Kerberos environment. - Update test 2057 to check that negotiate auth is silently skipped with no Authorization header when only NTLM stub credentials are available. - Add SPNEGO NTLM blocking test 2093 which verifies that Kerberos credentials still succeed when NTLM is blocked within SPNEGO. - Suppress tests valgrind leak for MIT krb5 gss_display_status, since the leak is in the library and not in curl. To suppress the tests valgrind leak, the wildcard '...' bridges over an anonymous frame inside libgssapi_krb5.so that valgrind reports as '???'. Signed-off-by: Matthew John Cheetham <mjcheetham@outlook.com> Aided-by: Johannes Schindelin Closes https://github.com/curl/curl/pull/21315 Closes https://github.com/curl/curl/pull/22410
This commit is contained in:
parent
c9ead9bd1c
commit
a8881e5e1d
19 changed files with 524 additions and 69 deletions
|
|
@ -517,6 +517,7 @@ the parent project, ideally in the "extra" find package redirect file:
|
|||
Available variables:
|
||||
|
||||
- `HAVE_DES_ECB_ENCRYPT`: `DES_ecb_encrypt` present in OpenSSL (or fork).
|
||||
- `HAVE_GSS_SET_NEG_MECHS`: `gss_set_neg_mechs` present in GSS-API library.
|
||||
- `HAVE_LDAP_INIT_FD`: `ldap_init_fd` present in LDAP library.
|
||||
- `HAVE_LDAP_URL_PARSE`: `ldap_url_parse` present in LDAP library.
|
||||
- `HAVE_MBEDTLS_DES_CRYPT_ECB`: `mbedtls_des_crypt_ecb` present in mbedTLS <4.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue