United StatesChange Country, Oracle Worldwide Web Sites Communities I am a... I want to...
Bug ID: JDK-6851973 ignore incoming channel binding if acceptor does not set one
JDK-6851973 : ignore incoming channel binding if acceptor does not set one

Details
Type:
Enhancement
Submit Date:
2009-06-17
Status:
Resolved
Updated Date:
2011-12-23
Project Name:
JDK
Resolved Date:
2009-07-17
Component:
security-libs
OS:
generic,windows_xp,linux_redhat_5.0
Sub-Component:
org.ietf.jgss:krb5
CPU:
x86,generic
Priority:
P4
Resolution:
Fixed
Affected Versions:
1.4.2,1.4.2_22-rev,7
Fixed Versions:

Related Reports
Backport:
Backport:
Backport:
Backport:
Backport:
Backport:
Backport:
Backport:

Sub Tasks

Description
JSS/krb5 should ignore remote channel binding info when not requested at local side (RFC 4121 4.1.1.2: the acceptor MAY ignore...).

All major krb5 implementors implement this "MAY", and some applications depend on it as a workaround for not having a way to negotiate the use of channel binding -- the initiator application always uses CB and hopes the acceptor will ignore the CB if the acceptor doesn't support CB.

                                    

Comments
EVALUATION

http://hg.openjdk.java.net/jdk7/tl/jdk/rev/37ed72fe7561
                                     
2009-06-19



Hardware and Software, Engineered to Work Together