Comment 22 for bug 551901

Revision history for this message
Thierry Carrez (ttx) wrote :

Right, we are missing two pieces of information:

"Someone familiar with the MIT SPNEGO code needs to look at the patch and confirm it actually ignores MIC tokens only when MIC tokens are optional. In particular, we want to confirm that if the mechanism supports integrity and a MIC token would be required either through request-mic state or because the acceptor didn't choose tho optimistic mechanism,that a MIC token is still required."

--> This requires the patch to be discussed upstream, so it needs to be submitted there

"Confirm the impact is limited to Windows 2000 Server DCs"

--> Which versions of DCs are impacted, so that we can set the importance accordingly