Skip to main content

tech.pisoft.teagent.GSSAPIAuthentication

The GSSAPIAuthentication class is the exchange behind GSSAPIAuthenticationContext: the Key Service's AM10 login relayed through te_gss_initiator (TE81-474, ADR 0166).

AUTH_INIT names GSSAPIAuthentication; each initiator token travels in one AUTH_UPDATE carrying one PT_BUFFER_BYREF; the key server answers with its token or AUTH_FINAL; when the initiator completes on the key server's AP-REP with nothing to send, AUTH_FINAL arrives unasked. At most eight rounds. The helper's protocol: argv service <principal> [ccache <name>]; stdin line 1 the binding as 64 hex characters, then each key server token in base64; stdout one line per step, TOKEN <b64>, DONE <name> [<b64>] or ERROR <reason>; exit 0 after DONE.

The binding is a secret of the connection: it reaches only the helper's stdin, is never logged, and is zeroed after the exchange.

Since: 8.1

© Pi Soft, 2018-2026 · Tricryption Engine 8.1

Inheritance​

Public Member Functions​

MemberDescription
GSSAPIAuthentication()
long authenticate(TEAgentConnection conn)