Displaying 2 results from an estimated 2 matches for "kdc_pkinit_revok".
Did you mean:
kdc_pkinit_revoke
2023 Jul 20
1
Samba 4 AD SmartCard Authentication Problem
I found an old bugzilla report for this behavior:
https://bugzilla.samba.org/show_bug.cgi?id=9612
According to the statements in it, there was a patch already in version
4.16 and in heimdal 8 last year? Which option must be in the krb5.conf?
I have tried kdc_pkinit_revoke and pkinit_revoke. Both have no effect.
Am 19.07.2023 um 14:27 schrieb Hans Schulze via samba:
> Unfortunately this does not work.
>
> Example: Yes, when i give it a few Days, the client will retrieve the
> actual crl faster. But the auth still works.
>
> I have tried it. I re...
2023 Jul 19
1
Samba 4 AD SmartCard Authentication Problem
Unfortunately this does not work.
Example: Yes, when i give it a few Days, the client will retrieve the
actual crl faster. But the auth still works.
I have tried it. I revoked an cert. Installed a new win10 client and
joined the domain. After login with the revoked p12 cert on a yubikey, i
can see he queries the CDP and still allows the login.
With certutil and a cert in DER format, i tried