search for: kdc_pkinit_revoke

Displaying 2 results from an estimated 2 matches for "kdc_pkinit_revoke".

2023 Jul 20
1
Samba 4 AD SmartCard Authentication Problem
I found an old bugzilla report for this behavior: https://bugzilla.samba.org/show_bug.cgi?id=9612 According to the statements in it, there was a patch already in version 4.16 and in heimdal 8 last year? Which option must be in the krb5.conf? I have tried kdc_pkinit_revoke and pkinit_revoke. Both have no effect. Am 19.07.2023 um 14:27 schrieb Hans Schulze via samba: > Unfortunately this does not work. > > Example: Yes, when i give it a few Days, the client will retrieve the > actual crl faster. But the auth still works. > > I have tried it. I rev...
2023 Jul 19
1
Samba 4 AD SmartCard Authentication Problem
Unfortunately this does not work. Example: Yes, when i give it a few Days, the client will retrieve the actual crl faster. But the auth still works. I have tried it. I revoked an cert. Installed a new win10 client and joined the domain. After login with the revoked p12 cert on a yubikey, i can see he queries the CDP and still allows the login. With certutil and a cert in DER format, i tried