User-agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.12) Gecko/20050915
Nicolas Williams wrote:
If we allow use of GSS-API mechanisms that don't offer integrity
protection then:
a) GS2 has to be modified so the client sends the authzid without
wrapping;