Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-103408

Add channel binding support in requests-gssapi [rhel-10]

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • rhel-10.0
    • python-requests-gssapi
    • None
    • No
    • None
    • rhel-idm-uah
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      Certificate Auto Enrollment in Samba with CEP/CES isn't working against Windows 2025 as support for channel binding is missing in python-requests-gssapi. This is required since 2024-12.

      This is also known as Extended Protection for Authentication.

      See

      https://msrc.microsoft.com/blog/2024/12/mitigating-ntlm-relay-attacks-by-default/
      https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/2c3ea153-eff9-46a7-8614-19b677efa4e0 

              ftrivino@redhat.com Francisco Trivino Garcia
              anschnei@redhat.com Andreas Schneider
              Francisco Trivino Garcia Francisco Trivino Garcia
              Michal Polovka Michal Polovka
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: