You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This PR adds support for the IAKERB extension according to the IAKERB specification.
The main changes are focused on the Kerberos state machine. Previously, the Preauthentication state handled the entire KDC message exchange withing a single async intialize_security_context call. This approach does not work with IAKERB, where KDC messages are exchanged via a server that acts as a proxy. The Preauthentication state has therefore been split into multiple states, allowing the state machine to save Kerberos state between KDC message exchanges.
Additionaly, the AS and TGS exchanges have been extracted into separate state machines. These new state machines are KDC transport-agnostic and can be used with both external KDC and an IAKERB proxy.
What is IAKERB
IAKERB extends Kerberos to support scenarios where the client cannot directly access the KDC. Instead, KDC messages are encapsulated in GSS-API tokens and exchanged through an IAKERB proxy. The server forwards these messages to the LocalKDC, allowing the client to obtain the required Kerberos tickets without direct network access to the KDC.
The reason will be displayed to describe this comment to others. Learn more.
These patches of picky-rs can be removed once a new version containing the following changes will be released: (Devolutions/picky-rs#531) will be released.
The reason will be displayed to describe this comment to others. Learn more.
Requesting changes for the three blocking issues already documented in open inline threads (avoiding duplicate comments): the sibling-only picky dependency patches prevent a clean checkout from building (#751 (comment)); cross-realm referrals never transition back to TgsRequest (#751 (comment)); and the client accepts the server mechListMIC without verification for every SPNEGO mechanism (#751 (comment)). I reproduced the dependency failure with cargo check --locked --offline -p sspi. Please resolve these before merging.
Map IAKERB availability failures to NoAuthenticatingAuthority
src/utils.rs:217
Both errors mean the proxy could not reach a KDC, but mapping them to KdcInvalidRequest prevents Negotiate's documented NTLM fallback, which only handles such network/proxy failures as NoAuthenticatingAuthority (src/negotiate/client.rs:17-30). Map both IAKERB availability errors accordingly so authentication can fall back when NTLM is enabled.
Classify proxy availability failures as NoAuthenticatingAuthority
src/utils.rs:217
Both proxy availability failures are classified as KdcInvalidRequest, so Negotiate will not take its documented network/proxy-error fallback path, which only recognizes NoAuthenticatingAuthority (src/negotiate/client.rs:17-30). These codes mean the proxy could not locate or contact a KDC, not that the client request was invalid; classify them as NoAuthenticatingAuthority so callers receive the correct SSPI status and configured NTLM fallback remains functional.
The new multi-call IAKERB branch has no end-to-end state-machine test; the added test only exercises decode_kdc_reply. Add a mocked AS-error/AS-reply/TGS-reply exchange that checks each ContinueNeeded proxy token, cookie forwarding, transcript accumulation, and the final AP request so regressions in the core feature are detected.
Report the actual invalid server state in diagnostics
src/kerberos/client/mod.rs:697
Because mem::take has already installed the default Failed state, this error always says the context was in Failed rather than identifying the actual Final or Server state that caused the out-of-sequence call. Bind and report the consumed state instead.
Report the actual invalid client state in diagnostics
src/kerberos/server/mod.rs:171
mem::take has already replaced server.state with Failed, so this diagnostic always reports Failed instead of the actual invalid Client or Final state. Bind the matched value and format it directly to preserve an actionable out-of-sequence error.
Copilot also still have a few "High" findings, did you confirm whether it was false positives or fixed?
This branch has not been deployed
No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR adds support for the IAKERB extension according to the IAKERB specification.
The main changes are focused on the
Kerberosstate machine. Previously, thePreauthenticationstate handled the entire KDC message exchange withing a single asyncintialize_security_contextcall. This approach does not work with IAKERB, where KDC messages are exchanged via a server that acts as a proxy. ThePreauthenticationstate has therefore been split into multiple states, allowing the state machine to saveKerberosstate between KDC message exchanges.Additionaly, the
ASandTGSexchanges have been extracted into separate state machines. These new state machines are KDC transport-agnostic and can be used with both external KDC and an IAKERB proxy.What is IAKERB
IAKERB extends Kerberos to support scenarios where the client cannot directly access the KDC. Instead, KDC messages are encapsulated in GSS-API tokens and exchanged through an IAKERB proxy. The server forwards these messages to the LocalKDC, allowing the client to obtain the required Kerberos tickets without direct network access to the KDC.
Microsoft recently introduced IAKERB support in Windows Insider builds as part of its effort to reduce NTLM dependency: https://techcommunity.microsoft.com/blog/windows-itpro-blog/reducing-ntlm-dependency-iakerb-and-localkdc-in-windows-insider-preview/4524615.
Related PRs
KdcResolutionenum instead of KDC url IronRDP#1987