fix(kerberos): recover from KDC clock skew during AS exchange - #757
Merged
Benoît Cortier (CBenoit) merged 2 commits intoSep 28, 2026
Merged
Conversation
Retry pre-authentication once using KDC error time and use the corrected clock for later authenticators. Apply the configured skew window symmetrically in the built-in KDC and cover recovery, bounded retries, and unrelated errors. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot started reviewing on behalf of
Marc-André Moreau (mamoreau-devolutions)
September 26, 2026 00:18
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The retry is bounded, error propagation is preserved, and the affected authentication paths have focused validation.
Review effort: Balanced
Findings: None
What changed in this PR
Adds per-context KDC clock-skew recovery during Kerberos AS pre-authentication and propagates corrected time to subsequent authenticators.
Changes:
- Retries AS pre-authentication once after
KRB_AP_ERR_SKEW. - Applies learned offsets across password, keytab, smart-card, TGS, AP, and password-change flows.
- Corrects bidirectional KDC skew validation and adds tests.
| File | Description |
|---|---|
tests/sspi/client_server/kerberos/mod.rs |
Tests recovery, retry limits, and unrelated errors. |
tests/sspi/client_server/kerberos/kdc.rs |
Adds configurable mock clock skew. |
src/pk_init.rs |
Supports supplied smart-card timestamps. |
src/kerberos/tests.rs |
Initializes the new context field. |
src/kerberos/pa_datas.rs |
Routes corrected time through pre-auth generation. |
src/kerberos/mod.rs |
Stores and applies the per-context offset. |
src/kerberos/client/mod.rs |
Uses corrected time for TGS and AP authenticators. |
src/kerberos/client/generators.rs |
Adds timestamp-aware generators and keytab coverage. |
src/kerberos/client/change_password.rs |
Corrects password-change authenticator time. |
src/kerberos/client/as_exchange.rs |
Parses skew errors and performs one retry. |
crates/kdc/src/as_exchange.rs |
Accepts skew within the configured window in either direction. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Decrypt the AP-REQ and assert its authenticator timestamp tracks the simulated KDC clock for positive and negative skew while preserving the full authentication checks. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Pavlo Myroniuk (TheBestTvarynka)
approved these changes
Sep 27, 2026
Pavlo Myroniuk (TheBestTvarynka)
left a comment
Collaborator
There was a problem hiding this comment.
LGTM
Benoît Cortier (CBenoit)
deleted the
copilot/fix-kerberos-clock-skew
branch
September 28, 2026 03:09
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
KRB_AP_ERR_SKEW, derive a per-context time offset from the error'sstime/susecand retry once. Propagate a second skew error or any other error without additional retries.max_time_skew.Review and validation
cargo test -q -p sspi -p kdc --features network_client,__test-datacargo check -q -p sspi --all-featurescargo clippy -q -p sspi -p kdc --features network_client,__test-data --lib --tests -- -D warnings -A unreachable-pub -A clippy::non-ascii-literal(the two allowances are for pre-existing warnings outside this change)cargo fmt --allScope: This addresses KDC AS pre-authentication skew. There is no trace from the original PSWSMan report to prove it is the exact failure; a separately skewed application server rejecting the AP exchange is not handled here (related: #83).