// Create 2 KDCs that has almost the same settings
OneKDC[] kdcs = new OneKDC[2]; boolean[] touched = newboolean[2]; for (int i = 0; i < 2; i++) { finalint pos = i;
kdcs[i] = new OneKDC(null) { protectedbyte[] processTgsReq(byte[] in) throws Exception {
touched[pos] = true; returnsuper.processTgsReq(in);
}
};
kdcs[i].setOption(KDC.Option.ALLOW_S4U2SELF,
List.of(OneKDC.USER + "@" + OneKDC.REALM));
kdcs[i].setOption(KDC.Option.ALLOW_S4U2PROXY, Map.of(
OneKDC.USER + "@" + OneKDC.REALM,
List.of(OneKDC.BACKEND + "@" + OneKDC.REALM)));
}
kdcs[0].writeJAASConf();
// except that the 1st issues a non-forwardable S4U2self // ticket and only the 2nd accepts it
kdcs[0].setOption(KDC.Option.S4U2SELF_NOT_FORWARDABLE, true);
kdcs[1].setOption(KDC.Option.S4U2SELF_ALLOW_NOT_FORWARDABLE, true);
Context c = Context.fromJAAS("client");
c = c.impersonate(OneKDC.USER2);
c.startAsClient(OneKDC.BACKEND, GSSUtil.GSS_KRB5_MECH_OID);
c.take(newbyte[0]);
Asserts.assertTrue(touched[0]); // get S4U2self from 1st one
Asserts.assertTrue(touched[1]); // get S4U2proxy from 2nd one
}
}
Messung V0.5 in Prozent
¤ Dauer der Verarbeitung: 0.11 Sekunden
(vorverarbeitet am 2026-10-11)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.