0.12.4 - 2026-10-06
- Fix SSPI acceptor with explicit
PasswordorKerberosKeytabcredentials failing withSEC_E_LOGON_DENIEDwhen the username is in the UPN formuser@REALM- The
pszPrincipalvalue is no longer passed toAcquireCredentialsHandle, it was set to the SPN for acceptors but does not control the acceptor identity
- The
- Fix
spnego.server(credentials=..., protocol="negotiate", options=NegotiateOptions.use_negotiate)to pass the credentials to the Kerberos and NTLM acceptor contexts it creates- On Windows the Kerberos acceptor had no credential to accept with and was dropped from the mech list, leaving only NTLM
- Fix SPNEGO acceptor to echo the Kerberos OID the initiator offered as the
supportedMech- Windows initiators list the MS Kerberos OID
1.2.840.48018.1.2.2ahead of the standard OID and reject aNegTokenRespthat does not echo it - The MS Kerberos OID and the pre RFC draft OID
1.3.5.1.5.2are treated as aliases of Kerberos when matching the mech list andsupportedMech, matching MIT krb5 - The acceptor no longer requests a
mechListMICwhen the initiator listed a Kerberos alias first as the optimistic mech was the one selected
- Windows initiators list the MS Kerberos OID
- Use
socket.gethostname()rather thansocket.getfqdn()for theDnsComputerNamein the NTLM acceptorCHALLENGEmessagesocket.getfqdn()does a DNS lookup which can block for a few seconds when DNS is not set up for the host
- Fix the SSPI
negotiated_protocolandsession_keyproperties failing with aTypeErrorbefore the first stepnegotiated_protocolreturns the protocol requested, orNonefornegotiate, like the GSSAPI and Python Negotiate proxiessession_keyraisesNoContextErrorlike the GSSAPI proxy
What's Changed
- Bump version after release by @jborean93 in #111
- Fix up some SSPI interop by @jborean93 in #112
- Migrate to Obol KDC in tests by @jborean93 in #113
Full Changelog: v0.12.3...v0.12.4