Re: ISC_RET_xxx and ASC_RET_xxx bits

From: Roy Chastain (roy_at_kmsys.com)
Date: 07/26/05

  • Next message: Frank: "Re: Current user's security identifier"
    Date: Tue, 26 Jul 2005 06:38:26 -0400
    
    

    No, you misunderstand.

    Yes, I realize the ISC_REQ_CONFIDENTIALITY has to be requested by both sides. My point is that when both sides request
    ISC_REQ_CONFIDENTIALITY and the SSL handshake completes with an OK (final calls), the ISC_RET_CONFIDENTIALITY bit is not set, yet
    EncryptMessage and DecryptMessage work.

    When I say "quit working", I mean that about 6-9 months ago, this code was written and tested on a 2000 server with SP4. At that
    point, the ISC_RET_CONFIDENTIALITY bit was returned. Now, with 2000 server SP4 plus recent roll-up, that bit is not returned. I
    also believe that the bit is not being returned on a 2003 SP1.

    Does your example program actaully request encryption and the dump the resulting bits?

    On Tue, 26 Jul 2005 07:29:25 GMT, v-raygon@online.microsoft.com (Rhett Gong [MSFT]) wrote:

    >>Bottom line, is that ISC_RET_CONFIDENTIALITY is missing.
    >You just request ISC_RET_CONFIDENTIALITY in the call, since whether ISC_RET_CONFIDENTIALITY is returned or not
    >depends on the result from the negotiation, there is no guarantee that you will receive this flag, if client/server does not prefer.
    >
    >You said it stopped working while ISC return OK, could you post what subsequent call fails and what error it reports? In
    >addition, have you tested the SDK sample, what result you get?
    >
    >Thanks,
    >Rhett Gong [MSFT]
    >Microsoft Online Partner Support
    >Get Secure! - www.microsoft.com/security
    >http://support.microsoft.com/default.aspx?scid=/servicedesks/msdn/nospam.asp&SD=msdn
    >
    >This posting is provided "AS IS" with no warranties and confers no rights.

    -------------------------------------------
    Roy Chastain
    KMSYS Worldwide, Inc.
    http://www.kmsys.com


  • Next message: Frank: "Re: Current user's security identifier"

    Relevant Pages

    • Re: Some Ruby assistance
      ... your request seems a little too complex to be handled on the ML, ... But maybe the Ruby Mentor project might be of interest for you. ... There are worse things than having people misunderstand your work. ... -- Paul Graham ...
      (comp.lang.ruby)
    • Re: araneida logging
      ... > Unless I misunderstand how Araneida works you want to replace the ... > logfile with a new one whenever a new request comes in. ...
      (comp.lang.lisp)
    • Re: Language Features Id Like To See
      ... So, then I did misunderstand the scope of the request, and all anyone ... wants from this request is an optimized string lookup? ...
      (borland.public.delphi.non-technical)