mirror of
https://github.com/samba-team/samba.git
synced 2025-02-04 17:47:26 +03:00
9ad03f51a3
Because the KDC does not limit protocol transition (S4U2Self), two new well-known SIDs are available to give this control to the resource administrator. These SIDs identify whether protocol transition (S4U2Self) has occurred, and can be used with standard access control lists to grant or limit access as needed. See https://docs.microsoft.com/en-us/windows-server/security/kerberos/kerberos-constrained-delegation-overview Pair-Programmed-With: Stefan Metzmacher <metze@samba.org> Signed-off-by: Andreas Schneider <asn@samba.org> Signed-off-by: Stefan Metzmacher <metze@samba.org> Autobuild-User(master): Andreas Schneider <asn@cryptomilk.org> Autobuild-Date(master): Wed Apr 13 13:54:27 UTC 2022 on sn-devel-184