Skip to content

Conversation

@steffen-kiess
Copy link

Add the require_fast option which will cause the authentication to
fail if FAST is not available.

This is useful to prevent KDC reply spoofing and to prevent an attacker from intercepting the encrypted password hash and performing an offline attack on it (when SPAKE is not used).

Add the require_fast option which will cause the authentication to
fail if FAST is not available.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant