#1055184 python3-kerberos: Please update to at least version 1.2.4

Package:
python3-kerberos
Source:
python3-kerberos
Description:
GSSAPI interface module - Python 3.x
Submitter:
Carsten Leonhardt
Date:
2024-06-17 07:09:05 UTC
Severity:
normal
#1055184#5
Date:
2023-11-01 20:05:47 UTC
From:
To:
Dear maintainer,

starting with at least version 1.2.1 pykerberos gained the ability to
do message encryption. This is very useful when trying to setup
ansible to control windows hosts. See
e.g. https://github.com/diyan/pywinrm/issues/300

I have locally packaged version 1.2.4 that I'm using without problems
so far.

You may want to have a look at https://pypi.org/project/kerberos/ too.

Regards

Carsten

#1055184#10
Date:
2024-06-17 07:05:49 UTC
From:
To:
Hi,

I'd like to echo the bug's original submitter and provide another reason
this should be done:

With the current version of pykerberos in Debian, it is impossible to
communicate with a Microsoft IIS server with fairly common settings, as it
seems it makes it very easy to turn on a requirement for channel bindings.

Worse, when this is the case, the failure mode is incredibly non-obvious -
I spent a day or so analysing ASN.1 dumps to try to figure out why some
clients worked and others didn't.



The current version of pykerberos in Debian was released in 2017!  Please
update to 1.2.4 from 2022.


Note that the pykerberos project now bears this message "NOTE: this fork of
ccs-kerberos is currently on life support mode as Apple has resumed work on
upstream. Please try to use https://pypi.python.org/pypi/kerberos instead
of this fork if possible." however I suggest this message is no longer
accurate as the referenced PyPI project has NOT had any release since 2021,
and the related GitHub repository has since been archived (
https://github.com/apple/ccs-pykerberos). Thus, pykerberos remains the
least-inactive project, and it is not worth Debian switching forks.