Skip to content

Conversation

@laxa
Copy link
Contributor

@laxa laxa commented Nov 24, 2025

When forging or retrieving Kerberos tickets using impacket, they are created without specific umask.
This PR forces the use of 600 chmod by default to improve:

  • Security of tickets
  • The use of samba related tools. Indeed, smbclient and other binaries of the suite will refuse tickets having wrong permissions but the error message is not explicit. This may mislead users.

@anadrianmanrique anadrianmanrique added the in review This issue or pull request is being analyzed label Nov 27, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in review This issue or pull request is being analyzed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants