No description
Find a file
felix h 3ca86602ef spnego_sspi: pass channel bindings on initial context
HTTP Negotiate can create and send a Kerberos token before receiving a
server challenge. The SSPI backend only supplied Schannel endpoint
bindings when a challenge token was present, causing IIS with EPA
enabled to reject preemptive Kerberos authentication with
STATUS_BAD_BINDINGS.

Build the SSPI input descriptor independently of the challenge token so
Schannel endpoint bindings are included on both initial and subsequent
InitializeSecurityContext calls.

Assisted-by: martin-fzi@users.noreply.github.com

Fixes https://github.com/curl/curl/issues/22466
Closes https://github.com/curl/curl/pull/22537
2026-08-25 03:44:46 -04:00
.circleci circleci: bump images to their latest revision 2026-08-24 11:02:04 +02:00
.github tool_doswin: don't use TerminateThread in stdin relay 2026-08-25 03:39:15 -04:00
CMake build: drop detecting gettimeofday() on Windows 2026-08-16 12:34:35 +02:00
docs docs: mention possible auth option conflicts 2026-08-23 23:26:08 +02:00
include urlapi: improved return codes 2026-07-28 13:37:28 +02:00
lib spnego_sspi: pass channel bindings on initial context 2026-08-25 03:44:46 -04:00
LICENSES spacecheck: check long lines and repeat spaces, fix fallouts 2026-03-25 11:02:08 +01:00
m4 build: minor debug option message fixes/improvements 2026-08-10 18:51:15 +02:00
projects lib: new easy option string storage 2026-08-21 09:36:07 +02:00
scripts protocol: simpler Curl_getn_scheme runs faster 2026-08-24 22:57:40 +02:00
src tool_doswin: don't use TerminateThread in stdin relay 2026-08-25 03:39:15 -04:00
tests tool_doswin: don't use TerminateThread in stdin relay 2026-08-25 03:39:15 -04:00
.clang-tidy.yml clang-tidy: enable more checks, fix fallouts 2026-04-14 02:20:16 +02:00
.dir-locals.el copyright: update all copyright lines and remove year ranges 2023-01-03 09:19:21 +01:00
.editorconfig .editorconfig: add 2025-09-02 08:36:40 +02:00
.git-blame-ignore-revs copyright: update all copyright lines and remove year ranges 2023-01-03 09:19:21 +01:00
.gitattributes buildconf: remove 2026-04-04 11:35:24 +02:00
.gitignore gitignore: maintenance updates 2026-07-30 12:00:22 +02:00
.mailmap mailmap: Ralf Mueller 2026-08-12 16:23:58 +02:00
acinclude.m4 build: assume POSIX select() is available 2026-07-31 12:38:52 +02:00
appveyor.sh CI: dump libcurl.pc (and curl-config) to log, verify .pc with pccritic tool 2026-08-12 12:53:06 +02:00
appveyor.yml appveyor: sync Debug options in two jobs 2026-08-10 19:42:22 +02:00
CHANGES.md CHANGES: fix typo in filename 2026-01-01 12:20:10 +01:00
CMakeLists.txt build: drop detecting gettimeofday() on Windows 2026-08-16 12:34:35 +02:00
configure.ac build: drop detecting gettimeofday() on Windows 2026-08-16 12:34:35 +02:00
COPYING COPYING: bump copyright year range to 1996 - 2026 2026-01-08 23:19:44 +01:00
curl-config.in autotools: tidy-up if expressions 2025-12-10 22:29:19 +01:00
Dockerfile Dockerfile: Update debian:bookworm-slim Docker digest to abd67ff 2026-08-05 08:01:28 +02:00
GIT-INFO.md docs/INTERNALS.md -> docs/DEPENDENCIES.md 2026-07-29 14:20:36 +02:00
libcurl.pc.in libcurl.pc: Add Copyright tag to the pkgconf file 2026-08-13 10:11:41 -07:00
Makefile.am autotools: minor fixes and improvements 2026-06-25 11:32:36 +02:00
README tidy-up: comments, messages, formatting 2026-07-30 11:26:22 +02:00
README.md rtmp: drop support 2026-03-21 14:56:06 +01:00
RELEASE-NOTES RELEASE-NOTES: synced 2026-08-23 23:34:48 +02:00
renovate.json renovate: use standard bump formula for OpenSSL 2026-04-15 10:17:33 +02:00
REUSE.toml github: Add AI usage warning to issue, doc and PR templates 2026-06-02 13:47:01 -04:00
SECURITY.md stop using the word 'just' 2026-03-03 15:30:22 +01:00

curl logo

curl is a command-line tool for transferring data from or to a server using URLs. It supports these protocols: DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, MQTTS, POP3, POP3S, RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS.

Learn how to use curl by reading the man page or everything curl.

Find out how to install curl by reading the INSTALL document.

libcurl is the library curl is using to do its job. It is readily available to be used by your software. Read the libcurl man page to learn how.

Open Source

curl is Open Source and is distributed under an MIT-like license.

Contact

Contact us on a suitable mailing list or use GitHub issues/ pull requests/ discussions.

All contributors to the project are listed in the THANKS document.

Commercial support

For commercial support, maybe private and dedicated help with your problems or applications using (lib)curl visit the support page.

Website

Visit the curl website for the latest news and downloads.

Source code

Download the latest source from the Git server:

git clone https://github.com/curl/curl

Security problems

Report suspected security problems privately and not in public.

Backers

Thank you to all our backers 🙏 Become a backer.

Sponsors

Support this project by becoming a sponsor.