Luke Kenneth Casson Leighton <lkcl@samba-tng.org> writes: > does the kdc have sufficient information to perform > the signing? It should. > or is it a better idea to create and use an SSPI crypto > api (see ntsecapi project on dcerpc.net) to perform the > signing? Then to be used by the KDC? If that's the wrapping that's used by the signed stuff, probably so. /assar