> I can only repeat the spnego code is for more than 4 years not needed as the Kerberos libraries can now handle spnego token. Why are you still using it ?
> Can you show me a case where it is needed ?


I have been trying to get SPNEGO working with fallback to NTLM (rather than using kerberos). Should this work out of the box? To do this I built curl with fbopenssl and have had to make a few changes to handle the 3-way protocol for NTLM and change the default gss mech to NTLM. Should I have started from a different base? For example using the Heimdal library to handle everything and ignoring the fbopenssl SPNEGO code? BTW it's not yet working so this is an experiment-in-progress. I'm also planning on trying the Heimdal library only today.

