diff options
author | Greg Hudson <ghudson@mit.edu> | 2011-02-07 18:40:00 +0000 |
---|---|---|
committer | Greg Hudson <ghudson@mit.edu> | 2011-02-07 18:40:00 +0000 |
commit | 66587fcd6380eac2c53674df4f64a827d337aee5 (patch) | |
tree | e3e98004479a87b3f1e1171056464f3a6be65d95 /src/lib/krb5/libkrb5.exports | |
parent | 1b46b254240d95534b7a3ee1f45ac85f6c38db1b (diff) | |
download | krb5-66587fcd6380eac2c53674df4f64a827d337aee5.tar.gz krb5-66587fcd6380eac2c53674df4f64a827d337aee5.tar.xz krb5-66587fcd6380eac2c53674df4f64a827d337aee5.zip |
Improve acceptor name flexibility
Be more flexible about the principal names we will accept for a given
GSS acceptor name. Also add support for a new libdefaults profile
variable ignore_acceptor_hostname, which causes the hostnames of
host-based service principals to be ignored when passed by server
applications as acceptor names.
Note that we still always invoke krb5_sname_to_principal() when
importing a gss-krb5 mechanism name, even though we won't always use
the result. This is an unfortunate waste of getaddrinfo/getnameinfo
queries in some situations, but the code surgery necessary to defer
it appears too risky at this time.
The project proposal for this change is at:
http://k5wiki.kerberos.org/wiki/Projects/Acceptor_Names
ticket: 6855
git-svn-id: svn://anonsvn.mit.edu/krb5/trunk@24616 dc483132-0cff-0310-8789-dd5450dbe970
Diffstat (limited to 'src/lib/krb5/libkrb5.exports')
-rw-r--r-- | src/lib/krb5/libkrb5.exports | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/src/lib/krb5/libkrb5.exports b/src/lib/krb5/libkrb5.exports index c8918dccdb..6866813975 100644 --- a/src/lib/krb5/libkrb5.exports +++ b/src/lib/krb5/libkrb5.exports @@ -556,6 +556,7 @@ krb5_set_time_offsets krb5_size_opaque krb5_skdc_timeout_1 krb5_skdc_timeout_shift +krb5_sname_match krb5_sname_to_principal krb5_string_to_deltat krb5_string_to_salttype |