summaryrefslogtreecommitdiffstats
path: root/src/lib
diff options
context:
space:
mode:
authorTom Yu <tlyu@mit.edu>2003-03-19 00:48:47 +0000
committerTom Yu <tlyu@mit.edu>2003-03-19 00:48:47 +0000
commit8398785c2e4e44a84e5d96bc123e7dce91310573 (patch)
tree26b8cca7818bac31e999c67ec108c62fbdb287dd /src/lib
parentef57ceebaf979cfad932f14f2c3a7647ae102a90 (diff)
downloadkrb5-8398785c2e4e44a84e5d96bc123e7dce91310573.tar.gz
krb5-8398785c2e4e44a84e5d96bc123e7dce91310573.tar.xz
krb5-8398785c2e4e44a84e5d96bc123e7dce91310573.zip
fix kadmind startup failure with krb4 vuln patch
* keytab.c (krb5_ktkdb_get_entry): Do not perform the enctype comparison if the requested enctype is a wildcard. ticket: new status: open tags: pullup git-svn-id: svn://anonsvn.mit.edu/krb5/trunk@15295 dc483132-0cff-0310-8789-dd5450dbe970
Diffstat (limited to 'src/lib')
-rw-r--r--src/lib/kdb/ChangeLog5
-rw-r--r--src/lib/kdb/keytab.c18
2 files changed, 15 insertions, 8 deletions
diff --git a/src/lib/kdb/ChangeLog b/src/lib/kdb/ChangeLog
index 4592b4c195..e461fdc273 100644
--- a/src/lib/kdb/ChangeLog
+++ b/src/lib/kdb/ChangeLog
@@ -1,3 +1,8 @@
+2003-03-18 Tom Yu <tlyu@mit.edu>
+
+ * keytab.c (krb5_ktkdb_get_entry): Do not perform the enctype
+ comparison if the requested enctype is a wildcard.
+
2003-03-16 Sam Hartman <hartmans@mit.edu>
* keytab.c (krb5_ktkdb_get_entry): Match only against the first
diff --git a/src/lib/kdb/keytab.c b/src/lib/kdb/keytab.c
index 6a1dea1524..90a81cac84 100644
--- a/src/lib/kdb/keytab.c
+++ b/src/lib/kdb/keytab.c
@@ -172,15 +172,17 @@ krb5_ktkdb_get_entry(in_context, id, principal, kvno, enctype, entry)
if (kerror)
goto error;
- kerror = krb5_c_enctype_compare(context, enctype, entry->key.enctype, &similar);
- if (kerror)
- goto error;
-
- if (!similar) {
- kerror = KRB5_KDB_NO_PERMITTED_KEY;
- goto error;
+ if (enctype > 0) {
+ kerror = krb5_c_enctype_compare(context, enctype,
+ entry->key.enctype, &similar);
+ if (kerror)
+ goto error;
+
+ if (!similar) {
+ kerror = KRB5_KDB_NO_PERMITTED_KEY;
+ goto error;
+ }
}
-
/*
* Coerce the enctype of the output keyblock in case we got an
* inexact match on the enctype.