diff options
| author | Greg Hudson <ghudson@mit.edu> | 2013-04-29 11:52:55 -0400 |
|---|---|---|
| committer | Greg Hudson <ghudson@mit.edu> | 2013-04-29 11:52:55 -0400 |
| commit | bcece3a8289dcce0dc0a2bf7a35ed339ee9a98ec (patch) | |
| tree | 653bf063d89ebf371a4e700b9e9d046c3f325c77 /src/include | |
| parent | 9977eb769b9def8fbbf289f7eac3938c863fa2ef (diff) | |
| download | krb5-bcece3a8289dcce0dc0a2bf7a35ed339ee9a98ec.tar.gz krb5-bcece3a8289dcce0dc0a2bf7a35ed339ee9a98ec.tar.xz krb5-bcece3a8289dcce0dc0a2bf7a35ed339ee9a98ec.zip | |
Better fix for not using expired TGTs in TGS-REQs
We want to generate a KRB5_AP_ERR_TKT_EXPIRED code when the TGT is
expired, like we would if we tried the TGT against the KCD. To make
this work, separate the helpers for getting local and crossrealm
cached TGTs. For a crossrealm TGT, match against the endtime, as
there could be multiple entries. For a local TGT, find any match, but
check if it's expired. The cache_code field is no longer needed after
this change, so get rid of it.
ticket: 6948
Diffstat (limited to 'src/include')
0 files changed, 0 insertions, 0 deletions
