diff options
author | Greg Hudson <ghudson@mit.edu> | 2013-08-29 18:17:29 -0400 |
---|---|---|
committer | Greg Hudson <ghudson@mit.edu> | 2013-09-03 21:38:31 -0400 |
commit | 2f37634ae89f8bd13ec64120fce56ba5613c498c (patch) | |
tree | e2eec8eaccbc921adacacbdf964139303f0a410c /src/tests/gssapi/t_gssapi.py | |
parent | 95b03a6fef4b86d1f8fac0a6ef92e86d836e261f (diff) | |
download | krb5-2f37634ae89f8bd13ec64120fce56ba5613c498c.tar.gz krb5-2f37634ae89f8bd13ec64120fce56ba5613c498c.tar.xz krb5-2f37634ae89f8bd13ec64120fce56ba5613c498c.zip |
Tighten up referral recognition in KDC TGS code
In do_tgs_req(), treat the search_sprinc() result as a referral only
if it is a cross-TGS principal and it doesn't match the requested
server principal. This change fixes two corner cases: (1) when a
client requests a cross-realm TGT, we won't squash the name type in
the response; and (2) if we are serving multiple realms out of the
same KDB, we will properly handle aliases to any local-realm TGT, not
just the one for the configured realm name.
ticket: 7555
Diffstat (limited to 'src/tests/gssapi/t_gssapi.py')
0 files changed, 0 insertions, 0 deletions