summaryrefslogtreecommitdiffstats
path: root/src
diff options
context:
space:
mode:
Diffstat (limited to 'src')
-rw-r--r--src/appl/bsd/login.c3
1 files changed, 2 insertions, 1 deletions
diff --git a/src/appl/bsd/login.c b/src/appl/bsd/login.c
index dee36247a..e2fd62d27 100644
--- a/src/appl/bsd/login.c
+++ b/src/appl/bsd/login.c
@@ -818,7 +818,8 @@ static int verify_krb_v4_tgt (realm)
memcpy ((char *) &addr, (char *)hp->h_addr, sizeof (addr));
/* Do we have rcmd.<host> keys? */
#if 0 /* Be paranoid. If srvtab exists, assume it must contain the
- right key. */
+ right key. The more paranoid mode also helps avoid a
+ possible DNS spoofing issue. */
have_keys = read_service_key (rcmd_str, phost, realm, 0, KEYFILE, key)
? 0 : 1;
memset (key, 0, sizeof (key));