Skip Menu |
 

From: ghudson@mit.edu
Subject: SVN Commit

Avoid setting AD-SIGNEDPATH when returning a cross-realm TGT.
Previously we were avoiding it when answering a cross-realm client,
which was wrong.

Don't fail out on an invalid AD-SIGNEDPATH checksum; just don't trust
the ticket for S4U2Proxy (as if AD-SIGNEDPATH weren't present).


https://github.com/krb5/krb5/commit/6581735ddea7215935e91c34a2103de1acfe3952
Commit By: ghudson
Revision: 23697
Changed Files:
U trunk/src/kdc/kdc_authdata.c
U trunk/src/kdc/kdc_util.c
U trunk/src/kdc/kdc_util.h
From: tlyu@mit.edu
Subject: SVN Commit

pull up r23697 from trunk

------------------------------------------------------------------------
r23697 | ghudson | 2010-02-04 22:43:54 -0500 (Thu, 04 Feb 2010) | 12 lines

ticket: 6655
subject: Fix cross-realm handling of AD-SIGNEDPATH
target_version: 1.8
tags: pullup

Avoid setting AD-SIGNEDPATH when returning a cross-realm TGT.
Previously we were avoiding it when answering a cross-realm client,
which was wrong.

Don't fail out on an invalid AD-SIGNEDPATH checksum; just don't trust
the ticket for S4U2Proxy (as if AD-SIGNEDPATH weren't present).

https://github.com/krb5/krb5/commit/e983c0f99cba07cb7c0a23cf4b8ac3aaba553c46
Commit By: tlyu
Revision: 23708
Changed Files:
U branches/krb5-1-8/src/kdc/kdc_authdata.c
U branches/krb5-1-8/src/kdc/kdc_util.c
U branches/krb5-1-8/src/kdc/kdc_util.h