[103] in Kerberos-V5-bugs
krb5_get_cred_from_kdc in src/lib/krb/gc_frm_kdc.c
daemon@ATHENA.MIT.EDU (daemon@ATHENA.MIT.EDU)
Fri Feb 1 09:56:16 1991
Date: Fri, 1 Feb 91 09:53:16 EST
From: PAU@IBM.COM
To: krb5-testers@ATHENA.MIT.EDU
In lines 90-91 of the function krb5_get_cred_from_kdc, should the role
of the client and server be reversed? I think the client should try to
find the server realm's TGS registered in the client's realm; i.e.,
change
90 if(retval = krb5_tgtname(krb5_princ_realm(cred->client),
91 krb5_princ_realm(cred->server), &tgtq.server))
to
90 if(retval = krb5_tgtname(krb5_princ_realm(cred->server),
91 krb5_princ_realm(cred->client), &tgtq.server))
This change is consistent with the comments (lines 77-81).
Regards, Pau-Chen