[11746] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

[krbdev.mit.edu #6768] SVN Commit

daemon@ATHENA.MIT.EDU (Tom Yu via RT)
Fri Oct 15 17:42:29 2010

Mail-followup-to: rt@krbdev.mit.edu
mail-copies-to: never
From: "Tom Yu via RT" <rt-comment@krbdev.MIT.EDU>
In-Reply-To: <rt-6768@krbdev.mit.edu>
Message-ID: <rt-6768-33330.2.01250102447624@krbdev.mit.edu>
To: "'AdminCc of krbdev.mit.edu Ticket #6768'":;"'AdminCc of krbdev.mit.edu Ticket #6768'":;@MIT.EDU
Date: Fri, 15 Oct 2010 17:42:26 -0400 (EDT)
Reply-To: rt-comment@krbdev.MIT.EDU
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krb5-bugs-bounces@mit.edu


pull up r24399 from trunk

 ------------------------------------------------------------------------
 r24399 | ghudson | 2010-09-30 23:45:43 -0400 (Thu, 30 Sep 2010) | 12 lines

 ticket: 6768
 subject: GSSAPI forwarded credentials must be encrypted in session key
 target_version: 1.8.4
 tags: pullup

 When IAKERB support was added, the krb5_mk_req checksum function
 gained access to the send subkey.  This caused GSSAPI forwarded
 credentials to be encrypted in the subkey, which violates RFC 4121
 section 4.1.1 and is not accepted by Microsoft's implementation.
 Temporarily null out the send subkey in the auth context so that
 krb5_mk_ncred uses the session key instead.

http://src.mit.edu/fisheye/changelog/krb5/?cs=24460
Commit By: tlyu
Revision: 24460
Changed Files:
U   branches/krb5-1-8/src/lib/gssapi/krb5/init_sec_context.c

_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
https://mailman.mit.edu/mailman/listinfo/krb5-bugs

home help back first fref pref prev next nref lref last post