[12007] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

[krbdev.mit.edu #6917] SVN Commit

daemon@ATHENA.MIT.EDU (Greg Hudson via RT)
Thu Jun 2 21:01:01 2011

Mail-followup-to: rt@krbdev.mit.edu
mail-copies-to: never
From: "Greg Hudson via RT" <rt-comment@krbdev.MIT.EDU>
In-Reply-To: <rt-6917@krbdev.mit.edu>
Message-ID: <rt-6917-34079.5.1567147307312@krbdev.mit.edu>
To: "'AdminCc of krbdev.mit.edu Ticket #6917'":;"'AdminCc of krbdev.mit.edu Ticket #6917'":;@MIT.EDU
Date: Thu,  2 Jun 2011 21:00:53 -0400 (EDT)
Reply-To: rt-comment@krbdev.MIT.EDU
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krb5-bugs-bounces@mit.edu


MIT krb5 1.2 and earlier KDCs reject TGS requests if the canonicalize
bit is set.  Prior to 1.9, we used to handle this by making a
non-referral fallback request on any error, but the rewrite in 1.9
mistakenly changed the behavior so that fallback requests are only
made if the original request used the referral realm and the fallback
realm is different from the default realm.  Restore the old behavior.

http://src.mit.edu/fisheye/changelog/krb5/?cs=24946
Commit By: ghudson
Revision: 24946
Changed Files:
U   trunk/src/lib/krb5/krb/get_creds.c

_______________________________________________
krb5-bugs mailing list
krb5-bugs@mit.edu
https://mailman.mit.edu/mailman/listinfo/krb5-bugs

home help back first fref pref prev next nref lref last post