[2922] in Kerberos-V5-bugs

home help back first fref pref prev next nref lref last post

krb5-libs/590: des_read_pw_string in libdes425

daemon@ATHENA.MIT.EDU (ghudson@MIT.EDU)
Wed May 13 12:49:28 1998

Resent-From: gnats@rt-11.MIT.EDU (GNATS Management)
Resent-To: krb5-unassigned@RT-11.MIT.EDU
Resent-Reply-To: krb5-bugs@MIT.EDU, ghudson@MIT.EDU
Date: Wed, 13 May 1998 12:43:11 -0400 (EDT)
From: ghudson@MIT.EDU
Reply-To: ghudson@MIT.EDU
To: krb5-bugs@MIT.EDU


>Number:         590
>Category:       krb5-libs
>Synopsis:       des_read_pw_string() is not backward-compatible
>Confidential:   no
>Severity:       serious
>Priority:       low
>Responsible:    krb5-unassigned
>State:          open
>Class:          sw-bug
>Submitter-Id:   unknown
>Arrival-Date:   Wed May 13 12:44:00 EDT 1998
>Last-Modified:
>Originator:     Greg Hudson
>Organization:
MIT
>Release:        1.0pl1
>Environment:
	
System: NetBSD snorklewacker.mit.edu 1.3.1 NetBSD 1.3.1 (ATHENA) #0: Mon Apr 27 17:21:42 EDT 1998 nathanw@antisnork.mit.edu:/u1/var/tmp/sys-1.3.1/arch/i386/compile/ATHENA i386


>Description:
libdes425 is supposed to provide backward compatibility with the krb4
libdes.  Unfortunately, des_read_pw_string() is not compatible; in
both MIT Kerberos and CNS, the fourth argument is a flag "verify"
(which verifies with a prompt "Verifying, please re-enter <first
prompt>").  In libdes425, the fourth argument is a second prompt to
use when verifying, or NULL if verification is not to be done.
>How-To-Repeat:
Compile the CNS kpasswd against the krb4 compatibility libraries.  Watch
it dump core.
>Fix:
None provided, although it's fairly simple.
>Audit-Trail:
>Unformatted:

home help back first fref pref prev next nref lref last post