[1252] in Kerberos_V5_Development
Re: security flaw in get_in_tkt: address verification
daemon@ATHENA.MIT.EDU (Barry Jaspan)
Thu May 30 13:34:41 1996
Date: Thu, 30 May 1996 13:34:34 -0400
From: "Barry Jaspan" <bjaspan@MIT.EDU>
To: epeisach@MIT.EDU
Cc: krbdev@MIT.EDU
In-Reply-To: <9605301722.AA03376@kangaroo.mit.edu> (message from Ezra Peisach on Thu, 30 May 1996 13:22:45 EDT)
Date: Thu, 30 May 1996 13:22:45 EDT
From: Ezra Peisach <epeisach@MIT.EDU>
Question: Your code fragment implied that the code was commented out... I
Do you think that was to handle the multiple homed hosts out there now?
Yes, the code is commented out, and I have no idea why. Perhaps
someone commented it out because the addrs variable is no available,
but in fact the addresses are in the request structure, which is
available.
Barry