[19161] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: get_cred starting realm

daemon@ATHENA.MIT.EDU (Benjamin Kaduk)
Wed Apr 29 18:24:19 2015

Date: Wed, 29 Apr 2015 18:24:07 -0400 (EDT)
From: Benjamin Kaduk <kaduk@mit.edu>
To: Nico Williams <nico@cryptonector.com>
In-Reply-To: <20150429171826.GN6026@localhost>
Message-ID: <alpine.GSO.1.10.1504291822410.22210@multics.mit.edu>
MIME-Version: 1.0
Cc: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On Wed, 29 Apr 2015, Nico Williams wrote:

> > The LSA itself permits insertion; our MSLSA interface to it may not be
> > quite so generous, though I don't remember offhand.
>
> Does it permit storing of ccconfigs?  (That would be handy.)

   2060     if (krb5_is_config_principal(context, creds->server)) {
   2061         /* mslsa cannot store config creds, so we have to bail.
   2062          * The 'right' thing to do would be to return an appropriate error,
   2063          * but that would require modifying the calling code to check
   2064          * for that error and ignore it.
   2065          */
   2066         return KRB5_OK;
   2067     }

Though, I expect that code was written ten or fifteen years ago and the
comment may be stale.

-Ben
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post