[krbdev.mit.edu #8868] git commit

"Greg Hudson via RT" <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.bugs
Message-ID <[email protected]>
Wed Jan 22 14:10:34 2020: Request 8868 was acted upon.
 Transaction: Ticket created by [email protected]
       Queue: krb5
     Subject: git commit
       Owner: [email protected]
  Requestors: 
      Status: new
 Ticket <URL: https://krbdev.mit.edu/rt/Ticket/Display.html?id=8868 >



Allow cross-realm RBCD with PAC and other authdata

For cross-realm S4U2Proxy requests, require a PAC to be present to
bypass signedpath verification, but do not require it to be the only
authdata element.  For within-realm requests, add and verify
signedpath authdata regardless of the presence of a PAC.

Simplify the test KDB authdata module and the existing RBCD tests as
we no longer need a way to suppress the test module's KDB authdata.

[[email protected]: rewrote commit message; reordered a condition for
efficiency]

https://github.com/krb5/krb5/commit/94f7c9705879500b1dc8dda8592490efce05688f
Author: Isaac Boukris <[email protected]>
Committer: Greg Hudson <[email protected]>
Commit: 94f7c9705879500b1dc8dda8592490efce05688f
Branch: master
 src/include/kdb.h               |    6 +++---
 src/kdc/kdc_authdata.c          |   21 ++++++++-------------
 src/plugins/kdb/test/kdb_test.c |   23 ++++++-----------------
 src/tests/gssapi/t_s4u.py       |    3 ---
 4 files changed, 17 insertions(+), 36 deletions(-)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.