[krbdev.mit.edu #8869] git commit

"Greg Hudson via RT" <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.bugs
Message-ID <[email protected]>
Thu Jan 23 14:34:22 2020: Request 8869 was acted upon.
 Transaction: Ticket created by [email protected]
       Queue: krb5
     Subject: git commit
       Owner: [email protected]
  Requestors: 
      Status: new
 Ticket <URL: https://krbdev.mit.edu/rt/Ticket/Display.html?id=8869 >



Apply permitted_enctypes to KDC request enctypes

permitted_enctypes was initially intended only to restrict the
processing of AP requests (and was later applied to KDB key data
searches so that the KDC wouldn't issue a ticket it would refuse to
accept).  Because the documentation was never clear about its scope,
many configurations assume that permitted_enctypes also applies to
clients.

In light of the existing configurations, take the simple way out and
use permitted_enctypes as the default for default_tkt_enctypes and
default_tgs_enctypes.  Update the documentation, add a test to
explicitly check the new behavior, and remove now-unnecessary
configuration from the test suite.

[[email protected]: unrolled helper function; edited documentation and
commit message; simplified test case]

https://github.com/krb5/krb5/commit/8f13fb2342b2a715cfb694688e3435e7f11691f8
Author: Robbie Harwood <[email protected]>
Committer: Greg Hudson <[email protected]>
Commit: 8f13fb2342b2a715cfb694688e3435e7f11691f8
Branch: master
 doc/admin/conf_files/krb5_conf.rst   |   20 ++++--
 doc/admin/enctypes.rst               |    8 ++-
 src/lib/krb5/krb/init_ctx.c          |  144 ++++++++++++++++++----------------
 src/man/krb5.conf.man                |   22 ++++--
 src/tests/dejagnu/config/default.exp |   16 ----
 src/tests/gssapi/t_enctypes.py       |    6 +-
 src/tests/t_sesskeynego.py           |    8 ++
 src/util/k5test.py                   |   30 ++------
 8 files changed, 128 insertions(+), 126 deletions(-)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.