[krbdev.mit.edu #8869] git commit

"Greg Hudson via RT" <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.bugs
Message-ID <[email protected]>
<URL: https://krbdev.mit.edu/rt/Ticket/Display.html?id=8869 >


Apply permitted_enctypes to KDC request enctypes

permitted_enctypes was initially intended only to restrict the
processing of AP requests (and was later applied to KDB key data
searches so that the KDC wouldn't issue a ticket it would refuse to
accept).  Because the documentation was never clear about its scope,
many configurations assume that permitted_enctypes also applies to
clients.

In light of the existing configurations, take the simple way out and
use permitted_enctypes as the default for default_tkt_enctypes and
default_tgs_enctypes.  Update the documentation, add a test to
explicitly check the new behavior, and remove now-unnecessary
configuration from the test suite.

[[email protected]: unrolled helper function; edited documentation and
commit message; simplified test case]

(cherry picked from commit 8f13fb2342b2a715cfb694688e3435e7f11691f8)

https://github.com/krb5/krb5/commit/62c1cb2e33ab719e6df8b03388ddd3c3fd459a27
Author: Robbie Harwood <[email protected]>
Committer: Greg Hudson <[email protected]>
Commit: 62c1cb2e33ab719e6df8b03388ddd3c3fd459a27
Branch: krb5-1.18
 doc/admin/conf_files/krb5_conf.rst   |   20 ++++--
 doc/admin/enctypes.rst               |    8 ++-
 src/lib/krb5/krb/init_ctx.c          |  144 ++++++++++++++++++----------------
 src/man/krb5.conf.man                |   22 ++++--
 src/tests/dejagnu/config/default.exp |   16 ----
 src/tests/gssapi/t_enctypes.py       |    6 +-
 src/tests/t_sesskeynego.py           |    8 ++
 src/util/k5test.py                   |   30 ++------
 8 files changed, 128 insertions(+), 126 deletions(-)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.