[krbdev.mit.edu #8935] git commit

"Greg Hudson via RT" <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.bugs
Message-ID <[email protected]>
Tue Aug 04 17:58:48 2020: Request 8935 was acted upon.
 Transaction: Ticket created by [email protected]
       Queue: krb5
     Subject: git commit
       Owner: [email protected]
  Requestors: 
      Status: new
 Ticket <URL: https://krbdev.mit.edu/rt/Ticket/Display.html?id=8935 >



Don't create hostbased principals in new KDBs

Unix-like platforms do not provide a simple method to find the
fully-qualified local hostname as the machine is expected to appear to
other hosts.  Canonicalizing the gethostname() result with
getaddrinfo() usually works, but potentially uses DNS.  Now that
dns_canonicalize_hostname=true is no longer the default, KDB creation
would generally create the wrong host-based principals.

kadmin/hostname is unnecessary because the client software can also
use kadmin/admin, and kiprop/hostname is one of several principals
that must be created for incremental propagation.

https://github.com/krb5/krb5/commit/ac2b693d0ec464e0bcda4953acd79f201169f396
Author: Greg Hudson <[email protected]>
Commit: ac2b693d0ec464e0bcda4953acd79f201169f396
Branch: master
 src/kadmin/dbutil/kadm5_create.c                 |   52 ++-------------------
 src/plugins/kdb/ldap/ldap_util/kdb5_ldap_realm.c |   35 +--------------
 src/tests/dejagnu/krb-standalone/kadmin.exp      |    7 ++-
 src/tests/t_iprop.py                             |    1 +
 src/tests/t_kadmin_acl.py                        |    1 +
 5 files changed, 12 insertions(+), 84 deletions(-)
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.