krb5 commit [krb5-1.14]: Fix PKINIT two-component matching rule parsing

Greg Hudson <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.cvs
Message-ID <[email protected]>
https://github.com/krb5/krb5/commit/cf3fafb2f0558f0ca984ebe33afd15c97192e17c
commit cf3fafb2f0558f0ca984ebe33afd15c97192e17c
Author: Greg Hudson <[email protected]>
Date:   Fri Feb 24 13:41:53 2017 -0500

    Fix PKINIT two-component matching rule parsing
    
    In pkinit_matching.c:parse_rule_set(), apply the default relation when
    parsing the second component of a rule, not the third.  Otherwise we
    apply no default relation to two-component matching rules, effectively
    reducing such rules to their second components.  Reported by Sumit
    Bose.
    
    (cherry picked from commit 67ae7bbe1ea7032d1cb79682be3a14e7e13ec64f)
    
    ticket: 8553
    version_fixed: 1.14.5

 src/plugins/preauth/pkinit/pkinit_matching.c |    2 +-
 1 files changed, 1 insertions(+), 1 deletions(-)

diff --git a/src/plugins/preauth/pkinit/pkinit_matching.c b/src/plugins/preauth/pkinit/pkinit_matching.c
index a3bf3f4..a50c50c 100644
--- a/src/plugins/preauth/pkinit/pkinit_matching.c
+++ b/src/plugins/preauth/pkinit/pkinit_matching.c
@@ -409,7 +409,7 @@ parse_rule_set(krb5_context context,
     }
     rs->num_crs = 0;
     while (remaining > 0) {
-        if (rs->relation == relation_none && rs->num_crs > 1) {
+        if (rs->relation == relation_none && rs->num_crs > 0) {
             pkiDebug("%s: Assuming AND relation for multiple components in rule '%s'\n",
                      __FUNCTION__, rule_in);
             rs->relation = relation_and;
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.