Re: [External] Re: kprop across NAT boundaries (patching privsafe)
Jorj Bauer <[email protected]> Thu, 7 Jan 2021 22:00:45 +0000
| Newsgroups | gmane.comp.encryption.kerberos.devel |
|---|---|
| Message-ID | <0e47e7c5-6010-40c1-bb69-a1a7d04b0132@Spark> |
That works! Thanks... — j On Jan 7, 2021, 2:57 PM -0500, Greg Hudson <[email protected]>, wrote: On 1/7/21 1:35 PM, Jorj Bauer wrote: It’s failing at the head of recv_database, where it tries to krb5_rd_safe(). It seems that k5_privsafe_check_addrs() checks the message r-address against the list of local addresses if the auth context doesn't contain a specific local address. However, the r-address is optional (even if the receiver's auth context does contain a local address), so we can just modify kprop not to send it. Please try this commit: https://github.com/greghudson/krb5/commit/f1f5b5eed3ef0779225ada6ab4f092b5267f1398 _______________________________________________ krbdev mailing list [email protected] https://mailman.mit.edu/mailman/listinfo/krbdev