Re: Bug in 1.5.1 KDC is session key selection
Love Hörnquist Åstrand <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <[email protected]> |
>> >> This is what Jeffrey Altman wrote on the openafs-info mailing list: >> >> --- >> Heimdal 1.5.1 should also be restricting the session key to one of the >> encryption types that are known to the [email protected] principal. That is >> also a bug and should be reported on the heimdal mailing list. >> --- >> >> Love, can you confirm this? >> >> Cheers, >> Andreas > > The bug exists only in the AS-REQ processing and not the TGS-REQ > processing. The TGS-REQ is properly restricting the possible enc-type list. Correct, the issue is that when getting a non krbtgt with AS-REQ, the TGS method of selecting session key should be used. Love
smime.p7s
(application/pkcs7-signature, 4.3 KB) - not displayed