Re: saslauthd+kerberos infinite loop inside sendto_kdc.c at function service_fds

Dan White <[email protected]>
Newsgroups gmane.comp.security.cyrus.sasl
Message-ID <[email protected]>
On 09/18/13 19:33 +0100, Rodrigo Nuno Bragança da Cunha wrote:
>On 18/09/13 18:49, Dan White wrote:
>> As a work around, you could try using saslauthd's pam backend with a krb5
>> pam module.
>>
>
>I'm using saslauthd as an authentication method for slapd, so that's not
>really an option...

I do not believe slapd should care, with regards to pass-through
authentication.

>I could patch kerberos code so that if the cycle goes on for X times
>without returning the process dies, or something like that... or I could
>simply kill and relaunch saslauthd automatically if it goes weird...
>
>Could this be a saslauthd bug? Is it a problem with kerberos library?

I am not sure. Could you compile saslauthd against heimdal to see if the
same issue exists?

-- 
Dan White
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.