[krbdev.mit.edu #2023] auth_to_localnames drops realm before match

Public Submitter via RT rt-comment at krbdev.mit.edu
Mon Mar 21 17:15:22 EST 2005


The attached patch (against the current 1.4 release) does what i think
the original requestor was after and which i'm also keen on doing:
it turns auth_to_local_names and auth_to_local into real per-realm
configs, specifying auth-to-local conversion based on the aname's
realm. In the absence of an auth_to_local config for a given realm
(besides the default realm), though, the prior behavior of using the
default realm's auth_to_local config is fallen back upon. No such
provision is made for auth_to_local_names, however, as that doesn't
seem to make much sense to me (and it complicates the patch and raises
configuration precedence issues, though somebody with more insight
may be able to work those out, in addition to filtering out the bugs
that the patch no doubt introduces)

--buck


More information about the krb5-bugs mailing list