[krbdev.mit.edu #6473] strip ok-as-delegate if not in cross-realm TGT chain

Tom Yu via RT rt-comment at krbdev.mit.edu
Tue Apr 21 14:54:33 EDT 2009


The existing implementation of GSS_C_DELEG_POLICY_FLAG does not examine cross-realm 
tickets leading to the service ticket.  Implement Heimdal's solution of stripping ok-as-delegate 
flags inside get_creds if an intervening cross-realm TGT lacks it.



More information about the krb5-bugs mailing list