[krbdev.mit.edu #7016] SVN Commit

Greg Hudson via RT rt-comment at krbdev.mit.edu
Mon Nov 14 13:02:54 EST 2011


krb5 1.6 through 1.8 contained a workaround for the Active Directory
behavior of returning a TGS referral to the same realm as the request.
1.9 responds to this behavior by caching the returned TGT, trying
again, and detecting a referral loop.  This is a partial regression of
ticket #4955.  Detect this case and fall back to a non-referreal
request.

http://src.mit.edu/fisheye/changelog/krb5/?cs=25472
Commit By: ghudson
Revision: 25472
Changed Files:
U   trunk/src/include/k5-trace.h
U   trunk/src/lib/krb5/krb/get_creds.c




More information about the krb5-bugs mailing list