[krbdev.mit.edu #7016] SVN Commit 
    Greg Hudson via RT 
    rt-comment at krbdev.mit.edu
       
    Mon Nov 14 13:02:54 EST 2011
    
    
  
krb5 1.6 through 1.8 contained a workaround for the Active Directory
behavior of returning a TGS referral to the same realm as the request.
1.9 responds to this behavior by caching the returned TGT, trying
again, and detecting a referral loop.  This is a partial regression of
ticket #4955.  Detect this case and fall back to a non-referreal
request.
http://src.mit.edu/fisheye/changelog/krb5/?cs=25472
Commit By: ghudson
Revision: 25472
Changed Files:
U   trunk/src/include/k5-trace.h
U   trunk/src/lib/krb5/krb/get_creds.c
    
    
More information about the krb5-bugs
mailing list