[krbdev.mit.edu #7910] KDC does not log client principal if TGS header ticket verification fails

Greg Hudson via RT rt-comment at krbdev.mit.edu
Wed Jun 4 13:23:32 EDT 2014


I will adjust this change by paring down the comments and adding a test 
case, and submit a pull request.  The relatively minor behavior change to 
krb5_rd_req_decoded is fine because it hasn't been a public API since 
1.2.2.  The behavior change isn't visible through krb5_rd_req.

I will also add some notes to http://k5wiki.kerberos.org/wiki/Cleanups on 
hygienic changes we might make based on the analysis I did while looking 
at this issue.


More information about the krb5-bugs mailing list