[krbdev.mit.edu #8139] SIGNTICKET creation and verification doesn't always use the right key

Greg Hudson via RT rt-comment at krbdev.mit.edu
Sun Dec 4 00:10:36 EST 2016


Renewed tickets can apparently also become unusable across a TGT rekey with 
a different first enctype, due to this bug.  I believe the scenario is 
identical to the forwarding case.

http://mailman.mit.edu/pipermail/kerberos/2016-December/021536.html


More information about the krb5-bugs mailing list