krb5_sname_to_principal question
Russ Allbery
rra at stanford.edu
Tue Jul 29 15:26:17 EDT 2008
Jos Backus <jos at catnook.com> writes:
> In Kerberos 1.5, krb5_sname_to_principal calls krb5_get_host_realm which
> (when KRB5_DNS_LOOKUP is defined) causes DNS to be queried for a
> _kerberos.FQDN TXT RR when no applicable domain_realm entry is found and
> dns_lookup_realm is set.
>
> In 1.6 the KRB5_DNS_LOOKUP ifdef'ed code was removed. This means that
> the domain_realm section HAS to have a matching entry for the machine,
> mapping it into a realm, whereas in 1.5 this didn't need to be the case
> if the above conditions were met.
I believe this was to support server-side referrals. The idea is that the
client will ask the server for a principal with an empty realm and the
server will figure out the realm.
I don't know exactly how this works, though.
--
Russ Allbery (rra at stanford.edu) <http://www.eyrie.org/~eagle/>
More information about the Kerberos
mailing list