[krbdev.mit.edu #1540] verify_as_reply on client incorrectly checks KDC_OPT_RENEWABLE_OK

Alexandra Ellwood via RT rt-comment at krbdev.mit.edu
Fri May 30 14:52:14 EDT 2003


verify_as_reply() on the client side incorrectly checks
KDC_OPT_RENEWABLE_OK.  It should only check the renewable lifetime of
tickets whose request options included KDC_OPT_RENEWABLE_OK if those
options did not also include KDC_OPT_RENEWABLE.  Otherwise
verify_as_reply() will fail for all renewable tickets.


More information about the krb5-bugs mailing list