[krbdev.mit.edu #5712] Random issue reported by Kevin

Jeffrey Altman via RT rt-comment at krbdev.mit.edu
Tue Sep 11 09:52:42 EDT 2007


Kevin Koch via RT wrote:
> Now I am confused.
> 
> The original issues list for the KfW release team had a report of NIM 
> returning the default testprinc at SUCHDAMAGE.ORG to SecureCRT when 
> SecureCRT's username was kpkoch.  In a private message, Sam basically 
> said 'NIM will return creds for the default identity.'  That model of 
> what NIM does seemed to work until the post-KfW 3.2.1 changes.
> 
> If SecureCRT doesn't ask for a particular identity, are you saying 
> there are conditions under which NIM will return something other than 
> the default identity?  Is this different from the 3.2.1 behavior?

I am saying that you should read the code.    Obtaining the "default
identity" does not involve NIM.   By the time that NIM (or Leash) is
queried the user is being prompted and the user can choose to provide
credentials for whatever identity she wants to.

Attach a debugger, set break points, and walk the code.

Jeffrey Altman




More information about the krb5-bugs mailing list