[krbdev.mit.edu #7646] PAC checksum verification failed with enterprise principals

Greg Hudson via RT rt-comment at krbdev.mit.edu
Sat May 25 10:56:28 EDT 2013


I think this is as simple as parsing with KRB5_PRINCIPAL_PARSE_ENTERPRISE 
instead of KRB5_PRINCIPAL_PARSE_NO_REALM.

I'm a bit puzzled why there is an enterprise principal in a PAC client-
info buffer, though.  I thought enterprise principals were for lookup, 
while a PAC contains a canonical name.


More information about the krb5-bugs mailing list