Thoughts on initial ticket acquisition/verification on Sun (slightly OT)

Frank Cusack fcusack at fcusack.com
Thu Nov 17 12:40:50 EST 2005


On November 17, 2005 8:06:29 AM -0800 Frank Cusack <fcusack at fcusack.com> wrote:
> On November 17, 2005 12:06:54 AM -0800 Frank Cusack <fcusack at fcusack.com> wrote:
>> It seems unlikely to me that Sun LDAP 5.2 uses a fork/exec model, so you
>> should verify that the Sun LDAP 5.2 server does not leak these before
>> going the PAM route.  Running the LDAP server with libumem might be able
>> to show leaks.
>
> But come to think of it, the PAM functionality must already be present and
> therefore tested, so it seems like it should be ok.

And I just looked at Solaris 10 PAM source and I see it's fine.  I guess
it's just my module that is leaky.

-frank


More information about the krbdev mailing list