Catching more principals in ads_keytab_verify_ticket()

Andrew Bartlett abartlet at samba.org
Sat Mar 12 01:22:11 GMT 2005


On Fri, 2005-03-11 at 17:13 -0800, Jeremy Allison wrote:

> And of course MIT and Heimdal have different requirements for freeing a keytab
> entry after iterating it... See the function smb_krb5_kt_free_entry() for details.
> Essentially you can't guarentee that a kt_entry is a pointer. It may be a struct,
> so you can't assign NULL to it.
> 
> I *hate* kerberos :-).

This is partly why I'm interested in the idea of 'just pick one' on
Kerberos.  If we just pick one distribution (Heimdal, in a version we
can use), and depend on it explicitly, we might just get one, mostly
sane, set of semantics (that we can fix).

Anyway, that's all Samba4 stuff and you don't care about that ;-)

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org
Student Network Administrator, Hawker College  http://hawkerc.net
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
Url : http://lists.samba.org/archive/samba-technical/attachments/20050312/881fc431/attachment.bin


More information about the samba-technical mailing list