[19546] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: Implicit REALM/DNS Mapping

daemon@ATHENA.MIT.EDU (Greg Hudson)
Thu Feb 9 22:14:10 2017

To: Nathaniel McCallum <npmccallum@redhat.com>, Simo Sorce <simo@redhat.com>,
        Matt Rogers <mrogers@redhat.com>
From: Greg Hudson <ghudson@mit.edu>
Message-ID: <2ebb6e66-6d56-d130-eb1e-fd1e01727476@mit.edu>
Date: Thu, 9 Feb 2017 22:13:53 -0500
MIME-Version: 1.0
In-Reply-To: <CAOASepMdYG2sjpnO3M0_pXTyQbw_diH8fJLT1wBBgx1SX6r7vw@mail.gmail.com>
Cc: krbdev <krbdev@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On 02/09/2017 03:17 PM, Nathaniel McCallum wrote:
> Is MIT willing to merge a patch for this?

Yes.  I think the right place to insert the new logic is at the
beginning of krb5_cc_select().  If server has the referral realm (use
krb5_is_referral_realm() for clarity, although we're just looking for an
empty realm), then call krb5_get_fallback_host_realm() and, if it
succeeds, construct a copy of server using the first fallback realm, to
be passed to the modules.
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post