Bug 456 - Krb5 ticket forwarding is tryied even if krb5 authentication failed
Summary: Krb5 ticket forwarding is tryied even if krb5 authentication failed
Status: CLOSED WONTFIX
Alias: None
Product: Portable OpenSSH
Classification: Unclassified
Component: Kerberos support (show other bugs)
Version: -current
Hardware: All All
: P2 normal
Assignee: OpenSSH Bugzilla mailing list
URL:
Keywords:
: 455 (view as bug list)
Depends on:
Blocks:
 
Reported: 2002-12-13 20:33 AEDT by Daniel Kouril
Modified: 2004-04-14 12:24 AEST (History)
0 users

See Also:


Attachments
Don't delegate/accept delegated ticket if krb5 authentication hasn't been done (3.06 KB, patch)
2002-12-13 20:34 AEDT, Daniel Kouril
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Kouril 2002-12-13 20:33:37 AEDT
The client should forward krb5 ticket to the server only if krb5 authentication
was done. Otherwise the krb5 session keys are not set properly and creating of
the  credentials to delegate fails. Likewise, the server should accept
delegation of krb5 ticket only if the client has authenticated by means of krb5.
Current code coredumps (both client and server) without this patch.
Comment 1 Daniel Kouril 2002-12-13 20:34:52 AEDT
Created attachment 185 [details]
Don't delegate/accept delegated ticket if krb5 authentication hasn't been done
Comment 2 Damien Miller 2003-01-03 14:43:15 AEDT
*** Bug 455 has been marked as a duplicate of this bug. ***
Comment 3 Darren Tucker 2003-11-20 00:23:15 AEDT
krb5 has been replaced by gssapi-with-mic, is this still relevant?
Comment 4 Daniel Kouril 2003-11-27 16:24:15 AEDT
The patch fixes the ticket handling in auth-krb5.c (implementing the server part
of krb5 support in ssh v.1) and in sshconnect1.c (client part for krb5 in ssh1).
If you removed the auth-krb5.c file from current release and the krb5 part from
the sshconnect1.c the patch is certainly not needed any more. It has nothing in
common with the new GSS stuff.
Comment 5 Darren Tucker 2004-01-24 18:52:54 AEDT
Simon Wilkinson advises that the code referred to here has been removed and it
is not applicable to the new gssapi code.
Comment 6 Damien Miller 2004-04-14 12:24:18 AEST
Mass change of RESOLVED bugs to CLOSED