kdc: check for cname-in-addl-tkt flag in constrained delegation
Before accepting an additional ticket for use with constrained delegation, verify the cname-in-addl-tkt flag was set. If not, ignore the request.
This commit is contained in:
@@ -2183,6 +2183,7 @@ server_lookup:
|
|||||||
if (client != NULL
|
if (client != NULL
|
||||||
&& b->additional_tickets != NULL
|
&& b->additional_tickets != NULL
|
||||||
&& b->additional_tickets->len != 0
|
&& b->additional_tickets->len != 0
|
||||||
|
&& b->kdc_options.cname_in_addl_tkt
|
||||||
&& b->kdc_options.enc_tkt_in_skey == 0)
|
&& b->kdc_options.enc_tkt_in_skey == 0)
|
||||||
{
|
{
|
||||||
int ad_signedpath = 0;
|
int ad_signedpath = 0;
|
||||||
|
Reference in New Issue
Block a user