From 10a5976e450ac591d32cfa57f7e2d14621eabaa7 Mon Sep 17 00:00:00 2001 From: Love Hornquist Astrand Date: Tue, 22 Dec 2009 07:36:01 +0100 Subject: [PATCH 1/3] Log what principal was used in the failure case --- kdc/kx509.c | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) diff --git a/kdc/kx509.c b/kdc/kx509.c index eb757bb57..f6f8f8a3b 100644 --- a/kdc/kx509.c +++ b/kdc/kx509.c @@ -345,10 +345,24 @@ _kdc_do_kx509(krb5_context context, ret = krb5_principal_compare(context, sprincipal, principal); krb5_free_principal(context, principal); if (ret != TRUE) { + char *expected, *used; + + ret = krb5_unparse_name(context, sprincipal, &expected); + if (ret) + goto out; + ret = krb5_unparse_name(context, principal, &used); + if (ret) { + krb5_xfree(expected); + goto out; + } + ret = KRB5KDC_ERR_SERVER_NOMATCH; krb5_set_error_message(context, ret, - "User %s used wrong Kx509 service principal", - cname); + "User %s used wrong Kx509 service " + "principal, expected: %s, used %s", + cname, expected, used); + krb5_xfree(expected); + krb5_xfree(used); goto out; } } From 4182a61ebaa89a2a7ee7ebee08d73926f8e3d8f4 Mon Sep 17 00:00:00 2001 From: Love Hornquist Astrand Date: Tue, 22 Dec 2009 09:03:05 +0100 Subject: [PATCH 2/3] rename closesocket to rk_closesocket --- lib/krb5/send_to_kdc.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/lib/krb5/send_to_kdc.c b/lib/krb5/send_to_kdc.c index 87e6fb24f..a9be31e81 100644 --- a/lib/krb5/send_to_kdc.c +++ b/lib/krb5/send_to_kdc.c @@ -293,7 +293,7 @@ send_via_proxy (krb5_context context, continue; rk_cloexec(s); if (connect (s, a->ai_addr, a->ai_addrlen) < 0) { - closesocket (s); + rk_closesocket (s); continue; } break; @@ -311,7 +311,7 @@ send_via_proxy (krb5_context context, } ret = send_and_recv_http(s, context->kdc_timeout, prefix, send_data, receive); - closesocket (s); + rk_closesocket (s); free(prefix); if(ret == 0 && receive->length != 0) return 0; @@ -420,7 +420,7 @@ krb5_sendto (krb5_context context, continue; rk_cloexec(fd); if (connect (fd, a->ai_addr, a->ai_addrlen) < 0) { - closesocket (fd); + rk_closesocket (fd); continue; } switch (hi->proto) { @@ -437,7 +437,7 @@ krb5_sendto (krb5_context context, send_data, receive); break; } - closesocket (fd); + rk_closesocket (fd); if(ret == 0 && receive->length != 0) goto out; } From ecf9e3c989d289d839f4a758b4b654374454639a Mon Sep 17 00:00:00 2001 From: Love Hornquist Astrand Date: Tue, 22 Dec 2009 13:36:58 +0100 Subject: [PATCH 3/3] Clean kadm5-pwcheck.h --- include/kadm5/Makefile.am | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/include/kadm5/Makefile.am b/include/kadm5/Makefile.am index c7bb38524..19d782e13 100644 --- a/include/kadm5/Makefile.am +++ b/include/kadm5/Makefile.am @@ -2,4 +2,5 @@ include $(top_srcdir)/Makefile.am.common -CLEANFILES = admin.h kadm5_err.h private.h kadm5-private.h kadm5-protos.h +CLEANFILES = admin.h kadm5_err.h private.h +CLEANFILES += kadm5-private.h kadm5-protos.h kadm5-pwcheck.h