Jeffrey Altman 13568961ec krb5: DNS A record fallback test for invalid gTLD
As per
https://www.icann.org/en/system/files/files/name-collision-mitigation-01aug14-en.pdf
prior to a new top-level domain being put into service there is controlled
interuption service which will return explicit responses to DNS A, MX, SRV, and TXT
queries that can be used to detect private namespace collisions.

When performing fallback_get_hosts() check the AF_INET responses to ensure
that they are not the gTLD name collision address 127.0.53.53.  If so, add
an error message to the context and return KRB5_KDC_UNREACH.

Write a warning to the log (if any).

Change-Id: I2578f13948b8327cc3f06542c1e489f02410143a
2016-04-10 17:05:07 -05:00
2014-09-09 18:50:22 +02:00
2016-02-26 00:55:32 -06:00
2016-02-26 00:55:33 -06:00
2016-02-26 12:08:05 -06:00
2016-02-29 19:13:13 -06:00
2016-02-29 19:13:13 -06:00
2016-02-29 19:13:12 -06:00
2016-02-29 19:13:13 -06:00
2016-02-26 01:04:31 -06:00
2014-04-25 02:42:17 +02:00
2004-02-12 14:19:16 +00:00
2016-01-21 12:43:31 -06:00
2000-06-07 10:01:25 +00:00
2002-08-21 13:29:08 +00:00
2016-01-20 11:34:41 -06:00
2014-08-23 19:14:10 -07:00
2014-02-01 22:04:10 +00:00
2014-02-16 08:10:09 -08:00
2016-01-21 12:43:31 -06:00
2009-09-27 18:26:54 -07:00
2011-07-24 22:45:55 -07:00
2010-01-05 19:21:45 +01:00

Heimdal is a Kerberos 5 implementation.

For information how to install see <http://www.h5l.org/compile.html>.

There are briefer man pages for most of the commands.

Bug reports and bugs are appreciated, see more under Bug reports in
the manual on how we prefer them: <heimdal-bugs@h5l.org>.

For more information see the web-page at
<http://www.h5l.org/> or the mailing lists:

heimdal-announce@sics.se	low-volume announcement
heimdal-discuss@sics.se		high-volume discussion

send a mail to heimdal-announce-request@sics.se and
heimdal-discuss-request@sics.se respectively to subscribe.
Languages
C 92.1%
Roff 2.8%
Shell 2.3%
Makefile 0.7%
M4 0.5%
Other 1.4%