diff options
author | Jacques Vidrine <nectar@FreeBSD.org> | 2001-07-13 18:12:13 +0000 |
---|---|---|
committer | Jacques Vidrine <nectar@FreeBSD.org> | 2001-07-13 18:12:13 +0000 |
commit | b33edd3956170436a941e68c52cf4f8aa29ddb6f (patch) | |
tree | ca0f98072dcaca6a3189c501f46ac345b9faecc7 /share/man/man9/ucred.9 | |
parent | 5f662f42d6220c187754abacea79239ecffbe28e (diff) |
Bug fix: When the client connects to a server and Kerberos
authentication is enabled, the client effectively ignores any error
from krb5_rd_rep due to a missing branch.
In theory this could result in an ssh client using Kerberos 5
authentication accepting a spoofed AP-REP. I doubt this is a real
possiblity, however, because the AP-REP is passed from the server to
the client via the SSH encrypted channel. Any tampering should cause
the decryption or MAC to fail.
Approved by: green
MFC after: 1 week
Notes
Notes:
svn path=/head/; revision=79683
Diffstat (limited to 'share/man/man9/ucred.9')
0 files changed, 0 insertions, 0 deletions