Page MenuHomeFreeBSD

pam_krb5: Restore allow_kdc_spoof option
Needs ReviewPublic

Authored by des on Sat, Nov 22, 4:57 PM.
Tags
None
Referenced Files
F137368624: D53884.id166968.diff
Sat, Nov 22, 8:30 PM
F137368564: D53884.id.diff
Sat, Nov 22, 8:29 PM
F137368439: D53884.diff
Sat, Nov 22, 8:28 PM
Subscribers

Details

Reviewers
cy
ivy
Group Reviewers
security
Summary

Not only does the new pam_krb5 module not have the same allow_kdc_spoof
option that the old one had, its behavior in this matter defaults to
insecure. Reimplement allow_kdc_spoof and switch the default back.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 68808
Build 65691: arc lint + arc unit

Event Timeline

Note that this patch updates the source for the documentation but not the mdoc file that we actually install; see D53885 for that.