1
0
mirror of https://github.com/samba-team/samba.git synced 2024-12-23 17:34:34 +03:00
samba-mirror/source4/auth/kerberos
Joseph Sutton 0d8995910f CVE-2022-2031 s4:auth: Use PAC to determine whether ticket is a TGT
We use the presence or absence of a REQUESTER_SID PAC buffer to
determine whether the ticket is a TGT. We will later use this to reject
TGTs where a service ticket is expected.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=15047
BUG: https://bugzilla.samba.org/show_bug.cgi?id=15049

Signed-off-by: Joseph Sutton <josephsutton@catalyst.net.nz>
Reviewed-by: Andreas Schneider <asn@samba.org>
2022-07-27 10:52:36 +00:00
..
kerberos_credentials.h s4-auth-krb: Move function into more appropriate header. 2012-04-12 12:06:41 +02:00
kerberos_pac.c CVE-2022-2031 s4:auth: Use PAC to determine whether ticket is a TGT 2022-07-27 10:52:36 +00:00
kerberos_util.c krb5-mit: Enable S4U client support for MIT build 2022-03-04 14:05:31 +00:00
kerberos-notes.txt Fix spelling s/doens't/doesn't/ 2018-05-12 02:09:26 +02:00
kerberos-porting-to-mit-notes.txt Fix spelling s/doens't/doesn't/ 2018-05-12 02:09:26 +02:00
kerberos.h s4-auth: Remove unused headers 2021-12-09 14:14:12 +00:00
krb5_init_context.c s4:kerberos: adapt the heimdal send_to_kdc hooks to the send_to_kdc/realm plugin interface 2022-01-19 20:50:35 +00:00
krb5_init_context.h s4:kerberos: adapt the heimdal send_to_kdc hooks to the send_to_kdc/realm plugin interface 2022-01-19 20:50:35 +00:00
srv_keytab.c s4/auth/krb: fix spelling of entries 2019-03-04 21:41:17 +00:00
wscript_build s4:kerberos: adapt the heimdal send_to_kdc hooks to the send_to_kdc/realm plugin interface 2022-01-19 20:50:35 +00:00