commit | da9984fc3aafc194485556ae2c7dc6c52cbd56c2 | [log] [tgz] |
---|---|---|
author | Damien Miller <[email protected]> | Wed Aug 31 19:46:26 2005 +1000 |
committer | Damien Miller <[email protected]> | Wed Aug 31 19:46:26 2005 +1000 |
tree | f34f637005409c5d30b393dffe519bf7216d7f6f | |
parent | ca9ce95bdda599dbfa566385e66732327f27dd30 [diff] |
- (djm) OpenBSD CVS Sync - [email protected] 2005/08/30 22:08:05 [gss-serv.c sshconnect2.c] destroy credentials if krb5_kuserok() call fails. Stops credentials being delegated to users who are not authorised for GSSAPIAuthentication when GSSAPIDeletegateCredentials=yes and another authentication mechanism succeeds; bz#1073 reported by paul.moore AT centrify.com, fix by simon AT sxw.org.uk, tested todd@ biorn@ jakob@; ok deraadt@