| Commit message (Expand) | Author | Age | Files | Lines |
* | On decrypt, the ivec should be chained from ciphertextmskrb-integ | Sam Hartman | 2009-01-03 | 1 | -2/+5 |
* | Patch from Luke Howard: | Sam Hartman | 2009-01-03 | 1 | -3/+8 |
* | Luke Howard indicates that ser_sctx.c does not account for the size of the co... | Sam Hartman | 2009-01-03 | 1 | -1/+1 |
* | Revert "integrate Novell patch to always try referrals - I have not reviewed" | Sam Hartman | 2009-01-03 | 1 | -55/+11 |
* | Remove merge issues list | Sam Hartman | 2009-01-03 | 1 | -4/+0 |
* | git-svn managed to generate a bogus commit or otherwise get into a state wher... | Sam Hartman | 2009-01-03 | 4 | -18/+28 |
* | fix merge error | Sam Hartman | 2009-01-03 | 1 | -4/+4 |
* | Make depend | Sam Hartman | 2009-01-03 | 36 | -1025/+1366 |
* | Merge trunk at 21659 | Sam Hartman | 2009-01-03 | 243 | -35356/+1951 |
* | better application behavior although is somewhat non-intuitive. | Sam Hartman | 2009-01-03 | 2 | -16/+31 |
* | If KRB5_PRINCIPAL_UNPARSE_NO_REALM is specified, don't escape the @ | Luke Howard | 2009-01-03 | 1 | -2/+13 |
* | Indent fixup | Luke Howard | 2009-01-02 | 1 | -2/+2 |
* | Cleanup | Luke Howard | 2009-01-02 | 1 | -4/+2 |
* | Fix up comment to explain why the kdb keytab is not used in the tgs case any ... | Sam Hartman | 2009-01-02 | 1 | -4/+2 |
* | Handle KDC_ERR_WRONG_REALM in krb5_get_in_tkt() - needs review, not | Luke Howard | 2009-01-02 | 1 | -1/+38 |
* | cleanup | Luke Howard | 2009-01-02 | 1 | -2/+3 |
* | Revert r21667, it breaks authorization data backends that need access to | Luke Howard | 2009-01-02 | 1 | -0/+13 |
* | Validate k_nprincs != 0 before passing a pointer to krbtgt | Luke Howard | 2009-01-02 | 1 | -2/+2 |
* | Using the server name as a hint | Sam Hartman | 2009-01-02 | 1 | -21/+2 |
* | Use kdb keytab | Sam Hartman | 2009-01-02 | 1 | -13/+0 |
* | KDC always assumes a server | Sam Hartman | 2009-01-02 | 1 | -1/+1 |
* | Don't register any services with portmap. | Sam Hartman | 2009-01-02 | 1 | -1/+1 |
* | Layer gss_sign() on top of gss_get_mic(), gss_verify() on top of | Luke Howard | 2009-01-02 | 15 | -119/+70 |
* | be sure to decode enc_padata | Luke Howard | 2009-01-02 | 1 | -0/+1 |
* | Only allow the AS-REP server principal to be changed if we requested and | Luke Howard | 2009-01-02 | 1 | -5/+15 |
* | move common macros into int-proto.h | Luke Howard | 2009-01-02 | 4 | -12/+6 |
* | In an AS-REP, only canonicalize the server name if we are returning a | Luke Howard | 2009-01-02 | 1 | -14/+8 |
* | Set KRB5_KDB_FLAG_PKINIT flag, AD backends need this to return | Luke Howard | 2009-01-01 | 1 | -0/+3 |
* | Refactor by adding find_pa_data() helper | Luke Howard | 2009-01-01 | 2 | -19/+25 |
* | Use KRB5_PRINCIPAL_UNPARSE_NO_REALM for the logon name; cleanup | Luke Howard | 2009-01-01 | 1 | -9/+9 |
* | Only add FD to sstate.rfds if add_XXX_fd() succeeds | Luke Howard | 2009-01-01 | 1 | -11/+13 |
* | Keep krb5_gss_glue.c just for mechanism-specific API; move the rest into | Luke Howard | 2009-01-01 | 2 | -492/+488 |
* | Back out r2164[78]; although the mech_invoke abstraction is superfluous | Luke Howard | 2009-01-01 | 6 | -37/+247 |
* | remove superfluous comment | Luke Howard | 2009-01-01 | 1 | -2/+0 |
* | remove cruft | Luke Howard | 2009-01-01 | 1 | -25/+0 |
* | fix regression in last commit (use correct OID for inquiring session | Luke Howard | 2009-01-01 | 1 | -9/+7 |
* | gssspi_mech_invoke() is superfluous for mech_krb5, it's only useful for | Luke Howard | 2009-01-01 | 5 | -193/+30 |
* | Restore old gss_krb5_ccache_name() implementation, it does not need to | Luke Howard | 2009-01-01 | 3 | -68/+8 |
* | Don't add a socket to sstate.rfds until add_XXX_fd() has returned | Luke Howard | 2009-01-01 | 1 | -20/+25 |
* | Wrap gss_seal/gss_unseal (V1) on gss_wrap/gss_unrwap (V2), rather than | Luke Howard | 2009-01-01 | 10 | -95/+43 |
* | Use tgs_ktypes rather than permitted_enctypes for client-side EtypeList | Luke Howard | 2009-01-01 | 1 | -14/+15 |
* | Cleanup | Luke Howard | 2008-12-31 | 1 | -5/+1 |
* | skip over KRB5_CRYPTO_TYPE_EMPTY buffers when translating IOV | Luke Howard | 2008-12-31 | 1 | -0/+6 |
* | Correctly distinguish between initiator and acceptor subkey checksum | Luke Howard | 2008-12-31 | 5 | -59/+104 |
* | Previously, we tested explicitly for KRB5_KDB_PWCHANGE_SERVICE when | Luke Howard | 2008-12-30 | 2 | -12/+13 |
* | cleanup | Luke Howard | 2008-12-29 | 1 | -4/+7 |
* | Don't omit ticket session key enctypes when negotiating enctypes | Luke Howard | 2008-12-29 | 1 | -5/+2 |
* | don't return enc-pa-data if canon flag unset | Luke Howard | 2008-12-29 | 1 | -5/+7 |
* | Cleanup kg_make_confounder() somewhat | Luke Howard | 2008-12-29 | 1 | -12/+5 |
* | fix a logic error introduced in r21615 | Luke Howard | 2008-12-28 | 1 | -7/+4 |