summaryrefslogtreecommitdiff
path: root/source4/auth/kerberos
diff options
context:
space:
mode:
authorAaron Haslett <aaronhaslett@catalyst.net.nz>2018-05-01 11:10:24 +1200
committerAndreas Schneider <asn@cryptomilk.org>2018-05-15 12:41:55 +0200
commita3d6fdd5355d366f3d23915cecc10c6f039daa44 (patch)
tree71f7d788e1df5506c1cc92219197e1a7c38e5f4d /source4/auth/kerberos
parent506c520503eacff33064c1c23a068399f7296d86 (diff)
downloadsamba-a3d6fdd5355d366f3d23915cecc10c6f039daa44.tar.gz
auth: keytab invalidation test
chgtdcpass should add a new DC password and delete the old ones but the bug exposed by this test causes the tool to remove only a single record from the old entries, leaving the old passwords functional. Since the tool is used by administrators who may have disclosed their domain join password and want to invalidate it, this is a security concern. BUG: https://bugzilla.samba.org/show_bug.cgi?id=13415 Signed-off-by: Aaron Haslett <aaronhaslett@catalyst.net.nz> Reviewed-by: Andrew Bartlett <abartlet@samba.org> Reviewed-by: Andreas Schneider <asn@samba.org>
Diffstat (limited to 'source4/auth/kerberos')
0 files changed, 0 insertions, 0 deletions