Re: BUG #4824: KRB5/GSSAPI authentication fails when user != principal

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: BUG #4824: KRB5/GSSAPI authentication fails when user != principal
Дата
Msg-id 16076.1243454795@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: BUG #4824: KRB5/GSSAPI authentication fails when user != principal  (Peter Koczan <pjkoczan@gmail.com>)
Ответы Re: BUG #4824: KRB5/GSSAPI authentication fails when user != principal
Re: BUG #4824: KRB5/GSSAPI authentication fails when user != principal
Список pgsql-bugs
Peter Koczan <pjkoczan@gmail.com> writes:
> This is trust authentication with one rather inconsequential bit of
> verification, that's a fundamental breakage. One of the major points
> of Kerberos is that, for anything that talks Kerberos, you are the
> principal in that ticket. I understand the desire to change some of
> that old code, but why is that principal being ignored?

Well, the reason for that change was that the libpq code was absorbing
userid from any available Kerberos ticket, even if the server
subsequently issued a non-Kerberos authentication challenge.  I still
think that was wrong.  What your complaint seems to suggest is that
the server-side Kerberos auth code should be insisting that the supplied
principal's first component match the requested database userid.
I kinda thought we *had* been doing that, but can't claim to have read
that code closely.  Magnus?

            regards, tom lane

В списке pgsql-bugs по дате отправления:

Предыдущее
От: Peter Koczan
Дата:
Сообщение: Re: BUG #4824: KRB5/GSSAPI authentication fails when user != principal
Следующее
От: Stephen Frost
Дата:
Сообщение: Re: BUG #4824: KRB5/GSSAPI authentication fails when user != principal