SubjectComber removes expired tickets from the wrong set

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: P5
    • 6
    • Affects Version/s: 5.0
    • Component/s: security-libs
    • None
    • beta
    • generic
    • generic

      sun.security.jgss.krb5.SubjectComber
      removes expired tickets from a partial copy of the private credential
      set of the subject, instead of the intended internal set of the
      subject. Note that when fixing this problem, jgss should synchronize on
      the set returned by Subject.get*() before iterating through it, and also
      destroy the removed credentials.

            Assignee:
            Xuelei Fan
            Reporter:
            J. Duke
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: