Details
-
Bug
-
Resolution: Fixed
-
P3
-
8
-
b71
-
generic
-
generic
-
Verified
Backports
Issue | Fix Version | Assignee | Priority | Status | Resolution | Resolved In Build |
---|---|---|---|---|---|---|
JDK-8072265 | 7u85 | Weijun Wang | P3 | Resolved | Fixed | b01 |
JDK-8003243 | 7u80 | Mala Bankal | P3 | Resolved | Fixed | b03 |
JDK-8017395 | 6u65 | Mala Bankal | P3 | Closed | Fixed | b01 |
JDK-8000517 | 6u60 | Mala Bankal | P3 | Closed | Fixed | b01 |
Description
6893158 introduced kvno (key version number) check in AP-REQ parsing. This is a correct behavior but might cause interop/compatibility problems if the server uses a keytab with wrong kvno values. In fact, our vey own ktab.exe tool included in JDK can generate such keytab files because it does not know what the correct kvno is. (Other keytab generation tools like the kadmin or ktpass know the correct kvno because they need to connect to the KDC to work, but ktab.exe is a completely standalone tool)
Through 6984764, we've updated the ktab.exe tool so that user can specify the correct kvno on the command line, or specify it as 0 if it's unknown (0 will be accepted by the check). However, first it's quite difficult to find out the correct kvno. Second, there are old kaytab files that just contain wrong kvno.
This fix intends to add a fallback to the kvno checking, that when no key with matched kvno can be found, we will return the key of the same etype with the highest kvno, hoping it's the last one added to the keytab and therefore likely to be also the latest.
Through 6984764, we've updated the ktab.exe tool so that user can specify the correct kvno on the command line, or specify it as 0 if it's unknown (0 will be accepted by the check). However, first it's quite difficult to find out the correct kvno. Second, there are old kaytab files that just contain wrong kvno.
This fix intends to add a fallback to the kvno checking, that when no key with matched kvno can be found, we will return the key of the same etype with the highest kvno, hoping it's the last one added to the keytab and therefore likely to be also the latest.
Attachments
Issue Links
- backported by
-
JDK-8003243 accept different kvno if there no match
- Resolved
-
JDK-8072265 accept different kvno if there no match
- Resolved
-
JDK-8000517 accept different kvno if there no match
- Closed
-
JDK-8017395 accept different kvno if there no match
- Closed