wrong permissions checked in krb5

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: P4
    • 8
    • Affects Version/s: 7u79, 7u80, 7u85, 8
    • Component/s: security-libs
    • None
    • 7
    • b69
    • Verified

        In JAAS, PrivateCredentialPermissions are needed to read various kinds of private credentials. For krb5, they are normally for KerberosTicket, KerberosKey and KeyTab classes. However, JDK 7 stores a special kind of sun.security.jgss.krb5.Krb5Util$KeysFromKeyTab objects which is not covered by the normal permissions.

              Assignee:
              Weijun Wang
              Reporter:
              Weijun Wang
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated:
                Resolved: