CVE-2022-2031 s4:kdc: Limit kpasswd ticket lifetime to two minutes or less
authorJoseph Sutton <josephsutton@catalyst.net.nz>
Tue, 24 May 2022 05:53:49 +0000 (17:53 +1200)
committerJule Anger <janger@samba.org>
Wed, 27 Jul 2022 10:52:36 +0000 (10:52 +0000)
commit3e773a3954ff95c4ec9daeedf2739a5edd81e8dc
treecc2ebddfe8af34205186d971020a40e59744913f
parentc0282bbbc132f0409d97f5745ad34eec99176f5d
CVE-2022-2031 s4:kdc: Limit kpasswd ticket lifetime to two minutes or less

This matches the behaviour of Windows.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=15047

Signed-off-by: Joseph Sutton <josephsutton@catalyst.net.nz>
Reviewed-by: Andreas Schneider <asn@samba.org>
selftest/knownfail_heimdal_kdc
selftest/knownfail_mit_kdc
source4/kdc/db-glue.c
source4/kdc/mit-kdb/kdb_samba_principals.c
source4/kdc/samba_kdc.h