s3:kerberos_verify: ads_dedicated_keytab_verify_ticket() only needs read access
[metze/samba/wip.git] / source3 / libads / kerberos_verify.c
index f11ea88477878a7de385703ca1c912eeb27cb038..0c44db988e62e364816906388470339a5c9c673a 100644 (file)
@@ -58,7 +58,7 @@ static bool ads_dedicated_keytab_verify_ticket(krb5_context context,
 
        ZERO_STRUCT(kt_entry);
 
-       ret = smb_krb5_open_keytab(context, lp_dedicated_keytab_file(), true,
+       ret = smb_krb5_open_keytab(context, lp_dedicated_keytab_file(), false,
            &keytab);
        if (ret) {
                DEBUG(1, ("smb_krb5_open_keytab failed (%s)\n",
@@ -298,7 +298,7 @@ out:
                }
        }
 
-       SAFE_FREE(entry_princ_s);
+       TALLOC_FREE(entry_princ_s);
 
        {
                krb5_keytab_entry zero_kt_entry;