HEIMDAL:kdc: let check_PAC() to verify the incoming server and krbtgt cheksums
authorStefan Metzmacher <metze@samba.org>
Fri, 25 Mar 2011 13:57:42 +0000 (14:57 +0100)
committerStefan Metzmacher <metze@samba.org>
Wed, 18 May 2011 05:46:33 +0000 (07:46 +0200)
commitcc0ff48f28d13fd155489e08f75e64ff0e11b1de
treee0f28b44812e8219d5734094f92725c9390b8ab4
parent28734295557620c36ffe8f51dcef7158c46d78a0
HEIMDAL:kdc: let check_PAC() to verify the incoming server and krbtgt cheksums

For a normal TGS-REQ they're both signed with krbtgt key.
But for S4U2Proxy requests which ask for contrained delegation,
the keys differ.

metze
source4/heimdal/kdc/krb5tgs.c