aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorGreg Hudson <ghudson@mit.edu>2017-04-11 17:00:01 -0400
committerGreg Hudson <ghudson@mit.edu>2017-07-17 17:33:47 -0400
commitab8ab286f9c27ea34fb569dcb4472896abbf96d8 (patch)
tree0fdb7191a75d8cde7ad2030bc6d4841ea108c889
parentd1f8fc8a7532d26b3b44a050b3ef71491f5a224d (diff)
downloadkrb5-ab8ab286f9c27ea34fb569dcb4472896abbf96d8.zip
krb5-ab8ab286f9c27ea34fb569dcb4472896abbf96d8.tar.gz
krb5-ab8ab286f9c27ea34fb569dcb4472896abbf96d8.tar.bz2
Check for FAST in encrypted challenge client
If we reach the encrypted challenge clpreauth process method without an armor key, error out instead of crashing. This can happen if (a) the KDC offers encrypted challenge even though the request doesn't use FAST (the Heimdal KDC apparently does this), and (b) we fall back to that preauth method before generating a preauthenticated request, typically because of a prompter failure in encrypted timestamp. Reported by Nico Williams. (cherry picked from commit ff6aac3e018e80fa32df2e14446c6ed9595dfc3c) ticket: 8573 version_fixed: 1.15.2
-rw-r--r--src/lib/krb5/krb/preauth_ec.c2
1 files changed, 2 insertions, 0 deletions
diff --git a/src/lib/krb5/krb/preauth_ec.c b/src/lib/krb5/krb/preauth_ec.c
index b197833..c1aa909 100644
--- a/src/lib/krb5/krb/preauth_ec.c
+++ b/src/lib/krb5/krb/preauth_ec.c
@@ -58,6 +58,8 @@ ec_process(krb5_context context, krb5_clpreauth_moddata moddata,
krb5_keyblock *challenge_key = NULL, *armor_key, *as_key;
armor_key = cb->fast_armor(context, rock);
+ if (armor_key == NULL)
+ return ENOENT;
retval = cb->get_as_key(context, rock, &as_key);
if (retval == 0 && padata->length) {
krb5_enc_data *enc = NULL;