diff options
Diffstat (limited to 'src/kdc')
-rw-r--r-- | src/kdc/do_tgs_req.c | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/src/kdc/do_tgs_req.c b/src/kdc/do_tgs_req.c index b77c9eb..d41bc5d 100644 --- a/src/kdc/do_tgs_req.c +++ b/src/kdc/do_tgs_req.c @@ -1148,7 +1148,9 @@ find_referral_tgs(kdc_realm_t *kdc_active_realm, krb5_kdc_req *request, kdc_err(kdc_context, retval, "unable to find realm of host"); goto cleanup; } - if (realms == NULL || realms[0] == '\0') { + /* Don't return a referral to the empty realm or the service realm. */ + if (realms == NULL || realms[0] == '\0' || + data_eq_string(srealm, realms[0])) { retval = KRB5KDC_ERR_S_PRINCIPAL_UNKNOWN; goto cleanup; } |