s4:kdc: strictly have 2 16-bit parts in krbtgt kvnos
authorStefan Metzmacher <metze@samba.org>
Wed, 16 Feb 2022 13:11:10 +0000 (14:11 +0100)
committerStefan Metzmacher <metze@samba.org>
Thu, 28 Apr 2022 15:42:38 +0000 (15:42 +0000)
commit82d86282ca64177fe65cb5ab017a475a95d67cf3
tree5302f153f2c37916bb8ea131ad14de0cf1205f7f
parent6cbaa31fe0a04825f1a7011d6c2ecb50c91861bf
s4:kdc: strictly have 2 16-bit parts in krbtgt kvnos

Even if the msDS-KeyVersionNumber of the main krbtgt
account if larger than 65535, we need to have
the 16 upper bits all zero in order to avoid
mixing the keys with an RODC.

BUG: https://bugzilla.samba.org/show_bug.cgi?id=14951

Signed-off-by: Stefan Metzmacher <metze@samba.org>
Reviewed-by: Andrew Bartlett <abartlet@samba.org>
(cherry picked from commit ab0946a75d51b8f4826d98c61c3ad503615009fe)

Autobuild-User(v4-16-test): Stefan Metzmacher <metze@samba.org>
Autobuild-Date(v4-16-test): Thu Apr 28 15:42:38 UTC 2022 on sn-devel-184
source4/kdc/db-glue.c