kdc: Return NEVER_VALID error code if ticket will never be valid
[lorikeet-heimdal.git] / kdc /
2023-05-16 Joseph Suttonkdc: Return NEVER_VALID error code if ticket will never... lorikeet-heimdal lorikeet-heimdal-202305160500
2023-05-16 Joseph Suttonkdc: Always apply maximum ticket lifetime and renew...
2023-05-16 Joseph Suttonkdc: Pass in HDB_F_ARMOR_PRINCIPAL when fetching armor...
2023-05-16 Joseph Suttonkdc: Have caller pass HDB_F_FOR_TGS_REQ into _kdc_fast_...
2023-05-03 Joseph Suttonkdc: Set PAC as trusted if indicated by the plugin
2023-05-03 Joseph Suttonkdc: Move _krb5_pac_get_attributes_info() call to right...
2023-05-03 Joseph Suttonkdc-plugin: Split updating a PAC out of PAC verification
2023-05-03 Joseph Suttonkdc: Call _kdc_fast_check_armor_pac() prior to calling...
2023-05-03 Andrew BartlettCVE-2022-37966 kdc: Implement new Kerberos session...
2023-05-03 Joseph SuttonCVE-2022-37967 Add new PAC checksum
2023-05-03 Andrew BartlettCVE-2022-37966 HEIMDAL: Look up the server keys to...
2023-05-03 Joseph SuttonSAMBA ONLY kdc: Always include PAC if it is non-NULL
2023-05-03 Joseph Suttonkdc: Allow requesting no PAC for AS-REQ to non-TGS...
2023-05-03 Stefan Metzmacherkdc: don't fail salt_fastuser_crypto with r->req.req_bo...
2023-05-03 Joseph Suttonkdc: Add function to get current KDC time
2023-05-03 Stefan Metzmacherkdc: add kdc_log() before _kdc_fast_mk_error() also...
2023-05-03 Joseph Suttonkdc: Reinstate publicly accessible configuration struct...
2023-05-03 Andrew Bartlettkdc: Change KDC to respect HDB server name type if...
2023-05-03 Joseph Suttonkdc: Don't conceal error code when using FAST
2023-05-03 Joseph Suttonkdc: Send ETYPE-INFO2 instead of PW-SALT for validated...
2023-01-10 Nicolas WilliamsRevert "kdc: Quiet warning in FAST unwrap"
2023-01-04 Nicolas Williamskdc: Explicitly ignore return in audit code
2023-01-04 Nicolas Williamshttpkadmind: If early ENOMEM, close the connection
2023-01-04 Nicolas Williamsbx509d: If early ENOMEM, close the connection
2023-01-04 Nicolas Williamsbx509: Fix error path NULL dereference
2023-01-04 Nicolas Williamshttpkadmind: Quiet warning
2023-01-04 Nicolas Williamskdc: Fix deref-before-NULL-check in _kdc_db_fetch()
2023-01-04 Nicolas Williamshttpkadmind: Fix ENOMEM leak
2023-01-04 Nicolas Williamshttpkadmind: Quiet set-but-not-use variable warning
2023-01-04 Nicolas Williamshpropd: Fix use-after-free? (WIP)
2023-01-04 Nicolas Williamsbx509d: Fix leaks
2023-01-04 Nicolas Williamsbx509d: Fix free() of text string
2023-01-04 Nicolas Williamstest_token_validator: Quiet set-but-not-use variable...
2023-01-04 Nicolas Williamstest_csr_authorizer: Fix use-after-free
2023-01-04 Nicolas Williamskdc: Quiet warnings re: debug logging
2023-01-04 Nicolas Williamskdc: Quiet set-but-not-use variable warning in HDB...
2023-01-04 Nicolas Williamskdc: Quiet a static analyzer warning
2023-01-04 Nicolas Williamskdc: Fix ENOMEM double-free in IPC CSR authorizer
2023-01-04 Nicolas Williamskdc: Fix #1059
2023-01-04 Nicolas Williamskdc: Quiet set-but-not-use variable warning
2023-01-04 Nicolas Williamskdc: Quiet set-but-not-use variable warning in kdc...
2023-01-04 Nicolas Williamskdc: Quiet warning in FAST unwrap
2022-12-15 Nicolas Williamsbx509d: Add test of IPC CSR authorizer
2022-12-15 Nicolas Williamsbx509d: /get-tgts: Allow piecemeal authorization
2022-12-15 Nicolas Williamsbx509d: Set log destination
2022-12-15 Nicolas Williamsbx509d: Fix leak of error messages
2022-11-22 Nicolas Williamskdc: OpenSSL 3.0 support
2022-11-17 Joseph SuttonIntroduce macro for common plugin structure elements
2022-11-17 Stefan Metzmacherkdc: add missing enctype = p[i] assignments to _kdc_fin...
2022-11-17 Joseph Suttonkdc: Check generate_pac() return code
2022-11-17 Volker Lendeckeheimdal: Fix the 32-bit build on FreeBSD
2022-10-03 Nicolas Williamshttpkadmind: Make more like bx509d internally
2022-10-03 Nicolas Williamsbx509d: Add /get-tgts batch end-point
2022-09-25 Stefan Metzmacherkdc: add enable_fast option (enabled by default)
2022-08-07 Nicolas Williamsbx509: Fix typos in commentary
2022-04-30 Joseph SuttonUse constant-time memcmp when comparing sensitive buffers
2022-04-26 Nicolas Williamshttpkadmind: Clarify namespace in man page
2022-04-26 Nicolas Williamshttpkadmind: Enable materialization
2022-04-26 Nicolas Williamshttpkadmind: Make get_keys_max_spns configurable
2022-04-26 Nicolas Williamshttpkadmind: Support ok-as-delegate and such
2022-03-16 Nicolas Williamskdc: Add error symbols for error logging
2022-03-08 Joseph Suttonkdc: Add function to add encrypted padata
2022-03-02 Luke Howardkdc: allow audit plugins to influence return code
2022-03-02 Stefan Metzmacherkdc: provide kdc_request_get_explicit_armor_{clientdb...
2022-03-02 Stefan Metzmacherkdc-plugin: also pass astgs_request_t to the pac relate...
2022-02-16 Nicolas Williamskdc: HDB max_life/max_renew == 0 -> unlimited
2022-02-15 Nicolas Williamskdc: Honor "unlimited" max_life/max_renew
2022-02-15 Nicolas Williamsbx509d: Do not leak temp ccaches
2022-01-30 Luke Howardgss: remove gss_get_instance()
2022-01-29 Jeffrey Altmanmore dealloc functions require HEIM_CALLCONV
2022-01-28 Luke Howardkdc: fix warning in kdc_array_iterate()
2022-01-28 Luke Howardkdc: add wrappers for heimbase object accessors
2022-01-28 Luke Howardkdc: fix warning in GSS pre-authentication support
2022-01-24 Jeffrey Altmankdc: _kdc_find_etype if is_preauth must use long term...
2022-01-24 Jeffrey Altmankdc: hprop propagate_database do not leak 'server'
2022-01-24 Jeffrey Altmankdc: hprop check return code if local realm
2022-01-22 Luke Howardkdc: kdc_request_add_pac_buffer() make pactype unsigned
2022-01-20 Luke Howardkdc: declare calling/linkage conventions for accessors
2022-01-20 Nicolas Williamskdc: Fix copy_Principal_ptr() bug (plugin acc.)
2022-01-20 Luke Howardkdc: add _nocopy setter for use by mssfu
2022-01-20 Luke Howardkdc: add accessor functions for KDC request structure
2022-01-20 Luke Howardbase: change ret fieldname to error_code in request...
2022-01-20 Nicolas Williamskdc: Do not announce via Bonjour when testing
2022-01-19 Nicolas Williamskdc: Fix leak caused by a1481f1f0
2022-01-18 Nicolas Williamskdc: Fix recent dangling ptr; move more into r
2022-01-18 Nicolas Williamskdc: Rewrite get_pa_etype_info and set_salt_padata
2022-01-18 Nicolas Williamskdc: Check krb5_ret_uint32() in connect loop
2022-01-18 Nicolas Williamskdc: Check errors from krb5_auth_con_getauthenticator()
2022-01-18 Nicolas Williamskdc: Make --kdc-request-log-file concrrency-safe
2022-01-18 Nicolas Williamskdc: Explicitly ignore setsockopt() result
2022-01-18 Luke Howardkdc: use public audit API in altsecid authorizer plugin
2022-01-18 Luke Howardkdc: make auditing API public
2022-01-18 Luke Howardkdc: remove krb5_ prefix for KDC attribute functions
2022-01-18 Jeffrey Altmankdc: kdc_issue_certificate remove dead code
2022-01-18 Jeffrey Altmankdc: cmd_append fix broken commit
2022-01-18 Jeffrey Altmankdc: cmd_append do not forget va_end()
2022-01-18 Jeffrey Altmankdc: _kdc_do_kx509 prevent use of NULL cprincipal
2022-01-18 Jeffrey Altmankdc: _kdc_find_etype prevent NULL dereference
2022-01-17 Nicolas Williamskdc: One more memcmp() implicit comparison to 0
2022-01-17 Joseph Suttonkdc: Still prefer encryption types with "not default...
next