kdc: don't misidentify constrained delegation requests as anonymous
commitcdd0b70d37d87026e8618ff44b8d636c0bf9cb6c
authorLuke Howard <lukeh@padl.com>
Mon, 3 Jun 2019 04:36:36 +0000 (3 14:36 +1000)
committerLuke Howard <lukeh@padl.com>
Mon, 3 Jun 2019 04:36:36 +0000 (3 14:36 +1000)
treeba658faf2440029bd156ebcb631099bd7c29154c
parent27c6cf7a9f26883eee0b17b36dd58a52d2ca3d98
kdc: don't misidentify constrained delegation requests as anonymous

Earlier (pre-7.6) Heimdal clients would send both the request-anonymous and
cname-in-addl-tkt flags for constrained delegation requests. A true anonymous
TGS request will only have the former flag set. Do not treat TGS requests with
both flags set as anonymous requests.
kdc/kerberos5.c
kdc/krb5tgs.c