diff options
author | Stefan Metzmacher <metze@samba.org> | 2008-09-11 06:46:43 +0200 |
---|---|---|
committer | Stefan Metzmacher <metze@samba.org> | 2008-09-23 11:30:01 +0200 |
commit | 02cffed79dc74541ac9e9c7835573e8dfad1bb05 (patch) | |
tree | 84e5ec4d70a5157bf61354a45df0a936e0b95fb0 | |
parent | 23e31350f5ba23b0b995ff3d14bfbff50cdece6c (diff) | |
download | samba-02cffed79dc74541ac9e9c7835573e8dfad1bb05.tar.gz samba-02cffed79dc74541ac9e9c7835573e8dfad1bb05.tar.bz2 samba-02cffed79dc74541ac9e9c7835573e8dfad1bb05.zip |
gensec_gssapi: only give away the session key, when the authentication is done
metze
-rw-r--r-- | source4/auth/gensec/gensec_gssapi.c | 9 |
1 files changed, 5 insertions, 4 deletions
diff --git a/source4/auth/gensec/gensec_gssapi.c b/source4/auth/gensec/gensec_gssapi.c index 1334e799ae..e791226cf6 100644 --- a/source4/auth/gensec/gensec_gssapi.c +++ b/source4/auth/gensec/gensec_gssapi.c @@ -1181,6 +1181,10 @@ static NTSTATUS gensec_gssapi_session_key(struct gensec_security *gensec_securit OM_uint32 maj_stat, min_stat; krb5_keyblock *subkey; + if (gensec_gssapi_state->sasl_state != STAGE_DONE) { + return NT_STATUS_NO_USER_SESSION_KEY; + } + if (gensec_gssapi_state->session_key.data) { *session_key = gensec_gssapi_state->session_key; return NT_STATUS_OK; @@ -1200,10 +1204,7 @@ static NTSTATUS gensec_gssapi_session_key(struct gensec_security *gensec_securit *session_key = data_blob_talloc(gensec_gssapi_state, KRB5_KEY_DATA(subkey), KRB5_KEY_LENGTH(subkey)); krb5_free_keyblock(gensec_gssapi_state->smb_krb5_context->krb5_context, subkey); - if (gensec_gssapi_state->sasl_state == STAGE_DONE) { - /* only cache in the done stage */ - gensec_gssapi_state->session_key = *session_key; - } + gensec_gssapi_state->session_key = *session_key; dump_data_pw("KRB5 Session Key:\n", session_key->data, session_key->length); return NT_STATUS_OK; |