Skip to content

Conversation

@simo5
Copy link
Contributor

@simo5 simo5 commented Feb 24, 2017

This option is useful to select and allow only a specific credential
when keys for multiple principals are available in a keytab.

&cfg->acceptor_name);
if (GSS_ERROR(maj)) {
ap_log_error(APLOG_MARK, APLOG_WARNING, 0, parms->server,
"gss_import_name([%s]) failed", w);
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why not return "error: malformed name" here? I think it is more useful to detect the error at init time.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are you suggesting to log at APLOG_ERROR level, or also to return a non-NULL error ?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Return non-null, so the directive won't get silently ignored.

@simo5
Copy link
Contributor Author

simo5 commented Feb 24, 2017

Ok now a bad name (like an empry name) returns an error.

Copy link
Contributor

@iboukris iboukris left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me.

Copy link
Member

@frozencemetery frozencemetery left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems good to me.

simo5 added a commit to simo5/mod_auth_gssapi that referenced this pull request Feb 27, 2017
This option is useful to select and allow only a specific credential
when keys for multiple principals are available in a keytab.

Signed-off-by: Simo Sorce <simo@redhat.com>
Reviewed-by: Robbie Harwood <rharwood@redhat.com>
Reviewed-by: Isaac Boukris <iboukris@gmail.com>

Closes gssapi#131
This way this error reporting function can be used also when a
request_rec is not available, like i the configuration phase.

Signed-off-by: Simo Sorce <simo@redhat.com>
Reviewed-by: Robbie Harwood <rharwood@redhat.com>
Reviewed-by: Isaac Boukris <iboukris@gmail.com>
This option is useful to select and allow only a specific credential
when keys for multiple principals are available in a keytab.

Signed-off-by: Simo Sorce <simo@redhat.com>
Reviewed-by: Robbie Harwood <rharwood@redhat.com>
Reviewed-by: Isaac Boukris <iboukris@gmail.com>

Closes gssapi#131
@simo5 simo5 merged commit 605ed4d into gssapi:master Feb 27, 2017
simo5 added a commit that referenced this pull request Mar 1, 2017
Had this in my tree but forgot to add to the commit.
Related to #131

Signed-off-by: Simo Sorce <simo@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants