Use cannonical DNS name when constructing the principal for passwd verification ...
authorkouril <kouril>
Thu, 1 Jul 2004 07:20:41 +0000 (07:20 +0000)
committerkouril <kouril>
Thu, 1 Jul 2004 07:20:41 +0000 (07:20 +0000)
src/mod_auth_kerb.c

index 2532b30..e204b69 100644 (file)
@@ -573,7 +573,7 @@ verify_krb5_user(request_rec *r, krb5_context context, krb5_principal principal,
    }
 
    ret = krb5_sname_to_principal(context, ap_get_server_name(r), service, 
-                                KRB5_NT_UNKNOWN, &server);
+                                KRB5_NT_SRV_HST, &server);
    if (ret) {
       log_rerror(APLOG_MARK, APLOG_ERR, 0, r,
                 "krb5_sname_to_principal() failed: %s",