From 557fdf9f5864c488612379902038791e7eedd20d Mon Sep 17 00:00:00 2001 From: kouril Date: Thu, 1 Jul 2004 07:20:41 +0000 Subject: [PATCH] Use cannonical DNS name when constructing the principal for passwd verification (to be consistent with GSSAPI) --- src/mod_auth_kerb.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/mod_auth_kerb.c b/src/mod_auth_kerb.c index 2532b30..e204b69 100644 --- a/src/mod_auth_kerb.c +++ b/src/mod_auth_kerb.c @@ -573,7 +573,7 @@ verify_krb5_user(request_rec *r, krb5_context context, krb5_principal principal, } ret = krb5_sname_to_principal(context, ap_get_server_name(r), service, - KRB5_NT_UNKNOWN, &server); + KRB5_NT_SRV_HST, &server); if (ret) { log_rerror(APLOG_MARK, APLOG_ERR, 0, r, "krb5_sname_to_principal() failed: %s", -- 2.1.4