Bug#1069858: libkrb5-3: krb5.conf seems to ignore rdns = false

2024-04-26 Thread Russ Allbery
Lukas Grässlin writes: > It's ldapsearch in all cases with libsasl2-modules-gssapi-mit:amd64 > 2.1.28+dfsg-10 on Debian and cyrus-sasl-gssapi-2.1.27-6.el8_5.x86_64 on > the RHEL machine. I suspect you are being bitten by:

Bug#1069858: libkrb5-3: krb5.conf seems to ignore rdns = false

2024-04-26 Thread Lukas Grässlin
On 26.04.2024 10:06, Lukas Grässlin wrote: On 25.04.2024 23:25, Sam Hartman wrote: How are you actually triggering the GSS-API authentication? ldapsearch in all cases? And you are confident that libkrb5 is triggering the reverse lookup not your application? (I realize that you may be using the

Bug#1069858: libkrb5-3: krb5.conf seems to ignore rdns = false

2024-04-26 Thread Lukas Grässlin
On 25.04.2024 23:25, Sam Hartman wrote: How are you actually triggering the GSS-API authentication? ldapsearch in all cases? And you are confident that libkrb5 is triggering the reverse lookup not your application? (I realize that you may be using the same application on Debian and RH, but there

Bug#1069858: libkrb5-3: krb5.conf seems to ignore rdns = false

2024-04-25 Thread Sam Hartman
> "Lukas" == Lukas Grässlin writes: Lukas> We have a scenario where we need to disable reverse lookups for Lukas> canonicalization in Kerberos as the customer's PTR records are not Lukas> consistent and lead to wrongly requested SPNs otherwise (see Lukas>

Bug#1069858: libkrb5-3: krb5.conf seems to ignore rdns = false

2024-04-25 Thread Lukas Grässlin
Package: libkrb5-3 Version: 1.20.1-2+deb12u1 Severity: normal X-Debbugs-Cc: lukas.graess...@adfinis.com We have a scenario where we need to disable reverse lookups for canonicalization in Kerberos as the customer's PTR records are not consistent and