> For interoperability, AP-REQ decryption uses the key with the highest kvno in > the keytab if no exact match is found. If decryption fails, a normal > "checksum failed" error is reported, which may hide the real cause that the > wrong key is used. This code change throws a KRB_AP_ERR_BADKEYVER error in > this case. > > The change is only made in AP-REQ decryption to minimize impact. A previous > test is enhanced to cover the case.
Weijun Wang has updated the pull request incrementally with one additional commit since the last revision: typo ------------- Changes: - all: https://git.openjdk.org/jdk/pull/27298/files - new: https://git.openjdk.org/jdk/pull/27298/files/17c944a9..10e409d6 Webrevs: - full: https://webrevs.openjdk.org/?repo=jdk&pr=27298&range=03 - incr: https://webrevs.openjdk.org/?repo=jdk&pr=27298&range=02-03 Stats: 1 line in 1 file changed: 0 ins; 0 del; 1 mod Patch: https://git.openjdk.org/jdk/pull/27298.diff Fetch: git fetch https://git.openjdk.org/jdk.git pull/27298/head:pull/27298 PR: https://git.openjdk.org/jdk/pull/27298
