Red Hat Bugzilla – Bug 137613
Kerberos 5 1.2 does not provide a writable keytab access method ("WRFILE:")
Last modified: 2012-06-20 12:16:13 EDT
Description of problem:
Applications which attempt to manipulate the contents of Kerberos
keytabs need to open those files using the "WRFILE:" method in order
to have read-write access. By default, libkrb5 provides "FILE:", but
does not "know" about the "WRFILE:" method. Kerberos 5 1.3 allows
"WRFILE:" access to any application.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
1. Configure Samba 3.0.6 or later with "use kerberos keytab" enabled.
2. Attempt to set up a key in the system keytab using "net ads keytab
"net" will because it has attempted to call a NULL method pointer
"net" runs to completion
Samba detects if the Kerberos implementation supports WRFILE: at
compile-time, and assumes that FILE: is writable if WRFILE: is not
available. Because this is determined at compile-time, Samba must be
recompiled to notice that the implementation supports WRFILE:.
For reference for others who may be looking for a solution to this
problem before this is resolved, you can add the following to your
default_keytab_name = WRFILE:/etc/krb5.keytab
and 'net ads keytab CREATE' (at least; haven't tested others) will
work as expected.
Thank you for submitting this issue for consideration in Red Hat Enterprise Linux. The release for which you requested us to review is now End of Life.
Please See https://access.redhat.com/support/policy/updates/errata/
If you would like Red Hat to re-consider your feature request for an active release, please re-open the request via appropriate support channels and provide additional supporting details about the importance of this issue.