Red Hat Bugzilla – Bug 854997
Add details about TGT validation to sssd-krb5 man page
Last modified: 2013-02-21 04:36:58 EST
This bug is created as a clone of upstream ticket: https://fedorahosted.org/sssd/ticket/1499 The sssd-krb5 man page should describe how the keytab entry for TGT validation is selected and what needs to be done make make validation in an environment with trusted domains possible.
Verified in version 1.9.2-74 Manpage of sssd-krb5 verified with following text: Verify with the help of krb5_keytab that the TGT obtained has not been spoofed. The keytab is checked for entries sequentially, and the first entry with a matching realm is used for validation. If no entry matches the realm, the last entry in the keytab is used. This process can be used to validate environments using cross-realm trust by placing the appropriate keytab entry as the last entry or the only entry in the keytab file.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHSA-2013-0508.html