The Samba-Bugzilla – Attachment 14432 Details for
Bug 13571
[SECURITY] CVE-2018-16853 S4U2Self crash with MIT KDC build
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
[patch]
blackbox test
13571_test.patch.txt (text/plain), 2.86 KB, created by
Isaac Boukris
on 2018-08-18 13:16:55 UTC
(
hide
)
Description:
blackbox test
Filename:
MIME Type:
Creator:
Isaac Boukris
Created:
2018-08-18 13:16:55 UTC
Size:
2.86 KB
patch
obsolete
>From 827bfdbd47696854f2a2590973c18b4775d9dbca Mon Sep 17 00:00:00 2001 >From: Isaac Boukris <iboukris@gmail.com> >Date: Sat, 18 Aug 2018 15:32:43 +0300 >Subject: [PATCH 1/2] mit-kdc: fix kinit test on system lacking ldbsearch > >By fixing bindir variable name. > >Signed-off-by: Isaac Boukris <iboukris@gmail.com> >--- > testprogs/blackbox/test_kinit_mit.sh | 8 ++++---- > 1 file changed, 4 insertions(+), 4 deletions(-) > >diff --git a/testprogs/blackbox/test_kinit_mit.sh b/testprogs/blackbox/test_kinit_mit.sh >index dabf9915ed1..370542536e1 100755 >--- a/testprogs/blackbox/test_kinit_mit.sh >+++ b/testprogs/blackbox/test_kinit_mit.sh >@@ -32,13 +32,13 @@ samba_enableaccount="$samba_tool user enable" > machineaccountccache="$samba_srcdir/scripting/bin/machineaccountccache" > > ldbmodify="ldbmodify" >-if [ -x "$samba4bindir/ldbmodify" ]; then >- ldbmodify="$samba4bindir/ldbmodify" >+if [ -x "$samba_bindir/ldbmodify" ]; then >+ ldbmodify="$samba_bindir/ldbmodify" > fi > > ldbsearch="ldbsearch" >-if [ -x "$samba4bindir/ldbsearch" ]; then >- ldbsearch="$samba4bindir/ldbsearch" >+if [ -x "$samba_bindir/ldbsearch" ]; then >+ ldbsearch="$samba_bindir/ldbsearch" > fi > > . `dirname $0`/subunit.sh >-- >2.14.3 > > >From cef57a158e5fd4097a70a4c641354377b056a59d Mon Sep 17 00:00:00 2001 >From: Isaac Boukris <iboukris@gmail.com> >Date: Sat, 18 Aug 2018 16:01:59 +0300 >Subject: [PATCH 2/2] mit-kdc: add test for s4u2self crash > >Signed-off-by: Isaac Boukris <iboukris@gmail.com> >--- > testprogs/blackbox/test_kinit_mit.sh | 12 ++++++++++++ > 1 file changed, 12 insertions(+) > >diff --git a/testprogs/blackbox/test_kinit_mit.sh b/testprogs/blackbox/test_kinit_mit.sh >index 370542536e1..f691b0f15d7 100755 >--- a/testprogs/blackbox/test_kinit_mit.sh >+++ b/testprogs/blackbox/test_kinit_mit.sh >@@ -24,6 +24,7 @@ samba_srcdir="$SRCDIR/source4" > samba_kinit=kinit > samba_kdestroy=kdestroy > samba_kpasswd=kpasswd >+samba_kvno=kvno > > samba_tool="$samba_bindir/samba-tool" > samba_texpect="$samba_bindir/texpect" >@@ -299,6 +300,17 @@ test_smbclient "Test machine account login with kerberos ccache" 'ls' -k yes || > > testit "reset password policies" $VALGRIND $samba_tool domain passwordsettings set $ADMIN_LDBMODIFY_CONFIG --complexity=default --history-length=default --min-pwd-length=default --min-pwd-age=default --max-pwd-age=default || failed=`expr $failed + 1` > >+########################################################### >+### Test basic s4u2self request >+########################################################### >+ >+# Use previous acquired machine creds to request a ticket for self. >+# We expect it to fail for now. >+MACHINE_ACCOUNT="$(hostname -s | tr [a-z] [A-Z])\$@$REALM" >+$samba_kvno -U$MACHINE_ACCOUNT $MACHINE_ACCOUNT >+# But we expect the KDC to be up and running still >+testit "kinit with machineaccountccache after s4u2self" $machineaccountccache $CONFIGURATION $KRB5CCNAME || failed=`expr $failed + 1` >+ > ### Cleanup > > $samba_kdestroy >-- >2.14.3 >
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 13571
:
14431
|
14432
|
14451
|
14626
|
14676
|
14677
|
14678
|
14679