Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-44781

Fix keytab service DNS check in mongokerberos

    XMLWordPrintableJSON

Details

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: Major - P3 Major - P3
    • 4.3.3
    • None
    • None
    • None
    • Fully Compatible
    • ALL
    • Security 2019-12-16

    Description

      mongokerberos' s keytab DNS check verifies the DNS name of service principals against the KDC host name instead of the service's host name. We want to verify that the host name in service keytab entries resolves to the same host name as the provided service.

      Attachments

        Activity

          People

            adam.cooper@mongodb.com Adam Cooper (Inactive)
            adam.cooper@mongodb.com Adam Cooper (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: