Bug#725454: libapache2-mod-auth-kerb: should read keytab before dropping privileges

2013-10-05 Thread Russ Allbery
"brian m. carlson" writes: > On Sat, Oct 05, 2013 at 05:29:04PM -0700, Russ Allbery wrote: >> Unfortunately, I believe that this would break KrbServiceName Any, >> which at least for me is vital functionality. You would need to >> explicitly import one particular set of credentials from the keyt

Bug#725454: libapache2-mod-auth-kerb: should read keytab before dropping privileges

2013-10-05 Thread brian m. carlson
On Sat, Oct 05, 2013 at 05:29:04PM -0700, Russ Allbery wrote: > "brian m. carlson" writes: > > > I am trying to use mpm_itk along with mod_auth_kerb to force > > authentication before running a CGI script as a user (in this case, the > > git smart HTTP server). However, mod_auth_kerb reads the k

Bug#725454: libapache2-mod-auth-kerb: should read keytab before dropping privileges

2013-10-05 Thread Russ Allbery
"brian m. carlson" writes: > I am trying to use mpm_itk along with mod_auth_kerb to force > authentication before running a CGI script as a user (in this case, the > git smart HTTP server). However, mod_auth_kerb reads the keytab after > it has dropped privileges, resulting in the problem that t

Bug#725454: libapache2-mod-auth-kerb: should read keytab before dropping privileges

2013-10-05 Thread brian m. carlson
Package: libapache2-mod-auth-kerb Version: 5.4-2.1 Severity: wishlist I am trying to use mpm_itk along with mod_auth_kerb to force authentication before running a CGI script as a user (in this case, the git smart HTTP server). However, mod_auth_kerb reads the keytab after it has dropped privilege