+2004-06-24 Tom Yu <tlyu@mit.edu>
+
+ * kadmin.c (kadmin_startup): Use host-based service name from
+ kadm5_get_admin_service_name() for SEAM compatibility when old
+ AUTH_GSSAPI not requested.
+
2004-06-15 Tom Yu <tlyu@mit.edu>
* kadmin.c (kadmin_startup): Add option to force old AUTH_GSSAPI
krb5_ccache cc;
krb5_principal princ;
kadm5_config_params params;
+ char svcnamebuf[MAXHOSTNAMELEN + 8];
+ char *svcname;
memset((char *) ¶ms, 0, sizeof(params));
params.mask |= KADM5_CONFIG_REALM;
params.realm = def_realm;
+ retval = kadm5_get_admin_service_name(context, def_realm, svcnamebuf,
+ sizeof(svcnamebuf));
+ if (retval) {
+ fprintf(stderr, "%s: failed to get admin service name", whoami);
+ exit(1);
+ }
+ if (params.mask & KADM5_CONFIG_OLD_AUTH_GSSAPI)
+ svcname = KADM5_ADMIN_SERVICE;
+ else
+ svcname = svcnamebuf;
+
/*
* Set cc to an open credentials cache, either specified by the -c
* argument or the default.
printf("Authenticating as principal %s with existing credentials.\n",
princstr);
retval = kadm5_init_with_creds(princstr, cc,
- KADM5_ADMIN_SERVICE,
+ svcname,
¶ms,
KADM5_STRUCT_VERSION,
KADM5_API_VERSION_2,
printf("Authenticating as principal %s with default keytab.\n",
princstr);
retval = kadm5_init_with_skey(princstr, keytab_name,
- KADM5_ADMIN_SERVICE,
+ svcname,
¶ms,
KADM5_STRUCT_VERSION,
KADM5_API_VERSION_2,
printf("Authenticating as principal %s with password.\n",
princstr);
retval = kadm5_init_with_password(princstr, password,
- KADM5_ADMIN_SERVICE,
+ svcname,
¶ms,
KADM5_STRUCT_VERSION,
KADM5_API_VERSION_2,