[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ASN1_* Errors Returned from GSSAPI Functions




Andrew Bartlett <abartlet@samba.org> writes:

> On Tue, 2005-10-25 at 17:56 +0200, Love Hörnquist Åstrand wrote:
>> Andrew Bartlett <abartlet@samba.org> writes:
>> 
>> > Actually, I was more worried by the fact that I just got a numeric error
>> > message, because the asn1 error table was used, and it was not loaded.
>> > I'm not sure if I should have done that (as the application), the
>> > kerberos libarary should have, or I should have expected only krb5 error
>> > returns from the krb5 libs.
>> 
>> I think you should expect com_error errors from the kerberos library, how
>> did you manage to not load the asn1 errors ?
>
> I don't know.  What was I mean to do?  This part of the system should be
> standard krb5...

The asn1 errors are part of the kerberos API as far as I'm concerned.

>> > I'm not worried what the client gets sent, but what I see in my
>> > application logs and logic.
>> 
>> If your application avoid sending broken packets, it wont see them :)
>
> This is a matter of when the client was sending garbage, the server
> error messages/logs were hard to understand.  

A somewhat sensable string should be returned by krb5_get_err_text().

Love

PGP signature