Due to an inverted test in adb_policy_init, kadm5_flush calls
krb5_db_open twice. With the DB2 KDB module, the second open is a
no-op, but with the LDAP module, a new DB handle is allocated and the
old one is leaked.
[ghudson@mit.edu: rewrote commit message]
(cherry picked from commit
372e4cb6f5d4a603e6e3157c7b5d354953836136)
ticket: 7897
version_fixed: 1.12.2
status: resolved
adb_policy_init(kadm5_server_handle_t handle)
{
/* now policy is initialized as part of database. No seperate call needed */
- if( krb5_db_inited( handle->context ) )
+ if (krb5_db_inited(handle->context) == 0)
return KADM5_OK;
return krb5_db_open( handle->context, NULL,