]> git.ipfire.org Git - thirdparty/bind9.git/commit
tsiggss: regenerate kerberos credentials 12002/head
authorMark Andrews <marka@isc.org>
Wed, 17 Aug 2022 01:13:41 +0000 (11:13 +1000)
committerMichal Nowak <mnowak@isc.org>
Tue, 12 May 2026 12:26:08 +0000 (14:26 +0200)
commit48eb8487c432fb608947a7c588ee1b4e1de34eba
tree926709a490d213ca6a998ad0c9f4a157e54bffc3
parentcc8fa5349a9fbfff3662afff32206d00592b71e4
tsiggss: regenerate kerberos credentials

The existing set of kerberos credential used deprecated algorithms
which are not supported by some implementations in FIPS mode.
Regenerate the saved credentials using more modern algorithms.

Added tsiggss/krb/setup.sh which sets up a test KDC with the required
principals for the system test to work.  The tsiggss system test
needs to be run once with this active and KRB5_CONFIG appropriately.
set.  See tsiggss/tests.sh for an example of how to do this.

(cherry picked from commit 3da79d408f3dcbe040a29298fbe3f6d5f57b278d)
bin/tests/system/tsiggss/krb/setup.sh [new file with mode: 0644]
bin/tests/system/tsiggss/ns1/administrator.ccache
bin/tests/system/tsiggss/ns1/dns.keytab
bin/tests/system/tsiggss/ns1/testdenied.ccache
bin/tests/system/tsiggss/tests.sh