From 7dc0c3eba0fe9f24e88b6fd4fb4339f2ab42b815 Mon Sep 17 00:00:00 2001 From: Timo Sirainen Date: Sun, 26 Jul 2009 22:00:46 -0400 Subject: [PATCH] gssapi: Don't do krb5_kuserok() to authz_name. It shouldn't be necessary. --HG-- branch : HEAD --- src/auth/mech-gssapi.c | 6 ------ 1 file changed, 6 deletions(-) diff --git a/src/auth/mech-gssapi.c b/src/auth/mech-gssapi.c index 065a0a7b59..9874e18a75 100644 --- a/src/auth/mech-gssapi.c +++ b/src/auth/mech-gssapi.c @@ -443,12 +443,6 @@ mech_gssapi_userok(struct gssapi_auth_request *request, const char *login_user) return -1; } - if (!mech_gssapi_krb5_userok(request, request->authz_name, - login_user, FALSE)) { - auth_request_log_info(auth_request, "gssapi", - "authz_name (%s) not authorized", login_user); - return -1; - } return 0; #else auth_request_log_info(auth_request, "gssapi", -- 2.47.3