OBSOLETE Patch-ID# 113990-05 Keywords: security pam_krb5 rpc_gss_seccreate gss_display_status kerberos Synopsis: Obsoleted by: 115168-04 SunOS 5.9_x86: krb5 Patch Date: Feb/23/2004 Install Requirements: Install in Single User Mode Reboot immediately after patch is installed Solaris Release: 9_x86 SunOS Release: 5.9_x86 Unbundled Product: Unbundled Release: Xref: This patch available for SPARC as patch 112908 Topic: SunOS 5.9_x86: krb5 Patch Relevant Architectures: i386 BugId's fixed with this patch: 4526202 4630574 4727224 4743181 4744280 4836676 4847827 4882946 Changes incorporated in this version: 4882946 Patches accumulated and obsoleted by this patch: Patches which conflict with this patch: Patches required with this patch: Obsoleted by: Files included with this patch: /kernel/misc/kgss/gl_kmech_krb5 /usr/lib/gss/gl/abi/abi_mech_krb5.so.1 /usr/lib/gss/gl/mech_krb5.so.1 Problem Description: 4882946 GSS_C_NO_BUFFER: gss_init_sec_context gives an Error code (from 113990-04) 4836676 Bounds checks not in place for princs in krbv5 (from 113990-03) 4847827 Kerberos patch 112908-07 Error verifying TGT with host, Bad encryption type (from 113990-02) 4630574 pam_krb5 should not reimplement utility functions and use libpam utilities 4743181 gss/kerberos frees a buffer returned to caller (from 113990-01) 4526202 pam_krb5 auth can fail with multiple ftp sessions of same user 4727224 user application hangs at rpc_gss_seccreate() 4744280 gss_display_status() always returning error Patch Installation Instructions: -------------------------------- For Solaris 2.0-2.6 releases, refer to the Install.info file and/or the README within the patch for instructions on using the generic 'installpatch' and 'backoutpatch' scripts provided with each patch. For Solaris 7-9 releases, refer to the man pages for instructions on using 'patchadd' and 'patchrm' scripts provided with Solaris. Any other special or non-generic installation instructions should be described below as special instructions. The following example installs a patch to a standalone machine: example# patchadd /var/spool/patch/104945-02 The following example removes a patch from a standalone system: example# patchrm 104945-02 For additional examples please see the appropriate man pages. Special Install Instructions: ----------------------------- NOTE: To get the complete fix of bug 4836676 "Bounds checks not in place for princs in krbv5" please install the following patches: 116044-01 (or newer) kdb5_util 116045-01 (or newer) krb5kdc 116046-02 (or newer) libkadm5srv.so.1 113990-04 (or newer) mech_krb5.so.1 gl_kmech_krb5 (This patch) 115168-02 (or newer) pam_krb5.so.1 README -- Last modified date: Wednesday, June 16, 2004