ipa-kdb: reject principals from disabled domains as a KDC policy

Fixes https://fedorahosted.org/freeipa/ticket/4788

Reviewed-By: Sumit Bose <sbose@redhat.com>
Reviewed-By: Simo Sorce <ssorce@redhat.com>
This commit is contained in:
Alexander Bokovoy 2014-12-10 14:59:38 +02:00 committed by Martin Kosek
parent 92c3a9f1fd
commit 373a04870d

View File

@ -1372,7 +1372,7 @@ static krb5_error_code filter_logon_info(krb5_context context,
&domain->parent->sid_blacklist_incoming[k], true);
if (result) {
filter_logon_info_log_message(info->info->info3.base.domain_sid);
return EINVAL;
return KRB5KDC_ERR_POLICY;
}
}
}