RFR: 8367344: Better error message when decryption of AP-REQ fails because of kvno mismatch [v2]
Weijun Wang
weijun at openjdk.org
Tue Sep 16 17:43:34 UTC 2025
> For interoperability, AP-REQ decryption uses the key with the highest kvno in the keytab if no exact match is found. If decryption fails, a normal "checksum failed" error is reported, which may hide the real cause that the wrong key is used. This code change throws a KRB_AP_ERR_BADKEYVER error in this case.
>
> The change is only made in AP-REQ decryption to minimize impact. A previous test is enhanced to cover the case.
Weijun Wang has updated the pull request incrementally with one additional commit since the last revision:
different exception for other etypes; test
-------------
Changes:
- all: https://git.openjdk.org/jdk/pull/27298/files
- new: https://git.openjdk.org/jdk/pull/27298/files/28cd0d11..ecf2f5b8
Webrevs:
- full: https://webrevs.openjdk.org/?repo=jdk&pr=27298&range=01
- incr: https://webrevs.openjdk.org/?repo=jdk&pr=27298&range=00-01
Stats: 94 lines in 2 files changed: 56 ins; 12 del; 26 mod
Patch: https://git.openjdk.org/jdk/pull/27298.diff
Fetch: git fetch https://git.openjdk.org/jdk.git pull/27298/head:pull/27298
PR: https://git.openjdk.org/jdk/pull/27298
More information about the security-dev
mailing list