Robbie Harwood
09f9308fd8
Continue after KRB5_CC_END in KCM cache iteration
2018-03-29 10:43:22 -04:00
Robbie Harwood
27ca1f2678
Fix SPAKE memory leak
...
Also fix build problem
2018-03-27 18:01:05 +00:00
Robbie Harwood
99cea2e511
Fix gitignore problem with previous patchset
2018-03-27 15:13:46 +00:00
Robbie Harwood
2c340efca2
Add SPAKE support
...
- Improve protections on internal sensitive buffers
- Improve internal hex encoding/decoding
2018-03-27 15:09:05 +00:00
Robbie Harwood
8b49b0644c
Fix problem with ccache_name logic in previous build
2018-03-20 18:20:01 +00:00
Robbie Harwood
6b1b652d4d
Add pkinit_anchors default value to krb5.conf
...
Reindent krb5.conf to not be terrible
2018-03-20 17:53:38 +00:00
Robbie Harwood
2eafc4d8aa
Include preauth names in trace output where possible
...
Also fix misc bugs
2018-03-20 15:21:19 +00:00
Robbie Harwood
a387becbf5
Add PKINIT KDC support for freshness token
...
Also, fix securid_sam2 preauth for non-default salt
2018-03-19 22:16:46 +00:00
Robbie Harwood
ed142b51b1
Exit with status 0 from kadmind
2018-03-14 14:44:04 -04:00
Robbie Harwood
5f3f6ef19b
Fix hex conversion of PKINIT certid strings
2018-03-13 17:45:47 -04:00
Robbie Harwood
4b5cd8c1f8
Fix capaths "." values on client
...
Resolves: 1551099
2018-03-07 17:41:04 +00:00
Igor Gnatenko
03afcfa42c
Remove %clean section
...
None of currently supported distributions need that.
Last one was EL5 which is EOL for a while.
Signed-off-by: Igor Gnatenko <ignatenkobrain@fedoraproject.org>
2018-02-14 09:55:56 +01:00
Igor Gnatenko
307e1c3fab
Remove BuildRoot definition
...
None of currently supported distributions need that.
It was needed last for EL5 which is EOL now
Signed-off-by: Igor Gnatenko <ignatenkobrain@fedoraproject.org>
2018-02-13 23:36:56 +01:00
Robbie Harwood
392309c493
Fix flaws in LDAP DN checking
...
CVE-2018-5729, CVE-2018-5730
2018-02-13 11:09:41 -05:00
Robbie Harwood
c4848e3332
Fix a leak in the previous commit
...
Also, restore dist macro that was accidentally removed
Resolves : #1540939
2018-02-12 17:40:48 +00:00
Fedora Release Engineering
bfe3c598b5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
...
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2018-02-07 20:27:38 +00:00
Igor Gnatenko
caf02999e0
Switch to %ldconfig_scriptlets
...
Signed-off-by: Igor Gnatenko <ignatenkobrain@fedoraproject.org>
2018-02-03 17:31:01 +01:00
Robbie Harwood
85d9f736b5
Process included directories in alphabetical order
2018-01-29 17:48:17 +01:00
Robbie Harwood
30d56290b3
Fix network service dependencies
...
Resolves : #1525230
2017-12-12 21:45:17 +00:00
Robbie Harwood
e714c57927
Fix copr rule sop that the spec file builds
2017-12-06 18:10:36 +00:00
Robbie Harwood
9869daa1e8
New upstream release (1.16)
...
- No changes from beta2
- Add spec file support for COPR
2017-12-06 18:07:52 +00:00
Robbie Harwood
6f4f842e5f
New upstream prerelease (1.16-beta2)
2017-11-27 22:15:31 +00:00
Robbie Harwood
23141c22b1
Fix CVE-2017-15088 (Buffer overflow in get_matching_data())
2017-10-24 16:10:22 -04:00
Robbie Harwood
6e83fb6a5e
Drop dependency on python2-pyrad (dead upstream, broken with new python)
2017-10-23 16:28:55 +00:00
Robbie Harwood
e02d5c1dac
Actually bump kdbversion like I was supposed to
2017-10-09 15:24:04 +00:00
Robbie Harwood
533a73fdd1
New upstream prerelease (1.16-beta1)
2017-10-05 20:29:13 +00:00
Robbie Harwood
0c7302b5bc
Add German translation
2017-09-28 21:50:19 +00:00
Robbie Harwood
f1e535bb81
New upstream release - krb5-1.15.2
...
Adjust patches as appropriate
2017-09-25 19:24:33 +00:00
Robbie Harwood
11b90e9e6e
Save other programs from worrying about CVE-2017-11462
...
Resolves : #1488873
Resolves : #1488874
2017-09-06 16:43:59 +00:00
Robbie Harwood
f6b653fac2
Add hostname-based ccselect module
...
Also update certauth EKU stuff
Resolves : #1463665
2017-09-05 18:16:58 +00:00
Robbie Harwood
8f0349dc3e
Backport certauth eku security fix
2017-08-25 16:43:43 +00:00
Robbie Harwood
95b80fb0b9
Backport kdc policy plugin, but this time with dependencies
2017-08-22 19:11:06 +00:00
Robbie Harwood
48ad53c66e
Backport kdcpolicy interface
2017-08-21 17:23:54 +00:00
Robbie Harwood
2674e01b27
* Mon Aug 07 2017 Robbie Harwood <rharwood@redhat.com> 1.15.1-21
...
Display an error message if ocsp pkinit is requested
2017-08-16 20:07:07 +00:00
Robbie Harwood
0d402dae7f
Display an error message if ocsp pkinit is requested
2017-08-07 20:42:47 +00:00
Robbie Harwood
ccd78d8ee9
Disable dns_canonicalize_hostname. This may break some setups.
2017-08-02 17:02:48 +00:00
Robbie Harwood
0f2af40d1e
Re-enable test suite on ppc64le (no other changes)
2017-08-02 14:42:30 +00:00
Fedora Release Engineering
e2a7f10a2f
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
2017-07-26 17:59:47 +00:00
Robbie Harwood
45c6f63563
Fix CVE-2017-11368 (remote triggerable assertion failure)
2017-07-20 15:31:44 +00:00
Robbie Harwood
bb9cd0748a
Explicitly require python2 packages
2017-07-19 20:08:14 +00:00
Robbie Harwood
dd3f3e78a4
Add support to query the SSF of a context
2017-07-19 18:24:50 +00:00
Petr Písař
887df81921
perl dependency renamed to perl-interpreter < https://fedoraproject.org/wiki/Changes/perl_Package_to_Install_Core_Modules >
2017-07-12 14:04:40 +02:00
Robbie Harwood
ff9e66e349
Fix leaks in gss_inquire_cred_by_oid()
2017-07-06 17:06:13 +00:00
Robbie Harwood
b3eef12e9a
Fix arch name (ppc64le, not ppc64el)
...
Related-to: #1464381
2017-06-26 19:49:21 +00:00
Robbie Harwood
a51673420f
Skip test suite on ppc64el
...
Related-to: #1464381
2017-06-26 19:45:34 +00:00
Robbie Harwood
db0f9d981a
Include more test suite changes from upstream
...
Resolves : #1464381
2017-06-23 20:45:16 +00:00
Robbie Harwood
58aed41605
Fix custom build with -DDEBUG
2017-06-07 15:18:05 +00:00
Robbie Harwood
d322a08712
Use standard trigger logic for krb5 snippet
2017-05-24 19:04:22 +00:00
Robbie Harwood
3cae6ae5c3
Add kprop service env config file
2017-04-28 20:14:01 +00:00
Robbie Harwood
21848ec3e1
Update backports of certauth and corresponding test
2017-04-19 17:49:45 +00:00