Nalin Dahyabhai
c835c2a921
- switch buildrequires: and requires: on e2fsprogs-devel into
...
buildrequires: and requires: on libss-devel, libcom_err-devel, per
sandeen on fedora-devel-list
2009-06-29 19:28:01 +00:00
Nalin Dahyabhai
3f291ca045
- selinux labeling: use selabel_open() family of functions rather than
...
matchpathcon(), bail on it if attempting to get the mutex lock fails
2009-06-26 21:45:54 +00:00
Nalin Dahyabhai
84ade2f840
- fix a type mismatch in krb5_copy_error_message()
...
- ftp: fix some odd use of strlen()
2009-06-26 21:36:54 +00:00
Nalin Dahyabhai
1d6f8b9bad
- compile with %%{?_smp_mflags} (Steve Grubb)
...
- drop the bit where we munge part of the error table header, as it's not
needed any more
2009-06-16 21:29:37 +00:00
Nalin Dahyabhai
aecce15d40
add and own %%{_libdir}/krb5/plugins/authdata
2009-06-05 15:18:29 +00:00
Nalin Dahyabhai
34072014a1
remove obsolete files
2009-06-04 22:38:18 +00:00
Nalin Dahyabhai
2f1613d440
- update to 1.7, second pass
2009-06-04 22:09:07 +00:00
Nalin Dahyabhai
3c1272ff63
- add an auth stack to ksu's PAM configuration so that pam_setcred() calls
...
won't just fail
2009-05-19 23:21:48 +00:00
Nalin Dahyabhai
06c77ea1cd
- make PAM support for ksu also set PAM_RUSER
2009-05-11 18:19:08 +00:00
Nalin Dahyabhai
df43b1e2b6
yeah, actually bump the release number
2009-04-23 22:51:25 +00:00
Nalin Dahyabhai
5ebd815122
- extend PAM support to ksu: perform account and session management for the
...
target user
- pull up and merge James Leddy's changes to also set PAM_RHOST in
PAM-aware network-facing services
2009-04-23 22:43:26 +00:00
Nalin Dahyabhai
d3b2b69619
- fix a typo in a ksu error message (Marek Mahut)
2009-04-21 18:46:52 +00:00
Nalin Dahyabhai
f0389e0488
note why we don't just run make check here
2009-04-20 21:15:12 +00:00
Nalin Dahyabhai
724545eab6
- add LSB-style informational headers to the init scripts
2009-04-20 20:32:02 +00:00
Nalin Dahyabhai
980855a07a
- explicitly run the pdf generation script using sh (part of #225974 )
2009-04-17 13:29:41 +00:00
Nalin Dahyabhai
f51ed46fff
- remove obsolete patch for CVE-2009-0845
...
- add patches for read overflow and null pointer dereference in the
implementation of the SPNEGO mechanism (CVE-2009-0844, CVE-2009-0845)
- add patch for attempt to free uninitialized pointer in libkrb5
(CVE-2009-0846)
- add patch to fix length validation bug in libkrb5 (CVE-2009-0847)
2009-04-07 18:16:28 +00:00
Nalin Dahyabhai
d43a03520f
- make the kpropd init script treat reload as restart (part of #225974 )
2009-04-06 20:33:44 +00:00
Nalin Dahyabhai
45bffcbf45
- take the execute bit off of the protocol docs (part of #225974 )
...
- unflag init scripts as configuration files (part of #225974 )
2009-04-06 18:22:58 +00:00
Nalin Dahyabhai
303d2c20d2
- fixup summary texts (part of #225974 )
2009-04-06 18:00:53 +00:00
Nalin Dahyabhai
fa314d1962
- escape possible macros in the changelog (part of #225974 )
2009-04-06 17:52:21 +00:00
Nalin Dahyabhai
5ee95cc082
- clean up buildprereq/prereqs, explicit mktemp requires, and add the
...
ldconfig for the -server-ldap subpackage (part of #225974 )
2009-04-06 17:45:29 +00:00
Nalin Dahyabhai
98a3610002
- make splitting up of the workstation bits unconditional
2009-04-06 16:46:35 +00:00
Nalin Dahyabhai
1644a79505
- move the libraries to /%{_lib}, but leave --libdir alone so that plugins
...
get installed and are searched for in the same locations (#473333 )
2009-04-06 16:22:45 +00:00
Nalin Dahyabhai
e61be4fa97
- turn off krb4 support (it won't be part of the 1.7 release, but do it
...
now)
- use triggeruns to properly shut down and disable krb524d when -server and
-workstation-servers gets upgraded, because it's gone now
2009-04-06 15:56:45 +00:00
Nalin Dahyabhai
434cefd85a
- libgssapi_krb5: backport fix for some errors which can occur when we fail
...
to set up the server half of a context (CVE-2009-0845)
2009-03-17 22:26:27 +00:00
Jesse Keating
78b02cd911
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
2009-02-25 11:58:27 +00:00
Nalin Dahyabhai
4c798e4ee7
aargh, what year is it?
2009-01-16 16:19:02 +00:00
Nalin Dahyabhai
2bf7daea40
rebuild
2009-01-16 16:17:56 +00:00
Nalin Dahyabhai
b1efb9b86d
- if we successfully change the user's password during an attempt to get
...
initial credentials, but then fail to get initial creds from a
non-master using the new password, retry against the master (#432334 )
2008-09-04 15:13:51 +00:00
Tom Callaway
bb9aa2106c
fix license tag
2008-08-05 17:46:07 +00:00
Nalin Dahyabhai
2352d208e3
- define ASN1BUF_OMIT_INLINE_FUNCS at compile-time (for now) to keep
...
building
2008-07-16 21:54:24 +00:00
Nalin Dahyabhai
b5dfa8576a
quote %%{__cc} where needed because it includes whitespace now
2008-07-16 18:40:35 +00:00
Nalin Dahyabhai
6197407f58
- clear fuzz out of patches, dropping a man page patch which is no longer
...
necessary
2008-07-16 18:09:47 +00:00
Nalin Dahyabhai
14f675bab9
- build with -fno-strict-aliasing, which is needed because the library
...
triggers these warnings
2008-07-11 15:16:54 +00:00
Nalin Dahyabhai
37b6c5e715
- rework how labeling is handled to avoid a bootstrapping problem in
...
headers
- don't forget to label the principal database lock file
2008-07-11 15:14:57 +00:00
Tom Callaway
f06f7f1e03
generate include/krb5/krb5.h before building, fix conditional for sparcv9
2008-06-14 18:22:01 +00:00
Nalin Dahyabhai
9f105b4df2
- ftp: use the correct local filename during mget when the 'case' option is
...
enabled (#442713 )
2008-04-16 18:54:08 +00:00
Nalin Dahyabhai
af9bedd61a
- stop exporting kadmin keys to a keytab file when kadmind starts -- the
...
daemon's been able to use the database directly for a long long time
now
- belatedly add aes128,aes256 to the default set of supported key types
2008-04-04 21:29:53 +00:00
Nalin Dahyabhai
f56b6ee2db
bump for build
2008-04-01 20:54:54 +00:00
Nalin Dahyabhai
ddde7d0f6e
- libgssapi_krb5: properly export the acceptor subkey when creating a lucid
...
context (Kevin Coffman, via the nfs4 mailing list)
2008-04-01 20:53:54 +00:00
Nalin Dahyabhai
7668599d1d
- add fixes from MITKRB5-SA-2008-001 for use of null or dangling pointer
...
when v4 compatibility is enabled on the KDC (CVE-2008-0062,
CVE-2008-0063, #432620 , #432621 )
- add fixes from MITKRB5-SA-2008-002 for array out-of-bounds accesses when
high-numbered descriptors are used (CVE-2008-0947, #433596 )
- add backport bug fix for an attempt to free non-heap memory in
libgssapi_krb5 (CVE-2007-5901, #415321 )
- add backport bug fix for a double-free in out-of-memory situations in
libgssapi_krb5 (CVE-2007-5971, #415351 )
2008-03-18 18:13:22 +00:00
Nalin Dahyabhai
638efe585f
- rework file labeling patch to not depend on fragile preprocessor
...
trickery, in another attempt at fixing #428355 and friends
2008-03-18 15:35:39 +00:00
Nalin Dahyabhai
723980d239
bump release number for rebuild
2008-02-26 21:48:24 +00:00
Nalin Dahyabhai
d4963922a8
- ftp: add patch to fix "runique on" case when globbing fixes applied
...
- stop adding a redundant but harmless call to initialize the gssapi
internals
2008-02-26 21:18:38 +00:00
Nalin Dahyabhai
2a567feda3
- add the bug ID, close the bug
2008-02-25 20:55:41 +00:00
Nalin Dahyabhai
d5971d2776
- add patch to suppress double-processing of /etc/krb5.conf when we build
...
with --sysconfdir=/etc, thereby suppressing double-logging (#231147 )
2008-02-25 20:53:41 +00:00
Nalin Dahyabhai
d73fcc15fb
- remove a patch to fix problems with interfaces which are "up" but which
...
have no address assigned which conflicted with a change to fix the same
problem in 1.5 (#200979 )
2008-02-25 19:58:51 +00:00
Nalin Dahyabhai
2cc4303bbc
- ftp: don't lose track of a descriptor on passive get when the server
...
fails to open a file
2008-02-25 19:50:42 +00:00
Nalin Dahyabhai
a7d42c7b03
- in login, allow PAM to interact with the user when they've been strongly
...
authenticated
- in login, signal PAM when we're changing an expired password that it's an
expired password, so that when cracklib flags a password as being weak
it's treated as an error even if we're running as root
2008-02-25 18:33:34 +00:00
Nalin Dahyabhai
8e9e1c07b0
- drop netdb patch
...
- kdb_ldap: add patch to treat 'nsAccountLock: true' as an indication that
the DISALLOW_ALL_TIX flag is set on an entry, for better interop with
Fedora, Netscape, Red Hat Directory Server (Simo Sorce)
2008-02-18 18:44:39 +00:00