Commit Graph

936 Commits

Author SHA1 Message Date
Robbie Harwood
cd0b1d6ba6 Temporarily dns_canonicalize_hostname=fallback changes
Hopefully unbreak IPA while we debug further
2020-08-13 09:50:45 -04:00
Robbie Harwood
c59e4a1c67 Expand dns_canonicalize_hostname=fallback support 2020-08-07 19:03:02 -04:00
Robbie Harwood
2091f29399 Fix leak in KERB_AP_OPTIONS_CBT server support 2020-08-04 14:24:08 -04:00
Robbie Harwood
4530bb6de9 Revert qualify_shortname removal 2020-08-03 15:39:37 -04:00
Robbie Harwood
8be5252136 Disable tests on s390x
Resolves: #1863952
2020-08-03 15:36:24 -04:00
Fedora Release Engineering
d0cfa344c7 - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-08-01 03:47:16 +00:00
Robbie Harwood
710f626f12 Revert qualify_shortname changes 2020-07-31 13:31:53 -04:00
Fedora Release Engineering
d314641a26 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-07-28 03:39:56 +00:00
Robbie Harwood
86ecb1b3d2 Ignore bad enctypes in krb5_string_to_keysalts()
Allow gss_unwrap_iov() of unpadded RC4 tokens
2020-07-22 17:28:11 -04:00
Robbie Harwood
b1b925635d Ignore bad enctypes in krb5_string_to_keysalts() 2020-07-22 15:20:11 -04:00
Tom Stellard
da1e8dbb3f Use make macros
https://fedoraproject.org/wiki/Changes/UseMakeBuildInstallMacro
2020-07-21 22:06:50 +00:00
Robbie Harwood
f15271f04d Set qualify_shortname empty in default configuration
Resolves: #1852041
2020-07-08 16:10:07 -04:00
Robbie Harwood
80e06352b8 Use two queues for concurrent t_otp.py daemons 2020-06-15 17:27:59 -04:00
Robbie Harwood
e326a52474 Match Heimdal behavior for channel bindings 2020-06-15 16:57:30 -04:00
Robbie Harwood
feaafc07b2 Fix test suite by removing wrapper workarounds 2020-06-08 22:00:22 +00:00
Robbie Harwood
3c4e18f2f3 Omit PA_FOR_USER if we can't compute its checksum 2020-06-08 16:01:55 -04:00
Robbie Harwood
49849de329 Replace gssrpc tests with a Python script 2020-05-30 12:38:04 -04:00
Robbie Harwood
883355750a Default dns_canonicalize_hostname to "fallback" 2020-05-30 12:01:58 -04:00
Robbie Harwood
331a9df349 dns_canonicalize_hostname = fallback 2020-05-26 21:47:51 +00:00
Robbie Harwood
dec02b8411 Pass channel bindings through SPNEGO 2020-05-26 14:34:53 -04:00
Robbie Harwood
102adf5edf New upstream release (1.18.2) 2020-05-22 14:26:04 -04:00
Robbie Harwood
d370e2a431 Fix SPNEGO acceptor mech filtering 2020-05-22 13:28:09 -04:00
Robbie Harwood
0963a62bc3 Fix typo ("in in") in the ksu man page 2020-05-18 14:02:44 -04:00
Robbie Harwood
a9ccd6fd57 Omit KDC indicator check for S4U2Self requests 2020-05-08 14:14:22 -04:00
Robbie Harwood
19d5d2e504 Pass gss_localname() through SPNEGO 2020-04-28 13:12:21 -04:00
Robbie Harwood
7fca7fd076 New upstream version (1.18.1) 2020-04-14 15:45:43 -04:00
Robbie Harwood
66ec722479 Make ksu honor KRB5CCNAME again 2020-04-07 15:51:54 -04:00
Robbie Harwood
9f3201c4bc Do expiration warnings for all init_creds APIs 2020-04-02 14:03:07 -04:00
Robbie Harwood
c262ec69f6 Correctly import "service@" GSS host-based name 2020-04-01 14:24:49 -04:00
Robbie Harwood
4e7e5fe69b Eliminate redundant PKINIT responder invocation 2020-03-26 16:01:18 -04:00
Robbie Harwood
dd7e9481aa Add finalization safety check to com_err 2020-03-26 10:20:02 -04:00
Robbie Harwood
5c9732a545 Add maximum openssl version in preparation for openssl 3 2020-03-20 16:16:55 +00:00
Robbie Harwood
bea8330f52 Document client keytab usage 2020-03-17 15:26:56 -04:00
Robbie Harwood
f6c62d5e63 Refresh manually acquired creds from client keytab 2020-03-03 12:34:50 -05:00
Robbie Harwood
812c07a94f Allow deletion of require_auth with LDAP KDB 2020-02-28 13:35:47 -05:00
Robbie Harwood
0ecf7a0e65 Allow certauth modules to set hw-authent flag 2020-02-27 16:13:51 -05:00
Robbie Harwood
3b6955d99e Fix AS-REQ checking of KDB-modified indicators 2020-02-21 13:16:49 -05:00
Robbie Harwood
48a220a102 Fix missing dist 2020-02-12 17:47:03 -05:00
Robbie Harwood
f287f939a9 New upstream version (1.18) 2020-02-12 22:29:13 +00:00
Robbie Harwood
dd3e136188 Don't assume OpenSSL failures are memory errors 2020-02-07 10:59:57 -05:00
Robbie Harwood
edfb00e001 Put KDB authdata first 2020-02-06 10:17:38 -05:00
Robbie Harwood
8fb4697062 New upstream beta release - 1.18-beta2
Adjust naming convention for downstream patches
2020-01-31 20:31:53 +00:00
Fedora Release Engineering
b3d5b8f719 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-01-29 07:50:49 +00:00
Robbie Harwood
7f642b1512 New upstream beta release - 1.18-beta1 2020-01-13 18:19:19 -05:00
Robbie Harwood
84aac1fa6d Fix LDAP policy enforcement of pw_expiration
Fix handling of invalid CAMMAC service verifier
2020-01-08 14:07:00 -05:00
Robbie Harwood
2496b50d00 Fix xdr_bytes() strict-aliasing violations 2020-01-06 16:36:41 -05:00
Robbie Harwood
fd463aed6a Don't warn in kadmin when no policy is specified
Do not always canonicalize enterprise principals
2020-01-03 11:36:21 -05:00
Robbie Harwood
d6ef09022c Enable the LMDB backend for the KDB 2019-12-13 19:11:07 +00:00
Robbie Harwood
9d642021d7 New upstream version - 1.17.1
Stop building and packaging PDFs
2019-12-12 18:42:51 +00:00
Robbie Harwood
4aee4bdd71 Qualify short hostnames when not using DNS 2019-12-06 13:44:42 -05:00
Robbie Harwood
02c0c74c74 Various gssalloc fixes 2019-11-27 12:36:19 -05:00
Robbie Harwood
76d9979dc3 Turns out openssl has an epoch 2019-11-21 22:06:25 +00:00
Robbie Harwood
4c128ec39a Fix runtime openssl version to actually propogate 2019-11-20 23:03:40 +00:00
Robbie Harwood
b9ea889e2a Add runtime openssl version requirement too 2019-11-20 21:13:58 +00:00
Robbie Harwood
4b8056ef08 Fix kadmin addprinc -randkey -kvno 2019-11-20 14:16:04 -05:00
Robbie Harwood
1404656ded Use OpenSSL's backported KDFs
Restore MD4 in FIPS mode (for samba)
2019-11-19 14:45:23 -05:00
Robbie Harwood
cbf35c8b1f Add default_principal_flags to example kdc.conf 2019-11-08 20:45:40 +00:00
Robbie Harwood
9ce53b906d Log unknown enctypes as unsupported in KDC 2019-10-02 11:19:07 -04:00
Robbie Harwood
1a6673d2ee Fix KDC crash when logging PKINIT enctypes (CVE-2019-14844) 2019-09-25 13:15:11 -04:00
Robbie Harwood
bff738a25d Static analyzer appeasement 2019-09-12 10:15:52 -04:00
Robbie Harwood
6ea5e5fa9a Simplify krb5_dbe_def_search_enctype() 2019-08-27 11:24:25 -04:00
Robbie Harwood
2dabf02464 Update FIPS patches to remove SPAKE 2019-08-22 15:54:34 -04:00
Robbie Harwood
4906d9dae9 Support building in COPR now that %{copr_username} is gone 2019-08-16 12:24:27 -04:00
Robbie Harwood
cdaea01dc8 Fix KCM client time offset propagation 2019-08-15 16:32:06 -04:00
Robbie Harwood
6fb26c9d3d Initialize life/rlife in kdcpolicy interface 2019-08-09 16:05:18 -04:00
Robbie Harwood
e73c24bb36 Fix memory leaks in soft-pkcs11 code 2019-08-06 09:46:36 -04:00
Robbie Harwood
f4c04f8cde Add soft-pkcs11 and use it for testing 2019-07-30 08:56:06 -04:00
Fedora Release Engineering
52c0e4ab88 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-07-25 12:06:52 +00:00
Robbie Harwood
7c5b49f828 Filter enctypes in gss_set_allowable_enctypes() 2019-07-18 12:49:23 -04:00
Robbie Harwood
4c8ed38666 Don't error on invalid enctypes in keytab
Resolves: #1724380
2019-07-15 13:07:54 -04:00
Robbie Harwood
a0277fd396 Remove now-unused checksum functions 2019-07-02 11:42:28 -04:00
Robbie Harwood
490a817464 Fix typo in 3des commit 2019-06-26 18:23:02 -04:00
Robbie Harwood
7bee5f19e1 Remove PKINIT draft9 support (compat with EOL, pre-2008 Windows) 2019-06-26 18:07:12 -04:00
Robbie Harwood
2843572c2f Remove strerror() calls from k5_get_error() 2019-06-10 12:41:26 -04:00
Robbie Harwood
6d60b0827f Remove 3des from kdc.conf example 2019-06-07 08:52:53 -04:00
Robbie Harwood
1cae0b7e96 Remove 3DES support 2019-06-03 17:33:31 -04:00
Robbie Harwood
19e2656c15 Remove 3des support 2019-06-03 17:25:49 -04:00
Robbie Harwood
48af99c1f7 Remove krb5int_c_combine_keys() and no-flags SAM-2 preauth 2019-05-30 13:32:37 -04:00
Robbie Harwood
3f80a77313 Remove support for single-DES and CRC 2019-05-28 15:22:45 -04:00
Robbie Harwood
f50ceacadf Add missing newlines to deprecation warnings
Switch to upstream's ksu path patch
2019-05-22 10:59:16 -04:00
Robbie Harwood
79613952e3 Update default krb5kdc mkey manual-entry enctype
Also update account lockout patch to upstream version
2019-05-21 12:59:56 -04:00
Robbie Harwood
39ba823db6 Test & docs fixes in preparation for DES removal 2019-05-20 16:49:04 -04:00
Robbie Harwood
f91545040c Drop krb5_realm_compare() etc. NULL check patches 2019-05-15 17:01:26 -04:00
Robbie Harwood
bebe7bd29f Re-provide krb5-kdb-version in -devel as well (IPA wants it) 2019-05-15 15:16:18 +00:00
Robbie Harwood
aa55266a84 (Patch consolidation; hopefully no changes) 2019-05-14 12:34:12 -04:00
Robbie Harwood
4b3d9079ae Remove checksum type profile variables 2019-05-14 11:07:43 -04:00
Robbie Harwood
0b0d802a54 Pull in 2019-05-02 static analysis updates 2019-05-10 13:50:56 -04:00
Robbie Harwood
d1b5e24f4c Drop --with-pkinit-crypto-impl 2019-05-06 14:38:08 -04:00
Robbie Harwood
85664dde3d Move krb5-kdb-version provide into krb5-server for freeipa 2019-05-03 18:36:31 +00:00
Robbie Harwood
4c5654d0fb Use secure_getenv() where appropriate 2019-05-01 12:47:31 -04:00
Robbie Harwood
cdfd42332f Get that squeaky rpmlint clean 2019-04-24 15:51:18 -04:00
Robbie Harwood
0555bc87c8 Add dns_canonicalize_hostname=fallback support 2019-04-24 11:45:11 -04:00
Robbie Harwood
9d9730eb07 Check more errors in OpenSSL crypto backend 2019-04-24 11:39:04 -04:00
Robbie Harwood
aa800df204 Fix potential close(-1) in cc_file.c 2019-04-22 13:09:23 -04:00
Robbie Harwood
707673a505 Remove ovsec_adm_export and confvalidator 2019-04-17 16:17:17 -04:00
Robbie Harwood
5ebfb70254 Fix config realm change logic in FILE remove_cred 2019-04-17 16:16:38 -04:00
Robbie Harwood
05efb47898 Remove Kerberos v4 support vestiges (including ktany support) 2019-04-11 16:44:09 -04:00
Robbie Harwood
7f7eba0cef Implement krb5_cc_remove_cred for remaining types
Resolves: #1693836
2019-04-11 13:18:46 -04:00
Robbie Harwood
caa2dd1a26 FIPS-aware SPAKE group negotiation 2019-04-01 13:13:49 -04:00
Robbie Harwood
bf081fdccd Fix memory leak in 'none' replay cache type
Silence a coverity warning while we're here.
2019-02-25 15:24:36 -05:00