Commit Graph

  • da5db561e5 Merged update from upstream sources DistroBaker 2020-11-24 18:42:16 +0000
  • b783a5421c Document -k option in kvno(1) synopsis Robbie Harwood 2020-11-24 12:55:33 -0500
  • ab7a2a35c2 Upstream executable shared libraries patch Robbie Harwood 2020-11-20 11:43:18 -0500
  • 85d9be4ef7 RHEL 9.0.0 Alpha bootstrap Troy Dawson 2020-11-18 14:34:00 -0800
  • dc8775d11d Fix build failure in -1 Robbie Harwood 2020-11-18 13:33:37 -0500
  • 5facc9df4d New upstream version (1.18.3) Robbie Harwood 2020-11-18 18:16:20 +0000
  • dcd44d26dc RHEL 9.0.0 Alpha bootstrap Troy Dawson 2020-11-18 09:51:25 -0800
  • 015255764a Sigh, date fix Robbie Harwood 2020-11-17 12:50:36 -0500
  • ec1ab43ca2 Migrate /var/run to /run, an exercise in pointlessness Robbie Harwood 2020-11-17 17:27:37 +0000
  • f0185a4c0a Merged update from upstream sources DistroBaker 2020-11-05 18:01:23 +0000
  • d2da394f67 Add recursion limit for ASN.1 indefinite lengths (CVE-2020-28196) Robbie Harwood 2020-11-05 12:09:39 -0500
  • 2c0634c50d Merged update from upstream sources DistroBaker 2020-10-27 21:13:14 +0100
  • bfdc7c0b7b Fix minor static analysis defects Robbie Harwood 2020-10-23 10:25:37 -0400
  • fced14e78a Fix build of previous Robbie Harwood 2020-10-21 11:49:22 -0400
  • 7c8b50fca5 Cross-realm s4u fixes for samba (#1836630) Robbie Harwood 2020-10-21 11:24:24 -0400
  • da77b5dcf8 Drop unnecessary conflict with openssl-libs >= 3.0.0 Tomas Mraz 2020-10-19 11:25:53 +0200
  • 96c0dcc1c7 Unify kvno option documentation Robbie Harwood 2020-10-15 16:18:06 -0400
  • 908aeb56b2 RHEL 9.0.0 Alpha bootstrap Petr Šabata 2020-10-15 15:05:18 +0200
  • c5329a1c4a New branch setup Release Configuration Management 2020-10-08 16:19:50 +0000
  • 501e298072 Add md5 override to krad Robbie Harwood 2020-10-02 16:36:12 -0400
  • c06ba2920a Use `systemctl reload` to HUP the KDC during logrotate Resolves: #1877692 Robbie Harwood 2020-09-10 14:22:32 +0000
  • d7334ebf68 Fix input length checking in SPNEGO DER decoding Robbie Harwood 2020-09-09 17:47:18 -0400
  • 1003328588 Mark crypto-polices snippet as missingok Robbie Harwood 2020-08-28 16:23:22 +0000
  • cd0b1d6ba6 Temporarily dns_canonicalize_hostname=fallback changes Robbie Harwood 2020-08-13 09:50:45 -0400
  • c59e4a1c67 Expand dns_canonicalize_hostname=fallback support Robbie Harwood 2020-08-07 19:03:02 -0400
  • 2091f29399 Fix leak in KERB_AP_OPTIONS_CBT server support Robbie Harwood 2020-08-04 14:24:08 -0400
  • 4530bb6de9 Revert qualify_shortname removal Robbie Harwood 2020-08-03 15:39:37 -0400
  • 8be5252136 Disable tests on s390x Robbie Harwood 2020-08-03 19:30:15 +0000
  • d0cfa344c7 - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild Fedora Release Engineering 2020-08-01 03:47:16 +0000
  • 710f626f12 Revert qualify_shortname changes Robbie Harwood 2020-07-31 13:31:53 -0400
  • d314641a26 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild Fedora Release Engineering 2020-07-28 03:39:56 +0000
  • 86ecb1b3d2 Ignore bad enctypes in krb5_string_to_keysalts() Robbie Harwood 2020-07-22 17:28:11 -0400
  • b1b925635d Ignore bad enctypes in krb5_string_to_keysalts() Robbie Harwood 2020-07-15 16:30:20 -0400
  • da1e8dbb3f Use make macros Tom Stellard 2020-07-13 20:32:39 +0000
  • f15271f04d Set qualify_shortname empty in default configuration Robbie Harwood 2020-07-08 20:10:01 +0000
  • 80e06352b8 Use two queues for concurrent t_otp.py daemons Robbie Harwood 2020-06-15 17:27:59 -0400
  • e326a52474 Match Heimdal behavior for channel bindings Robbie Harwood 2020-06-15 16:57:30 -0400
  • feaafc07b2 Fix test suite by removing wrapper workarounds Robbie Harwood 2020-06-08 22:00:22 +0000
  • 3c4e18f2f3 Omit PA_FOR_USER if we can't compute its checksum Robbie Harwood 2020-06-08 16:01:55 -0400
  • 49849de329 Replace gssrpc tests with a Python script Robbie Harwood 2020-05-30 12:38:04 -0400
  • 883355750a Default dns_canonicalize_hostname to "fallback" Robbie Harwood 2020-05-30 12:01:58 -0400
  • 331a9df349 dns_canonicalize_hostname = fallback Robbie Harwood 2020-05-26 21:47:51 +0000
  • dec02b8411 Pass channel bindings through SPNEGO Robbie Harwood 2020-05-26 14:34:53 -0400
  • 102adf5edf New upstream release (1.18.2) Robbie Harwood 2020-05-22 14:22:05 -0400
  • d370e2a431 Fix SPNEGO acceptor mech filtering Robbie Harwood 2020-05-22 13:28:09 -0400
  • 0963a62bc3 Fix typo ("in in") in the ksu man page Robbie Harwood 2020-05-18 14:02:44 -0400
  • a9ccd6fd57 Omit KDC indicator check for S4U2Self requests Robbie Harwood 2020-05-08 14:14:22 -0400
  • 19d5d2e504 Pass gss_localname() through SPNEGO Robbie Harwood 2020-04-28 13:12:21 -0400
  • 46d8c677ae It usually helps if I commit the sources file Robbie Harwood 2020-04-14 15:50:03 -0400
  • 7fca7fd076 New upstream version (1.18.1) Robbie Harwood 2020-04-14 15:45:43 -0400
  • 66ec722479 Make ksu honor KRB5CCNAME again Robbie Harwood 2020-04-07 15:51:54 -0400
  • 9f3201c4bc Do expiration warnings for all init_creds APIs Robbie Harwood 2020-04-02 14:03:07 -0400
  • c262ec69f6 Correctly import "service@" GSS host-based name Robbie Harwood 2020-04-01 14:24:49 -0400
  • 4e7e5fe69b Eliminate redundant PKINIT responder invocation Robbie Harwood 2020-03-26 16:01:18 -0400
  • dd7e9481aa Add finalization safety check to com_err Robbie Harwood 2020-03-26 10:20:02 -0400
  • 5c9732a545 Add maximum openssl version in preparation for openssl 3 Robbie Harwood 2020-03-20 16:16:55 +0000
  • bea8330f52 Document client keytab usage Robbie Harwood 2020-03-17 15:26:56 -0400
  • bef2ba57a2 Update for new rpmlint shenanigans Robbie Harwood 2020-03-09 15:26:46 -0400
  • f6c62d5e63 Refresh manually acquired creds from client keytab Robbie Harwood 2020-03-03 12:34:50 -0500
  • 812c07a94f Allow deletion of require_auth with LDAP KDB Robbie Harwood 2020-02-28 13:35:47 -0500
  • 0ecf7a0e65 Allow certauth modules to set hw-authent flag Robbie Harwood 2020-02-27 16:13:51 -0500
  • 3b6955d99e Fix AS-REQ checking of KDB-modified indicators Robbie Harwood 2020-02-21 13:16:49 -0500
  • 48a220a102 Fix missing dist Robbie Harwood 2020-02-12 17:47:03 -0500
  • f287f939a9 New upstream version (1.18) Robbie Harwood 2020-02-12 22:29:13 +0000
  • dd3e136188 Don't assume OpenSSL failures are memory errors Robbie Harwood 2020-02-07 10:59:57 -0500
  • edfb00e001 Put KDB authdata first Robbie Harwood 2020-02-06 10:17:38 -0500
  • 8fb4697062 New upstream beta release - 1.18-beta2 Adjust naming convention for downstream patches Robbie Harwood 2020-01-31 20:31:53 +0000
  • b3d5b8f719 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild Fedora Release Engineering 2020-01-29 07:50:49 +0000
  • 7f642b1512 New upstream beta release - 1.18-beta1 Robbie Harwood 2020-01-10 21:31:31 +0000
  • 84aac1fa6d Fix LDAP policy enforcement of pw_expiration Robbie Harwood 2020-01-08 14:07:00 -0500
  • 2496b50d00 Fix xdr_bytes() strict-aliasing violations Robbie Harwood 2020-01-06 16:36:41 -0500
  • fd463aed6a Don't warn in kadmin when no policy is specified Robbie Harwood 2020-01-03 11:36:21 -0500
  • d6ef09022c Enable the LMDB backend for the KDB Robbie Harwood 2019-12-13 19:11:07 +0000
  • 9d642021d7 New upstream version - 1.17.1 Robbie Harwood 2019-12-12 18:34:55 +0000
  • 4aee4bdd71 Qualify short hostnames when not using DNS Robbie Harwood 2019-12-06 13:44:42 -0500
  • 02c0c74c74 Various gssalloc fixes Robbie Harwood 2019-11-27 12:36:19 -0500
  • 76d9979dc3 Turns out openssl has an epoch Robbie Harwood 2019-11-21 22:06:25 +0000
  • 4c128ec39a Fix runtime openssl version to actually propogate Robbie Harwood 2019-11-20 23:03:40 +0000
  • b9ea889e2a Add runtime openssl version requirement too Robbie Harwood 2019-11-20 21:13:58 +0000
  • 4b8056ef08 Fix kadmin addprinc -randkey -kvno Robbie Harwood 2019-11-20 14:16:04 -0500
  • 1404656ded Use OpenSSL's backported KDFs Robbie Harwood 2019-11-19 14:45:23 -0500
  • cbf35c8b1f Add default_principal_flags to example kdc.conf Robbie Harwood 2019-11-08 20:45:40 +0000
  • 9ce53b906d Log unknown enctypes as unsupported in KDC Robbie Harwood 2019-10-02 11:19:07 -0400
  • 1a6673d2ee Fix KDC crash when logging PKINIT enctypes (CVE-2019-14844) Robbie Harwood 2019-09-25 13:15:11 -0400
  • bff738a25d Static analyzer appeasement Robbie Harwood 2019-09-12 10:15:52 -0400
  • 6ea5e5fa9a Simplify krb5_dbe_def_search_enctype() Robbie Harwood 2019-08-27 11:24:25 -0400
  • 2dabf02464 Update FIPS patches to remove SPAKE Robbie Harwood 2019-08-22 15:53:25 -0400
  • 4906d9dae9 Support building in COPR now that %{copr_username} is gone Robbie Harwood 2019-08-16 12:24:27 -0400
  • cdaea01dc8 Fix KCM client time offset propagation Robbie Harwood 2019-08-15 16:32:06 -0400
  • 6fb26c9d3d Initialize life/rlife in kdcpolicy interface Robbie Harwood 2019-08-09 16:05:18 -0400
  • e73c24bb36 Fix memory leaks in soft-pkcs11 code Robbie Harwood 2019-08-06 09:46:36 -0400
  • f4c04f8cde Add soft-pkcs11 and use it for testing Robbie Harwood 2019-07-30 08:56:06 -0400
  • 52c0e4ab88 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild Fedora Release Engineering 2019-07-25 12:06:52 +0000
  • 7c5b49f828 Filter enctypes in gss_set_allowable_enctypes() Robbie Harwood 2019-07-18 12:49:23 -0400
  • 4c8ed38666 Don't error on invalid enctypes in keytab Robbie Harwood 2019-07-15 13:07:54 -0400
  • a0277fd396 Remove now-unused checksum functions Robbie Harwood 2019-07-02 11:42:28 -0400
  • 490a817464 Fix typo in 3des commit Robbie Harwood 2019-06-26 18:23:02 -0400
  • 7bee5f19e1 Remove PKINIT draft9 support (compat with EOL, pre-2008 Windows) Robbie Harwood 2019-06-26 18:07:12 -0400
  • 2843572c2f Remove strerror() calls from k5_get_error() Robbie Harwood 2019-06-10 12:41:26 -0400
  • 6d60b0827f Remove 3des from kdc.conf example Robbie Harwood 2019-06-07 08:52:53 -0400