Commit Graph

335 Commits

Author SHA1 Message Date
Jan Vcelak
749896483d fix bug number in recent patch 2012-09-14 16:56:03 +02:00
Jan Vcelak
331465716f fix: libldap does not load PEM certificate if certdb is used as TLS_CACERTDIR
Resolves: #857455
2012-09-14 16:14:43 +02:00
Jan Vcelak
557bf01306 fix: MozNSS certificate database in SQL format cannot be used
Resolves: #857390
2012-09-14 16:14:21 +02:00
Jan Vcelak
060a306e1e fix: not all certificates in OpenSSL compatible CA certificate directory format are loaded
Resolves: #852786
2012-09-14 16:13:59 +02:00
Jan Vcelak
1f24c419dd fix: connection hangs after fallback to second server when certificate hostname verification fails
Resolves: #852476
2012-09-14 16:13:39 +02:00
Jan Vcelak
9627ad75ef fix: some TLS ciphers cannot be enabled
Resolves: #852338
2012-09-14 16:13:12 +02:00
Jan Vcelak
ad070fca8d prefer key from authenticated slot, allow certificate name with token
Resolves TLS failures in replication in 389 Directory Server introduced
by recent Mozilla NSS backend fixes.
2012-08-20 20:34:34 +02:00
Jan Vcelak
bfe48e26db add KRB5_KTNAME to /etc/sysconfig/slapd 2012-08-09 10:39:07 +02:00
Jan Vcelak
6304a48a54 new upstream release (2.4.32) 2012-08-01 13:39:25 +02:00
Jan Vcelak
c736adad77 use tabs consistently 2012-08-01 10:21:44 +02:00
Jan Vcelak
2d64625e78 fix: slapd refuses to set up TLS with self-signed PEM certificate
Resolves: #842022
2012-07-21 17:59:04 +02:00
Jan Vcelak
54e357771f multilib fix: move libslapi from openldap-servers to openldap package 2012-07-20 16:59:28 +02:00
Jan Vcelak
9e7cf6735d fix: smbk5pwd module computes invalid LM hashes
Resolves: #841560
2012-07-19 14:27:10 +02:00
Jan Vcelak
20875f4fb9 fix: querying for IPv6 DNS records when IPv6 is disabled on the host
Resolves: #835013
2012-07-19 11:00:43 +02:00
Jan Vcelak
824671e8d7 clean the package build process 2012-07-18 19:02:28 +02:00
Jan Vcelak
9eda95bba4 fix: remove isa macro from BuildRequires 2012-07-18 09:37:59 +02:00
Jan Vcelak
50ed49760b fix: less influence between individual TLS contexts
Resolves: #795763 (and possibly others)
2012-06-27 14:40:59 +02:00
Jan Vcelak
397ce0c946 fix: default cipher suite is always selected
Resolves: #828790
2012-06-27 14:10:28 +02:00
Jan Vcelak
916cbca281 fix: slapd fails to start on reboot
Resolves: #829272
2012-06-27 14:05:10 +02:00
Jan Vcelak
904778f620 CVE-2012-2668: cipher suite selection by name can be ignored
Resolves: #825875
2012-06-27 13:55:02 +02:00
Jan Vcelak
fe1c1e0eeb fix: reading pin from file can make all TLS connections hang
Resolves: #829317
2012-06-27 13:48:40 +02:00
Jan Vcelak
0cda8087e0 fix: TLS error messages overwriting in tlsm_verify_cert()
Resolves: #810462
2012-06-27 13:36:51 +02:00
Jan Vcelak
ac8a31ed53 fix: invalid order of TLS shutdown operations
Resolves: #808465
2012-06-27 13:31:05 +02:00
Jan Vcelak
5172ff7830 update fix: count constraint broken when using multiple modifications
Resolves: #795766
2012-06-27 13:26:24 +02:00
Jan Vcelak
60d09d71cf fix: MozNSS CA certdir does not work together with PEM CA cert file
Resolves: #819536
2012-05-18 12:47:45 +02:00
Jan Vcelak
61feb71485 changelog: nss-tools has to be required by base package 2012-05-18 12:47:41 +02:00
Jan Vcelak
f8f3a2b33f nss-tools has to be required by base package 2012-05-02 11:25:36 +02:00
Jan Vcelak
05bc41c858 remove upstream merged patches 2012-04-24 10:44:16 +02:00
Jan Vcelak
6e16cb7901 new upstream release (2.4.31) 2012-04-24 10:35:02 +02:00
Jan Vcelak
df6cf45ec2 merge master and f17 to have the same history 2012-04-05 20:47:14 +02:00
Jan Vcelak
440b96e85c rebuild due to libdb rebase 2012-04-05 20:41:25 +02:00
Jan Synacek
8453acdae3 fix: Re-binding to a failed connection can segfault
Resolves: #784989
(cherry picked from commit 0992cf19a9)
2012-03-26 13:54:39 +02:00
Jan Synacek
0992cf19a9 fix: Re-binding to a failed connection can segfault
Resolves: #784989
2012-03-26 13:41:40 +02:00
Jan Vcelak
a4d33565bb new upstream release (2.4.30)
Resolves: #798958
2012-03-01 14:24:19 +01:00
Jan Vcelak
412132a293 fix update: missing options in manual pages of client tools
Upstream considers '-C' as an obsolete and intentionally undocumented
option.

Resolves: #796232
2012-02-23 15:04:46 +01:00
Jan Vcelak
862f73dffa fix: SASL_NOCANON option missing in ldap.conf manual page
Resolves: #732915
2012-02-22 15:46:23 +01:00
Jan Vcelak
c2db986060 fix: missing options in manual pages of client tools
Resolves: #796232
2012-02-22 15:41:53 +01:00
Jan Vcelak
b2b2825914 fix: count constraint broken when using multiple modifications
Resolves: #795766
2012-02-21 15:44:56 +01:00
Jan Vcelak
20125eca06 fix: ldap_result does not succeed for sssd
Resolves: #771484
2012-02-21 15:37:51 +01:00
Jan Vcelak
558f709787 fix update provide ldif2ldbm, not ldib2ldbm
Resolves: #437104
2012-02-20 15:31:58 +01:00
Jan Synacek
f25689a388 unify systemctl binary paths throughout the specfile and make them usrmove compliant
make path to chkconfig binary usrmove compliant
2012-02-20 15:14:53 +01:00
Jan Vcelak
d5cbb774ed fix: check-config.sh get stuck when executing command as a ldap user 2012-02-15 14:26:49 +01:00
Jan Vcelak
dc2b490d64 temporarily disable certificates checking in check-config.sh
MozNSS support is missing yet.
2012-02-15 13:15:07 +01:00
Jan Synacek
b95104a6a1 fix: correct path to check-config.sh in service file 2012-02-15 09:10:16 +01:00
Jan Vcelak
b5e66b7ea2 remove obsoleted slapd.conf 2012-02-14 17:22:53 +01:00
Jan Vcelak
a7572065e5 certificates management improvements
Resolves: #772890
2012-02-14 17:22:50 +01:00
Jan Vcelak
934ba146a8 move maintainance scripts from libexec/slapd to libexec/openldap 2012-02-14 13:42:07 +01:00
Jan Vcelak
78a563b273 openldap-servers: provide ldib2ldbm for migrationtools
References: #437104
2012-02-14 13:40:58 +01:00
Jan Vcelak
5e3dba33db clean requirements: remove explicit versions, add %{_isa} macro 2012-02-14 13:40:42 +01:00
Jan Vcelak
31026088da new upstream release (2.4.29) 2012-02-13 13:07:11 +01:00