Commit Graph

23 Commits

Author SHA1 Message Date
Iker Pedrosa
40c8b8bba6 pam_access: rework resolving of tokens as hostname
Resolves: CVE-2024-10963 and RHEL-66242

Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
2024-11-25 09:54:50 +01:00
Iker Pedrosa
c8f3c30ddb Various fixes
- pam_unix: always run the helper to obtain shadow password file
  entries.
- pam_access: always match local address and clarify LOCAL keyword
  behaviour.
- libpam: support long lines in service files.

Resolves: CVE-2024-10041. RHEL-62877
Resolves: RHEL-23018
Resolves: RHEL-5051

Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
2024-11-05 13:10:14 +01:00
Iker Pedrosa
42c9e277a6 fix formatting of audit messages
Resolves: RHEL-28620

Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
2024-04-04 09:31:00 +02:00
Iker Pedrosa
b214c5305b pam_namespace: protect_dir(): use O_DIRECTORY to prevent local DoS
situations. CVE-2024-22365

Resolves: RHEL-21242

Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
2024-02-12 15:43:10 +01:00
Iker Pedrosa
b108df3047 pam_access: handle hostnames in access.conf
Resolves: RHEL-3374

Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
2024-01-26 09:34:38 +01:00
Iker Pedrosa
e552669fef pam_faillock: create tallydir before creating tallyfile
Resolves: RHEL-19810

Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
2024-01-08 11:42:13 +01:00
Iker Pedrosa
95587a8173 pam_unix: enable bcrypt
Resolves: RHEL-5057

Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
2023-11-02 12:28:21 +01:00
Iker Pedrosa
b90ff37b84 pam_unix: set default number of rounds
Resolves: RHEL-5057

Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
2023-11-02 10:59:50 +01:00
Iker Pedrosa
118548e948 pam_unix: enable bcrypt
Resolves: RHEL-5057

Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
2023-10-30 10:44:13 +01:00
Iker Pedrosa
9b6c54edc3 pam_misc: make length of misc_conv() configurable and set to 4096
Resolves: 

Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
2023-06-26 10:16:41 +02:00
Iker Pedrosa
df193628c3 spec: fix date
Resolves: 

Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
2023-05-16 16:36:44 +02:00
Iker Pedrosa
77bdfeeb99 smartcard-auth: modify the content to remove unnecessary modules
Resolves: 

Signed-off-by: Iker Pedrosa <ipedrosa@redhat.com>
2023-05-16 15:31:45 +02:00
Troy Dawson
88ec60d717 Bring gating.yaml over from Brew dist-git
Signed-off-by: Troy Dawson <tdawson@redhat.com>
2023-03-10 11:11:44 -08:00
James Antill
7a789ef213 Import rpm: c8s 2023-02-27 14:41:49 -05:00
CentOS Sources
1f028daee3 Auto sync2gitlab import of pam-1.3.1-25.el8.src.rpm 2022-12-01 06:12:16 +00:00
CentOS Sources
2a56641285 Auto sync2gitlab import of pam-1.3.1-24.el8.src.rpm 2022-09-29 20:11:33 +00:00
CentOS Sources
1179a401c1 Auto sync2gitlab import of pam-1.3.1-22.el8.src.rpm 2022-07-21 16:11:30 +00:00
James Antill
c98acce680 Auto sync2gitlab import of pam-1.3.1-20.el8.src.rpm 2022-06-29 14:20:13 -04:00
CentOS Sources
c14799b890 Auto sync2gitlab import of pam-1.3.1-21.el8.src.rpm 2022-06-28 22:13:57 +00:00
James Antill
b26566830b Auto sync2gitlab import of pam-1.3.1-20.el8.src.rpm 2022-06-06 23:09:17 -04:00
James Antill
53f991c34b Auto sync2gitlab import of pam-1.3.1-18.el8.src.rpm 2022-05-31 14:48:50 -04:00
James Antill
2784e60cc3 Auto sync2gitlab import of pam-1.3.1-16.el8.src.rpm 2022-05-26 12:38:09 -04:00
James Antill
fa8b49a471 Initial c8s branch. 2022-05-26 12:38:02 -04:00