Commit Graph

  • 9e16356e4a Add missing patch Stephen Gallagher 2012-07-16 10:02:33 -0400
  • 7a12c895a2 Fix broken ARM build Stephen Gallagher 2012-07-16 09:50:52 -0400
  • f681bd4766 Own several directories Jakub Hrozek 2012-07-15 16:45:13 +0200
  • 32842a881b New upstream release 1.9.0 beta 4 Jakub Hrozek 2012-07-11 09:57:09 +0200
  • 058cfb833c New upstream release 1.9.0 beta 3 Stephen Gallagher 2012-06-25 13:15:35 -0400
  • 2cb25205a4 Switch unicode library from libunistring to Glib Stephen Gallagher 2012-06-20 10:32:39 -0400
  • f8c88041e5 Fix accidental disabling of the DIR cache support Stephen Gallagher 2012-06-18 10:16:49 -0400
  • 666a39284d New upstream release 1.9.0 beta 2 Stephen Gallagher 2012-06-15 15:43:49 -0400
  • 26151dabf9 Fix regression in endianness patch Stephen Gallagher 2012-05-30 15:10:43 -0400
  • 12d78e10a6 Rebuild SSSD against ding-libs 0.3.0beta1 Stephen Gallagher 2012-05-29 11:23:46 -0400
  • 359d341a35 Fix several regressions since 1.5.x Stephen Gallagher 2012-05-24 08:23:25 -0400
  • 7fa00add1e New upstream release 1.9.0 beta 1 Stephen Gallagher 2012-05-11 16:02:54 -0400
  • 05471b8b76 New upstream release 1.8.3 Stephen Gallagher 2012-05-03 15:46:32 -0400
  • 77acf296a2 New upstream release 1.8.2 Stephen Gallagher 2012-04-09 15:06:43 -0400
  • d023298922 Don't duplicate libsss_autofs.so in two packages Stephen Gallagher 2012-03-26 09:35:09 -0400
  • af80d0ea8a Fix uninitialized value bug causing crashes throughout the code Stephen Gallagher 2012-03-21 07:35:03 -0400
  • 8c71823719 New upstream release 1.8.1 Stephen Gallagher 2012-03-12 19:25:42 -0400
  • 41359781c6 New upstream release 1.8.0 Stephen Gallagher 2012-02-28 15:23:22 -0500
  • d474da7ce3 Change default kerberos credential cache location to /run/user/<username> Stephen Gallagher 2012-02-22 09:11:05 -0500
  • e16d49fc65 New upstream release 1.8.0 beta 3 Stephen Gallagher 2012-02-15 16:11:31 -0500
  • 14c3c0777e Fix python Provides: filtering Stephen Gallagher 2012-02-15 10:38:10 -0500
  • 111a1d5cbe Rebuild against PCRE 8.30 Petr Písař 2012-02-10 13:08:38 +0100
  • 01ac0e1a3e New upstream release Stephen Gallagher 2012-02-07 09:57:04 -0500
  • 881479933b New upstream release Stephen Gallagher 2012-02-06 20:08:04 -0500
  • e8905f5363 Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for Stephen Gallagher 2012-02-04 20:20:10 -0500
  • b6ef581001 Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider. Stephen Gallagher 2012-02-02 14:23:16 -0500
  • 2381e855ec Fix typo in date and version Stephen Gallagher 2012-02-01 14:27:24 -0500
  • ae664ccc43 Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for Stephen Gallagher 2012-02-01 14:22:00 -0500
  • 6ec779e9e4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild Dennis Gilmore 2012-01-13 22:24:58 -0600
  • a885ab8a9d New upstream release 1.7.0 https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 Support for case-insensitive domains Support for multiple search bases in the LDAP provider Support for the native FreeIPA netgroup implementation Reliability improvements to the process monitor New DEBUG facility with more consistent log levels New tool to change debug log levels without restarting SSSD SSSD will now disconnect from LDAP server when idle FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains Assorted performance improvements in the LDAP provider Stephen Gallagher 2011-12-22 15:12:50 -0500
  • f73d44d40a New upstream release 1.6.4 Rolls up previous patches applied to the 1.6.3 tarball Fixes a rare issue causing crashes in the failover logic Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize. Stephen Gallagher 2011-12-19 16:13:43 -0500
  • 5633dc7e99 Rebuild against libldb 1.1.4 Stephen Gallagher 2011-12-07 07:47:53 -0500
  • ece3519410 Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() Resolves: rhbz#758425 - LDAP failover not working if server refuses connections Stephen Gallagher 2011-11-29 14:20:31 -0500
  • 95fec2a877 Rebuild for libldb 1.1.3 Jakub Hrozek 2011-11-24 14:18:54 +0100
  • 50d0fe5c94 Resolves: rhbz#752495 - Crash when apply settings Stephen Gallagher 2011-11-10 12:03:57 -0500
  • dd4aa148dd Rebuild for new libldb Stephen Gallagher 2011-11-09 09:02:44 -0500
  • 46a6ee6147 New upstream release 1.6.3 Stephen Gallagher 2011-11-04 12:26:54 -0400
  • 9ef1f397c1 - Rebuilt for glibc bug#747377 Dennis Gilmore 2011-10-26 19:24:26 -0500
  • 9a79ed0faa Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version. Stephen Gallagher 2011-10-23 13:48:09 -0700
  • 14552a85ab Add explicit requirement on selinux-policy version to address new SBUS symlinks. Stephen Gallagher 2011-10-21 08:02:25 -0700
  • 359707a48b Remove %%files reference to sss_debuglevel copied from wrong upstreeam spec file. Stephen Gallagher 2011-10-19 07:32:09 -0400
  • 75138e2284 Improved handling of users and groups with multi-valued name attributes (aliases) Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing Improved process-hang detection and restarting Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) Cleaned up the example configuration New tool to change debug level on the fly Stephen Gallagher 2011-10-18 17:24:31 -0400
  • a6910c0007 New upstream release 1.6.1 https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) Three HBAC regressions have been fixed. Fix for an infinite loop in the deref code Stephen Gallagher 2011-08-29 15:45:02 -0400
  • 04d8c969b5 Build with _hardened_build macro Stephen Gallagher 2011-08-03 09:31:33 -0400
  • 679b5f7a1b New upstream release 1.6.0 https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 Add host access control support for LDAP (similar to pam_host_attr) Finer-grained control on principals used with Kerberos (such as for FAST or validation) Added a new tool sss_cache to allow selective expiring of cached entries Added support for LDAP DEREF and ASQ controls Added access control features for Novell Directory Server FreeIPA dynamic DNS update now checks first to see if an update is needed Complete rewrite of the HBAC library New libraries: libipa_hbac and libipa_hbac-python Stephen Gallagher 2011-08-03 08:08:26 -0400
  • ce222bafe5 New upstream release 1.5.11 https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 Fix a serious regression that prevented SSSD from working with ldaps:// URIs IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 address being saved to the AAAA record Stephen Gallagher 2011-07-05 15:03:55 -0400
  • 72bc2e1636 New upstream release 1.5.11 https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 Fix a serious regression that prevented SSSD from working with ldaps:// URIs IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 address being saved to the AAAA record Stephen Gallagher 2011-07-05 15:00:32 -0400
  • 807b79d3dd New upstream release 1.5.10 https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 Fixed a regression introduced in 1.5.9 that could result in blocking calls to LDAP Stephen Gallagher 2011-07-01 08:31:11 -0400
  • 4ef0c7f5e6 New upstream release 1.5.9 https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 Support for overriding home directory, shell and primary GID locally Properly honor TTL values from SRV record lookups Support non-POSIX groups in nested group chains (for RFC2307bis LDAP servers) Properly escape IPv6 addresses in the failover code Do not crash if inotify fails (e.g. resource exhaustion) Don't add multiple TGT renewal callbacks (too many log messages) Stephen Gallagher 2011-06-30 14:57:29 -0400
  • 91fde1e873 New upstream release 1.5.8 https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 Support for the LDAP paging control Support for multiple DNS servers for name resolution Fixes for several group membership bugs Fixes for rare crash bugs Stephen Gallagher 2011-05-27 16:41:02 -0400
  • 5796dc7438 Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d Make sure to properly convert to systemd if upgrading from newer updates for Fedora 14 Stephen Gallagher 2011-05-23 14:51:01 -0400
  • d4aff4665f Fix segfault in TGT renewal Stephen Gallagher 2011-05-02 12:29:25 -0400
  • e4bdfb2159 Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites cached password with predicatable filename Stephen Gallagher 2011-04-29 14:36:34 -0400
  • eedc5ecda8 Re-add manpage translations Stephen Gallagher 2011-04-20 16:27:19 -0400
  • 8ada5dc2d5 New upstream release 1.5.6 https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 Fixed a serious memory leak in the memberOf plugin Fixed a regression with the negative cache that caused it to be essentially nonfunctional Fixed an issue where the user's full name would sometimes be removed from the cache Fixed an issue with password changes in the kerberos provider not working with kpasswd Stephen Gallagher 2011-04-20 15:26:05 -0400
  • d9b22a78e6 Resolves: rhbz#697057 - kpasswd fails when using sssd and kadmin server != kdc server Upgrades from SysV should now maintain enabled/disabled status Stephen Gallagher 2011-04-20 12:44:13 -0400
  • d7effc61bd Fix %postun Stephen Gallagher 2011-04-18 11:02:57 -0400
  • d895a5f72c Fix systemd conversion. Upgrades from SysV to systemd weren't properly enabling the systemd service. Fix a serious memory leak in the memberOf plugin Fix an issue where the user's full name would sometimes be removed from the cache Stephen Gallagher 2011-04-14 14:16:04 -0400
  • 7dcee20614 Install systemd unit file instead of sysv init script Stephen Gallagher 2011-04-12 11:52:28 -0400
  • c8fb340975 New upstream release 1.5.5 https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 Fixes for several crash bugs LDAP group lookups will no longer abort if there is a zero-length member attribute Add automatic fallback to 'cn' if the 'gecos' attribute does not exist Stephen Gallagher 2011-04-12 11:14:23 -0400
  • 3eed4c3557 Update to SSSD 1.5.4 Stephen Gallagher 2011-03-24 15:17:41 -0400
  • f6c362454d Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication Stephen Gallagher 2011-03-17 11:47:25 -0400
  • 53637a07d3 New upstream release 1.5.3 Support for libldb >= 1.0.0 Stephen Gallagher 2011-03-11 13:50:22 -0500
  • 1dadc663de Update sources file for sssd-1.5.2 Stephen Gallagher 2011-03-10 16:38:54 -0500
  • 3b364490a6 New upstream release 1.5.2 https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 Fixes for support of FreeIPA v2 Fixes for failover if DNS entries change Improved sss_obfuscate tool with better interactive mode Fix several crash bugs Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this Delete users from the local cache if initgroups calls return 'no such user' (previously only worked for getpwnam/getpwuid) Use new Transifex.net translations Better support for automatic TGT renewal (now survives restart) Netgroup fixes Stephen Gallagher 2011-03-10 15:00:40 -0500
  • b28cafe61b - Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425 Simo Sorce 2011-02-27 21:54:52 -0500
  • 7a33e7710b - Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users Stephen Gallagher 2011-02-21 15:42:00 -0500
  • da2a04f651 - Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf Stephen Gallagher 2011-02-11 11:41:33 -0500
  • 0ad47aae65 - Fix memberOf install path Stephen Gallagher 2011-02-11 11:22:33 -0500
  • e8ab291d89 - Add support for libldb 1.0.0 Stephen Gallagher 2011-02-11 09:36:41 -0500
  • 8923e26c46 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild Dennis Gilmore 2011-02-09 10:00:19 -0600
  • d12cd5dd26 - Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage Stephen Gallagher 2011-02-01 08:40:52 -0500
  • 749bf2d662 Bump release number Stephen Gallagher 2011-01-27 14:40:33 -0500
  • 7e3a2cd879 - Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild Stephen Gallagher 2011-01-27 14:38:13 -0500
  • f151b0669b - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes Stephen Gallagher 2011-01-27 13:50:21 -0500
  • 3a15e92ce7 - CVE-2010-4341 - DoS in sssd PAM responder can prevent logins Stephen Gallagher 2011-01-11 12:32:39 -0500
  • 5225c3262b - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations Stephen Gallagher 2010-12-22 14:08:33 -0500
  • 9600ada0fd Fix release number Stephen Gallagher 2010-11-18 08:44:23 -0500
  • 069ad4076b - Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade Stephen Gallagher 2010-11-18 08:41:39 -0500
  • 4e1de07cd8 - Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf Stephen Gallagher 2010-11-16 12:48:57 -0500
  • 9d5bcde0eb - New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base Stephen Gallagher 2010-11-01 09:02:47 -0400
  • 75efc48618 Fix incorrect tarball URL Stephen Gallagher 2010-10-18 16:06:09 -0400
  • d8a8ec9a9a Fix tarball URL Stephen Gallagher 2010-10-18 16:04:39 -0400
  • 4926f3ae3a Merge branch 'master' into f14 Stephen Gallagher 2010-10-18 15:37:53 -0400
  • e439c0b36c Uploading SSSD 1.4.0 tarball Stephen Gallagher 2010-10-18 14:50:39 -0400
  • 9b0ef1cecd - New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated Stephen Gallagher 2010-10-18 14:44:48 -0400
  • d856e9b109 Merge branch 'master' into f14 Stephen Gallagher 2010-10-04 09:48:41 -0400
  • 2d631b340a - Fix pre and post script requirements Stephen Gallagher 2010-10-04 09:47:22 -0400
  • c0762ac0e0 Merge branch 'master' into f14 Stephen Gallagher 2010-10-04 09:27:12 -0400
  • 3f786445f0 - Resolves: rhbz#606887 - sssd stops on upgrade Stephen Gallagher 2010-10-04 09:23:20 -0400
  • 8cdc9d4fbc - Resolves: rhbz#626205 - Unable to unlock screen Stephen Gallagher 2010-10-04 09:13:13 -0400
  • c7ce53cc09 - Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it Stephen Gallagher 2010-09-28 07:49:22 -0400
  • c99e02ae14 Bump release number and fix changelog message Stephen Gallagher 2010-09-28 07:55:09 -0400
  • d19c240979 - Resolves: 637955 - libini_config-devel needs libcollection-devel but - doesn't require it Stephen Gallagher 2010-09-28 07:49:22 -0400
  • 6931ca88fa - Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib Stephen Gallagher 2010-09-16 09:34:47 -0400
  • cfa7be9344 - Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib Stephen Gallagher 2010-09-16 09:32:53 -0400
  • 8c665d0af5 Resolves: CVE-2010-2940 Stephen Gallagher 2010-08-24 12:10:04 -0400
  • 22218bb857 dist-git conversion Fedora Release Engineering 2010-07-29 13:10:57 +0000
  • eb2fc3c856 - Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild dmalcolm 2010-07-22 06:37:10 +0000
  • bd215c451c - New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection Stephen Gallagher 2010-07-09 18:52:22 +0000