1
0
forked from pool/openldap2
Commit Graph

236 Commits

Author SHA256 Message Date
5d9f2f4b15 - Update to release 2.6.6
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=317
2023-11-03 06:39:50 +00:00
William Brown
62264abc6d Accepting request 1109222 from home:kukuk:cleanup
- Disable SLP by default for Factory and ALP (bsc#1214884)

OBS-URL: https://build.opensuse.org/request/show/1109222
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=315
2023-09-11 23:45:04 +00:00
45f0da8982 Accepting request 1093958 from home:rfrohl:branches:network:ldap
add CVE ref

OBS-URL: https://build.opensuse.org/request/show/1093958
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=313
2023-06-20 12:00:45 +00:00
c5f22a6f3d - update to 2.6.4:
* Fixed client tools to remove 'h' and 'p' options
  * Fixed ldapsearch memory leak with paged results (ITS#9860)
  * Fixed libldap ldif_open_urlto check for failure (ITS#9904)
  * Fixed libldap ldap_url_parsehosts check for failure
  * Fixed liblunicode UTF8bvnormalize buffer size (ITS#9955)
  * Fixed lloadd memory leaks (ITS#9907)
  * Fixed lloadd shutdown code to protect memory correctly
  * Fixed lloadd race in epoch.c (ITS#9947)
  * Fixed lloadd potential deadlock with cn=monitor (ITS#9951)
  * Fixed lloadd to keep listener base around when not active
  * Fixed lloadd object reclamation sequencing (ITS#9983)
  * Fixed slapd memory leak with olcAuthIDRewrite (ITS#6035)
  * Fixed slapd free of redundant cmdline option (ITS#9912)
  * Fixed slapd transactions extended operations cleanup after
  * Fixed slapd deadlock with replicated cn=config
  * Fixed slapd connection close logic (ITS#9991)
  * Fixed slapd bconfig locking of cn=config entries (ITS#9045)
  * Fixed slapd-mdb max number of index databases to 256
  * Fixed slapd-mdb to always release entries from ADD operations
  * Fixed slapd-mdb to fully init empty DN in tool_entry_get
  * Fixed slapd-monitor memory leaks with lloadd (ITS#9906)
  * Fixed slapd-monitor to free remembered cookies (ITS#9339)
  * Fixed slapo-accesslog reqStart ordering matching rule
  * Fixed slapo-deref memory leak (ITS#9924)
  * Fixed slapo-dynlist to ignore irrelevant objectClasses
  * Fixed slapo-dynlist to avoid unnecessary searches (ITS#9929)
  * Fixed slapo-dynlist to mark internal searches as such
  * Fixed slapo-pcache crash in consistency_check (ITS#9966)
  * Fixed slapo-remoteauth memory leaks (ITS#9438)

OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=311
2023-04-15 10:42:50 +00:00
0da1e6801e Accepting request 1041971 from home:dirkmueller:Factory
- add reproducible.patch to avoid using compile-time specific date/time
  constructs

OBS-URL: https://build.opensuse.org/request/show/1041971
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=309
2022-12-10 10:45:40 +00:00
William Brown
8644a7376a Accepting request 1031422 from home:firstyear:branches:network:ldap
- bsc#1202931 - CVE-2022-31253 - Openldap start script allowed the ldap user
  to privilege escalate to root due to unbound chown commands.

OBS-URL: https://build.opensuse.org/request/show/1031422
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=307
2022-10-27 01:27:25 +00:00
5c86a602e3 trim changelog of non-user visible parts (BSD, build system) and heed syntax requirements
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=305
2022-07-15 07:57:41 +00:00
37510db636 Accepting request 989267 from home:stroeder:branches:network:ldap
update to 2.6.3

OBS-URL: https://build.opensuse.org/request/show/989267
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=304
2022-07-15 07:53:50 +00:00
02af4aa37e heed changelog syntax
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=302
2022-05-25 10:56:35 +00:00
079edf9d81 Accepting request 978686 from home:stroeder:branches:network:ldap
Update to release 2.6.2

OBS-URL: https://build.opensuse.org/request/show/978686
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=301
2022-05-25 10:53:16 +00:00
39a91ec86a Accepting request 976504 from home:firstyear:branches:network:ldap
- bsc#1199277 - Resolve segfault when calling new ctx with global ctx
* 0017-Resolve-error-handling-in-new-ctx-when-global.patch

OBS-URL: https://build.opensuse.org/request/show/976504
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=299
2022-05-22 00:07:21 +00:00
a9e4866cde Accepting request 969283 from home:stroeder:branches:network:ldap
- Use libargon2 instead of libsodium because it supports p>1
- Added new contrib overlays: authzid, datamorph, variant, vc

OBS-URL: https://build.opensuse.org/request/show/969283
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=297
2022-04-11 21:25:05 +00:00
1362cffd3a Accepting request 966577 from home:jengelh:branches:network:ldap
- Update to release 2.6.1

OBS-URL: https://build.opensuse.org/request/show/966577
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=296
2022-04-11 20:23:11 +00:00
67bef5017a Accepting request 965156 from home:coolo:branches:network:ldap
- Add _multibuild support to integrate the build of libldapcpp-devel
  to drop the outdated copy

OBS-URL: https://build.opensuse.org/request/show/965156
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=294
2022-03-30 10:18:15 +00:00
Michael Ströder
3c3f552ff2 update to 2.5.9
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=293
2021-10-25 22:49:48 +00:00
Michael Ströder
45462c64fa update to 2.5.8
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=292
2021-10-11 19:19:33 +00:00
Michael Ströder
02d24c9d35 Accepting request 914625 from home:phiwag:branches:network:ldap
Updated the changelog to mention removed patches, which is required for to pass the factory submission bot.

OBS-URL: https://build.opensuse.org/request/show/914625
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=291
2021-08-27 13:57:23 +00:00
Michael Ströder
18364f265d Accepting request 914040 from home:phiwag:branches:network:ldap
Since version 2.5.7 the update from the 2.4 release series to 2.5 has 
become easier: existing MDB databases can be upgraded (this was already 
the case before, but the documentation was slightly too cautious). 
Additionally, slapcat in version 2.5 can read databases from version 2.4, 
which wasn't possible in earlier 2.5 releases.

- Update to upstream version 2.5.7
	Fixed lloadd client state tracking (ITS#9624)
	Fixed slapd bconfig to canonicalize structuralObjectclass (ITS#9611)
	Fixed slapd-ldif duplicate controls response (ITS#9497)
	Fixed slapd-mdb multival crash when attribute is missing an equality matchingrule (ITS#9621)
	Fixed slapd-mdb compatibility with OpenLDAP 2.4 MDB databases (ITS#8958)
	Fixed slapd-mdb idlexp maximum size handling (ITS#9637)
	Fixed slapd-monitor number of ops executing with asynchronous backends (ITS#9628)
	Fixed slapd-sql to add support for ppolicy attributes (ITS#9629)
	Fixed slapd-sql to close transactions after bind and search (ITS#9630)
	Fixed slapo-accesslog to make reqMod optional (ITS#9569)
	Fixed slapo-ppolicy logging when pwdChangedTime attribute is not present (ITS#9625)
	Documentation
		slapd-mdb(5) note max idlexp size is 30, not 31 (ITS#9637)
		slapo-accesslog(5) note that reqMod is optional (ITS#9569)
		Add ldapvc(1) man page (ITS#9549)
		Add guide section on load balancer (ITS#9443)
		Updated guide to document multiprovider as replacement for mirrormode (ITS#9200)
		Updated guide to clarify slapd-mdb upgrade requirements (ITS#9200)
		Updated guide to document removal of deprecated options from client tools (ITS#9200)

- Major version update to 2.5.6
  See https://www.openldap.org/software/release/announce.html for a list of
  changes.
- The threaded version of the OpenLDAP libraries, libldap_r, has been merged
  with libldap with 2.5. Removed all related downstream changes.
  Introduce a new compatibility symlink in the other direction: libldap_r
  pointing to libldap.
- Removed the ppolicy-check-password module. It is unmaintained and does not
  build any more.

OBS-URL: https://build.opensuse.org/request/show/914040
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=290
2021-08-26 20:16:29 +00:00
Michael Ströder
2604d4bc2f Accepting request 897299 from home:stroeder:branches:network:ldap
updated to 2.4.59

OBS-URL: https://build.opensuse.org/request/show/897299
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=288
2021-06-04 04:59:48 +00:00
Michael Ströder
a3ffef5182 update to 2.4.58
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=286
2021-03-16 20:23:16 +00:00
Michael Ströder
25833921cb Accepting request 864145 from home:stroeder:branches:network:ldap
updated to 2.4.57

OBS-URL: https://build.opensuse.org/request/show/864145
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=284
2021-01-18 20:45:05 +00:00
Michael Ströder
63d2effee4 Accepting request 856589 from home:stroeder:branches:network:ldap
- added openldap2.keyring and source signature file

OBS-URL: https://build.opensuse.org/request/show/856589
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=282
2020-12-17 04:23:59 +00:00
Michael Ströder
c0e4cb715e updated to 2.4.56
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=280
2020-11-11 12:14:04 +00:00
Michael Ströder
617ae2b561 Accepting request 844183 from home:firstyear:branches:network:ldap
- bsc#1175568 CVE-2020-8027
  openldap_update_modules_path.sh has a number of issues in it's
  design that lead to security issues. This file has been removed,
  from the package, and the %post execution of the install. The
  function is replaced by /usr/sbin/slapd-ldif-update-crc and
  /usr/lib/openldap/fixup-modulepath, through the addition of the
  source files:
  * fixup-modulepath.sh
  * slapd-ldif-update-crc.sh
  * update-crc.sh

OBS-URL: https://build.opensuse.org/request/show/844183
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=278
2020-10-27 01:14:55 +00:00
Michael Ströder
fc56a37d6c Accepting request 844168 from home:stroeder:branches:network:ldap
updated to 2.4.55

OBS-URL: https://build.opensuse.org/request/show/844168
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=277
2020-10-26 22:33:07 +00:00
Michael Ströder
b2e21ad84a Accepting request 841354 from home:stroeder:branches:network:ldap
updated to 2.4.54

OBS-URL: https://build.opensuse.org/request/show/841354
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=275
2020-10-12 21:07:22 +00:00
Michael Ströder
4720dd0502 updated to 2.4.53
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=273
2020-09-07 16:10:19 +00:00
Michael Ströder
e281cb7dc3 Accepting request 830371 from home:stroeder:branches:network:ldap
updated to 2.4.52

OBS-URL: https://build.opensuse.org/request/show/830371
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=271
2020-08-28 23:04:13 +00:00
Michael Ströder
37de44c207 Accepting request 828345 from home:kukuk:container
- Switch from shadow to sysusers to generate ldap account
- Remove if's for code older than SLE12 (Even SLE12 builds no longer)
- Remove 12 years old sasl2 migration code

OBS-URL: https://build.opensuse.org/request/show/828345
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=270
2020-08-21 07:12:10 +00:00
Michael Ströder
4754d1883c Accepting request 826784 from home:kukuk:container
- Drop obsolete, not working DB_CONFIG
- Remove init.d header from start script, does not work
- Use bash for start script as syntax is not POSIX sh supported
- Remove UPDATE_NEEDED section in start script, does never match

OBS-URL: https://build.opensuse.org/request/show/826784
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=268
2020-08-15 07:05:10 +00:00
Michael Ströder
2e24332235 Accepting request 826780 from home:kukuk:container
- Remove remaining rc.status usage in start script

OBS-URL: https://build.opensuse.org/request/show/826780
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=267
2020-08-15 06:44:31 +00:00
Michael Ströder
06ccfa2bad Accepting request 825908 from home:stroeder:branches:network:ldap
updated to 2.4.51

OBS-URL: https://build.opensuse.org/request/show/825908
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=264
2020-08-12 07:12:45 +00:00
Michael Ströder
19b4b4470b Accepting request 812601 from home:gmbr3:branches:Base:System3
- Revert changes to libexecdir

OBS-URL: https://build.opensuse.org/request/show/812601
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=262
2020-06-08 13:44:06 +00:00
Michael Ströder
4cf5ab1af6 Accepting request 812208 from home:stroeder:network
- More .spec cleanups

OBS-URL: https://build.opensuse.org/request/show/812208
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=261
2020-06-07 13:53:40 +00:00
Michael Ströder
cb00a4da51 Accepting request 812105 from home:gmbr3:branches:Base:System3
- Fixes for %_libexecdir changing to /usr/libexec
- Spec file cleanups

OBS-URL: https://build.opensuse.org/request/show/812105
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=260
2020-06-07 09:35:33 +00:00
William Brown
7341d09271 Accepting request 800820 from home:stroeder:branches:network:ldap
- updated to 2.4.50
- added 0014-ITS-8650-fix-debug-usage.patch
- enabled new contrib overlay pw-argon2
- replaced FTP by HTTPS download URL for source
- removed 0009-Fix-ldap-host-lookup-ipv6.patch (see bsc#1171127)

OBS-URL: https://build.opensuse.org/request/show/800820
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=258
2020-05-07 03:10:47 +00:00
Michael Ströder
447aef3759 Accepting request 768939 from home:stroeder:branches:network:ldap
updated to 2.4.49

OBS-URL: https://build.opensuse.org/request/show/768939
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=256
2020-01-31 10:56:52 +00:00
Michael Ströder
fd6933af62 Accepting request 762856 from home:stroeder:branches:network:ldap
- added back-port patch
  0013_openldap-its9124_fix_crash_with_cancel_exop.patch
  to fix OpenLDAP ITS#9124

OBS-URL: https://build.opensuse.org/request/show/762856
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=254
2020-01-10 14:50:39 +00:00
Michael Ströder
f161b5a476 Accepting request 758863 from home:stroeder:branches:network:ldap
- use BuildRequires:  pkgconfig(krb5) instead of krb5-devel-mini

OBS-URL: https://build.opensuse.org/request/show/758863
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=252
2020-01-01 17:19:14 +00:00
Dominique Leuenberger
528152a73b Accepting request 720498 from home:marxin:static
Use FAT LTO objects in order to provide proper static library.

OBS-URL: https://build.opensuse.org/request/show/720498
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=250
2019-08-13 08:20:19 +00:00
Michael Ströder
d40995658b Accepting request 718551 from home:stroeder:branches:network:ldap
removal of SuSEfirewall2 service

OBS-URL: https://build.opensuse.org/request/show/718551
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=248
2019-07-25 12:57:50 +00:00
Michael Ströder
d549f863e2 Accepting request 718342 from home:stroeder:branches:network:ldap
- Update to upstream release 2.4.48 with security fixes:
  * CVE-2019-13057 (ITS#9038):
    rootdn of any db can assert any identity
  * CVE-2019-13565 (ITS#9052):
    Unauthorized access caused by incorrect handling of SASL SSF values
- Fix CVE-2017-17740 by disabling nops overlay not maintained by upstream
  (see also bsc#1073313, comment #36)
- Removed obsolete patches:
  * 0002-openldap-its8727-plug-ber-leaks.patch
  * 0017-Fix-segfault-in-nops.patch

Note that I disabled slapo-nops instead of rebasing 0017-Fix-segfault-in-nops.patch which is somewhat debatable. You can take it or leave it.

OBS-URL: https://build.opensuse.org/request/show/718342
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=247
2019-07-25 12:39:20 +00:00
Michael Ströder
d5a3162b1f Accepting request 702733 from home:firstyear:branches:network:ldap
- bsc#1111388 - incorrect post script call causes tmpfiles create not to
  be run.

OBS-URL: https://build.opensuse.org/request/show/702733
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=245
2019-05-14 04:53:20 +00:00
Michael Ströder
25c5cc719b OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=243 2019-03-10 11:48:41 +00:00
Michael Ströder
7268f02881 OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=241 2019-03-10 11:46:15 +00:00
5a150e84ac Accepting request 662829 from home:stroeder:branches:network:ldap
added back-ported fix for OpenLDAP ITS#8727

OBS-URL: https://build.opensuse.org/request/show/662829
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=238
2019-02-06 09:16:52 +00:00
Michael Ströder
55d82b1c0a Accepting request 660237 from home:stroeder:branches:network:ldap
Update to upstream release 2.4.47 (successfully tested on Tumbleweed x86_84)

OBS-URL: https://build.opensuse.org/request/show/660237
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=236
2018-12-20 11:37:17 +00:00
Michael Ströder
31984da890 Accepting request 651181 from home:jengelh:branches:network:ldap
- Replace old $RPM_* shell vars
and fix that silly build error about --no-as-needed

OBS-URL: https://build.opensuse.org/request/show/651181
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=234
2018-11-22 16:52:58 +00:00
Peter Varkoly
e604505058 - Fix CVE-2017-17740: when both the nops module and the memberof
overlay are enabled, attempts to free a buffer that was allocated
  on the stack
  * patch: 0017-Fix-segfault-in-nops.patch
  (bsc#1073313)

OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=233
2018-11-21 15:17:38 +00:00
Peter Varkoly
7fcf270ced - bsc#1095816 libldap package does not contain and provide libldap anymore
OBS-URL: https://build.opensuse.org/package/show/network:ldap/openldap2?expand=0&rev=232
2018-11-20 20:48:05 +00:00