e5f49d0c42
- Remove build dependency doxygen, python-Cheetah, python-Sphinx, python-libxml2, python-lxml, most of which are python 2 programs. Consequently remove -doc subpackage. Users are encouraged to use online documentation. (bsc#1066461)
Howard Guo
2017-11-06 10:43:49 +00:00
45350c1e0c
- Set "rdns" and "dns_canonicalize_hostname" to false in krb5.conf in order to improve client security in handling service principle names. (bsc#1054028)
Howard Guo
2017-08-18 08:38:17 +00:00
17c6c6c5ee
- Prevent kadmind.service startup failure caused by absence of LDAP service. (bsc#903543)
Howard Guo
2017-08-11 09:12:41 +00:00
1d1e68ea09
- There is no change made about the package itself, this is only copying over some changelog texts from SLE package: - bug#918595 owned by varkoly@suse.com: VUL-0: CVE-2014-5355 krb5: denial of service in krb5_read_message - bug#912002 owned by varkoly@suse.com: VUL-0 CVE-2014-5352, CVE-2014-9421, CVE-2014-9422, CVE-2014-9423: krb5: Vulnerabilities in kadmind, libgssrpc, gss_process_context_token - bug#910458 owned by varkoly@suse.com: VUL-1 CVE-2014-5354: krb5: NULL pointer dereference when using keyless entries - bug#928978 owned by varkoly@suse.com: VUL-0 CVE-2015-2694: krb5: issues in OTP and PKINIT kdcpreauth modules leading to requires_preauth bypass - bug#910457 owned by varkoly@suse.com: VUL-1 CVE-2014-5353: krb5: NULL pointer dereference when using a ticket policy name as a password policy name - bug#991088 owned by hguo@suse.com: VUL-1 CVE-2016-3120: krb5: S4U2Self KDC crash when anon is restricted - bug#992853 owned by hguo@suse.com: krb5: bogus prerequires - [fate#320326](https://fate.suse.com/320326) - bug#982313 owned by pgajdos@suse.com: Doxygen unable to resolve reference from \cite
Howard Guo
2017-06-06 13:39:13 +00:00
f423fdf030
------------------------------------------------------------------ - Remove source file ccapi/common/win/OldCC/autolock.hxx that is not needed and does not carry an acceptable license. (bsc#968111) ------------------------------------------------------------------ - Remove source file ccapi/common/win/OldCC/autolock.hxx that is not needed and does not carry an acceptable license. (bsc#968111)
Howard Guo
2016-06-13 12:41:05 +00:00
7991a93622
- pre_checkin.sh aligned changes between krb5/krb5-mini - added krb5.keyring
Marcus Meissner2015-05-22 09:30:16 +00:00
8103840325
* Add client support for the Kerberos Cache Manager protocol. If the host * Add support for doing unlocked database dumps for the DB2 KDC back end, * krb5-1.7-doublelog.patch
Marcus Meissner2015-05-22 09:22:57 +00:00
e1506944cc
- buffer overrun in kadmind with LDAP backend CVE-2014-4345 (bnc#891082) krb5-1.12-CVE-2014-4345-buffer-overrun-in-kadmind-with-LDAP-backend.patch
Christian Kornacker
2014-08-11 11:01:01 +00:00
be8887f4d7
Accepting request 243586 from network
Stephan Kulow
2014-08-06 09:42:15 +00:00
f2e853070c
- Fix double-free in SPNEGO [CVE-2014-4343] (bnc#888697) krb5-1.12-CVE-2014-4343-Fix-double-free-in-SPNEGO.patch Fix null deref in SPNEGO acceptor [CVE-2014-4344] krb5-1.12-CVE-2014-4344-Fix-null-deref-in-SPNEGO-acceptor.patch
Christian Kornacker
2014-07-28 09:58:41 +00:00
ec41724c92
Accepting request 241736 from network
Stephan Kulow
2014-07-27 06:25:40 +00:00
3ac7b19a80
Accepting request 241590 from home:posophe:branches:network
Christian Kornacker
2014-07-21 12:42:45 +00:00
3f646c425e
- denial of service flaws when handling RFC 1964 tokens (bnc#886016) krb5-1.12-CVE-2014-4341-CVE-2014-4342.patch - start krb5kdc after slapd (bnc#886102) - obsolete krb5-plugin-preauth-pkinit-nss (bnc#881674) similar functionality is provided by krb5-plugin-preauth-pkinit
Christian Kornacker
2014-07-15 08:18:37 +00:00
76cd6119cf
Accepting request 222761 from network
Stephan Kulow
2014-02-19 10:39:16 +00:00
5f3b47a9fc
- don't deliver SysV init files to systemd distributions
Christian Kornacker
2014-02-18 17:40:34 +00:00
8dcb675a57
Accepting request 215374 from network
Stephan Kulow
2014-01-29 06:15:26 +00:00
869a682f2d
- update to version 1.12.1 * Make KDC log service principal names more consistently during some error conditions, instead of "<unknown server>" * Fix several bugs related to building AES-NI support on less common configurations * Fix several bugs related to keyring credential caches - upstream obsoletes: krb5-1.12-copy_context.patch krb5-1.12-enable-NX.patch krb5-1.12-pic-aes-ni.patch krb5-master-no-malloc0.patch krb5-master-ignore-empty-unnecessary-final-token.patch
Christian Kornacker
2014-01-21 15:06:23 +00:00
79d8b3686a
Accepting request 214093 from network
Stephan Kulow
2014-01-17 15:40:41 +00:00
673bd84f01
extended changelog for Factory
Christian Kornacker
2014-01-16 13:19:42 +00:00
03254981cb
Accepting request 213903 from home:ckornacker:branches:network
Michael Calmer2014-01-15 14:14:20 +00:00