Name Status Last Modified Last Commit
lp:debian/stretch/libpam-krb5 1 Development 2015-05-24 09:52:37 UTC
29. * Upload to unstable. * Refresh upstr...

Author: Russ Allbery
Revision Date: 2015-04-26 20:23:59 UTC

* Upload to unstable.
* Refresh upstream signing key.
* Add debian/gbp.conf reflecting the branch layout of the default
  packaging repository.

lp:debian/libpam-krb5 bug 1 Development 2015-04-26 20:23:59 UTC
29. * Upload to unstable. * Refresh upstr...

Author: Russ Allbery
Revision Date: 2015-04-26 20:23:59 UTC

* Upload to unstable.
* Refresh upstream signing key.
* Add debian/gbp.conf reflecting the branch layout of the default
  packaging repository.

lp:debian/experimental/libpam-krb5 1 Development 2014-12-26 10:20:17 UTC
29. * Upload to experimental due to relea...

Author: Russ Allbery
Revision Date: 2014-12-25 19:36:00 UTC

* Upload to experimental due to release freeze.
* New upstream release.
  - Add no_update_user option to disable the normal update of PAM_USER
    after user canonicalization.
  - Suppress spurious Heimdal password prompt when using PKINIT.
  - Map unknown realm errors to PAM_AUTHINFO_UNAVAIL.
  - Treat more error codes as incorrect passwords for better
    compatibility between MIT client libraries and Heimdal KDCs.
  - Add version number when module options were added to the man page.
* Remove erroneous branch information from Vcs-Git.
* Fix debian/copyright to match the correct upstream licensing.
* Update standards version to 3.9.6 (no changes required).

lp:debian/jessie/libpam-krb5 1 Development 2014-05-13 06:02:24 UTC
28. * Drop version qualifications on Buil...

Author: Russ Allbery
Revision Date: 2014-04-13 13:13:38 UTC

* Drop version qualifications on Build-Depends that are satisfied by
  stable. Drop version qualifications on Depends that are satisfied by
  oldstable.
* Add the upstream release signing key and verify it in debian/watch.
* Prefer *.tar.xz in debian/watch to match packaging.
* Convert debian/copyright to copyright-format 1.0.
* Specify the Debian packaging branch in the Vcs-Git control field.
* Update standards version to 3.9.5 (no changes required).

lp:debian/wheezy/libpam-krb5 1 Development 2012-06-02 19:20:27 UTC
26. * New upstream release. - New anon_...

Author: Russ Allbery
Revision Date: 2012-06-02 19:20:27 UTC

* New upstream release.
  - New anon_fast option to attempt anonymous authentication and use
    those credentials to provide FAST armor. (Closes: #626509)
  - New user_realm option to set the realm for unqualified user
    principals without changing the default realm for all other
    operations.
  - New no_prompt option to suppress PAM prompting in favor of letting
    the Kerberos library handle it. (Closes: #626506)
  - New silent option that duplicates the behavior of PAM_SILENT.
  - New trace option for preliminary support of Kerberos trace logging.
  - Fix the doubled colon in password prompts from Heimdal.
  - Preserve the realm of the authentication identity when forming an
    alt_auth_map identity.
  - Allow the alt_auth_map format to contain a realm to force all mapped
    principals to be in that realm.
  - Avoid a NULL pointer dereference if krb5_init_context fails.
    (LP: #998525)
  - Close memory leaks in search_k5login and alt_auth_map.
  - Suppress bogus error messages about the realm option.
  - Retry authentication under try_first_pass for several other error
    conditions.
* Regenerate the Autotools build system with dh-autoreconf.
* Add krb5-config to Build-Depends so that the test programs don't abort
  with errors about not having a Kerberos configuration.
* Switch to xz compression for the upstream and Debian tarballs.
* Enable parallel builds.
* Update standards version to 3.9.3 (no changes required).

lp:debian/squeeze/libpam-krb5 1 Development 2010-06-09 18:08:04 UTC
18. * New upstream release. - New fast_...

Author: Russ Allbery
Revision Date: 2010-06-09 18:08:04 UTC

* New upstream release.
  - New fast_ccache option, which if set attempts to use credentials in
    that ticket cache to protect the Kerberos authentication with FAST.
    Requires FAST support in the Kerberos libraries and hence only is
    available in libpam-krb5, not libpam-heimdal, for right now.
  - Fix error in freeing a previous alt_auth_map setting.
* Switch to 3.0 (quilt) source format. Force a single Debian patch and
  include a custom patch header explaining that it is a rollup of any
  fixes cherry-picked from upstream and breaking those patches out
  separately would be work for no gain.

lp:debian/lenny/libpam-krb5 1 Development 2009-07-03 15:48:39 UTC
9. * SECURITY (CVE-2009-0360): If invoke...

Author: Russ Allbery
Revision Date: 2009-01-29 15:42:10 UTC

* SECURITY (CVE-2009-0360): If invoked in a setuid context, ignore user
  environment variables that specify the local keytab and Kerberos
  configuration. Protects against a privilege escalation vulnerability.
* SECURITY (CVE-2009-0361): Protect against applications calling
  pam_setcred with PAM_REINITIALIZE_CREDS as root in a setuid context.
  This API call is designed to reinitialize an existing Kerberos ticket
  cache and therefore trusts the KRB5CCNAME environment variable, but in
  a setuid context, this may allow overwriting arbitrary files.

17 of 7 results