Merge ~sergiodj/ubuntu/+source/openldap:merge-2.5.6-exp1 into ubuntu/+source/openldap:debian/experimental
- Git
- lp:~sergiodj/ubuntu/+source/openldap
- merge-2.5.6-exp1
- Merge into debian/experimental
Status: | Merged |
---|---|
Approved by: | Sergio Durigan Junior |
Approved revision: | 57499a903715d983fd2f2ce82f093ed6cbe7ea49 |
Merge reported by: | Bryce Harrington |
Merged at revision: | 57499a903715d983fd2f2ce82f093ed6cbe7ea49 |
Proposed branch: | ~sergiodj/ubuntu/+source/openldap:merge-2.5.6-exp1 |
Merge into: | ubuntu/+source/openldap:debian/experimental |
Diff against target: |
3376 lines (+3010/-3) 7 files modified
debian/apparmor-profile (+61/-0) debian/changelog (+2857/-0) debian/control (+4/-2) debian/rules (+17/-1) debian/slapd.README.Debian (+11/-0) debian/slapd.py (+51/-0) debian/slapd.ufw.profile (+9/-0) |
Related bugs: |
Reviewer | Review Type | Date Requested | Status |
---|---|---|---|
Canonical Server packageset reviewers | Pending | ||
Andreas Hasenack | Pending | ||
Canonical Server | Pending | ||
Review via email: mp+407279@code.launchpad.net |
Commit message
Description of the change
This is the merge of openldap 2.5.6+dfsg-1~exp1 from Debian experimental.
It is a relatively trivial merge; no patches have been dropped nor added to the Ubuntu package. Nevertheless, this is an important merge because it brings the new maint script code that is responsible to deal with scenarios where the upgrade from a 2.4.x version of openldap is not possible (most likely due to some old backends being removed in 2.5.x). This is something that Ryan (the Debian openldap maintainer) and I have been working for the last weeks. If you'd like more details, please refer to:
https:/
Another important addition here are the upgrade instructions written in the slapd.README.Debian file. These instructions are important because the user will most likely refer to them if the package upgrade fails. If you'd like more details, please refer to:
https:/
You can find a PPA with the proposed package here:
https:/
autopkgtest is still passing:
autopkgtest [15:09:19]: @@@@@@@
slapd PASS (superficial)
smbk5pwd PASS (superficial)
Sergio Durigan Junior (sergiodj) wrote : | # |
Bryce Harrington (bryce) wrote : | # |
This has migrated successfully.
- Source Package: openldap
- Current Version: 2.5.6+dfsg-
- New Version: 2.5.6+dfsg-
- Migrated: True
Preview Diff
1 | diff --git a/debian/apparmor-profile b/debian/apparmor-profile | |||
2 | 0 | new file mode 100644 | 0 | new file mode 100644 |
3 | index 0000000..6a247aa | |||
4 | --- /dev/null | |||
5 | +++ b/debian/apparmor-profile | |||
6 | @@ -0,0 +1,61 @@ | |||
7 | 1 | # vim:syntax=apparmor | ||
8 | 2 | # Last Modified: Fri Jun 6 13:51:00 2020 | ||
9 | 3 | # Author: Jamie Strandboge <jamie@ubuntu.com> | ||
10 | 4 | |||
11 | 5 | #include <tunables/global> | ||
12 | 6 | |||
13 | 7 | /usr/sbin/slapd { | ||
14 | 8 | #include <abstractions/base> | ||
15 | 9 | #include <abstractions/nameservice> | ||
16 | 10 | #include <abstractions/p11-kit> | ||
17 | 11 | |||
18 | 12 | #include <abstractions/ssl_keys> | ||
19 | 13 | #include <abstractions/ssl_certs> | ||
20 | 14 | |||
21 | 15 | /etc/sasldb2 r, | ||
22 | 16 | |||
23 | 17 | capability dac_override, | ||
24 | 18 | capability net_bind_service, | ||
25 | 19 | capability setgid, | ||
26 | 20 | capability setuid, | ||
27 | 21 | |||
28 | 22 | /etc/gai.conf r, | ||
29 | 23 | /etc/hosts.allow r, | ||
30 | 24 | /etc/hosts.deny r, | ||
31 | 25 | |||
32 | 26 | # ldap files | ||
33 | 27 | /etc/ldap/** kr, | ||
34 | 28 | /etc/ldap/slapd.d/** rw, | ||
35 | 29 | |||
36 | 30 | # kerberos/gssapi | ||
37 | 31 | /dev/tty rw, | ||
38 | 32 | /etc/gss/mech.d/ r, | ||
39 | 33 | /etc/gss/mech.d/* kr, | ||
40 | 34 | /etc/krb5.keytab kr, | ||
41 | 35 | /etc/krb5/user/*/client.keytab kr, | ||
42 | 36 | owner /tmp/krb5cc_* rwk, | ||
43 | 37 | owner /var/tmp/krb5_*.rcache2 rwk, | ||
44 | 38 | /var/tmp/ rw, | ||
45 | 39 | /var/tmp/** rw, | ||
46 | 40 | |||
47 | 41 | # the databases and logs | ||
48 | 42 | /var/lib/ldap/ r, | ||
49 | 43 | /var/lib/ldap/** rwk, | ||
50 | 44 | |||
51 | 45 | # lock file | ||
52 | 46 | /var/lib/ldap/alock kw, | ||
53 | 47 | |||
54 | 48 | # pid files and sockets | ||
55 | 49 | /{,var/}run/slapd/* w, | ||
56 | 50 | /{,var/}run/slapd/ldapi rw, | ||
57 | 51 | /{,var/}run/nslcd/socket rw, | ||
58 | 52 | /{,var/}run/saslauthd/mux rw, | ||
59 | 53 | |||
60 | 54 | /usr/lib/ldap/ r, | ||
61 | 55 | /usr/lib/ldap/* mr, | ||
62 | 56 | |||
63 | 57 | /usr/sbin/slapd mr, | ||
64 | 58 | |||
65 | 59 | # Site-specific additions and overrides. See local/README for details. | ||
66 | 60 | #include <local/usr.sbin.slapd> | ||
67 | 61 | } | ||
68 | diff --git a/debian/changelog b/debian/changelog | |||
69 | index 99e4a40..3507a62 100644 | |||
70 | --- a/debian/changelog | |||
71 | +++ b/debian/changelog | |||
72 | @@ -1,3 +1,22 @@ | |||
73 | 1 | openldap (2.5.6+dfsg-1~exp1ubuntu1) impish; urgency=medium | ||
74 | 2 | |||
75 | 3 | * Merge with Debian unstable. Remaining changes: | ||
76 | 4 | - Enable AppArmor support: | ||
77 | 5 | + d/apparmor-profile: add AppArmor profile | ||
78 | 6 | + d/rules: use dh_apparmor | ||
79 | 7 | + d/control: Build-Depends on dh-apparmor | ||
80 | 8 | + d/slapd.README.Debian: add note about AppArmor | ||
81 | 9 | - Enable ufw support: | ||
82 | 10 | + d/control: suggest ufw. | ||
83 | 11 | + d/rules: install ufw profile. | ||
84 | 12 | + d/slapd.ufw.profile: add ufw profile. | ||
85 | 13 | - d/{rules,slapd.py}: Add apport hook. | ||
86 | 14 | - d/rules: better regexp to match the Maintainer tag in d/control, | ||
87 | 15 | needed in the Ubuntu case because of XSBC-Original-Maintainer | ||
88 | 16 | (Closes #960448, LP #1875697) | ||
89 | 17 | |||
90 | 18 | -- Sergio Durigan Junior <sergio.durigan@canonical.com> Tue, 17 Aug 2021 14:06:00 -0400 | ||
91 | 19 | |||
92 | 1 | openldap (2.5.6+dfsg-1~exp1) experimental; urgency=medium | 20 | openldap (2.5.6+dfsg-1~exp1) experimental; urgency=medium |
93 | 2 | 21 | ||
94 | 3 | [ Ryan Tandy ] | 22 | [ Ryan Tandy ] |
95 | @@ -32,6 +51,59 @@ openldap (2.5.6+dfsg-1~exp1) experimental; urgency=medium | |||
96 | 32 | 51 | ||
97 | 33 | -- Ryan Tandy <ryan@nardis.ca> Mon, 16 Aug 2021 18:32:29 -0700 | 52 | -- Ryan Tandy <ryan@nardis.ca> Mon, 16 Aug 2021 18:32:29 -0700 |
98 | 34 | 53 | ||
99 | 54 | openldap (2.5.5+dfsg-1~exp1ubuntu1) impish; urgency=medium | ||
100 | 55 | |||
101 | 56 | * Merge with Debian unstable. Remaining changes: | ||
102 | 57 | - Enable AppArmor support: | ||
103 | 58 | + d/apparmor-profile: add AppArmor profile | ||
104 | 59 | + d/rules: use dh_apparmor | ||
105 | 60 | + d/control: Build-Depends on dh-apparmor | ||
106 | 61 | + d/slapd.README.Debian: add note about AppArmor | ||
107 | 62 | - Enable ufw support: | ||
108 | 63 | + d/control: suggest ufw. | ||
109 | 64 | + d/rules: install ufw profile. | ||
110 | 65 | + d/slapd.ufw.profile: add ufw profile. | ||
111 | 66 | - d/{rules,slapd.py}: Add apport hook. | ||
112 | 67 | - d/rules: better regexp to match the Maintainer tag in d/control, | ||
113 | 68 | needed in the Ubuntu case because of XSBC-Original-Maintainer | ||
114 | 69 | (Closes #960448, LP #1875697) | ||
115 | 70 | * Dropped changes: | ||
116 | 71 | - Enable GSSAPI support (first added in 2.4.18-0ubuntu2): | ||
117 | 72 | + d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
118 | 73 | - Add --with-gssapi support | ||
119 | 74 | - Make guess_service_principal() more robust when determining | ||
120 | 75 | principal | ||
121 | 76 | + d/configure.options: Configure with --with-gssapi | ||
122 | 77 | + d/control: Added heimdal-dev as a build depend | ||
123 | 78 | + d/rules: | ||
124 | 79 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
125 | 80 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
126 | 81 | + d/libldap-2.4-2.symbols: add symbols for GSSAPI support | ||
127 | 82 | This should be dropped when the soname changes. | ||
128 | 83 | [ Dropped as planned after soname bump due to 2.5.5 update. ] | ||
129 | 84 | - Enable nss overlay: | ||
130 | 85 | + d/rules: | ||
131 | 86 | - add nssov to CONTRIB_MODULES | ||
132 | 87 | - add sysconfdir to CONTRIB_MAKEVARS | ||
133 | 88 | + d/slapd.install: install nssov overlay | ||
134 | 89 | + d/slapd.manpages: install slapo-nssov(5) man page | ||
135 | 90 | + d/p/contrib-makefiles: given the change in 2.4.47+dfsg-3 regarding | ||
136 | 91 | Debian bug #919136, we also have to patch the nssov makefile | ||
137 | 92 | accordingly and thus update this patch. | ||
138 | 93 | [ Dropped as planned after soname bump due to 2.5.5 update. ] | ||
139 | 94 | - Add support for CLDAP (UDP) support, back then required by | ||
140 | 95 | likewise-open (first enabled in 2.4.17-1ubuntu2): | ||
141 | 96 | + d/rules: Enable -DLDAP_CONNECTIONLESS | ||
142 | 97 | + d/libldap-2.4-2.symbols: add symbols for CLDAP (UDP) | ||
143 | 98 | This should be dropped when the soname changes. | ||
144 | 99 | [ Dropped as planned after soname bump due to 2.5.5 update. ] | ||
145 | 100 | - debian/patches/fix_test_timing.patch: fix FTBFS on riscv64 because | ||
146 | 101 | of test timing issue. | ||
147 | 102 | [ Dropped because the latest update improved the testcase and | ||
148 | 103 | there is no FTBFS on riscv64 anymore. ] | ||
149 | 104 | |||
150 | 105 | -- Sergio Durigan Junior <sergio.durigan@canonical.com> Tue, 15 Jun 2021 17:20:34 -0400 | ||
151 | 106 | |||
152 | 35 | openldap (2.5.5+dfsg-1~exp1) experimental; urgency=medium | 107 | openldap (2.5.5+dfsg-1~exp1) experimental; urgency=medium |
153 | 36 | 108 | ||
154 | 37 | * New upstream release. | 109 | * New upstream release. |
155 | @@ -137,6 +209,53 @@ openldap (2.4.57+dfsg-3) unstable; urgency=medium | |||
156 | 137 | 209 | ||
157 | 138 | -- Ryan Tandy <ryan@nardis.ca> Sat, 15 May 2021 16:03:34 -0700 | 210 | -- Ryan Tandy <ryan@nardis.ca> Sat, 15 May 2021 16:03:34 -0700 |
158 | 139 | 211 | ||
159 | 212 | openldap (2.4.57+dfsg-2ubuntu1) hirsute; urgency=medium | ||
160 | 213 | |||
161 | 214 | * Merge with Debian unstable. Remaining changes: | ||
162 | 215 | - Enable AppArmor support: | ||
163 | 216 | + d/apparmor-profile: add AppArmor profile | ||
164 | 217 | + d/rules: use dh_apparmor | ||
165 | 218 | + d/control: Build-Depends on dh-apparmor | ||
166 | 219 | + d/slapd.README.Debian: add note about AppArmor | ||
167 | 220 | - Enable GSSAPI support (first added in 2.4.18-0ubuntu2): | ||
168 | 221 | + d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
169 | 222 | - Add --with-gssapi support | ||
170 | 223 | - Make guess_service_principal() more robust when determining | ||
171 | 224 | principal | ||
172 | 225 | + d/configure.options: Configure with --with-gssapi | ||
173 | 226 | + d/control: Added heimdal-dev as a build depend | ||
174 | 227 | + d/rules: | ||
175 | 228 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
176 | 229 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
177 | 230 | + d/libldap-2.4-2.symbols: add symbols for GSSAPI support | ||
178 | 231 | This should be dropped when the soname changes. | ||
179 | 232 | - Enable ufw support: | ||
180 | 233 | + d/control: suggest ufw. | ||
181 | 234 | + d/rules: install ufw profile. | ||
182 | 235 | + d/slapd.ufw.profile: add ufw profile. | ||
183 | 236 | - Enable nss overlay: | ||
184 | 237 | + d/rules: | ||
185 | 238 | - add nssov to CONTRIB_MODULES | ||
186 | 239 | - add sysconfdir to CONTRIB_MAKEVARS | ||
187 | 240 | + d/slapd.install: install nssov overlay | ||
188 | 241 | + d/slapd.manpages: install slapo-nssov(5) man page | ||
189 | 242 | + d/p/contrib-makefiles: given the change in 2.4.47+dfsg-3 regarding | ||
190 | 243 | Debian bug #919136, we also have to patch the nssov makefile | ||
191 | 244 | accordingly and thus update this patch. | ||
192 | 245 | - d/{rules,slapd.py}: Add apport hook. | ||
193 | 246 | - Add support for CLDAP (UDP) support, back then required by | ||
194 | 247 | likewise-open (first enabled in 2.4.17-1ubuntu2): | ||
195 | 248 | + d/rules: Enable -DLDAP_CONNECTIONLESS | ||
196 | 249 | + d/libldap-2.4-2.symbols: add symbols for CLDAP (UDP) | ||
197 | 250 | This should be dropped when the soname changes. | ||
198 | 251 | - debian/patches/fix_test_timing.patch: fix FTBFS on riscv64 because | ||
199 | 252 | of test timing issue. | ||
200 | 253 | - d/rules: better regexp to match the Maintainer tag in d/control, | ||
201 | 254 | needed in the Ubuntu case because of XSBC-Original-Maintainer | ||
202 | 255 | (Closes #960448, LP #1875697) | ||
203 | 256 | |||
204 | 257 | -- Marc Deslauriers <marc.deslauriers@ubuntu.com> Thu, 18 Feb 2021 10:15:38 -0500 | ||
205 | 258 | |||
206 | 140 | openldap (2.4.57+dfsg-2) unstable; urgency=medium | 259 | openldap (2.4.57+dfsg-2) unstable; urgency=medium |
207 | 141 | 260 | ||
208 | 142 | * Fix slapd assertion failure in Certificate List Exact Assertion validation | 261 | * Fix slapd assertion failure in Certificate List Exact Assertion validation |
209 | @@ -166,6 +285,65 @@ openldap (2.4.57+dfsg-1) unstable; urgency=medium | |||
210 | 166 | 285 | ||
211 | 167 | -- Ryan Tandy <ryan@nardis.ca> Sat, 23 Jan 2021 08:57:07 -0800 | 286 | -- Ryan Tandy <ryan@nardis.ca> Sat, 23 Jan 2021 08:57:07 -0800 |
212 | 168 | 287 | ||
213 | 288 | openldap (2.4.56+dfsg-1ubuntu2) hirsute; urgency=medium | ||
214 | 289 | |||
215 | 290 | * debian/apparmor-profile: add AppArmor rule for locking replay cache. | ||
216 | 291 | In Hirsute, a change (presumably in src:krb5) has caused slapd to be | ||
217 | 292 | denied by AppArmor for locking /var/tmp/krb5_*.rcache2. This is | ||
218 | 293 | acceptable, so add it to the AppArmor profile. This fixes the dep8 | ||
219 | 294 | test in src:krb5 that uses slapd for testing. | ||
220 | 295 | |||
221 | 296 | -- Robie Basak <robie.basak@ubuntu.com> Tue, 26 Jan 2021 13:02:40 +0000 | ||
222 | 297 | |||
223 | 298 | openldap (2.4.56+dfsg-1ubuntu1) hirsute; urgency=medium | ||
224 | 299 | |||
225 | 300 | * Merge with Debian unstable. Remaining changes: | ||
226 | 301 | - Enable AppArmor support: | ||
227 | 302 | + d/apparmor-profile: add AppArmor profile | ||
228 | 303 | + d/rules: use dh_apparmor | ||
229 | 304 | + d/control: Build-Depends on dh-apparmor | ||
230 | 305 | + d/slapd.README.Debian: add note about AppArmor | ||
231 | 306 | - Enable GSSAPI support (first added in 2.4.18-0ubuntu2): | ||
232 | 307 | + d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
233 | 308 | - Add --with-gssapi support | ||
234 | 309 | - Make guess_service_principal() more robust when determining | ||
235 | 310 | principal | ||
236 | 311 | + d/configure.options: Configure with --with-gssapi | ||
237 | 312 | + d/control: Added heimdal-dev as a build depend | ||
238 | 313 | + d/rules: | ||
239 | 314 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
240 | 315 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
241 | 316 | + d/libldap-2.4-2.symbols: add symbols for GSSAPI support | ||
242 | 317 | This should be dropped when the soname changes. | ||
243 | 318 | - Enable ufw support: | ||
244 | 319 | + d/control: suggest ufw. | ||
245 | 320 | + d/rules: install ufw profile. | ||
246 | 321 | + d/slapd.ufw.profile: add ufw profile. | ||
247 | 322 | - Enable nss overlay: | ||
248 | 323 | + d/rules: | ||
249 | 324 | - add nssov to CONTRIB_MODULES | ||
250 | 325 | - add sysconfdir to CONTRIB_MAKEVARS | ||
251 | 326 | + d/slapd.install: install nssov overlay | ||
252 | 327 | + d/slapd.manpages: install slapo-nssov(5) man page | ||
253 | 328 | + d/p/contrib-makefiles: given the change in 2.4.47+dfsg-3 regarding | ||
254 | 329 | Debian bug #919136, we also have to patch the nssov makefile | ||
255 | 330 | accordingly and thus update this patch. | ||
256 | 331 | - d/{rules,slapd.py}: Add apport hook. | ||
257 | 332 | - Add support for CLDAP (UDP) support, back then required by | ||
258 | 333 | likewise-open (first enabled in 2.4.17-1ubuntu2): | ||
259 | 334 | + d/rules: Enable -DLDAP_CONNECTIONLESS | ||
260 | 335 | + d/libldap-2.4-2.symbols: add symbols for CLDAP (UDP) | ||
261 | 336 | This should be dropped when the soname changes. | ||
262 | 337 | - debian/patches/fix_test_timing.patch: fix FTBFS on riscv64 because | ||
263 | 338 | of test timing issue. | ||
264 | 339 | - d/rules: better regexp to match the Maintainer tag in d/control, | ||
265 | 340 | needed in the Ubuntu case because of XSBC-Original-Maintainer | ||
266 | 341 | (Closes #960448, LP #1875697) | ||
267 | 342 | * d/apparmor-profile: use abstractions/ssl_keys instead of manual rules, | ||
268 | 343 | allows letsencrypt to work. Thanks to Paul McEnery (LP: #1909748) | ||
269 | 344 | |||
270 | 345 | -- Paride Legovini <paride.legovini@canonical.com> Mon, 04 Jan 2021 16:18:57 +0100 | ||
271 | 346 | |||
272 | 169 | openldap (2.4.56+dfsg-1) unstable; urgency=medium | 347 | openldap (2.4.56+dfsg-1) unstable; urgency=medium |
273 | 170 | 348 | ||
274 | 171 | * New upstream release. | 349 | * New upstream release. |
275 | @@ -192,12 +370,151 @@ openldap (2.4.54+dfsg-1) unstable; urgency=medium | |||
276 | 192 | 370 | ||
277 | 193 | -- Ryan Tandy <ryan@nardis.ca> Sun, 18 Oct 2020 16:03:46 +0000 | 371 | -- Ryan Tandy <ryan@nardis.ca> Sun, 18 Oct 2020 16:03:46 +0000 |
278 | 194 | 372 | ||
279 | 373 | openldap (2.4.53+dfsg-1ubuntu5) hirsute; urgency=medium | ||
280 | 374 | |||
281 | 375 | * SECURITY UPDATE: assertion failure in Certificate List syntax | ||
282 | 376 | validation | ||
283 | 377 | - debian/patches/CVE-2020-25709.patch: properly handle error in | ||
284 | 378 | servers/slapd/schema_init.c. | ||
285 | 379 | - CVE-2020-25709 | ||
286 | 380 | * SECURITY UPDATE: assertion failure in CSN normalization with invalid | ||
287 | 381 | input | ||
288 | 382 | - debian/patches/CVE-2020-25710.patch: properly handle error in | ||
289 | 383 | servers/slapd/schema_init.c. | ||
290 | 384 | - CVE-2020-25710 | ||
291 | 385 | |||
292 | 386 | -- Marc Deslauriers <marc.deslauriers@ubuntu.com> Tue, 17 Nov 2020 09:41:47 -0500 | ||
293 | 387 | |||
294 | 388 | openldap (2.4.53+dfsg-1ubuntu4) hirsute; urgency=medium | ||
295 | 389 | |||
296 | 390 | * SECURITY UPDATE: DoS via NULL pointer dereference | ||
297 | 391 | - debian/patches/CVE-2020-25692.patch: skip normalization if there's no | ||
298 | 392 | equality rule in servers/slapd/modrdn.c. | ||
299 | 393 | - CVE-2020-25692 | ||
300 | 394 | |||
301 | 395 | -- Marc Deslauriers <marc.deslauriers@ubuntu.com> Mon, 09 Nov 2020 14:02:02 -0500 | ||
302 | 396 | |||
303 | 397 | openldap (2.4.53+dfsg-1ubuntu3) hirsute; urgency=medium | ||
304 | 398 | |||
305 | 399 | * No-change rebuild for the perl update. | ||
306 | 400 | |||
307 | 401 | -- Matthias Klose <doko@ubuntu.com> Mon, 09 Nov 2020 12:53:38 +0100 | ||
308 | 402 | |||
309 | 403 | openldap (2.4.53+dfsg-1ubuntu2) hirsute; urgency=medium | ||
310 | 404 | |||
311 | 405 | * No-change rebuild for the perl update. | ||
312 | 406 | |||
313 | 407 | -- Matthias Klose <doko@ubuntu.com> Mon, 09 Nov 2020 10:51:32 +0100 | ||
314 | 408 | |||
315 | 409 | openldap (2.4.53+dfsg-1ubuntu1) groovy; urgency=medium | ||
316 | 410 | |||
317 | 411 | * Merge with Debian unstable (LP: #1894838). Remaining changes: | ||
318 | 412 | - Enable AppArmor support: | ||
319 | 413 | + d/apparmor-profile: add AppArmor profile | ||
320 | 414 | + d/rules: use dh_apparmor | ||
321 | 415 | + d/control: Build-Depends on dh-apparmor | ||
322 | 416 | + d/slapd.README.Debian: add note about AppArmor | ||
323 | 417 | - Enable GSSAPI support (first added in 2.4.18-0ubuntu2): | ||
324 | 418 | + d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
325 | 419 | - Add --with-gssapi support | ||
326 | 420 | - Make guess_service_principal() more robust when determining | ||
327 | 421 | principal | ||
328 | 422 | + d/configure.options: Configure with --with-gssapi | ||
329 | 423 | + d/control: Added heimdal-dev as a build depend | ||
330 | 424 | + d/rules: | ||
331 | 425 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
332 | 426 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
333 | 427 | + d/libldap-2.4-2.symbols: add symbols for GSSAPI support | ||
334 | 428 | This should be dropped when the soname changes. | ||
335 | 429 | - Enable ufw support: | ||
336 | 430 | + d/control: suggest ufw. | ||
337 | 431 | + d/rules: install ufw profile. | ||
338 | 432 | + d/slapd.ufw.profile: add ufw profile. | ||
339 | 433 | - Enable nss overlay: | ||
340 | 434 | + d/rules: | ||
341 | 435 | - add nssov to CONTRIB_MODULES | ||
342 | 436 | - add sysconfdir to CONTRIB_MAKEVARS | ||
343 | 437 | + d/slapd.install: install nssov overlay | ||
344 | 438 | + d/slapd.manpages: install slapo-nssov(5) man page | ||
345 | 439 | + d/p/contrib-makefiles: given the change in 2.4.47+dfsg-3 regarding | ||
346 | 440 | Debian bug #919136, we also have to patch the nssov makefile | ||
347 | 441 | accordingly and thus update this patch. | ||
348 | 442 | - d/{rules,slapd.py}: Add apport hook. | ||
349 | 443 | - Add support for CLDAP (UDP) support, back then required by | ||
350 | 444 | likewise-open (first enabled in 2.4.17-1ubuntu2): | ||
351 | 445 | + d/rules: Enable -DLDAP_CONNECTIONLESS | ||
352 | 446 | + d/libldap-2.4-2.symbols: add symbols for CLDAP (UDP) | ||
353 | 447 | This should be dropped when the soname changes. | ||
354 | 448 | - debian/patches/fix_test_timing.patch: fix FTBFS on riscv64 because | ||
355 | 449 | of test timing issue. | ||
356 | 450 | - d/rules: better regexp to match the Maintainer tag in d/control, | ||
357 | 451 | needed in the Ubuntu case because of XSBC-Original-Maintainer | ||
358 | 452 | (Closes #960448, LP #1875697) | ||
359 | 453 | |||
360 | 454 | -- Andreas Hasenack <andreas@canonical.com> Tue, 08 Sep 2020 09:36:58 -0300 | ||
361 | 455 | |||
362 | 195 | openldap (2.4.53+dfsg-1) unstable; urgency=medium | 456 | openldap (2.4.53+dfsg-1) unstable; urgency=medium |
363 | 196 | 457 | ||
364 | 197 | * New upstream release. | 458 | * New upstream release. |
365 | 198 | 459 | ||
366 | 199 | -- Ryan Tandy <ryan@nardis.ca> Mon, 07 Sep 2020 09:47:28 -0700 | 460 | -- Ryan Tandy <ryan@nardis.ca> Mon, 07 Sep 2020 09:47:28 -0700 |
367 | 200 | 461 | ||
368 | 462 | openldap (2.4.51+dfsg-1ubuntu1) groovy; urgency=medium | ||
369 | 463 | |||
370 | 464 | * Merge with Debian unstable. Remaining changes: | ||
371 | 465 | - Enable AppArmor support: | ||
372 | 466 | + d/apparmor-profile: add AppArmor profile | ||
373 | 467 | + d/rules: use dh_apparmor | ||
374 | 468 | + d/control: Build-Depends on dh-apparmor | ||
375 | 469 | + d/slapd.README.Debian: add note about AppArmor | ||
376 | 470 | - Enable GSSAPI support (first added in 2.4.18-0ubuntu2): | ||
377 | 471 | + d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
378 | 472 | - Add --with-gssapi support | ||
379 | 473 | - Make guess_service_principal() more robust when determining | ||
380 | 474 | principal | ||
381 | 475 | + d/configure.options: Configure with --with-gssapi | ||
382 | 476 | + d/control: Added heimdal-dev as a build depend | ||
383 | 477 | + d/rules: | ||
384 | 478 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
385 | 479 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
386 | 480 | + d/libldap-2.4-2.symbols: add symbols for GSSAPI support | ||
387 | 481 | This should be dropped when the soname changes. | ||
388 | 482 | - Enable ufw support: | ||
389 | 483 | + d/control: suggest ufw. | ||
390 | 484 | + d/rules: install ufw profile. | ||
391 | 485 | + d/slapd.ufw.profile: add ufw profile. | ||
392 | 486 | - Enable nss overlay: | ||
393 | 487 | + d/rules: | ||
394 | 488 | - add nssov to CONTRIB_MODULES | ||
395 | 489 | - add sysconfdir to CONTRIB_MAKEVARS | ||
396 | 490 | + d/slapd.install: install nssov overlay | ||
397 | 491 | + d/slapd.manpages: install slapo-nssov(5) man page | ||
398 | 492 | + d/p/contrib-makefiles: given the change in 2.4.47+dfsg-3 regarding | ||
399 | 493 | Debian bug #919136, we also have to patch the nssov makefile | ||
400 | 494 | accordingly and thus update this patch. | ||
401 | 495 | - d/{rules,slapd.py}: Add apport hook. | ||
402 | 496 | - Add support for CLDAP (UDP) support, back then required by | ||
403 | 497 | likewise-open (first enabled in 2.4.17-1ubuntu2): | ||
404 | 498 | + d/rules: Enable -DLDAP_CONNECTIONLESS | ||
405 | 499 | + d/libldap-2.4-2.symbols: add symbols for CLDAP (UDP) | ||
406 | 500 | This should be dropped when the soname changes. | ||
407 | 501 | - debian/patches/fix_test_timing.patch: fix FTBFS on riscv64 because | ||
408 | 502 | of test timing issue. | ||
409 | 503 | - d/rules: better regexp to match the Maintainer tag in d/control, | ||
410 | 504 | needed in the Ubuntu case because of XSBC-Original-Maintainer | ||
411 | 505 | (Closes #960448, LP #1875697) | ||
412 | 506 | * Dropped: | ||
413 | 507 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
414 | 508 | [In 2.4.51+dfsg-1] | ||
415 | 509 | - d/slapd.scripts-common: | ||
416 | 510 | + add slapcat_opts to local variables. | ||
417 | 511 | + Fix backup directory naming for multiple reconfiguration. | ||
418 | 512 | [In 2.4.51+dfsg-1] | ||
419 | 513 | - debian/patches/set-maintainer-name: our d/rules change needs to | ||
420 | 514 | be kept, but this patch is in 2.4.51+dfsg-1. | ||
421 | 515 | |||
422 | 516 | -- Andreas Hasenack <andreas@canonical.com> Wed, 26 Aug 2020 11:03:24 -0300 | ||
423 | 517 | |||
424 | 201 | openldap (2.4.51+dfsg-1) unstable; urgency=medium | 518 | openldap (2.4.51+dfsg-1) unstable; urgency=medium |
425 | 202 | 519 | ||
426 | 203 | * New upstream release. | 520 | * New upstream release. |
427 | @@ -243,6 +560,85 @@ openldap (2.4.51+dfsg-1) unstable; urgency=medium | |||
428 | 243 | 560 | ||
429 | 244 | -- Ryan Tandy <ryan@nardis.ca> Sun, 23 Aug 2020 11:09:57 -0700 | 561 | -- Ryan Tandy <ryan@nardis.ca> Sun, 23 Aug 2020 11:09:57 -0700 |
430 | 245 | 562 | ||
431 | 563 | openldap (2.4.50+dfsg-1ubuntu3) groovy; urgency=medium | ||
432 | 564 | |||
433 | 565 | * No change rebuild against new libnettle8 and libhogweed6 ABI. | ||
434 | 566 | |||
435 | 567 | -- Dimitri John Ledkov <xnox@ubuntu.com> Mon, 29 Jun 2020 22:31:30 +0100 | ||
436 | 568 | |||
437 | 569 | openldap (2.4.50+dfsg-1ubuntu2) groovy; urgency=medium | ||
438 | 570 | |||
439 | 571 | * d/apparmor-profile: Update apparmor profile to grant access to | ||
440 | 572 | the saslauthd socket, so that SASL authentication works. (LP: #1557157) | ||
441 | 573 | |||
442 | 574 | -- Sergio Durigan Junior <sergio.durigan@canonical.com> Fri, 12 Jun 2020 18:20:42 -0400 | ||
443 | 575 | |||
444 | 576 | openldap (2.4.50+dfsg-1ubuntu1) groovy; urgency=medium | ||
445 | 577 | |||
446 | 578 | * Merge with Debian unstable. Remaining changes: | ||
447 | 579 | - Enable AppArmor support: | ||
448 | 580 | + d/apparmor-profile: add AppArmor profile | ||
449 | 581 | + d/rules: use dh_apparmor | ||
450 | 582 | + d/control: Build-Depends on dh-apparmor | ||
451 | 583 | + d/slapd.README.Debian: add note about AppArmor | ||
452 | 584 | - Enable GSSAPI support (first added in 2.4.18-0ubuntu2): | ||
453 | 585 | + d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
454 | 586 | - Add --with-gssapi support | ||
455 | 587 | - Make guess_service_principal() more robust when determining | ||
456 | 588 | principal | ||
457 | 589 | + d/configure.options: Configure with --with-gssapi | ||
458 | 590 | + d/control: Added heimdal-dev as a build depend | ||
459 | 591 | + d/rules: | ||
460 | 592 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
461 | 593 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
462 | 594 | + d/libldap-2.4-2.symbols: add symbols for GSSAPI support | ||
463 | 595 | This should be dropped when the soname changes. | ||
464 | 596 | - Enable ufw support: | ||
465 | 597 | + d/control: suggest ufw. | ||
466 | 598 | + d/rules: install ufw profile. | ||
467 | 599 | + d/slapd.ufw.profile: add ufw profile. | ||
468 | 600 | - Enable nss overlay: | ||
469 | 601 | + d/rules: | ||
470 | 602 | - add nssov to CONTRIB_MODULES | ||
471 | 603 | - add sysconfdir to CONTRIB_MAKEVARS | ||
472 | 604 | + d/slapd.install: | ||
473 | 605 | - install nssov overlay | ||
474 | 606 | + d/slapd.manpages: | ||
475 | 607 | - install slapo-nssov(5) man page | ||
476 | 608 | + d/p/contrib-makefiles: given the change in 2.4.47+dfsg-3 regarding | ||
477 | 609 | Debian bug #919136, we also have to patch the nssov makefile | ||
478 | 610 | accordingly and thus update this patch. | ||
479 | 611 | - d/{rules,slapd.py}: Add apport hook. | ||
480 | 612 | - d/slapd.scripts-common: | ||
481 | 613 | + add slapcat_opts to local variables. | ||
482 | 614 | + Fix backup directory naming for multiple reconfiguration. | ||
483 | 615 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
484 | 616 | - Add support for CLDAP (UDP) support, back then required by | ||
485 | 617 | likewise-open (first enabled in 2.4.17-1ubuntu2): | ||
486 | 618 | + d/rules: Enable -DLDAP_CONNECTIONLESS | ||
487 | 619 | + d/libldap-2.4-2.symbols: add symbols for CLDAP (UDP) | ||
488 | 620 | This should be dropped when the soname changes. | ||
489 | 621 | - debian/patches/fix_test_timing.patch: fix FTBFS on riscv64 because | ||
490 | 622 | of test timing issue. | ||
491 | 623 | * Dropped: | ||
492 | 624 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
493 | 625 | either the default DIT nor via an Authn mapping. | ||
494 | 626 | [Not worth keeping a delta for, as having olcRootDN doesn't hurt] | ||
495 | 627 | - Show distribution in version: | ||
496 | 628 | - d/control: added lsb-release | ||
497 | 629 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
498 | 630 | [Debian now shows the full package version] | ||
499 | 631 | - SECURITY UPDATE: denial of service via nested search filters | ||
500 | 632 | + debian/patches/CVE-2020-12243.patch: limit depth of nested | ||
501 | 633 | filters in servers/slapd/filter.c. | ||
502 | 634 | [Fixed upstream] | ||
503 | 635 | * Added: | ||
504 | 636 | - d/rules, debian/patches/set-maintainer-name: Extract maintainer | ||
505 | 637 | address dynamically from debian/control. Thanks to Ryan Tandy | ||
506 | 638 | <ryan@nardis.ca> (Closes: #960448, LP: #1875697) | ||
507 | 639 | |||
508 | 640 | -- Andreas Hasenack <andreas@canonical.com> Mon, 01 Jun 2020 09:19:58 -0300 | ||
509 | 641 | |||
510 | 246 | openldap (2.4.50+dfsg-1) unstable; urgency=medium | 642 | openldap (2.4.50+dfsg-1) unstable; urgency=medium |
511 | 247 | 643 | ||
512 | 248 | * New upstream release. | 644 | * New upstream release. |
513 | @@ -285,6 +681,69 @@ openldap (2.4.49+dfsg-3) unstable; urgency=medium | |||
514 | 285 | 681 | ||
515 | 286 | -- Ryan Tandy <ryan@nardis.ca> Sat, 04 Apr 2020 10:43:56 -0700 | 682 | -- Ryan Tandy <ryan@nardis.ca> Sat, 04 Apr 2020 10:43:56 -0700 |
516 | 287 | 683 | ||
517 | 684 | openldap (2.4.49+dfsg-2ubuntu2) groovy; urgency=medium | ||
518 | 685 | |||
519 | 686 | * SECURITY UPDATE: denial of service via nested search filters | ||
520 | 687 | - debian/patches/CVE-2020-12243.patch: limit depth of nested filters in | ||
521 | 688 | servers/slapd/filter.c. | ||
522 | 689 | - debian/patches/fix_test_timing.patch: fix FTBFS on riscv64 because of | ||
523 | 690 | test timing issue. | ||
524 | 691 | - CVE-2020-12243 | ||
525 | 692 | |||
526 | 693 | -- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 01 May 2020 13:09:12 -0400 | ||
527 | 694 | |||
528 | 695 | openldap (2.4.49+dfsg-2ubuntu1) focal; urgency=medium | ||
529 | 696 | |||
530 | 697 | * Merge with Debian unstable (LP: #1866303). Remaining changes: | ||
531 | 698 | - Enable AppArmor support: | ||
532 | 699 | - d/apparmor-profile: add AppArmor profile | ||
533 | 700 | - d/rules: use dh_apparmor | ||
534 | 701 | - d/control: Build-Depends on dh-apparmor | ||
535 | 702 | - d/slapd.README.Debian: add note about AppArmor | ||
536 | 703 | - Enable GSSAPI support: | ||
537 | 704 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
538 | 705 | - Add --with-gssapi support | ||
539 | 706 | - Make guess_service_principal() more robust when determining | ||
540 | 707 | principal | ||
541 | 708 | [Dropped the ldap_gssapi_bind_s() hunk as that is already | ||
542 | 709 | - d/configure.options: Configure with --with-gssapi | ||
543 | 710 | - d/control: Added heimdal-dev as a build depend | ||
544 | 711 | - d/rules: | ||
545 | 712 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
546 | 713 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
547 | 714 | - Enable ufw support: | ||
548 | 715 | - d/control: suggest ufw. | ||
549 | 716 | - d/rules: install ufw profile. | ||
550 | 717 | - d/slapd.ufw.profile: add ufw profile. | ||
551 | 718 | - Enable nss overlay: | ||
552 | 719 | - d/rules: | ||
553 | 720 | - add nssov to CONTRIB_MODULES | ||
554 | 721 | - add sysconfdir to CONTRIB_MAKEVARS | ||
555 | 722 | - d/slapd.install: | ||
556 | 723 | - install nssov overlay | ||
557 | 724 | - d/slapd.manpages: | ||
558 | 725 | - install slapo-nssov(5) man page | ||
559 | 726 | - d/{rules,slapd.py}: Add apport hook. | ||
560 | 727 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
561 | 728 | either the default DIT nor via an Authn mapping. | ||
562 | 729 | - d/slapd.scripts-common: | ||
563 | 730 | - add slapcat_opts to local variables. | ||
564 | 731 | - Fix backup directory naming for multiple reconfiguration. | ||
565 | 732 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
566 | 733 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
567 | 734 | in the openldap library, as required by Likewise-Open | ||
568 | 735 | - Show distribution in version: | ||
569 | 736 | - d/control: added lsb-release | ||
570 | 737 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
571 | 738 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
572 | 739 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
573 | 740 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
574 | 741 | - d/p/contrib-makefiles: given the change in 2.4.47+dfsg-3 regarding | ||
575 | 742 | Debian bug #919136, we also have to patch the nssov makefile | ||
576 | 743 | accordingly and thus update this patch. | ||
577 | 744 | |||
578 | 745 | -- Andreas Hasenack <andreas@canonical.com> Fri, 06 Mar 2020 11:39:12 -0300 | ||
579 | 746 | |||
580 | 288 | openldap (2.4.49+dfsg-2) unstable; urgency=medium | 747 | openldap (2.4.49+dfsg-2) unstable; urgency=medium |
581 | 289 | 748 | ||
582 | 290 | * slapd.README.Debian: Document the initial setup performed by slapd's | 749 | * slapd.README.Debian: Document the initial setup performed by slapd's |
583 | @@ -296,6 +755,62 @@ openldap (2.4.49+dfsg-2) unstable; urgency=medium | |||
584 | 296 | 755 | ||
585 | 297 | -- Ryan Tandy <ryan@nardis.ca> Thu, 05 Mar 2020 12:59:46 -0800 | 756 | -- Ryan Tandy <ryan@nardis.ca> Thu, 05 Mar 2020 12:59:46 -0800 |
586 | 298 | 757 | ||
587 | 758 | openldap (2.4.49+dfsg-1ubuntu1) focal; urgency=medium | ||
588 | 759 | |||
589 | 760 | * Merge with Debian unstable. Remaining changes: | ||
590 | 761 | - Enable AppArmor support: | ||
591 | 762 | - d/apparmor-profile: add AppArmor profile | ||
592 | 763 | - d/rules: use dh_apparmor | ||
593 | 764 | - d/control: Build-Depends on dh-apparmor | ||
594 | 765 | - d/slapd.README.Debian: add note about AppArmor | ||
595 | 766 | - Enable GSSAPI support: | ||
596 | 767 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
597 | 768 | - Add --with-gssapi support | ||
598 | 769 | - Make guess_service_principal() more robust when determining | ||
599 | 770 | principal | ||
600 | 771 | [Dropped the ldap_gssapi_bind_s() hunk as that is already | ||
601 | 772 | - d/configure.options: Configure with --with-gssapi | ||
602 | 773 | - d/control: Added heimdal-dev as a build depend | ||
603 | 774 | - d/rules: | ||
604 | 775 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
605 | 776 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
606 | 777 | - Enable ufw support: | ||
607 | 778 | - d/control: suggest ufw. | ||
608 | 779 | - d/rules: install ufw profile. | ||
609 | 780 | - d/slapd.ufw.profile: add ufw profile. | ||
610 | 781 | - Enable nss overlay: | ||
611 | 782 | - d/rules: | ||
612 | 783 | - add nssov to CONTRIB_MODULES | ||
613 | 784 | - add sysconfdir to CONTRIB_MAKEVARS | ||
614 | 785 | - d/slapd.install: | ||
615 | 786 | - install nssov overlay | ||
616 | 787 | - d/slapd.manpages: | ||
617 | 788 | - install slapo-nssov(5) man page | ||
618 | 789 | - d/{rules,slapd.py}: Add apport hook. | ||
619 | 790 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
620 | 791 | either the default DIT nor via an Authn mapping. | ||
621 | 792 | - d/slapd.scripts-common: | ||
622 | 793 | - add slapcat_opts to local variables. | ||
623 | 794 | - Fix backup directory naming for multiple reconfiguration. | ||
624 | 795 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
625 | 796 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
626 | 797 | in the openldap library, as required by Likewise-Open | ||
627 | 798 | - Show distribution in version: | ||
628 | 799 | - d/control: added lsb-release | ||
629 | 800 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
630 | 801 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
631 | 802 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
632 | 803 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
633 | 804 | - d/p/contrib-makefiles: given the change in 2.4.47+dfsg-3 regarding | ||
634 | 805 | Debian bug #919136, we also have to patch the nssov makefile | ||
635 | 806 | accordingly and thus update this patch. | ||
636 | 807 | * Dropped: | ||
637 | 808 | - d/control: slapd can depend on perl:any since it only uses perl for | ||
638 | 809 | some maintainer and helper scripts. | ||
639 | 810 | [In 2.4.49+dfsg-1] | ||
640 | 811 | |||
641 | 812 | -- Andreas Hasenack <andreas@canonical.com> Mon, 10 Feb 2020 12:13:47 -0300 | ||
642 | 813 | |||
643 | 299 | openldap (2.4.49+dfsg-1) unstable; urgency=medium | 814 | openldap (2.4.49+dfsg-1) unstable; urgency=medium |
644 | 300 | 815 | ||
645 | 301 | * New upstream release. | 816 | * New upstream release. |
646 | @@ -324,6 +839,102 @@ openldap (2.4.49+dfsg-1) unstable; urgency=medium | |||
647 | 324 | 839 | ||
648 | 325 | -- Ryan Tandy <ryan@nardis.ca> Thu, 06 Feb 2020 10:08:12 -0800 | 840 | -- Ryan Tandy <ryan@nardis.ca> Thu, 06 Feb 2020 10:08:12 -0800 |
649 | 326 | 841 | ||
650 | 842 | openldap (2.4.48+dfsg-1ubuntu4) focal; urgency=medium | ||
651 | 843 | |||
652 | 844 | * d/control: slapd can depend on perl:any since it only uses perl for | ||
653 | 845 | some maintainer and helper scripts. The perl backend links against | ||
654 | 846 | the correct architecture perl libraries already. Can be dropped | ||
655 | 847 | after https://salsa.debian.org/openldap-team/openldap/commit/794c736 | ||
656 | 848 | is in a Debian upload. | ||
657 | 849 | |||
658 | 850 | -- Andreas Hasenack <andreas@canonical.com> Mon, 06 Jan 2020 16:46:11 -0300 | ||
659 | 851 | |||
660 | 852 | openldap (2.4.48+dfsg-1ubuntu3) focal; urgency=medium | ||
661 | 853 | |||
662 | 854 | * No-change rebuild against libnettle7 | ||
663 | 855 | |||
664 | 856 | -- Steve Langasek <steve.langasek@ubuntu.com> Thu, 31 Oct 2019 22:13:44 +0000 | ||
665 | 857 | |||
666 | 858 | openldap (2.4.48+dfsg-1ubuntu2) focal; urgency=medium | ||
667 | 859 | |||
668 | 860 | * No-change rebuild for the perl update. | ||
669 | 861 | |||
670 | 862 | -- Matthias Klose <doko@ubuntu.com> Fri, 18 Oct 2019 19:37:23 +0000 | ||
671 | 863 | |||
672 | 864 | openldap (2.4.48+dfsg-1ubuntu1) eoan; urgency=medium | ||
673 | 865 | |||
674 | 866 | * Merge with Debian unstable. Remaining changes: | ||
675 | 867 | - Enable AppArmor support: | ||
676 | 868 | - d/apparmor-profile: add AppArmor profile | ||
677 | 869 | - d/rules: use dh_apparmor | ||
678 | 870 | - d/control: Build-Depends on dh-apparmor | ||
679 | 871 | - d/slapd.README.Debian: add note about AppArmor | ||
680 | 872 | - Enable GSSAPI support: | ||
681 | 873 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
682 | 874 | - Add --with-gssapi support | ||
683 | 875 | - Make guess_service_principal() more robust when determining | ||
684 | 876 | principal | ||
685 | 877 | - d/configure.options: Configure with --with-gssapi | ||
686 | 878 | - d/control: Added heimdal-dev as a build depend | ||
687 | 879 | - d/rules: | ||
688 | 880 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
689 | 881 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
690 | 882 | - Enable ufw support: | ||
691 | 883 | - d/control: suggest ufw. | ||
692 | 884 | - d/rules: install ufw profile. | ||
693 | 885 | - d/slapd.ufw.profile: add ufw profile. | ||
694 | 886 | - Enable nss overlay: | ||
695 | 887 | - d/rules: | ||
696 | 888 | - add nssov to CONTRIB_MODULES | ||
697 | 889 | - add sysconfdir to CONTRIB_MAKEVARS | ||
698 | 890 | - d/slapd.install: | ||
699 | 891 | - install nssov overlay | ||
700 | 892 | - d/slapd.manpages: | ||
701 | 893 | - install slapo-nssov(5) man page | ||
702 | 894 | - d/{rules,slapd.py}: Add apport hook. | ||
703 | 895 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
704 | 896 | either the default DIT nor via an Authn mapping. | ||
705 | 897 | - d/slapd.scripts-common: | ||
706 | 898 | - add slapcat_opts to local variables. | ||
707 | 899 | - Fix backup directory naming for multiple reconfiguration. | ||
708 | 900 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
709 | 901 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
710 | 902 | in the openldap library, as required by Likewise-Open | ||
711 | 903 | - Show distribution in version: | ||
712 | 904 | - d/control: added lsb-release | ||
713 | 905 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
714 | 906 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
715 | 907 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
716 | 908 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
717 | 909 | - d/p/contrib-makefiles: given the change in 2.4.47+dfsg-3 regarding | ||
718 | 910 | Debian bug #919136, we also have to patch the nssov makefile | ||
719 | 911 | accordingly and thus update this patch. | ||
720 | 912 | * Dropped: | ||
721 | 913 | - Fix sysv-generator unit file by customizing parameters (LP #1821343) | ||
722 | 914 | + d/slapd-remain-after-exit.conf: Override RemainAfterExit to allow | ||
723 | 915 | correct systemctl status for slapd daemon. | ||
724 | 916 | + d/slapd.install: place override file in correct location. | ||
725 | 917 | [Included in 2.4.48+dfsg-1] | ||
726 | 918 | - SECURITY UPDATE: rootDN proxyauthz not restricted to its own databases | ||
727 | 919 | + debian/patches/CVE-2019-13057-1.patch: add restriction to | ||
728 | 920 | servers/slapd/saslauthz.c. | ||
729 | 921 | + debian/patches/CVE-2019-13057-2.patch: add tests to | ||
730 | 922 | tests/data/idassert.out, tests/data/slapd-idassert.conf, | ||
731 | 923 | tests/data/test-idassert1.ldif, tests/scripts/test028-idassert. | ||
732 | 924 | + debian/patches/CVE-2019-13057-3.patch: fix typo in | ||
733 | 925 | tests/scripts/test028-idassert. | ||
734 | 926 | + debian/patches/CVE-2019-13057-4.patch: fix typo in | ||
735 | 927 | tests/scripts/test028-idassert. | ||
736 | 928 | + CVE-2019-13057 | ||
737 | 929 | [Fixed upstream] | ||
738 | 930 | - SECURITY UPDATE: SASL SSF not initialized per connection | ||
739 | 931 | + debian/patches/CVE-2019-13565.patch: zero out sasl_ssf in | ||
740 | 932 | connection_init in servers/slapd/connection.c. | ||
741 | 933 | + CVE-2019-13565 | ||
742 | 934 | [Fixed upstream] | ||
743 | 935 | |||
744 | 936 | -- Andreas Hasenack <andreas@canonical.com> Wed, 31 Jul 2019 18:01:14 -0300 | ||
745 | 937 | |||
746 | 327 | openldap (2.4.48+dfsg-1) unstable; urgency=medium | 938 | openldap (2.4.48+dfsg-1) unstable; urgency=medium |
747 | 328 | 939 | ||
748 | 329 | * New upstream release. | 940 | * New upstream release. |
749 | @@ -351,6 +962,87 @@ openldap (2.4.48+dfsg-1) unstable; urgency=medium | |||
750 | 351 | 962 | ||
751 | 352 | -- Ryan Tandy <ryan@nardis.ca> Thu, 25 Jul 2019 08:32:00 -0700 | 963 | -- Ryan Tandy <ryan@nardis.ca> Thu, 25 Jul 2019 08:32:00 -0700 |
752 | 353 | 964 | ||
753 | 965 | openldap (2.4.47+dfsg-3ubuntu3) eoan; urgency=medium | ||
754 | 966 | |||
755 | 967 | * SECURITY UPDATE: rootDN proxyauthz not restricted to its own databases | ||
756 | 968 | - debian/patches/CVE-2019-13057-1.patch: add restriction to | ||
757 | 969 | servers/slapd/saslauthz.c. | ||
758 | 970 | - debian/patches/CVE-2019-13057-2.patch: add tests to | ||
759 | 971 | tests/data/idassert.out, tests/data/slapd-idassert.conf, | ||
760 | 972 | tests/data/test-idassert1.ldif, tests/scripts/test028-idassert. | ||
761 | 973 | - debian/patches/CVE-2019-13057-3.patch: fix typo in | ||
762 | 974 | tests/scripts/test028-idassert. | ||
763 | 975 | - debian/patches/CVE-2019-13057-4.patch: fix typo in | ||
764 | 976 | tests/scripts/test028-idassert. | ||
765 | 977 | - CVE-2019-13057 | ||
766 | 978 | * SECURITY UPDATE: SASL SSF not initialized per connection | ||
767 | 979 | - debian/patches/CVE-2019-13565.patch: zero out sasl_ssf in | ||
768 | 980 | connection_init in servers/slapd/connection.c. | ||
769 | 981 | - CVE-2019-13565 | ||
770 | 982 | |||
771 | 983 | -- Marc Deslauriers <marc.deslauriers@ubuntu.com> Fri, 26 Jul 2019 13:21:00 -0400 | ||
772 | 984 | |||
773 | 985 | openldap (2.4.47+dfsg-3ubuntu2) disco; urgency=medium | ||
774 | 986 | |||
775 | 987 | * Fix sysv-generator unit file by customizing parameters (LP: #1821343) | ||
776 | 988 | - d/slapd-remain-after-exit.conf: Override RemainAfterExit to allow | ||
777 | 989 | correct systemctl status for slapd daemon. | ||
778 | 990 | - d/slapd.install: place override file in correct location. | ||
779 | 991 | |||
780 | 992 | -- Heitor Alves de Siqueira <halves@canonical.com> Mon, 08 Apr 2019 12:39:12 -0300 | ||
781 | 993 | |||
782 | 994 | openldap (2.4.47+dfsg-3ubuntu1) disco; urgency=medium | ||
783 | 995 | |||
784 | 996 | * Merge with Debian unstable. Remaining changes: | ||
785 | 997 | - Enable AppArmor support: | ||
786 | 998 | - d/apparmor-profile: add AppArmor profile | ||
787 | 999 | - d/rules: use dh_apparmor | ||
788 | 1000 | - d/control: Build-Depends on dh-apparmor | ||
789 | 1001 | - d/slapd.README.Debian: add note about AppArmor | ||
790 | 1002 | - Enable GSSAPI support: | ||
791 | 1003 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
792 | 1004 | - Add --with-gssapi support | ||
793 | 1005 | - Make guess_service_principal() more robust when determining | ||
794 | 1006 | principal | ||
795 | 1007 | - d/configure.options: Configure with --with-gssapi | ||
796 | 1008 | - d/control: Added heimdal-dev as a build depend | ||
797 | 1009 | - d/rules: | ||
798 | 1010 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
799 | 1011 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
800 | 1012 | - Enable ufw support: | ||
801 | 1013 | - d/control: suggest ufw. | ||
802 | 1014 | - d/rules: install ufw profile. | ||
803 | 1015 | - d/slapd.ufw.profile: add ufw profile. | ||
804 | 1016 | - Enable nss overlay: | ||
805 | 1017 | - d/rules: | ||
806 | 1018 | - add nssov to CONTRIB_MODULES | ||
807 | 1019 | - add sysconfdir to CONTRIB_MAKEVARS | ||
808 | 1020 | - d/slapd.install: | ||
809 | 1021 | - install nssov overlay | ||
810 | 1022 | - d/slapd.manpages: | ||
811 | 1023 | - install slapo-nssov(5) man page | ||
812 | 1024 | - d/{rules,slapd.py}: Add apport hook. | ||
813 | 1025 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
814 | 1026 | either the default DIT nor via an Authn mapping. | ||
815 | 1027 | - d/slapd.scripts-common: | ||
816 | 1028 | - add slapcat_opts to local variables. | ||
817 | 1029 | - Fix backup directory naming for multiple reconfiguration. | ||
818 | 1030 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
819 | 1031 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
820 | 1032 | in the openldap library, as required by Likewise-Open | ||
821 | 1033 | - Show distribution in version: | ||
822 | 1034 | - d/control: added lsb-release | ||
823 | 1035 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
824 | 1036 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
825 | 1037 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
826 | 1038 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
827 | 1039 | * Added changes: | ||
828 | 1040 | - d/p/contrib-makefiles: given the change in 2.4.47+dfsg-3 regarding | ||
829 | 1041 | Debian bug #919136, we also have to patch the nssov makefile | ||
830 | 1042 | accordingly and thus update this patch. | ||
831 | 1043 | |||
832 | 1044 | -- Andreas Hasenack <andreas@canonical.com> Mon, 11 Feb 2019 09:20:47 -0200 | ||
833 | 1045 | |||
834 | 354 | openldap (2.4.47+dfsg-3) unstable; urgency=medium | 1046 | openldap (2.4.47+dfsg-3) unstable; urgency=medium |
835 | 355 | 1047 | ||
836 | 356 | * Restore patches to contrib Makefiles to set CFLAGS, CPPFLAGS, and LDFLAGS | 1048 | * Restore patches to contrib Makefiles to set CFLAGS, CPPFLAGS, and LDFLAGS |
837 | @@ -366,6 +1058,63 @@ openldap (2.4.47+dfsg-3) unstable; urgency=medium | |||
838 | 366 | 1058 | ||
839 | 367 | -- Ryan Tandy <ryan@nardis.ca> Sat, 02 Feb 2019 10:30:10 -0800 | 1059 | -- Ryan Tandy <ryan@nardis.ca> Sat, 02 Feb 2019 10:30:10 -0800 |
840 | 368 | 1060 | ||
841 | 1061 | openldap (2.4.47+dfsg-2ubuntu1) disco; urgency=medium | ||
842 | 1062 | |||
843 | 1063 | * Merge from Debian unstable (LP: #1811630). Remaining changes: | ||
844 | 1064 | - Enable AppArmor support: | ||
845 | 1065 | - d/apparmor-profile: add AppArmor profile | ||
846 | 1066 | - d/rules: use dh_apparmor | ||
847 | 1067 | - d/control: Build-Depends on dh-apparmor | ||
848 | 1068 | - d/slapd.README.Debian: add note about AppArmor | ||
849 | 1069 | - Enable GSSAPI support: | ||
850 | 1070 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
851 | 1071 | - Add --with-gssapi support | ||
852 | 1072 | - Make guess_service_principal() more robust when determining | ||
853 | 1073 | principal | ||
854 | 1074 | - d/configure.options: Configure with --with-gssapi | ||
855 | 1075 | - d/control: Added heimdal-dev as a build depend | ||
856 | 1076 | - d/rules: | ||
857 | 1077 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
858 | 1078 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
859 | 1079 | - Enable ufw support: | ||
860 | 1080 | - d/control: suggest ufw. | ||
861 | 1081 | - d/rules: install ufw profile. | ||
862 | 1082 | - d/slapd.ufw.profile: add ufw profile. | ||
863 | 1083 | - Enable nss overlay: | ||
864 | 1084 | - d/rules: | ||
865 | 1085 | - add nssov to CONTRIB_MODULES | ||
866 | 1086 | - add sysconfdir to CONTRIB_MAKEVARS | ||
867 | 1087 | - d/slapd.install: | ||
868 | 1088 | - install nssov overlay | ||
869 | 1089 | - d/slapd.manpages: | ||
870 | 1090 | - install slapo-nssov(5) man page | ||
871 | 1091 | - d/{rules,slapd.py}: Add apport hook. | ||
872 | 1092 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
873 | 1093 | either the default DIT nor via an Authn mapping. | ||
874 | 1094 | - d/slapd.scripts-common: | ||
875 | 1095 | - add slapcat_opts to local variables. | ||
876 | 1096 | - Fix backup directory naming for multiple reconfiguration. | ||
877 | 1097 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
878 | 1098 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
879 | 1099 | in the openldap library, as required by Likewise-Open | ||
880 | 1100 | - Show distribution in version: | ||
881 | 1101 | - d/control: added lsb-release | ||
882 | 1102 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
883 | 1103 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
884 | 1104 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
885 | 1105 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
886 | 1106 | * Update nssov build and packaging for Debian changes: | ||
887 | 1107 | - Drop patch nssov-build | ||
888 | 1108 | - d/rules: | ||
889 | 1109 | - add nssov to CONTRIB_MODULES | ||
890 | 1110 | - add sysconfdir to CONTRIB_MAKEVARS | ||
891 | 1111 | - d/slapd.install: | ||
892 | 1112 | - install nssov overlay | ||
893 | 1113 | - d/slapd.manpages: | ||
894 | 1114 | - install slapo-nssov(5) man page | ||
895 | 1115 | |||
896 | 1116 | -- Ryan Tandy <ryan@nardis.ca> Sun, 13 Jan 2019 04:47:09 +0000 | ||
897 | 1117 | |||
898 | 369 | openldap (2.4.47+dfsg-2) unstable; urgency=medium | 1118 | openldap (2.4.47+dfsg-2) unstable; urgency=medium |
899 | 370 | 1119 | ||
900 | 371 | * Reintroduce slapi-dev binary package. (Closes: #711469) | 1120 | * Reintroduce slapi-dev binary package. (Closes: #711469) |
901 | @@ -403,6 +1152,63 @@ openldap (2.4.47+dfsg-1) unstable; urgency=medium | |||
902 | 403 | 1152 | ||
903 | 404 | -- Ryan Tandy <ryan@nardis.ca> Sun, 23 Dec 2018 12:50:40 -0800 | 1153 | -- Ryan Tandy <ryan@nardis.ca> Sun, 23 Dec 2018 12:50:40 -0800 |
904 | 405 | 1154 | ||
905 | 1155 | openldap (2.4.46+dfsg-5ubuntu3) disco; urgency=medium | ||
906 | 1156 | |||
907 | 1157 | * d/apparmor-profile: update apparmor profile to allow reading of | ||
908 | 1158 | files needed when slapd is behaving as a kerberos/gssapi client | ||
909 | 1159 | and acquiring its own ticket. (LP: #1783183) | ||
910 | 1160 | |||
911 | 1161 | -- Andreas Hasenack <andreas@canonical.com> Fri, 09 Nov 2018 21:29:51 -0200 | ||
912 | 1162 | |||
913 | 1163 | openldap (2.4.46+dfsg-5ubuntu2) disco; urgency=medium | ||
914 | 1164 | |||
915 | 1165 | * No-change rebuild for the perl 5.28 transition. | ||
916 | 1166 | |||
917 | 1167 | -- Adam Conrad <adconrad@ubuntu.com> Fri, 02 Nov 2018 18:14:37 -0600 | ||
918 | 1168 | |||
919 | 1169 | openldap (2.4.46+dfsg-5ubuntu1) cosmic; urgency=medium | ||
920 | 1170 | |||
921 | 1171 | * Merge from Debian unstable. Remaining changes: | ||
922 | 1172 | - Enable AppArmor support: | ||
923 | 1173 | - d/apparmor-profile: add AppArmor profile | ||
924 | 1174 | - d/rules: use dh_apparmor | ||
925 | 1175 | - d/control: Build-Depends on dh-apparmor | ||
926 | 1176 | - d/slapd.README.Debian: add note about AppArmor | ||
927 | 1177 | - Enable GSSAPI support: | ||
928 | 1178 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
929 | 1179 | - Add --with-gssapi support | ||
930 | 1180 | - Make guess_service_principal() more robust when determining | ||
931 | 1181 | principal | ||
932 | 1182 | - d/configure.options: Configure with --with-gssapi | ||
933 | 1183 | - d/control: Added heimdal-dev as a build depend | ||
934 | 1184 | - d/rules: | ||
935 | 1185 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
936 | 1186 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
937 | 1187 | - Enable ufw support: | ||
938 | 1188 | - d/control: suggest ufw. | ||
939 | 1189 | - d/rules: install ufw profile. | ||
940 | 1190 | - d/slapd.ufw.profile: add ufw profile. | ||
941 | 1191 | - Enable nss overlay: | ||
942 | 1192 | - d/{patches/nssov-build,rules}: Apply, build and package the | ||
943 | 1193 | nss overlay. | ||
944 | 1194 | - d/{rules,slapd.py}: Add apport hook. | ||
945 | 1195 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
946 | 1196 | either the default DIT nor via an Authn mapping. | ||
947 | 1197 | - d/slapd.scripts-common: | ||
948 | 1198 | - add slapcat_opts to local variables. | ||
949 | 1199 | - Fix backup directory naming for multiple reconfiguration. | ||
950 | 1200 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
951 | 1201 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
952 | 1202 | in the openldap library, as required by Likewise-Open | ||
953 | 1203 | - Show distribution in version: | ||
954 | 1204 | - d/control: added lsb-release | ||
955 | 1205 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
956 | 1206 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
957 | 1207 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
958 | 1208 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
959 | 1209 | |||
960 | 1210 | -- Gianfranco Costamagna <locutusofborg@debian.org> Wed, 09 May 2018 13:44:37 +0200 | ||
961 | 1211 | |||
962 | 406 | openldap (2.4.46+dfsg-5) unstable; urgency=medium | 1212 | openldap (2.4.46+dfsg-5) unstable; urgency=medium |
963 | 407 | 1213 | ||
964 | 408 | * Restore slapd-smbk5pwd now that libldap is installable in unstable. | 1214 | * Restore slapd-smbk5pwd now that libldap is installable in unstable. |
965 | @@ -422,6 +1228,49 @@ openldap (2.4.46+dfsg-3) unstable; urgency=medium | |||
966 | 422 | 1228 | ||
967 | 423 | -- Ryan Tandy <ryan@nardis.ca> Fri, 04 May 2018 07:36:58 -0700 | 1229 | -- Ryan Tandy <ryan@nardis.ca> Fri, 04 May 2018 07:36:58 -0700 |
968 | 424 | 1230 | ||
969 | 1231 | openldap (2.4.46+dfsg-2ubuntu1) cosmic; urgency=low | ||
970 | 1232 | |||
971 | 1233 | * Merge from Debian unstable. Remaining changes: | ||
972 | 1234 | - Enable AppArmor support: | ||
973 | 1235 | - d/apparmor-profile: add AppArmor profile | ||
974 | 1236 | - d/rules: use dh_apparmor | ||
975 | 1237 | - d/control: Build-Depends on dh-apparmor | ||
976 | 1238 | - d/slapd.README.Debian: add note about AppArmor | ||
977 | 1239 | - Enable GSSAPI support: | ||
978 | 1240 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
979 | 1241 | - Add --with-gssapi support | ||
980 | 1242 | - Make guess_service_principal() more robust when determining | ||
981 | 1243 | principal | ||
982 | 1244 | - d/configure.options: Configure with --with-gssapi | ||
983 | 1245 | - d/control: Added heimdal-dev as a build depend | ||
984 | 1246 | - d/rules: | ||
985 | 1247 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
986 | 1248 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
987 | 1249 | - Enable ufw support: | ||
988 | 1250 | - d/control: suggest ufw. | ||
989 | 1251 | - d/rules: install ufw profile. | ||
990 | 1252 | - d/slapd.ufw.profile: add ufw profile. | ||
991 | 1253 | - Enable nss overlay: | ||
992 | 1254 | - d/{patches/nssov-build,rules}: Apply, build and package the | ||
993 | 1255 | nss overlay. | ||
994 | 1256 | - d/{rules,slapd.py}: Add apport hook. | ||
995 | 1257 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
996 | 1258 | either the default DIT nor via an Authn mapping. | ||
997 | 1259 | - d/slapd.scripts-common: | ||
998 | 1260 | - add slapcat_opts to local variables. | ||
999 | 1261 | - Fix backup directory naming for multiple reconfiguration. | ||
1000 | 1262 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1001 | 1263 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1002 | 1264 | in the openldap library, as required by Likewise-Open | ||
1003 | 1265 | - Show distribution in version: | ||
1004 | 1266 | - d/control: added lsb-release | ||
1005 | 1267 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
1006 | 1268 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
1007 | 1269 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
1008 | 1270 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
1009 | 1271 | |||
1010 | 1272 | -- Gianfranco Costamagna <locutusofborg@debian.org> Fri, 04 May 2018 10:19:24 +0200 | ||
1011 | 1273 | |||
1012 | 425 | openldap (2.4.46+dfsg-2) unstable; urgency=medium | 1274 | openldap (2.4.46+dfsg-2) unstable; urgency=medium |
1013 | 426 | 1275 | ||
1014 | 427 | * Remove version constraint from libldap-2.4-2 dependency on libldap-common. | 1276 | * Remove version constraint from libldap-2.4-2 dependency on libldap-common. |
1015 | @@ -451,6 +1300,49 @@ openldap (2.4.46+dfsg-1) unstable; urgency=medium | |||
1016 | 451 | 1300 | ||
1017 | 452 | -- Ryan Tandy <ryan@nardis.ca> Thu, 03 May 2018 07:03:30 -0700 | 1301 | -- Ryan Tandy <ryan@nardis.ca> Thu, 03 May 2018 07:03:30 -0700 |
1018 | 453 | 1302 | ||
1019 | 1303 | openldap (2.4.45+dfsg-1ubuntu1) artful; urgency=low | ||
1020 | 1304 | |||
1021 | 1305 | * Merge from Debian unstable. Remaining changes: | ||
1022 | 1306 | - Enable AppArmor support: | ||
1023 | 1307 | - d/apparmor-profile: add AppArmor profile | ||
1024 | 1308 | - d/rules: use dh_apparmor | ||
1025 | 1309 | - d/control: Build-Depends on dh-apparmor | ||
1026 | 1310 | - d/slapd.README.Debian: add note about AppArmor | ||
1027 | 1311 | - Enable GSSAPI support: | ||
1028 | 1312 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1029 | 1313 | - Add --with-gssapi support | ||
1030 | 1314 | - Make guess_service_principal() more robust when determining | ||
1031 | 1315 | principal | ||
1032 | 1316 | - d/configure.options: Configure with --with-gssapi | ||
1033 | 1317 | - d/control: Added heimdal-dev as a build depend | ||
1034 | 1318 | - d/rules: | ||
1035 | 1319 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
1036 | 1320 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
1037 | 1321 | - Enable ufw support: | ||
1038 | 1322 | - d/control: suggest ufw. | ||
1039 | 1323 | - d/rules: install ufw profile. | ||
1040 | 1324 | - d/slapd.ufw.profile: add ufw profile. | ||
1041 | 1325 | - Enable nss overlay: | ||
1042 | 1326 | - d/{patches/nssov-build,rules}: Apply, build and package the | ||
1043 | 1327 | nss overlay. | ||
1044 | 1328 | - d/{rules,slapd.py}: Add apport hook. | ||
1045 | 1329 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1046 | 1330 | either the default DIT nor via an Authn mapping. | ||
1047 | 1331 | - d/slapd.scripts-common: | ||
1048 | 1332 | - add slapcat_opts to local variables. | ||
1049 | 1333 | - Fix backup directory naming for multiple reconfiguration. | ||
1050 | 1334 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1051 | 1335 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1052 | 1336 | in the openldap library, as required by Likewise-Open | ||
1053 | 1337 | - Show distribution in version: | ||
1054 | 1338 | - d/control: added lsb-release | ||
1055 | 1339 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
1056 | 1340 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
1057 | 1341 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
1058 | 1342 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
1059 | 1343 | |||
1060 | 1344 | -- Gianfranco Costamagna <locutusofborg@debian.org> Fri, 28 Jul 2017 14:49:07 +0200 | ||
1061 | 1345 | |||
1062 | 454 | openldap (2.4.45+dfsg-1) unstable; urgency=medium | 1346 | openldap (2.4.45+dfsg-1) unstable; urgency=medium |
1063 | 455 | 1347 | ||
1064 | 456 | * New upstream release. | 1348 | * New upstream release. |
1065 | @@ -492,6 +1384,49 @@ openldap (2.4.45+dfsg-1) unstable; urgency=medium | |||
1066 | 492 | 1384 | ||
1067 | 493 | -- Ryan Tandy <ryan@nardis.ca> Thu, 27 Jul 2017 18:04:41 -0700 | 1385 | -- Ryan Tandy <ryan@nardis.ca> Thu, 27 Jul 2017 18:04:41 -0700 |
1068 | 494 | 1386 | ||
1069 | 1387 | openldap (2.4.44+dfsg-8ubuntu1) artful; urgency=low | ||
1070 | 1388 | |||
1071 | 1389 | * Merge from Debian unstable. Remaining changes: | ||
1072 | 1390 | - Enable AppArmor support: | ||
1073 | 1391 | - d/apparmor-profile: add AppArmor profile | ||
1074 | 1392 | - d/rules: use dh_apparmor | ||
1075 | 1393 | - d/control: Build-Depends on dh-apparmor | ||
1076 | 1394 | - d/slapd.README.Debian: add note about AppArmor | ||
1077 | 1395 | - Enable GSSAPI support: | ||
1078 | 1396 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1079 | 1397 | - Add --with-gssapi support | ||
1080 | 1398 | - Make guess_service_principal() more robust when determining | ||
1081 | 1399 | principal | ||
1082 | 1400 | - d/configure.options: Configure with --with-gssapi | ||
1083 | 1401 | - d/control: Added heimdal-dev as a build depend | ||
1084 | 1402 | - d/rules: | ||
1085 | 1403 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
1086 | 1404 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
1087 | 1405 | - Enable ufw support: | ||
1088 | 1406 | - d/control: suggest ufw. | ||
1089 | 1407 | - d/rules: install ufw profile. | ||
1090 | 1408 | - d/slapd.ufw.profile: add ufw profile. | ||
1091 | 1409 | - Enable nss overlay: | ||
1092 | 1410 | - d/{patches/nssov-build,rules}: Apply, build and package the | ||
1093 | 1411 | nss overlay. | ||
1094 | 1412 | - d/{rules,slapd.py}: Add apport hook. | ||
1095 | 1413 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1096 | 1414 | either the default DIT nor via an Authn mapping. | ||
1097 | 1415 | - d/slapd.scripts-common: | ||
1098 | 1416 | - add slapcat_opts to local variables. | ||
1099 | 1417 | - Fix backup directory naming for multiple reconfiguration. | ||
1100 | 1418 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1101 | 1419 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1102 | 1420 | in the openldap library, as required by Likewise-Open | ||
1103 | 1421 | - Show distribution in version: | ||
1104 | 1422 | - d/control: added lsb-release | ||
1105 | 1423 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
1106 | 1424 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
1107 | 1425 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
1108 | 1426 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
1109 | 1427 | |||
1110 | 1428 | -- Gianfranco Costamagna <locutusofborg@debian.org> Mon, 17 Jul 2017 10:58:24 +0200 | ||
1111 | 1429 | |||
1112 | 495 | openldap (2.4.44+dfsg-8) unstable; urgency=medium | 1430 | openldap (2.4.44+dfsg-8) unstable; urgency=medium |
1113 | 496 | 1431 | ||
1114 | 497 | * Disable test060-mt-hot on ppc64el temporarily to avoid failing tests until | 1432 | * Disable test060-mt-hot on ppc64el temporarily to avoid failing tests until |
1115 | @@ -502,6 +1437,52 @@ openldap (2.4.44+dfsg-8) unstable; urgency=medium | |||
1116 | 502 | 1437 | ||
1117 | 503 | -- Ryan Tandy <ryan@nardis.ca> Sun, 16 Jul 2017 12:57:41 -0700 | 1438 | -- Ryan Tandy <ryan@nardis.ca> Sun, 16 Jul 2017 12:57:41 -0700 |
1118 | 504 | 1439 | ||
1119 | 1440 | openldap (2.4.44+dfsg-7ubuntu1) artful; urgency=medium | ||
1120 | 1441 | |||
1121 | 1442 | * Merge from Debian unstable. Remaining changes: | ||
1122 | 1443 | - Enable AppArmor support: | ||
1123 | 1444 | - d/apparmor-profile: add AppArmor profile | ||
1124 | 1445 | - d/rules: use dh_apparmor | ||
1125 | 1446 | - d/control: Build-Depends on dh-apparmor | ||
1126 | 1447 | - d/slapd.README.Debian: add note about AppArmor | ||
1127 | 1448 | - Enable GSSAPI support: | ||
1128 | 1449 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1129 | 1450 | - Add --with-gssapi support | ||
1130 | 1451 | - Make guess_service_principal() more robust when determining | ||
1131 | 1452 | principal | ||
1132 | 1453 | - d/configure.options: Configure with --with-gssapi | ||
1133 | 1454 | - d/control: Added heimdal-dev as a build depend | ||
1134 | 1455 | - d/rules: | ||
1135 | 1456 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
1136 | 1457 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
1137 | 1458 | - Enable ufw support: | ||
1138 | 1459 | - d/control: suggest ufw. | ||
1139 | 1460 | - d/rules: install ufw profile. | ||
1140 | 1461 | - d/slapd.ufw.profile: add ufw profile. | ||
1141 | 1462 | - Enable nss overlay: | ||
1142 | 1463 | - d/{patches/nssov-build,rules}: Apply, build and package the | ||
1143 | 1464 | nss overlay. | ||
1144 | 1465 | - d/{rules,slapd.py}: Add apport hook. | ||
1145 | 1466 | [ d/rules modification mentioned above was dropped in | ||
1146 | 1467 | 2.4.23-6ubuntu1, re-adding it ] | ||
1147 | 1468 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1148 | 1469 | either the default DIT nor via an Authn mapping. | ||
1149 | 1470 | - d/slapd.scripts-common: | ||
1150 | 1471 | - add slapcat_opts to local variables. | ||
1151 | 1472 | - Fix backup directory naming for multiple reconfiguration. | ||
1152 | 1473 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1153 | 1474 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1154 | 1475 | in the openldap library, as required by Likewise-Open | ||
1155 | 1476 | - Show distribution in version: | ||
1156 | 1477 | - d/control: added lsb-release | ||
1157 | 1478 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
1158 | 1479 | [ Refreshed patch ] | ||
1159 | 1480 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
1160 | 1481 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
1161 | 1482 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
1162 | 1483 | |||
1163 | 1484 | -- Gianfranco Costamagna <locutusofborg@debian.org> Tue, 27 Jun 2017 10:21:41 +0200 | ||
1164 | 1485 | |||
1165 | 505 | openldap (2.4.44+dfsg-7) unstable; urgency=medium | 1486 | openldap (2.4.44+dfsg-7) unstable; urgency=medium |
1166 | 506 | 1487 | ||
1167 | 507 | * Relax the dependency of libldap-2.4-2 on libldap-common to also permit | 1488 | * Relax the dependency of libldap-2.4-2 on libldap-common to also permit |
1168 | @@ -509,6 +1490,52 @@ openldap (2.4.44+dfsg-7) unstable; urgency=medium | |||
1169 | 509 | 1490 | ||
1170 | 510 | -- Ryan Tandy <ryan@nardis.ca> Tue, 27 Jun 2017 18:53:12 -0700 | 1491 | -- Ryan Tandy <ryan@nardis.ca> Tue, 27 Jun 2017 18:53:12 -0700 |
1171 | 511 | 1492 | ||
1172 | 1493 | openldap (2.4.44+dfsg-6ubuntu1) artful; urgency=medium | ||
1173 | 1494 | |||
1174 | 1495 | * Merge from Debian unstable. Remaining changes: | ||
1175 | 1496 | - Enable AppArmor support: | ||
1176 | 1497 | - d/apparmor-profile: add AppArmor profile | ||
1177 | 1498 | - d/rules: use dh_apparmor | ||
1178 | 1499 | - d/control: Build-Depends on dh-apparmor | ||
1179 | 1500 | - d/slapd.README.Debian: add note about AppArmor | ||
1180 | 1501 | - Enable GSSAPI support: | ||
1181 | 1502 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1182 | 1503 | - Add --with-gssapi support | ||
1183 | 1504 | - Make guess_service_principal() more robust when determining | ||
1184 | 1505 | principal | ||
1185 | 1506 | - d/configure.options: Configure with --with-gssapi | ||
1186 | 1507 | - d/control: Added heimdal-dev as a build depend | ||
1187 | 1508 | - d/rules: | ||
1188 | 1509 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
1189 | 1510 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
1190 | 1511 | - Enable ufw support: | ||
1191 | 1512 | - d/control: suggest ufw. | ||
1192 | 1513 | - d/rules: install ufw profile. | ||
1193 | 1514 | - d/slapd.ufw.profile: add ufw profile. | ||
1194 | 1515 | - Enable nss overlay: | ||
1195 | 1516 | - d/{patches/nssov-build,rules}: Apply, build and package the | ||
1196 | 1517 | nss overlay. | ||
1197 | 1518 | - d/{rules,slapd.py}: Add apport hook. | ||
1198 | 1519 | [ d/rules modification mentioned above was dropped in | ||
1199 | 1520 | 2.4.23-6ubuntu1, re-adding it ] | ||
1200 | 1521 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1201 | 1522 | either the default DIT nor via an Authn mapping. | ||
1202 | 1523 | - d/slapd.scripts-common: | ||
1203 | 1524 | - add slapcat_opts to local variables. | ||
1204 | 1525 | - Fix backup directory naming for multiple reconfiguration. | ||
1205 | 1526 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1206 | 1527 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1207 | 1528 | in the openldap library, as required by Likewise-Open | ||
1208 | 1529 | - Show distribution in version: | ||
1209 | 1530 | - d/control: added lsb-release | ||
1210 | 1531 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
1211 | 1532 | [ Refreshed patch ] | ||
1212 | 1533 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
1213 | 1534 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
1214 | 1535 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
1215 | 1536 | |||
1216 | 1537 | -- Gianfranco Costamagna <locutusofborg@debian.org> Tue, 27 Jun 2017 10:21:41 +0200 | ||
1217 | 1538 | |||
1218 | 512 | openldap (2.4.44+dfsg-6) unstable; urgency=medium | 1539 | openldap (2.4.44+dfsg-6) unstable; urgency=medium |
1219 | 513 | 1540 | ||
1220 | 514 | * Update the list of non-translatable strings for the | 1541 | * Update the list of non-translatable strings for the |
1221 | @@ -517,6 +1544,54 @@ openldap (2.4.44+dfsg-6) unstable; urgency=medium | |||
1222 | 517 | 1544 | ||
1223 | 518 | -- Ryan Tandy <ryan@nardis.ca> Mon, 26 Jun 2017 19:42:02 -0700 | 1545 | -- Ryan Tandy <ryan@nardis.ca> Mon, 26 Jun 2017 19:42:02 -0700 |
1224 | 519 | 1546 | ||
1225 | 1547 | openldap (2.4.44+dfsg-5ubuntu1) artful; urgency=medium | ||
1226 | 1548 | |||
1227 | 1549 | * Merge from Debian unstable. Remaining changes: | ||
1228 | 1550 | - Enable AppArmor support: | ||
1229 | 1551 | - d/apparmor-profile: add AppArmor profile | ||
1230 | 1552 | - d/rules: use dh_apparmor | ||
1231 | 1553 | - d/control: Build-Depends on dh-apparmor | ||
1232 | 1554 | - d/slapd.README.Debian: add note about AppArmor | ||
1233 | 1555 | - Enable GSSAPI support: | ||
1234 | 1556 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1235 | 1557 | - Add --with-gssapi support | ||
1236 | 1558 | - Make guess_service_principal() more robust when determining | ||
1237 | 1559 | principal | ||
1238 | 1560 | - d/configure.options: Configure with --with-gssapi | ||
1239 | 1561 | - d/control: Added heimdal-dev as a build depend | ||
1240 | 1562 | - d/rules: | ||
1241 | 1563 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
1242 | 1564 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
1243 | 1565 | - Enable ufw support: | ||
1244 | 1566 | - d/control: suggest ufw. | ||
1245 | 1567 | - d/rules: install ufw profile. | ||
1246 | 1568 | - d/slapd.ufw.profile: add ufw profile. | ||
1247 | 1569 | - Enable nss overlay: | ||
1248 | 1570 | - d/{patches/nssov-build,rules}: Apply, build and package the | ||
1249 | 1571 | nss overlay. | ||
1250 | 1572 | - d/{rules,slapd.py}: Add apport hook. | ||
1251 | 1573 | [ d/rules modification mentioned above was dropped in | ||
1252 | 1574 | 2.4.23-6ubuntu1, re-adding it ] | ||
1253 | 1575 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1254 | 1576 | either the default DIT nor via an Authn mapping. | ||
1255 | 1577 | - d/slapd.scripts-common: | ||
1256 | 1578 | - add slapcat_opts to local variables. | ||
1257 | 1579 | - Fix backup directory naming for multiple reconfiguration. | ||
1258 | 1580 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1259 | 1581 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1260 | 1582 | in the openldap library, as required by Likewise-Open | ||
1261 | 1583 | - Show distribution in version: | ||
1262 | 1584 | - d/control: added lsb-release | ||
1263 | 1585 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
1264 | 1586 | [ Refreshed patch ] | ||
1265 | 1587 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
1266 | 1588 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
1267 | 1589 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
1268 | 1590 | [ undocumented in prior merge, added in 2.4.41+dfsg-1ubuntu1 ] | ||
1269 | 1591 | - Fix use after free with GnuTLS. (LP #1557248) | ||
1270 | 1592 | |||
1271 | 1593 | -- Gianfranco Costamagna <locutusofborg@debian.org> Sun, 28 May 2017 22:43:50 +0200 | ||
1272 | 1594 | |||
1273 | 520 | openldap (2.4.44+dfsg-5) unstable; urgency=medium | 1595 | openldap (2.4.44+dfsg-5) unstable; urgency=medium |
1274 | 521 | 1596 | ||
1275 | 522 | * debian/patches/ITS-8644-wait-for-slapd-to-start-in-test064.patch: Fix an | 1597 | * debian/patches/ITS-8644-wait-for-slapd-to-start-in-test064.patch: Fix an |
1276 | @@ -528,6 +1603,54 @@ openldap (2.4.44+dfsg-5) unstable; urgency=medium | |||
1277 | 528 | 1603 | ||
1278 | 529 | -- Ryan Tandy <ryan@nardis.ca> Sun, 28 May 2017 09:59:46 -0700 | 1604 | -- Ryan Tandy <ryan@nardis.ca> Sun, 28 May 2017 09:59:46 -0700 |
1279 | 530 | 1605 | ||
1280 | 1606 | openldap (2.4.44+dfsg-4ubuntu1) artful; urgency=low | ||
1281 | 1607 | |||
1282 | 1608 | * Merge from Debian unstable. Remaining changes: | ||
1283 | 1609 | - Enable AppArmor support: | ||
1284 | 1610 | - d/apparmor-profile: add AppArmor profile | ||
1285 | 1611 | - d/rules: use dh_apparmor | ||
1286 | 1612 | - d/control: Build-Depends on dh-apparmor | ||
1287 | 1613 | - d/slapd.README.Debian: add note about AppArmor | ||
1288 | 1614 | - Enable GSSAPI support: | ||
1289 | 1615 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1290 | 1616 | - Add --with-gssapi support | ||
1291 | 1617 | - Make guess_service_principal() more robust when determining | ||
1292 | 1618 | principal | ||
1293 | 1619 | - d/configure.options: Configure with --with-gssapi | ||
1294 | 1620 | - d/control: Added heimdal-dev as a build depend | ||
1295 | 1621 | - d/rules: | ||
1296 | 1622 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
1297 | 1623 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
1298 | 1624 | - Enable ufw support: | ||
1299 | 1625 | - d/control: suggest ufw. | ||
1300 | 1626 | - d/rules: install ufw profile. | ||
1301 | 1627 | - d/slapd.ufw.profile: add ufw profile. | ||
1302 | 1628 | - Enable nss overlay: | ||
1303 | 1629 | - d/{patches/nssov-build,rules}: Apply, build and package the | ||
1304 | 1630 | nss overlay. | ||
1305 | 1631 | - d/{rules,slapd.py}: Add apport hook. | ||
1306 | 1632 | [ d/rules modification mentioned above was dropped in | ||
1307 | 1633 | 2.4.23-6ubuntu1, re-adding it ] | ||
1308 | 1634 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1309 | 1635 | either the default DIT nor via an Authn mapping. | ||
1310 | 1636 | - d/slapd.scripts-common: | ||
1311 | 1637 | - add slapcat_opts to local variables. | ||
1312 | 1638 | - Fix backup directory naming for multiple reconfiguration. | ||
1313 | 1639 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1314 | 1640 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1315 | 1641 | in the openldap library, as required by Likewise-Open | ||
1316 | 1642 | - Show distribution in version: | ||
1317 | 1643 | - d/control: added lsb-release | ||
1318 | 1644 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
1319 | 1645 | [ Refreshed patch ] | ||
1320 | 1646 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
1321 | 1647 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
1322 | 1648 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
1323 | 1649 | [ undocumented in prior merge, added in 2.4.41+dfsg-1ubuntu1 ] | ||
1324 | 1650 | - Fix use after free with GnuTLS. (LP #1557248) | ||
1325 | 1651 | |||
1326 | 1652 | -- Gianfranco Costamagna <locutusofborg@debian.org> Sat, 22 Apr 2017 14:28:54 +0200 | ||
1327 | 1653 | |||
1328 | 531 | openldap (2.4.44+dfsg-4) unstable; urgency=medium | 1654 | openldap (2.4.44+dfsg-4) unstable; urgency=medium |
1329 | 532 | 1655 | ||
1330 | 533 | * Improve the slapd/ppolicy_schema_needs_update debconf template. Thanks to | 1656 | * Improve the slapd/ppolicy_schema_needs_update debconf template. Thanks to |
1331 | @@ -574,6 +1697,67 @@ openldap (2.4.44+dfsg-4) unstable; urgency=medium | |||
1332 | 574 | 1697 | ||
1333 | 575 | -- Ryan Tandy <ryan@nardis.ca> Sun, 16 Apr 2017 20:10:43 -0700 | 1698 | -- Ryan Tandy <ryan@nardis.ca> Sun, 16 Apr 2017 20:10:43 -0700 |
1334 | 576 | 1699 | ||
1335 | 1700 | openldap (2.4.44+dfsg-3ubuntu2) zesty; urgency=medium | ||
1336 | 1701 | |||
1337 | 1702 | * d/rules: Fix typo in previous upload. | ||
1338 | 1703 | |||
1339 | 1704 | -- Nishanth Aravamudan <nish.aravamudan@canonical.com> Fri, 10 Feb 2017 12:17:02 -0800 | ||
1340 | 1705 | |||
1341 | 1706 | openldap (2.4.44+dfsg-3ubuntu1) zesty; urgency=medium | ||
1342 | 1707 | |||
1343 | 1708 | * Merge with Debian unstable (LP: #1663702, LP: #1654416). Remaining | ||
1344 | 1709 | changes | ||
1345 | 1710 | - Enable AppArmor support: | ||
1346 | 1711 | - d/apparmor-profile: add AppArmor profile | ||
1347 | 1712 | - d/rules: use dh_apparmor | ||
1348 | 1713 | - d/control: Build-Depends on dh-apparmor | ||
1349 | 1714 | - d/slapd.README.Debian: add note about AppArmor | ||
1350 | 1715 | - Enable GSSAPI support: | ||
1351 | 1716 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1352 | 1717 | - Add --with-gssapi support | ||
1353 | 1718 | - Make guess_service_principal() more robust when determining | ||
1354 | 1719 | principal | ||
1355 | 1720 | - d/configure.options: Configure with --with-gssapi | ||
1356 | 1721 | - d/control: Added heimdal-dev as a build depend | ||
1357 | 1722 | - d/rules: | ||
1358 | 1723 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
1359 | 1724 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
1360 | 1725 | - Enable ufw support: | ||
1361 | 1726 | - d/control: suggest ufw. | ||
1362 | 1727 | - d/rules: install ufw profile. | ||
1363 | 1728 | - d/slapd.ufw.profile: add ufw profile. | ||
1364 | 1729 | - Enable nss overlay: | ||
1365 | 1730 | - d/{patches/nssov-build,rules}: Apply, build and package the | ||
1366 | 1731 | nss overlay. | ||
1367 | 1732 | - d/{rules,slapd.py}: Add apport hook. | ||
1368 | 1733 | [ d/rules modification mentioned above was dropped in | ||
1369 | 1734 | 2.4.23-6ubuntu1, re-adding it ] | ||
1370 | 1735 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1371 | 1736 | either the default DIT nor via an Authn mapping. | ||
1372 | 1737 | - d/slapd.scripts-common: | ||
1373 | 1738 | - add slapcat_opts to local variables. | ||
1374 | 1739 | - Fix backup directory naming for multiple reconfiguration. | ||
1375 | 1740 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1376 | 1741 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1377 | 1742 | in the openldap library, as required by Likewise-Open | ||
1378 | 1743 | - Show distribution in version: | ||
1379 | 1744 | - d/control: added lsb-release | ||
1380 | 1745 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
1381 | 1746 | [ Refreshed patch ] | ||
1382 | 1747 | - d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
1383 | 1748 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
1384 | 1749 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
1385 | 1750 | [ undocumented in prior merge, added in 2.4.41+dfsg-1ubuntu1 ] | ||
1386 | 1751 | - Fix use after free with GnuTLS. (LP #1557248) | ||
1387 | 1752 | * Drop: | ||
1388 | 1753 | - d/slapd.scripts-common: | ||
1389 | 1754 | + Remove unused variable new_conf. | ||
1390 | 1755 | [ configure_v2_protocol_support function removed in 2.4.44+dfsg-1 ] | ||
1391 | 1756 | - d/b/config.log: add config.log | ||
1392 | 1757 | [ previously undocumented, stray change ] | ||
1393 | 1758 | |||
1394 | 1759 | -- Nishanth Aravamudan <nish.aravamudan@canonical.com> Fri, 10 Feb 2017 11:38:57 -0800 | ||
1395 | 1760 | |||
1396 | 577 | openldap (2.4.44+dfsg-3) unstable; urgency=medium | 1761 | openldap (2.4.44+dfsg-3) unstable; urgency=medium |
1397 | 578 | 1762 | ||
1398 | 579 | * Apply upstream patch to fix FTBFS on kFreeBSD. (Closes: #845394) | 1763 | * Apply upstream patch to fix FTBFS on kFreeBSD. (Closes: #845394) |
1399 | @@ -646,6 +1830,73 @@ openldap (2.4.44+dfsg-1) unstable; urgency=medium | |||
1400 | 646 | 1830 | ||
1401 | 647 | -- Ryan Tandy <ryan@nardis.ca> Mon, 14 Nov 2016 18:59:30 -0800 | 1831 | -- Ryan Tandy <ryan@nardis.ca> Mon, 14 Nov 2016 18:59:30 -0800 |
1402 | 648 | 1832 | ||
1403 | 1833 | openldap (2.4.42+dfsg-2ubuntu5) zesty; urgency=medium | ||
1404 | 1834 | |||
1405 | 1835 | * No-change rebuild for perl 5.24 transition | ||
1406 | 1836 | |||
1407 | 1837 | -- Iain Lane <iain@orangesquash.org.uk> Mon, 24 Oct 2016 10:37:13 +0100 | ||
1408 | 1838 | |||
1409 | 1839 | openldap (2.4.42+dfsg-2ubuntu4) yakkety; urgency=medium | ||
1410 | 1840 | |||
1411 | 1841 | * Fix use after free with GnuTLS. (LP: #1557248) | ||
1412 | 1842 | |||
1413 | 1843 | -- Maciej Puzio <maciej@work.swmed.edu> Fri, 25 Mar 2016 15:24:25 -0500 | ||
1414 | 1844 | |||
1415 | 1845 | openldap (2.4.42+dfsg-2ubuntu3) xenial; urgency=medium | ||
1416 | 1846 | |||
1417 | 1847 | * Fix building with gssapi suppport: | ||
1418 | 1848 | - Explicitly add -I/usr/include/heimdal to CFLAGS. | ||
1419 | 1849 | - Explicitly add -I/usr/lib/<multiarch>/heimdal to LDFLAGS. | ||
1420 | 1850 | |||
1421 | 1851 | -- Matthias Klose <doko@ubuntu.com> Thu, 18 Feb 2016 09:17:27 +0100 | ||
1422 | 1852 | |||
1423 | 1853 | openldap (2.4.42+dfsg-2ubuntu2) xenial; urgency=medium | ||
1424 | 1854 | |||
1425 | 1855 | * No-change rebuild for gnutls transition. | ||
1426 | 1856 | |||
1427 | 1857 | -- Matthias Klose <doko@ubuntu.com> Wed, 17 Feb 2016 22:27:04 +0000 | ||
1428 | 1858 | |||
1429 | 1859 | openldap (2.4.42+dfsg-2ubuntu1) xenial; urgency=medium | ||
1430 | 1860 | |||
1431 | 1861 | * Merge from Debian testing (LP: #1532648). Remaining changes: | ||
1432 | 1862 | - Enable AppArmor support: | ||
1433 | 1863 | - d/apparmor-profile: add AppArmor profile | ||
1434 | 1864 | - d/rules: use dh_apparmor | ||
1435 | 1865 | - d/control: Build-Depends on dh-apparmor | ||
1436 | 1866 | - d/slapd.README.Debian: add note about AppArmor | ||
1437 | 1867 | - Enable GSSAPI support: | ||
1438 | 1868 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1439 | 1869 | - Add --with-gssapi support | ||
1440 | 1870 | - Make guess_service_principal() more robust when determining | ||
1441 | 1871 | principal | ||
1442 | 1872 | - d/configure.options: Configure with --with-gssapi | ||
1443 | 1873 | - d/control: Added heimdal-dev as a build depend | ||
1444 | 1874 | - Enable ufw support: | ||
1445 | 1875 | - d/control: suggest ufw. | ||
1446 | 1876 | - d/rules: install ufw profile. | ||
1447 | 1877 | - d/slapd.ufw.profile: add ufw profile. | ||
1448 | 1878 | - Enable nss overlay: | ||
1449 | 1879 | - d/{patches/nssov-build,rules}: Apply, build and package the | ||
1450 | 1880 | nss overlay. | ||
1451 | 1881 | - d/{rules,slapd.py}: Add apport hook. | ||
1452 | 1882 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1453 | 1883 | either the default DIT nor via an Authn mapping. | ||
1454 | 1884 | - d/slapd.scripts-common: | ||
1455 | 1885 | - add slapcat_opts to local variables. | ||
1456 | 1886 | - Remove unused variable new_conf. | ||
1457 | 1887 | - Fix backup directory naming for multiple reconfiguration. | ||
1458 | 1888 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1459 | 1889 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1460 | 1890 | in the openldap library, as required by Likewise-Open | ||
1461 | 1891 | - Show distribution in version: | ||
1462 | 1892 | - d/control: added lsb-release | ||
1463 | 1893 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
1464 | 1894 | * Drop CVE-2015-6908.patch, included in Debian. | ||
1465 | 1895 | * Remove DEB_HOST_ARCH from debian/rules: left over from when mdb was | ||
1466 | 1896 | disabled on ppc64el, no longer used, and missed in the previous merge. | ||
1467 | 1897 | |||
1468 | 1898 | -- Ryan Tandy <ryan@nardis.ca> Sun, 10 Jan 2016 15:50:53 -0800 | ||
1469 | 1899 | |||
1470 | 649 | openldap (2.4.42+dfsg-2) unstable; urgency=medium | 1900 | openldap (2.4.42+dfsg-2) unstable; urgency=medium |
1471 | 650 | 1901 | ||
1472 | 651 | [ Ryan Tandy ] | 1902 | [ Ryan Tandy ] |
1473 | @@ -713,6 +1964,71 @@ openldap (2.4.42+dfsg-1) unstable; urgency=medium | |||
1474 | 713 | 1964 | ||
1475 | 714 | -- Ryan Tandy <ryan@nardis.ca> Fri, 21 Aug 2015 13:07:51 -0700 | 1965 | -- Ryan Tandy <ryan@nardis.ca> Fri, 21 Aug 2015 13:07:51 -0700 |
1476 | 715 | 1966 | ||
1477 | 1967 | openldap (2.4.41+dfsg-1ubuntu3) xenial; urgency=medium | ||
1478 | 1968 | |||
1479 | 1969 | * Rebuild for Perl 5.22.1. | ||
1480 | 1970 | |||
1481 | 1971 | -- Colin Watson <cjwatson@ubuntu.com> Fri, 18 Dec 2015 15:10:17 +0000 | ||
1482 | 1972 | |||
1483 | 1973 | openldap (2.4.41+dfsg-1ubuntu2) wily; urgency=medium | ||
1484 | 1974 | |||
1485 | 1975 | * SECURITY UPDATE: denial of service via crafted BER data | ||
1486 | 1976 | - debian/patches/CVE-2015-6908.patch: remove obsolete assert in | ||
1487 | 1977 | libraries/liblber/io.c. | ||
1488 | 1978 | - CVE-2015-6908 | ||
1489 | 1979 | |||
1490 | 1980 | -- Marc Deslauriers <marc.deslauriers@ubuntu.com> Mon, 14 Sep 2015 10:25:04 -0400 | ||
1491 | 1981 | |||
1492 | 1982 | openldap (2.4.41+dfsg-1ubuntu1) wily; urgency=medium | ||
1493 | 1983 | |||
1494 | 1984 | * Merge from Debian testing (LP: #1471831). Remaining changes: | ||
1495 | 1985 | - Enable AppArmor support: | ||
1496 | 1986 | - d/apparmor-profile: add AppArmor profile | ||
1497 | 1987 | - d/rules: use dh_apparmor | ||
1498 | 1988 | - d/control: Build-Depends on dh-apparmor | ||
1499 | 1989 | - d/slapd.README.Debian: add note about AppArmor | ||
1500 | 1990 | - Enable GSSAPI support: | ||
1501 | 1991 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1502 | 1992 | - Add --with-gssapi support | ||
1503 | 1993 | - Make guess_service_principal() more robust when determining | ||
1504 | 1994 | principal | ||
1505 | 1995 | - d/configure.options: Configure with --with-gssapi | ||
1506 | 1996 | - d/control: Added heimdal-dev as a build depend | ||
1507 | 1997 | - Enable ufw support: | ||
1508 | 1998 | - d/control: suggest ufw. | ||
1509 | 1999 | - d/rules: install ufw profile. | ||
1510 | 2000 | - d/slapd.ufw.profile: add ufw profile. | ||
1511 | 2001 | - Enable nss overlay: | ||
1512 | 2002 | - d/{patches/nssov-build,rules}: Apply, build and package the | ||
1513 | 2003 | nss overlay. | ||
1514 | 2004 | - d/{rules,slapd.py}: Add apport hook. | ||
1515 | 2005 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1516 | 2006 | either the default DIT nor via an Authn mapping. | ||
1517 | 2007 | - d/slapd.scripts-common: | ||
1518 | 2008 | - add slapcat_opts to local variables. | ||
1519 | 2009 | - Remove unused variable new_conf. | ||
1520 | 2010 | - Fix backup directory naming for multiple reconfiguration. | ||
1521 | 2011 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1522 | 2012 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1523 | 2013 | in the openldap library, as required by Likewise-Open | ||
1524 | 2014 | - Show distribution in version: | ||
1525 | 2015 | - d/control: added lsb-release | ||
1526 | 2016 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
1527 | 2017 | * Dropped changes: | ||
1528 | 2018 | - Fix cpp calls for GCC 5: fixed upstream (ITS#8056) | ||
1529 | 2019 | * Upstream fixes: | ||
1530 | 2020 | - slapd crash with auditlog overlay and large (~27KB) attribute values | ||
1531 | 2021 | (ITS#8003) (LP: #1461276) | ||
1532 | 2022 | - nssov updated to support recent nss-pam-ldapd client libraries | ||
1533 | 2023 | (ITS#8097) (LP: #1393306) | ||
1534 | 2024 | * Update d/patches/nssov-build for upstream changes. | ||
1535 | 2025 | * Tweak d/patches/gssapi.diff to apply without fuzz. | ||
1536 | 2026 | * d/libldap-2.4-2.symbols: Add symbols not present in Debian. | ||
1537 | 2027 | - CLDAP (UDP) was added in 2.4.17-1ubuntu2 | ||
1538 | 2028 | - GSSAPI support was enabled in 2.4.18-0ubuntu2 | ||
1539 | 2029 | |||
1540 | 2030 | -- Ryan Tandy <ryan@nardis.ca> Fri, 24 Jul 2015 14:12:06 -0700 | ||
1541 | 2031 | |||
1542 | 716 | openldap (2.4.41+dfsg-1) unstable; urgency=medium | 2032 | openldap (2.4.41+dfsg-1) unstable; urgency=medium |
1543 | 717 | 2033 | ||
1544 | 718 | * New upstream release. | 2034 | * New upstream release. |
1545 | @@ -732,6 +2048,62 @@ openldap (2.4.40+dfsg-2) unstable; urgency=medium | |||
1546 | 732 | 2048 | ||
1547 | 733 | -- Ryan Tandy <ryan@nardis.ca> Sun, 28 Jun 2015 20:40:37 -0700 | 2049 | -- Ryan Tandy <ryan@nardis.ca> Sun, 28 Jun 2015 20:40:37 -0700 |
1548 | 734 | 2050 | ||
1549 | 2051 | openldap (2.4.40+dfsg-1ubuntu2) wily; urgency=medium | ||
1550 | 2052 | |||
1551 | 2053 | * No-change rebuild for the libnettle6 transition. | ||
1552 | 2054 | |||
1553 | 2055 | -- Adam Conrad <adconrad@ubuntu.com> Sun, 14 Jun 2015 03:58:30 -0600 | ||
1554 | 2056 | |||
1555 | 2057 | openldap (2.4.40+dfsg-1ubuntu1) wily; urgency=low | ||
1556 | 2058 | |||
1557 | 2059 | * Merge from Debian testing (LP: #1395098, LP: #1316124). Remaining changes: | ||
1558 | 2060 | - Enable AppArmor support: | ||
1559 | 2061 | - d/apparmor-profile: add AppArmor profile | ||
1560 | 2062 | - d/rules: use dh_apparmor | ||
1561 | 2063 | - d/control: Build-Depends on dh-apparmor | ||
1562 | 2064 | - d/slapd.README.Debian: add note about AppArmor | ||
1563 | 2065 | - Enable GSSAPI support: | ||
1564 | 2066 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1565 | 2067 | - Add --with-gssapi support | ||
1566 | 2068 | - Make guess_service_principal() more robust when determining | ||
1567 | 2069 | principal | ||
1568 | 2070 | - d/configure.options: Configure with --with-gssapi | ||
1569 | 2071 | - d/control: Added heimdal-dev as a build depend | ||
1570 | 2072 | - Enable ufw support: | ||
1571 | 2073 | - d/control: suggest ufw. | ||
1572 | 2074 | - d/rules: install ufw profile. | ||
1573 | 2075 | - d/slapd.ufw.profile: add ufw profile. | ||
1574 | 2076 | - Enable nss overlay: | ||
1575 | 2077 | - d/{patches/nssov-build,rules}: Apply, build and package the | ||
1576 | 2078 | nss overlay. | ||
1577 | 2079 | - d/{rules,slapd.py}: Add apport hook. | ||
1578 | 2080 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1579 | 2081 | either the default DIT nor via an Authn mapping. | ||
1580 | 2082 | - d/slapd.scripts-common: | ||
1581 | 2083 | - add slapcat_opts to local variables. | ||
1582 | 2084 | - Remove unused variable new_conf. | ||
1583 | 2085 | - Fix backup directory naming for multiple reconfiguration. | ||
1584 | 2086 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1585 | 2087 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1586 | 2088 | in the openldap library, as required by Likewise-Open | ||
1587 | 2089 | - Show distribution in version: | ||
1588 | 2090 | - d/control: added lsb-release | ||
1589 | 2091 | - d/patches/fix-ldap-distribution.patch: show distribution in version | ||
1590 | 2092 | * Drop patches included upstream: | ||
1591 | 2093 | - d/patches/0001-ITS-7430-GnuTLS-Avoid-use-of-deprecated-function.patch | ||
1592 | 2094 | - d/patches/bdb-deadlock.patch | ||
1593 | 2095 | - d/patches/its-7354-fix-delta-sync-mmr.diff | ||
1594 | 2096 | * Drop hardening-wrapper as Debian now sets PIE and bindnow flags. | ||
1595 | 2097 | * debian/patches/nssov-build: Adjust for upstream changes. | ||
1596 | 2098 | * debian/apparmor-profile: | ||
1597 | 2099 | - Change 'r' to 'rw' for ldapi and nslcd sockets, required for apparmor | ||
1598 | 2100 | kernel ABI v7 (utopic and later). (LP: #1392018) | ||
1599 | 2101 | - Reduce permissions on /run/nslcd to just the nslcd socket. | ||
1600 | 2102 | * Enable the mdb backend again on ppc64el, fixed upstream in ITS#7713. | ||
1601 | 2103 | (LP: #1293250) | ||
1602 | 2104 | |||
1603 | 2105 | -- Ryan Tandy <ryan@nardis.ca> Mon, 25 May 2015 19:49:21 -0700 | ||
1604 | 2106 | |||
1605 | 735 | openldap (2.4.40+dfsg-1) unstable; urgency=medium | 2107 | openldap (2.4.40+dfsg-1) unstable; urgency=medium |
1606 | 736 | 2108 | ||
1607 | 737 | * Remove inetorgperson.schema from the upstream source. Replace it with a | 2109 | * Remove inetorgperson.schema from the upstream source. Replace it with a |
1608 | @@ -920,6 +2292,187 @@ openldap (2.4.39-1) unstable; urgency=low | |||
1609 | 920 | 2292 | ||
1610 | 921 | -- Steve Langasek <vorlon@debian.org> Mon, 17 Mar 2014 15:27:31 -0700 | 2293 | -- Steve Langasek <vorlon@debian.org> Mon, 17 Mar 2014 15:27:31 -0700 |
1611 | 922 | 2294 | ||
1612 | 2295 | openldap (2.4.31-1+nmu2ubuntu12) vivid; urgency=medium | ||
1613 | 2296 | |||
1614 | 2297 | * Fix cpp calls for GCC 5. | ||
1615 | 2298 | |||
1616 | 2299 | -- Matthias Klose <doko@ubuntu.com> Fri, 06 Mar 2015 13:23:29 +0100 | ||
1617 | 2300 | |||
1618 | 2301 | openldap (2.4.31-1+nmu2ubuntu11) utopic; urgency=medium | ||
1619 | 2302 | |||
1620 | 2303 | * debian/apparmor-profile: | ||
1621 | 2304 | - allow p11-kit abstraction | ||
1622 | 2305 | - allow read of /etc/gss/mech.d/* | ||
1623 | 2306 | |||
1624 | 2307 | -- Jamie Strandboge <jamie@ubuntu.com> Tue, 02 Sep 2014 15:29:05 -0500 | ||
1625 | 2308 | |||
1626 | 2309 | openldap (2.4.31-1+nmu2ubuntu10) utopic; urgency=medium | ||
1627 | 2310 | |||
1628 | 2311 | * Rebuild for Perl 5.20.0. | ||
1629 | 2312 | |||
1630 | 2313 | -- Colin Watson <cjwatson@ubuntu.com> Thu, 21 Aug 2014 13:29:20 +0100 | ||
1631 | 2314 | |||
1632 | 2315 | openldap (2.4.31-1+nmu2ubuntu9) utopic; urgency=medium | ||
1633 | 2316 | |||
1634 | 2317 | * Cherry-pick upstream patch for compat with recent GNUTLS. | ||
1635 | 2318 | * Build-depend on libgnutls28-dev. | ||
1636 | 2319 | * Build-depend on libgcrypt20-dev. | ||
1637 | 2320 | |||
1638 | 2321 | -- Dimitri John Ledkov <xnox@ubuntu.com> Fri, 08 Aug 2014 11:01:56 +0100 | ||
1639 | 2322 | |||
1640 | 2323 | openldap (2.4.31-1+nmu2ubuntu8) trusty; urgency=medium | ||
1641 | 2324 | |||
1642 | 2325 | * Bump database_format_changed value to 2.4.31-1+nmu2ubuntu5 for db5.3. | ||
1643 | 2326 | |||
1644 | 2327 | -- Adam Conrad <adconrad@ubuntu.com> Mon, 17 Mar 2014 12:50:18 -0600 | ||
1645 | 2328 | |||
1646 | 2329 | openldap (2.4.31-1+nmu2ubuntu7) trusty; urgency=medium | ||
1647 | 2330 | |||
1648 | 2331 | * Disable mdb backend on ppc64el due to test-suite failures. | ||
1649 | 2332 | |||
1650 | 2333 | -- Dimitri John Ledkov <xnox@ubuntu.com> Mon, 17 Mar 2014 16:32:29 +0000 | ||
1651 | 2334 | |||
1652 | 2335 | openldap (2.4.31-1+nmu2ubuntu6) trusty; urgency=low | ||
1653 | 2336 | |||
1654 | 2337 | * Fix segfault issue with master-master syncrepl (LP: #1287730): | ||
1655 | 2338 | - d/patches/its-7354-fix-delta-sync-mmr.diff: Cherry picked | ||
1656 | 2339 | patch from upstream VCS. | ||
1657 | 2340 | |||
1658 | 2341 | -- Pierre Fersing <pfersing@sierrawireless.com> Tue, 04 Mar 2014 16:04:57 +0100 | ||
1659 | 2342 | |||
1660 | 2343 | openldap (2.4.31-1+nmu2ubuntu5) trusty; urgency=low | ||
1661 | 2344 | |||
1662 | 2345 | * Build-depend on libdb5.3-dev, instead of libdb5.1-dev. | ||
1663 | 2346 | |||
1664 | 2347 | -- Dmitrijs Ledkovs <xnox@ubuntu.com> Mon, 04 Nov 2013 08:04:30 +0000 | ||
1665 | 2348 | |||
1666 | 2349 | openldap (2.4.31-1+nmu2ubuntu4) trusty; urgency=low | ||
1667 | 2350 | |||
1668 | 2351 | * Rebuild for Perl 5.18. | ||
1669 | 2352 | |||
1670 | 2353 | -- Colin Watson <cjwatson@ubuntu.com> Tue, 22 Oct 2013 12:16:39 +0100 | ||
1671 | 2354 | |||
1672 | 2355 | openldap (2.4.31-1+nmu2ubuntu3) saucy; urgency=low | ||
1673 | 2356 | |||
1674 | 2357 | * Update build/config.guess and build/config.sub at build time; this was | ||
1675 | 2358 | not done automatically because the top-level configure.in does not use | ||
1676 | 2359 | Automake. | ||
1677 | 2360 | |||
1678 | 2361 | -- Colin Watson <cjwatson@ubuntu.com> Tue, 08 Oct 2013 17:24:59 +0100 | ||
1679 | 2362 | |||
1680 | 2363 | openldap (2.4.31-1+nmu2ubuntu2) saucy; urgency=low | ||
1681 | 2364 | |||
1682 | 2365 | * debian/control: added lsb-release | ||
1683 | 2366 | * debian/patches/fix-ldap-distribution.patch: show distribution in version | ||
1684 | 2367 | |||
1685 | 2368 | -- Yolanda Robla <yolanda.robla@canonical.com> Mon, 08 Jul 2013 16:53:09 +0200 | ||
1686 | 2369 | |||
1687 | 2370 | openldap (2.4.31-1+nmu2ubuntu1) saucy; urgency=low | ||
1688 | 2371 | |||
1689 | 2372 | * Merge from Debian unstable. Remaining changes: | ||
1690 | 2373 | - Enable AppArmor support: | ||
1691 | 2374 | - d/apparmor-profile: add AppArmor profile | ||
1692 | 2375 | - d/rules: use dh_apparmor | ||
1693 | 2376 | - d/control: Build-Depends on dh-apparmor | ||
1694 | 2377 | - d/slapd.README.Debian: add note about AppArmor | ||
1695 | 2378 | - d/slapd.dirs: add etc/apparmor.d/force-complain | ||
1696 | 2379 | - Enable GSSAPI support: | ||
1697 | 2380 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1698 | 2381 | - Add --with-gssapi support | ||
1699 | 2382 | - Make guess_service_principal() more robust when determining | ||
1700 | 2383 | principal | ||
1701 | 2384 | - d/configure.options: Configure with --with-gssapi | ||
1702 | 2385 | - d/control: Added libkrb5-dev as a build depend | ||
1703 | 2386 | - Enable ufw support: | ||
1704 | 2387 | - d/control: suggest ufw. | ||
1705 | 2388 | - d/rules: install ufw profile. | ||
1706 | 2389 | - d/slapd.ufw.profile: add ufw profile. | ||
1707 | 2390 | - Enable nss overlay: | ||
1708 | 2391 | - d/{patches/nssov-build,/rules}: Apply, build and package the | ||
1709 | 2392 | nss overlay. | ||
1710 | 2393 | - d/{rules,slapd.py}: Add apport hook. | ||
1711 | 2394 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1712 | 2395 | either the default DIT nor via an Authn mapping. | ||
1713 | 2396 | - d/slapd.scripts-common: | ||
1714 | 2397 | - add slapcat_opts to local variables. | ||
1715 | 2398 | - Remove unused variable new_conf. | ||
1716 | 2399 | - Fix backup directory naming for multiple reconfiguration. | ||
1717 | 2400 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1718 | 2401 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1719 | 2402 | in the openldap library, as required by Likewise-Open | ||
1720 | 2403 | - d/{control,rules}: enable PIE hardening | ||
1721 | 2404 | |||
1722 | 2405 | -- Marc Deslauriers <marc.deslauriers@ubuntu.com> Thu, 30 May 2013 13:03:25 -0400 | ||
1723 | 2406 | |||
1724 | 2407 | openldap (2.4.31-1+nmu2) unstable; urgency=high | ||
1725 | 2408 | |||
1726 | 2409 | * Non-maintainer upload. | ||
1727 | 2410 | * No-change rebuild in a clean environment | ||
1728 | 2411 | |||
1729 | 2412 | -- Jonathan Wiltshire <jmw@debian.org> Tue, 23 Apr 2013 13:10:00 +0100 | ||
1730 | 2413 | |||
1731 | 2414 | openldap (2.4.31-1+nmu1) unstable; urgency=medium | ||
1732 | 2415 | |||
1733 | 2416 | * Non-maintainer upload. | ||
1734 | 2417 | * Avoid deadlocks in back-bdb that truncate slapcat output (closes: #673038). | ||
1735 | 2418 | |||
1736 | 2419 | -- Michael Gilbert <mgilbert@debian.org> Tue, 16 Apr 2013 03:35:31 +0000 | ||
1737 | 2420 | |||
1738 | 2421 | openldap (2.4.31-1ubuntu2) quantal-proposed; urgency=low | ||
1739 | 2422 | |||
1740 | 2423 | * debian/slapd.py: Add AppArmor info and logs to apport hook. | ||
1741 | 2424 | |||
1742 | 2425 | -- Marc Deslauriers <marc.deslauriers@ubuntu.com> Mon, 20 Aug 2012 08:46:02 -0400 | ||
1743 | 2426 | |||
1744 | 2427 | openldap (2.4.31-1ubuntu1) quantal; urgency=low | ||
1745 | 2428 | |||
1746 | 2429 | * Merge from Debian unstable. Remaining changes: | ||
1747 | 2430 | - Enable AppArmor support: | ||
1748 | 2431 | - d/apparmor-profile: add AppArmor profile | ||
1749 | 2432 | - d/rules: use dh_apparmor | ||
1750 | 2433 | - d/control: Build-Depends on dh-apparmor | ||
1751 | 2434 | - d/slapd.README.Debian: add note about AppArmor | ||
1752 | 2435 | - d/slapd.dirs: add etc/apparmor.d/force-complain | ||
1753 | 2436 | - Enable GSSAPI support (LP: #495418): | ||
1754 | 2437 | - d/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1755 | 2438 | - Add --with-gssapi support | ||
1756 | 2439 | - Make guess_service_principal() more robust when determining | ||
1757 | 2440 | principal | ||
1758 | 2441 | - d/configure.options: Configure with --with-gssapi | ||
1759 | 2442 | - d/control: Added libkrb5-dev as a build depend | ||
1760 | 2443 | - Enable ufw support (LP: #423246): | ||
1761 | 2444 | - d/control: suggest ufw. | ||
1762 | 2445 | - d/rules: install ufw profile. | ||
1763 | 2446 | - d/slapd.ufw.profile: add ufw profile. | ||
1764 | 2447 | - Enable nss overlay (LP: #675391): | ||
1765 | 2448 | - d/{patches/nssov-build,/rules}: Apply, build and package the | ||
1766 | 2449 | nss overlay. | ||
1767 | 2450 | - d/{rules,slapd.py}: Add apport hook. (LP: #610544) | ||
1768 | 2451 | - d/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1769 | 2452 | either the default DIT nor via an Authn mapping. | ||
1770 | 2453 | - d/slapd.scripts-common: | ||
1771 | 2454 | - add slapcat_opts to local variables. | ||
1772 | 2455 | - Remove unused variable new_conf. | ||
1773 | 2456 | - Fix backup directory naming for multiple reconfiguration. | ||
1774 | 2457 | - d/{slapd.default,slapd.README.Debian}: use the new configuration style. | ||
1775 | 2458 | - d/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1776 | 2459 | in the openldap library, as required by Likewise-Open (LP: #390579) | ||
1777 | 2460 | - d/{control,rules}: enable PIE hardening | ||
1778 | 2461 | * Dropped changes: | ||
1779 | 2462 | - d/patches/its-7107-fix-Operation-init-on-reuse.diff: Included in upstream release. | ||
1780 | 2463 | - d/patches/CVE-2011-4079: Included in upstream release. | ||
1781 | 2464 | - d/patches/service-operational-before-detach: Included in upstream release. | ||
1782 | 2465 | - d/schema/extra/misc.ldif: Included upstream. | ||
1783 | 2466 | - d/{rules,schema/extra}: Fix configure and clean rules to support | ||
1784 | 2467 | extra schemas shipped as part of the debian/schema/ directory; no longer required. | ||
1785 | 2468 | - Included in Debian: | ||
1786 | 2469 | + Document cn=config in README file. | ||
1787 | 2470 | + Install a default DIT; actually a minimal configuration. | ||
1788 | 2471 | + d/patches/heimdal-fix. | ||
1789 | 2472 | * General tidy of d/patches to remove obsolete patches being held in Ubuntu delta. | ||
1790 | 2473 | |||
1791 | 2474 | -- James Page <james.page@ubuntu.com> Fri, 20 Jul 2012 13:48:32 +0100 | ||
1792 | 2475 | |||
1793 | 923 | openldap (2.4.31-1) unstable; urgency=low | 2476 | openldap (2.4.31-1) unstable; urgency=low |
1794 | 924 | 2477 | ||
1795 | 925 | * New upstream release. | 2478 | * New upstream release. |
1796 | @@ -946,6 +2499,121 @@ openldap (2.4.31-1) unstable; urgency=low | |||
1797 | 946 | 2499 | ||
1798 | 947 | -- Steve Langasek <vorlon@debian.org> Wed, 27 Jun 2012 03:27:34 +0000 | 2500 | -- Steve Langasek <vorlon@debian.org> Wed, 27 Jun 2012 03:27:34 +0000 |
1799 | 948 | 2501 | ||
1800 | 2502 | openldap (2.4.28-1.1ubuntu6) quantal; urgency=low | ||
1801 | 2503 | |||
1802 | 2504 | * Fix issue with intermittent connection issues when using LDAPv3 | ||
1803 | 2505 | protocol (LP: #1023025): | ||
1804 | 2506 | - d/patches/its-7107-fix-Operation-init-on-reuse.diff: Cherry picked | ||
1805 | 2507 | patch from upstream VCS which ensures objects are initialized before | ||
1806 | 2508 | re-use. | ||
1807 | 2509 | |||
1808 | 2510 | -- Pierre Fersing <pfersing@sierrawireless.com> Thu, 19 Jul 2012 14:05:09 +0100 | ||
1809 | 2511 | |||
1810 | 2512 | openldap (2.4.28-1.1ubuntu5) quantal; urgency=low | ||
1811 | 2513 | |||
1812 | 2514 | * debian/rules: Add smbk5pwd build. | ||
1813 | 2515 | * debian/control: Add slapd-smbk5pwd binary package. | ||
1814 | 2516 | * debian/patches/heimdal-fix: adapt parameters of | ||
1815 | 2517 | hdb_generate_key_set_password() to heimdal 1.6~git20120311 | ||
1816 | 2518 | (patch from Debian #664930). | ||
1817 | 2519 | |||
1818 | 2520 | -- Jorge Salamero Sanz <bencer@debian.org> Wed, 18 Jul 2012 09:30:28 -0400 | ||
1819 | 2521 | |||
1820 | 2522 | openldap (2.4.28-1.1ubuntu4) precise; urgency=low | ||
1821 | 2523 | |||
1822 | 2524 | * debian/control: Build-Depends on dh-apparmor (LP: #948481) | ||
1823 | 2525 | |||
1824 | 2526 | -- Jamie Strandboge <jamie@ubuntu.com> Thu, 05 Apr 2012 09:34:37 -0500 | ||
1825 | 2527 | |||
1826 | 2528 | openldap (2.4.28-1.1ubuntu3) precise; urgency=low | ||
1827 | 2529 | |||
1828 | 2530 | * Add its-7176-only-poll-sockets-for-write-as-needed.diff | ||
1829 | 2531 | (LP: #932823). | ||
1830 | 2532 | |||
1831 | 2533 | -- Timo Aaltonen <tjaalton@ubuntu.com> Tue, 21 Feb 2012 15:36:29 +0200 | ||
1832 | 2534 | |||
1833 | 2535 | openldap (2.4.28-1.1ubuntu2) precise; urgency=low | ||
1834 | 2536 | |||
1835 | 2537 | * Remove debian/patches/CVE-2011-4079; it's already in this upstream | ||
1836 | 2538 | version. Fixes FTBFS. | ||
1837 | 2539 | |||
1838 | 2540 | -- Daniel T Chen <crimsun@ubuntu.com> Wed, 25 Jan 2012 17:26:17 -0500 | ||
1839 | 2541 | |||
1840 | 2542 | openldap (2.4.28-1.1ubuntu1) precise; urgency=low | ||
1841 | 2543 | |||
1842 | 2544 | * Merge from Debian testing. Remaining changes: | ||
1843 | 2545 | - Install a default DIT (LP: #442498). | ||
1844 | 2546 | - Document cn=config in README file (LP: #370784). | ||
1845 | 2547 | - remaining changes: | ||
1846 | 2548 | + AppArmor support: | ||
1847 | 2549 | - debian/apparmor-profile: add AppArmor profile | ||
1848 | 2550 | - use dh_apparmor: | ||
1849 | 2551 | - debian/rules: use dh_apparmor | ||
1850 | 2552 | - debian/control: Build-Depends on debhelper 7.4.20ubuntu5 | ||
1851 | 2553 | - updated debian/slapd.README.Debian for note on AppArmor | ||
1852 | 2554 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
1853 | 2555 | + Enable GSSAPI support (LP: #495418): | ||
1854 | 2556 | - debian/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1855 | 2557 | - Add --with-gssapi support | ||
1856 | 2558 | - Make guess_service_principal() more robust when determining | ||
1857 | 2559 | principal | ||
1858 | 2560 | - debian/patches/series: apply gssapi.diff patch. | ||
1859 | 2561 | - debian/configure.options: Configure with --with-gssapi | ||
1860 | 2562 | - debian/control: Added libkrb5-dev as a build depend | ||
1861 | 2563 | + debian/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1862 | 2564 | in the openldap library, as required by Likewise-Open (LP: #390579) | ||
1863 | 2565 | + Don't build smbk5pwd overlay since it uses heimdal instead of krb5: | ||
1864 | 2566 | - debian/control: | ||
1865 | 2567 | - remove build-dependency on heimdal-dev. | ||
1866 | 2568 | - remove slapd-smbk5pwd binary package. | ||
1867 | 2569 | - debian/rules: don't build smbk5pwd slapd module. | ||
1868 | 2570 | + debian/{control,rules}: enable PIE hardening | ||
1869 | 2571 | + ufw support (LP: #423246): | ||
1870 | 2572 | - debian/control: suggest ufw. | ||
1871 | 2573 | - debian/rules: install ufw profile. | ||
1872 | 2574 | - debian/slapd.ufw.profile: add ufw profile. | ||
1873 | 2575 | + Enable nssoverlay: | ||
1874 | 2576 | - debian/patches/nssov-build, debian/series, debian/rules: | ||
1875 | 2577 | Apply, build and package the nss overlay. | ||
1876 | 2578 | - debian/schema/extra/misc.ldif: add ldif file for the misc schema | ||
1877 | 2579 | which defines rfc822MailMember (required by the nss overlay). | ||
1878 | 2580 | + debian/rules, debian/schema/extra/: | ||
1879 | 2581 | Fix configure rule to supports extra schemas shipped as part | ||
1880 | 2582 | of the debian/schema/ directory. | ||
1881 | 2583 | + debian/rules, debian/slapd.py: Add apport hook. (LP: #610544) | ||
1882 | 2584 | + debian/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1883 | 2585 | neither the default DIT nor via an Authn mapping. | ||
1884 | 2586 | + debian/slapd.scripts-common: adjust minimum version that triggers a | ||
1885 | 2587 | database upgrade. Upgrade from maverick shouldn't trigger database | ||
1886 | 2588 | upgrade (which would happen with the version used in Debian). | ||
1887 | 2589 | + debian/slapd.scripts-common: add slapcat_opts to local variables. | ||
1888 | 2590 | Remove unused variable new_conf. | ||
1889 | 2591 | + debian/slapd.script-common: Fix package reconfiguration. | ||
1890 | 2592 | - Fix backup directory naming for multiple reconfiguration. | ||
1891 | 2593 | + debian/slapd.default, debian/slapd.README.Debian: | ||
1892 | 2594 | use the new configuration style. | ||
1893 | 2595 | + Install nss overlay (LP: #675391): | ||
1894 | 2596 | - debian/rules: run install target for nssov module. | ||
1895 | 2597 | - debian/patches/nssov-build: fix patch to install schema in /etc/ldap/schema | ||
1896 | 2598 | + debian/patches/gssapi.diff: | ||
1897 | 2599 | - Update patch so that likewise-open is usuable again. (LP: #661547) | ||
1898 | 2600 | + debian/patches/service-operational-before-detach: New patch replacing old one | ||
1899 | 2601 | of the same name as previous could cause database corruption based on upstream commits. | ||
1900 | 2602 | (LP: #727973) | ||
1901 | 2603 | + debian/patches/CVE-2011-4079: fix off by one error in postalAddressNormalize() | ||
1902 | 2604 | (CVE-2011-4079) | ||
1903 | 2605 | |||
1904 | 2606 | |||
1905 | 2607 | -- Chuck Short <zulcss@ubuntu.com> Mon, 23 Jan 2012 10:01:13 -0500 | ||
1906 | 2608 | |||
1907 | 2609 | openldap (2.4.28-1.1) unstable; urgency=low | ||
1908 | 2610 | |||
1909 | 2611 | * Non-maintainer upload. | ||
1910 | 2612 | * Disable the mdb backend on non-Linux, it looks like it doesn't work with | ||
1911 | 2613 | linuxthreads (closes: #654824). | ||
1912 | 2614 | |||
1913 | 2615 | -- Julien Cristau <jcristau@debian.org> Mon, 16 Jan 2012 19:45:42 +0100 | ||
1914 | 2616 | |||
1915 | 949 | openldap (2.4.28-1) unstable; urgency=low | 2617 | openldap (2.4.28-1) unstable; urgency=low |
1916 | 950 | 2618 | ||
1917 | 951 | * New upstream release. | 2619 | * New upstream release. |
1918 | @@ -973,6 +2641,72 @@ openldap (2.4.28-1) unstable; urgency=low | |||
1919 | 973 | 2641 | ||
1920 | 974 | -- Steve Langasek <vorlon@debian.org> Thu, 05 Jan 2012 06:07:11 +0000 | 2642 | -- Steve Langasek <vorlon@debian.org> Thu, 05 Jan 2012 06:07:11 +0000 |
1921 | 975 | 2643 | ||
1922 | 2644 | openldap (2.4.25-4ubuntu1) precise; urgency=low | ||
1923 | 2645 | |||
1924 | 2646 | * Merge from Debian testing. Remaining changes: | ||
1925 | 2647 | - Install a default DIT (LP: #442498). | ||
1926 | 2648 | - Document cn=config in README file (LP: #370784). | ||
1927 | 2649 | - remaining changes: | ||
1928 | 2650 | + AppArmor support: | ||
1929 | 2651 | - debian/apparmor-profile: add AppArmor profile | ||
1930 | 2652 | - use dh_apparmor: | ||
1931 | 2653 | - debian/rules: use dh_apparmor | ||
1932 | 2654 | - debian/control: Build-Depends on debhelper 7.4.20ubuntu5 | ||
1933 | 2655 | - updated debian/slapd.README.Debian for note on AppArmor | ||
1934 | 2656 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
1935 | 2657 | + Enable GSSAPI support (LP: #495418): | ||
1936 | 2658 | - debian/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
1937 | 2659 | - Add --with-gssapi support | ||
1938 | 2660 | - Make guess_service_principal() more robust when determining | ||
1939 | 2661 | principal | ||
1940 | 2662 | - debian/patches/series: apply gssapi.diff patch. | ||
1941 | 2663 | - debian/configure.options: Configure with --with-gssapi | ||
1942 | 2664 | - debian/control: Added libkrb5-dev as a build depend | ||
1943 | 2665 | + debian/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
1944 | 2666 | in the openldap library, as required by Likewise-Open (LP: #390579) | ||
1945 | 2667 | + Don't build smbk5pwd overlay since it uses heimdal instead of krb5: | ||
1946 | 2668 | - debian/control: | ||
1947 | 2669 | - remove build-dependency on heimdal-dev. | ||
1948 | 2670 | - remove slapd-smbk5pwd binary package. | ||
1949 | 2671 | - debian/rules: don't build smbk5pwd slapd module. | ||
1950 | 2672 | + debian/{control,rules}: enable PIE hardening | ||
1951 | 2673 | + ufw support (LP: #423246): | ||
1952 | 2674 | - debian/control: suggest ufw. | ||
1953 | 2675 | - debian/rules: install ufw profile. | ||
1954 | 2676 | - debian/slapd.ufw.profile: add ufw profile. | ||
1955 | 2677 | + Enable nssoverlay: | ||
1956 | 2678 | - debian/patches/nssov-build, debian/series, debian/rules: | ||
1957 | 2679 | Apply, build and package the nss overlay. | ||
1958 | 2680 | - debian/schema/extra/misc.ldif: add ldif file for the misc schema | ||
1959 | 2681 | which defines rfc822MailMember (required by the nss overlay). | ||
1960 | 2682 | + debian/rules, debian/schema/extra/: | ||
1961 | 2683 | Fix configure rule to supports extra schemas shipped as part | ||
1962 | 2684 | of the debian/schema/ directory. | ||
1963 | 2685 | + debian/rules, debian/slapd.py: Add apport hook. (LP: #610544) | ||
1964 | 2686 | + debian/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
1965 | 2687 | neither the default DIT nor via an Authn mapping. | ||
1966 | 2688 | + debian/slapd.scripts-common: adjust minimum version that triggers a | ||
1967 | 2689 | database upgrade. Upgrade from maverick shouldn't trigger database | ||
1968 | 2690 | upgrade (which would happen with the version used in Debian). | ||
1969 | 2691 | + debian/slapd.scripts-common: add slapcat_opts to local variables. | ||
1970 | 2692 | Remove unused variable new_conf. | ||
1971 | 2693 | + debian/slapd.script-common: Fix package reconfiguration. | ||
1972 | 2694 | - Fix backup directory naming for multiple reconfiguration. | ||
1973 | 2695 | + debian/slapd.default, debian/slapd.README.Debian: | ||
1974 | 2696 | use the new configuration style. | ||
1975 | 2697 | + Install nss overlay (LP: #675391): | ||
1976 | 2698 | - debian/rules: run install target for nssov module. | ||
1977 | 2699 | - debian/patches/nssov-build: fix patch to install schema in /etc/ldap/schema | ||
1978 | 2700 | + debian/patches/gssapi.diff: | ||
1979 | 2701 | - Update patch so that likewise-open is usuable again. (LP: #661547) | ||
1980 | 2702 | + debian/patches/service-operational-before-detach: New patch replacing old one | ||
1981 | 2703 | of the same name as previous could cause database corruption based on upstream commits. | ||
1982 | 2704 | (LP: #727973) | ||
1983 | 2705 | + debian/patches/CVE-2011-4079: fix off by one error in postalAddressNormalize() | ||
1984 | 2706 | (CVE-2011-4079) | ||
1985 | 2707 | |||
1986 | 2708 | -- Chuck Short <zulcss@ubuntu.com> Tue, 22 Nov 2011 06:17:49 +0000 | ||
1987 | 2709 | |||
1988 | 976 | openldap (2.4.25-4) unstable; urgency=low | 2710 | openldap (2.4.25-4) unstable; urgency=low |
1989 | 977 | 2711 | ||
1990 | 978 | * Drop explicit depends on libdb4.8, since we're now linking against | 2712 | * Drop explicit depends on libdb4.8, since we're now linking against |
1991 | @@ -1006,6 +2740,85 @@ openldap (2.4.25-4) unstable; urgency=low | |||
1992 | 1006 | 2740 | ||
1993 | 1007 | -- Steve Langasek <vorlon@debian.org> Tue, 18 Oct 2011 01:08:34 +0000 | 2741 | -- Steve Langasek <vorlon@debian.org> Tue, 18 Oct 2011 01:08:34 +0000 |
1994 | 1008 | 2742 | ||
1995 | 2743 | openldap (2.4.25-3ubuntu3) precise; urgency=low | ||
1996 | 2744 | |||
1997 | 2745 | * Rebuild for Perl 5.14. | ||
1998 | 2746 | |||
1999 | 2747 | -- Colin Watson <cjwatson@ubuntu.com> Tue, 15 Nov 2011 20:50:09 +0000 | ||
2000 | 2748 | |||
2001 | 2749 | openldap (2.4.25-3ubuntu2) precise; urgency=low | ||
2002 | 2750 | |||
2003 | 2751 | * SECURITY UPDATE: potential denial of service (LP: #884163) | ||
2004 | 2752 | - debian/patches/CVE-2011-4079: fix off by one error in | ||
2005 | 2753 | postalAddressNormalize() | ||
2006 | 2754 | - CVE-2011-4079 | ||
2007 | 2755 | |||
2008 | 2756 | -- Jamie Strandboge <jamie@ubuntu.com> Mon, 14 Nov 2011 13:59:56 -0600 | ||
2009 | 2757 | |||
2010 | 2758 | openldap (2.4.25-3ubuntu1) precise; urgency=low | ||
2011 | 2759 | |||
2012 | 2760 | * Merge from debian unstable. Remaining changes: | ||
2013 | 2761 | - Install a default DIT (LP: #442498). | ||
2014 | 2762 | - Document cn=config in README file (LP: #370784). | ||
2015 | 2763 | - remaining changes: | ||
2016 | 2764 | + AppArmor support: | ||
2017 | 2765 | - debian/apparmor-profile: add AppArmor profile | ||
2018 | 2766 | - use dh_apparmor: | ||
2019 | 2767 | - debian/rules: use dh_apparmor | ||
2020 | 2768 | - debian/control: Build-Depends on debhelper 7.4.20ubuntu5 | ||
2021 | 2769 | - updated debian/slapd.README.Debian for note on AppArmor | ||
2022 | 2770 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
2023 | 2771 | + Enable GSSAPI support (LP: #495418): | ||
2024 | 2772 | - debian/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
2025 | 2773 | - Add --with-gssapi support | ||
2026 | 2774 | - Make guess_service_principal() more robust when determining | ||
2027 | 2775 | principal | ||
2028 | 2776 | - debian/patches/series: apply gssapi.diff patch. | ||
2029 | 2777 | - debian/configure.options: Configure with --with-gssapi | ||
2030 | 2778 | - debian/control: Added libkrb5-dev as a build depend | ||
2031 | 2779 | + debian/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
2032 | 2780 | in the openldap library, as required by Likewise-Open (LP: #390579) | ||
2033 | 2781 | + Don't build smbk5pwd overlay since it uses heimdal instead of krb5: | ||
2034 | 2782 | - debian/control: | ||
2035 | 2783 | - remove build-dependency on heimdal-dev. | ||
2036 | 2784 | - remove slapd-smbk5pwd binary package. | ||
2037 | 2785 | - debian/rules: don't build smbk5pwd slapd module. | ||
2038 | 2786 | + debian/{control,rules}: enable PIE hardening | ||
2039 | 2787 | + ufw support (LP: #423246): | ||
2040 | 2788 | - debian/control: suggest ufw. | ||
2041 | 2789 | - debian/rules: install ufw profile. | ||
2042 | 2790 | - debian/slapd.ufw.profile: add ufw profile. | ||
2043 | 2791 | + Enable nssoverlay: | ||
2044 | 2792 | - debian/patches/nssov-build, debian/series, debian/rules: | ||
2045 | 2793 | Apply, build and package the nss overlay. | ||
2046 | 2794 | - debian/schema/extra/misc.ldif: add ldif file for the misc schema | ||
2047 | 2795 | which defines rfc822MailMember (required by the nss overlay). | ||
2048 | 2796 | + debian/rules, debian/schema/extra/: | ||
2049 | 2797 | Fix configure rule to supports extra schemas shipped as part | ||
2050 | 2798 | of the debian/schema/ directory. | ||
2051 | 2799 | + debian/rules, debian/slapd.py: Add apport hook. (LP: #610544) | ||
2052 | 2800 | + debian/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
2053 | 2801 | neither the default DIT nor via an Authn mapping. | ||
2054 | 2802 | + debian/slapd.scripts-common: adjust minimum version that triggers a | ||
2055 | 2803 | database upgrade. Upgrade from maverick shouldn't trigger database | ||
2056 | 2804 | upgrade (which would happen with the version used in Debian). | ||
2057 | 2805 | + debian/slapd.scripts-common: add slapcat_opts to local variables. | ||
2058 | 2806 | Remove unused variable new_conf. | ||
2059 | 2807 | + debian/slapd.script-common: Fix package reconfiguration. | ||
2060 | 2808 | - Fix backup directory naming for multiple reconfiguration. | ||
2061 | 2809 | + debian/slapd.default, debian/slapd.README.Debian: | ||
2062 | 2810 | use the new configuration style. | ||
2063 | 2811 | + Install nss overlay (LP: #675391): | ||
2064 | 2812 | - debian/rules: run install target for nssov module. | ||
2065 | 2813 | - debian/patches/nssov-build: fix patch to install schema in /etc/ldap/schema | ||
2066 | 2814 | + debian/patches/gssapi.diff: | ||
2067 | 2815 | - Update patch so that likewise-open is usuable again. (LP: #661547) | ||
2068 | 2816 | + debian/patches/service-operational-before-detach: New patch replacing old one | ||
2069 | 2817 | of the same name as previous could cause database corruption based on upstream commits. | ||
2070 | 2818 | (LP: #727973) | ||
2071 | 2819 | |||
2072 | 2820 | -- Chuck Short <zulcss@ubuntu.com> Wed, 19 Oct 2011 20:53:08 +0000 | ||
2073 | 2821 | |||
2074 | 1009 | openldap (2.4.25-3) unstable; urgency=low | 2822 | openldap (2.4.25-3) unstable; urgency=low |
2075 | 1010 | 2823 | ||
2076 | 1011 | * Brown paper bag: really fix the .links.in handling, so we don't generate | 2824 | * Brown paper bag: really fix the .links.in handling, so we don't generate |
2077 | @@ -1028,6 +2841,92 @@ openldap (2.4.25-2) unstable; urgency=low | |||
2078 | 1028 | 2841 | ||
2079 | 1029 | -- Steve Langasek <vorlon@debian.org> Sun, 14 Aug 2011 23:17:09 -0700 | 2842 | -- Steve Langasek <vorlon@debian.org> Sun, 14 Aug 2011 23:17:09 -0700 |
2080 | 1030 | 2843 | ||
2081 | 2844 | openldap (2.4.25-1.1ubuntu4) oneiric; urgency=low | ||
2082 | 2845 | |||
2083 | 2846 | * Brown paper bag: really fix the .links.in handling, so we don't generate | ||
2084 | 2847 | broken /usr/lib/${DEB_HOST_MULTIARCH} dirs. | ||
2085 | 2848 | |||
2086 | 2849 | -- Steve Langasek <steve.langasek@ubuntu.com> Mon, 15 Aug 2011 09:43:29 +0000 | ||
2087 | 2850 | |||
2088 | 2851 | openldap (2.4.25-1.1ubuntu3) oneiric; urgency=low | ||
2089 | 2852 | |||
2090 | 2853 | * Cherry-pick multiarch support from Debian (LP: #826601): | ||
2091 | 2854 | - Bump to compat level 7, so we don't have to spell out debian/tmp in | ||
2092 | 2855 | every single .install file | ||
2093 | 2856 | - Build for multiarch. | ||
2094 | 2857 | |||
2095 | 2858 | -- Steve Langasek <steve.langasek@ubuntu.com> Mon, 15 Aug 2011 02:23:43 -0700 | ||
2096 | 2859 | |||
2097 | 2860 | openldap (2.4.25-1.1ubuntu2) oneiric; urgency=low | ||
2098 | 2861 | |||
2099 | 2862 | * debian/apparmor-profile: Allow /var/run and /run. (LP: #810270) | ||
2100 | 2863 | |||
2101 | 2864 | -- Martin Pitt <martin.pitt@ubuntu.com> Thu, 14 Jul 2011 15:18:02 +0200 | ||
2102 | 2865 | |||
2103 | 2866 | openldap (2.4.25-1.1ubuntu1) oneiric; urgency=low | ||
2104 | 2867 | |||
2105 | 2868 | * Merge from debian unstable. Remaining changes: | ||
2106 | 2869 | - Install a default DIT (LP: #442498). | ||
2107 | 2870 | - Document cn=config in README file (LP: #370784). | ||
2108 | 2871 | - remaining changes: | ||
2109 | 2872 | + AppArmor support: | ||
2110 | 2873 | - debian/apparmor-profile: add AppArmor profile | ||
2111 | 2874 | - use dh_apparmor: | ||
2112 | 2875 | - debian/rules: use dh_apparmor | ||
2113 | 2876 | - debian/control: Build-Depends on debhelper 7.4.20ubuntu5 | ||
2114 | 2877 | - updated debian/slapd.README.Debian for note on AppArmor | ||
2115 | 2878 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
2116 | 2879 | + Enable GSSAPI support (LP: #495418): | ||
2117 | 2880 | - debian/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
2118 | 2881 | - Add --with-gssapi support | ||
2119 | 2882 | - Make guess_service_principal() more robust when determining | ||
2120 | 2883 | principal | ||
2121 | 2884 | - debian/patches/series: apply gssapi.diff patch. | ||
2122 | 2885 | - debian/configure.options: Configure with --with-gssapi | ||
2123 | 2886 | - debian/control: Added libkrb5-dev as a build depend | ||
2124 | 2887 | + debian/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
2125 | 2888 | in the openldap library, as required by Likewise-Open (LP: #390579) | ||
2126 | 2889 | + Don't build smbk5pwd overlay since it uses heimdal instead of krb5: | ||
2127 | 2890 | - debian/control: | ||
2128 | 2891 | - remove build-dependency on heimdal-dev. | ||
2129 | 2892 | - remove slapd-smbk5pwd binary package. | ||
2130 | 2893 | - debian/rules: don't build smbk5pwd slapd module. | ||
2131 | 2894 | + debian/{control,rules}: enable PIE hardening | ||
2132 | 2895 | + ufw support (LP: #423246): | ||
2133 | 2896 | - debian/control: suggest ufw. | ||
2134 | 2897 | - debian/rules: install ufw profile. | ||
2135 | 2898 | - debian/slapd.ufw.profile: add ufw profile. | ||
2136 | 2899 | + Enable nssoverlay: | ||
2137 | 2900 | - debian/patches/nssov-build, debian/series, debian/rules: | ||
2138 | 2901 | Apply, build and package the nss overlay. | ||
2139 | 2902 | - debian/schema/extra/misc.ldif: add ldif file for the misc schema | ||
2140 | 2903 | which defines rfc822MailMember (required by the nss overlay). | ||
2141 | 2904 | + debian/rules, debian/schema/extra/: | ||
2142 | 2905 | Fix configure rule to supports extra schemas shipped as part | ||
2143 | 2906 | of the debian/schema/ directory. | ||
2144 | 2907 | + debian/rules, debian/slapd.py: Add apport hook. (LP: #610544) | ||
2145 | 2908 | + debian/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
2146 | 2909 | neither the default DIT nor via an Authn mapping. | ||
2147 | 2910 | + debian/slapd.scripts-common: adjust minimum version that triggers a | ||
2148 | 2911 | database upgrade. Upgrade from maverick shouldn't trigger database | ||
2149 | 2912 | upgrade (which would happen with the version used in Debian). | ||
2150 | 2913 | + debian/slapd.scripts-common: add slapcat_opts to local variables. | ||
2151 | 2914 | Remove unused variable new_conf. | ||
2152 | 2915 | + debian/slapd.script-common: Fix package reconfiguration. | ||
2153 | 2916 | - Fix backup directory naming for multiple reconfiguration. | ||
2154 | 2917 | + debian/slapd.default, debian/slapd.README.Debian: | ||
2155 | 2918 | use the new configuration style. | ||
2156 | 2919 | + Install nss overlay (LP: #675391): | ||
2157 | 2920 | - debian/rules: run install target for nssov module. | ||
2158 | 2921 | - debian/patches/nssov-build: fix patch to install schema in /etc/ldap/schema | ||
2159 | 2922 | + debian/patches/gssapi.diff: | ||
2160 | 2923 | - Update patch so that likewise-open is usuable again. (LP: #661547) | ||
2161 | 2924 | + debian/patches/service-operational-before-detach: New patch replacing old one | ||
2162 | 2925 | of the same name as previous could cause database corruption based on upstream commits. | ||
2163 | 2926 | (LP: #727973) | ||
2164 | 2927 | |||
2165 | 2928 | -- Chuck Short <zulcss@ubuntu.com> Sun, 05 Jun 2011 17:38:40 +0100 | ||
2166 | 2929 | |||
2167 | 1031 | openldap (2.4.25-1.1) unstable; urgency=low | 2930 | openldap (2.4.25-1.1) unstable; urgency=low |
2168 | 1032 | 2931 | ||
2169 | 1033 | * Non-maintainer upload to fix RC bug. | 2932 | * Non-maintainer upload to fix RC bug. |
2170 | @@ -1035,6 +2934,75 @@ openldap (2.4.25-1.1) unstable; urgency=low | |||
2171 | 1035 | 2934 | ||
2172 | 1036 | -- Thijs Kinkhorst <thijs@debian.org> Tue, 31 May 2011 11:57:29 +0200 | 2935 | -- Thijs Kinkhorst <thijs@debian.org> Tue, 31 May 2011 11:57:29 +0200 |
2173 | 1037 | 2936 | ||
2174 | 2937 | openldap (2.4.25-1ubuntu1) oneiric; urgency=low | ||
2175 | 2938 | |||
2176 | 2939 | * Merge from debian unstable. Remaining changes: | ||
2177 | 2940 | - Install a default DIT (LP: #442498). | ||
2178 | 2941 | - Document cn=config in README file (LP: #370784). | ||
2179 | 2942 | - remaining changes: | ||
2180 | 2943 | + AppArmor support: | ||
2181 | 2944 | - debian/apparmor-profile: add AppArmor profile | ||
2182 | 2945 | - use dh_apparmor: | ||
2183 | 2946 | - debian/rules: use dh_apparmor | ||
2184 | 2947 | - debian/control: Build-Depends on debhelper 7.4.20ubuntu5 | ||
2185 | 2948 | - updated debian/slapd.README.Debian for note on AppArmor | ||
2186 | 2949 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
2187 | 2950 | + Enable GSSAPI support (LP: #495418): | ||
2188 | 2951 | - debian/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
2189 | 2952 | - Add --with-gssapi support | ||
2190 | 2953 | - Make guess_service_principal() more robust when determining | ||
2191 | 2954 | principal | ||
2192 | 2955 | - debian/patches/series: apply gssapi.diff patch. | ||
2193 | 2956 | - debian/configure.options: Configure with --with-gssapi | ||
2194 | 2957 | - debian/control: Added libkrb5-dev as a build depend | ||
2195 | 2958 | + debian/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
2196 | 2959 | in the openldap library, as required by Likewise-Open (LP: #390579) | ||
2197 | 2960 | + Don't build smbk5pwd overlay since it uses heimdal instead of krb5: | ||
2198 | 2961 | - debian/control: | ||
2199 | 2962 | - remove build-dependency on heimdal-dev. | ||
2200 | 2963 | - remove slapd-smbk5pwd binary package. | ||
2201 | 2964 | - debian/rules: don't build smbk5pwd slapd module. | ||
2202 | 2965 | + debian/{control,rules}: enable PIE hardening | ||
2203 | 2966 | + ufw support (LP: #423246): | ||
2204 | 2967 | - debian/control: suggest ufw. | ||
2205 | 2968 | - debian/rules: install ufw profile. | ||
2206 | 2969 | - debian/slapd.ufw.profile: add ufw profile. | ||
2207 | 2970 | + Enable nssoverlay: | ||
2208 | 2971 | - debian/patches/nssov-build, debian/series, debian/rules: | ||
2209 | 2972 | Apply, build and package the nss overlay. | ||
2210 | 2973 | - debian/schema/extra/misc.ldif: add ldif file for the misc schema | ||
2211 | 2974 | which defines rfc822MailMember (required by the nss overlay). | ||
2212 | 2975 | + debian/rules, debian/schema/extra/: | ||
2213 | 2976 | Fix configure rule to supports extra schemas shipped as part | ||
2214 | 2977 | of the debian/schema/ directory. | ||
2215 | 2978 | + debian/rules, debian/slapd.py: Add apport hook. (LP: #610544) | ||
2216 | 2979 | + debian/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
2217 | 2980 | neither the default DIT nor via an Authn mapping. | ||
2218 | 2981 | + debian/slapd.scripts-common: adjust minimum version that triggers a | ||
2219 | 2982 | database upgrade. Upgrade from maverick shouldn't trigger database | ||
2220 | 2983 | upgrade (which would happen with the version used in Debian). | ||
2221 | 2984 | + debian/slapd.scripts-common: add slapcat_opts to local variables. | ||
2222 | 2985 | Remove unused variable new_conf. | ||
2223 | 2986 | + debian/slapd.script-common: Fix package reconfiguration. | ||
2224 | 2987 | - Fix backup directory naming for multiple reconfiguration. | ||
2225 | 2988 | + debian/slapd.default, debian/slapd.README.Debian: | ||
2226 | 2989 | use the new configuration style. | ||
2227 | 2990 | + Install nss overlay (LP: #675391): | ||
2228 | 2991 | - debian/rules: run install target for nssov module. | ||
2229 | 2992 | - debian/patches/nssov-build: fix patch to install schema in /etc/ldap/schema | ||
2230 | 2993 | + debian/patches/gssapi.diff: | ||
2231 | 2994 | - Update patch so that likewise-open is usuable again. (LP: #661547) | ||
2232 | 2995 | + debian/patches/service-operational-before-detach: New patch replacing old one | ||
2233 | 2996 | of the same name as previous could cause database corruption based on upstream commits. | ||
2234 | 2997 | (LP: #727973) | ||
2235 | 2998 | + Dropped: | ||
2236 | 2999 | - debian/patches/gold: Use the debian version instead | ||
2237 | 3000 | - debian/patches/CVE-2011-1024: Fixed upstream | ||
2238 | 3001 | - debian/patches/CVE-2011-1025: Fixed upstream | ||
2239 | 3002 | - debian/patches/CVE-2011-1081: Fixed upstream | ||
2240 | 3003 | |||
2241 | 3004 | -- Chuck Short <zulcss@ubuntu.com> Sun, 08 May 2011 16:34:09 +0100 | ||
2242 | 3005 | |||
2243 | 1038 | openldap (2.4.25-1) unstable; urgency=low | 3006 | openldap (2.4.25-1) unstable; urgency=low |
2244 | 1039 | 3007 | ||
2245 | 1040 | * New upstream version (Closes: #617606, #618904, #606815, #608813) | 3008 | * New upstream version (Closes: #617606, #618904, #606815, #608813) |
2246 | @@ -1066,6 +3034,116 @@ openldap (2.4.23-7) unstable; urgency=low | |||
2247 | 1066 | 3034 | ||
2248 | 1067 | -- Matthijs Mohlmann <matthijs@cacholong.nl> Sat, 06 Nov 2010 12:13:01 +0100 | 3035 | -- Matthijs Mohlmann <matthijs@cacholong.nl> Sat, 06 Nov 2010 12:13:01 +0100 |
2249 | 1068 | 3036 | ||
2250 | 3037 | openldap (2.4.23-6ubuntu7) oneiric; urgency=low | ||
2251 | 3038 | |||
2252 | 3039 | * Rebuild for Perl 5.12. | ||
2253 | 3040 | |||
2254 | 3041 | -- Colin Watson <cjwatson@ubuntu.com> Sun, 08 May 2011 13:40:28 +0100 | ||
2255 | 3042 | |||
2256 | 3043 | openldap (2.4.23-6ubuntu6) natty; urgency=low | ||
2257 | 3044 | |||
2258 | 3045 | * SECURITY UPDATE: fix successful anonymous bind via chain overlay when | ||
2259 | 3046 | using forwarded authentication failures | ||
2260 | 3047 | - debian/patches/CVE-2011-1024 | ||
2261 | 3048 | - CVE-2011-1024 | ||
2262 | 3049 | * SECURITY UPDATE: verify password when authenticating to rootdn and using ndb | ||
2263 | 3050 | backend. Note: Ubuntu is not compiled with --enable-ndb by default | ||
2264 | 3051 | - debian/patches/CVE-2011-1025 | ||
2265 | 3052 | - CVE-2011-1025 | ||
2266 | 3053 | * SECURITY UPDATE: fix DoS when processing unauthenticated modrdn requests | ||
2267 | 3054 | and requestDN is empty | ||
2268 | 3055 | - debian/patches/CVE-2011-1081 | ||
2269 | 3056 | - CVE-2011-1081 | ||
2270 | 3057 | - LP: #742104 | ||
2271 | 3058 | |||
2272 | 3059 | -- Jamie Strandboge <jamie@ubuntu.com> Thu, 07 Apr 2011 11:36:53 -0500 | ||
2273 | 3060 | |||
2274 | 3061 | openldap (2.4.23-6ubuntu5) natty; urgency=low | ||
2275 | 3062 | |||
2276 | 3063 | * debian/patches/service-operational-before-detach: New patch replacing | ||
2277 | 3064 | old one of same name as previous could cause database corruption, | ||
2278 | 3065 | based on upstream commits. (LP: #727973) | ||
2279 | 3066 | |||
2280 | 3067 | -- Dave Walker (Daviey) <DaveWalker@ubuntu.com> Wed, 02 Mar 2011 20:33:08 +0000 | ||
2281 | 3068 | |||
2282 | 3069 | openldap (2.4.23-6ubuntu4) natty; urgency=low | ||
2283 | 3070 | |||
2284 | 3071 | * Fix FTBFS with ld.gold. | ||
2285 | 3072 | |||
2286 | 3073 | -- Matthias Klose <doko@ubuntu.com> Wed, 19 Jan 2011 07:39:49 +0100 | ||
2287 | 3074 | |||
2288 | 3075 | openldap (2.4.23-6ubuntu3) natty; urgency=low | ||
2289 | 3076 | |||
2290 | 3077 | * debian/patches/gssapi.diff: | ||
2291 | 3078 | Update patch so that likewise-open is usable again (LP: #661547) | ||
2292 | 3079 | |||
2293 | 3080 | -- Thierry Carrez (ttx) <thierry.carrez@ubuntu.com> Fri, 26 Nov 2010 15:50:11 +0100 | ||
2294 | 3081 | |||
2295 | 3082 | openldap (2.4.23-6ubuntu2) natty; urgency=low | ||
2296 | 3083 | |||
2297 | 3084 | * Install nss overlay (LP: #675391): | ||
2298 | 3085 | - debian/rules: run install target for nssov module. | ||
2299 | 3086 | - debian/patches/nssov-build: fix patch to install schema in | ||
2300 | 3087 | /etc/ldap/schema. | ||
2301 | 3088 | |||
2302 | 3089 | -- Mathias Gug <mathiaz@ubuntu.com> Wed, 17 Nov 2010 18:16:42 -0500 | ||
2303 | 3090 | |||
2304 | 3091 | openldap (2.4.23-6ubuntu1) natty; urgency=low | ||
2305 | 3092 | |||
2306 | 3093 | * Merge from Debian unstable: | ||
2307 | 3094 | - Install a default DIT (LP: #442498). | ||
2308 | 3095 | - Document cn=config in README file (LP: #370784). | ||
2309 | 3096 | - remaining changes: | ||
2310 | 3097 | + AppArmor support: | ||
2311 | 3098 | - debian/apparmor-profile: add AppArmor profile | ||
2312 | 3099 | - use dh_apparmor: | ||
2313 | 3100 | - debian/rules: use dh_apparmor | ||
2314 | 3101 | - debian/control: Build-Depends on debhelper 7.4.20ubuntu5 | ||
2315 | 3102 | - updated debian/slapd.README.Debian for note on AppArmor | ||
2316 | 3103 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
2317 | 3104 | + Enable GSSAPI support (LP: #495418): | ||
2318 | 3105 | - debian/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
2319 | 3106 | - Add --with-gssapi support | ||
2320 | 3107 | - Make guess_service_principal() more robust when determining | ||
2321 | 3108 | principal | ||
2322 | 3109 | - debian/patches/series: apply gssapi.diff patch. | ||
2323 | 3110 | - debian/configure.options: Configure with --with-gssapi | ||
2324 | 3111 | - debian/control: Added libkrb5-dev as a build depend | ||
2325 | 3112 | + debian/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
2326 | 3113 | in the openldap library, as required by Likewise-Open (LP: #390579) | ||
2327 | 3114 | + Don't build smbk5pwd overlay since it uses heimdal instead of krb5: | ||
2328 | 3115 | - debian/control: | ||
2329 | 3116 | - remove build-dependency on heimdal-dev. | ||
2330 | 3117 | - remove slapd-smbk5pwd binary package. | ||
2331 | 3118 | - debian/rules: don't build smbk5pwd slapd module. | ||
2332 | 3119 | + debian/{control,rules}: enable PIE hardening | ||
2333 | 3120 | + ufw support (LP: #423246): | ||
2334 | 3121 | - debian/control: suggest ufw. | ||
2335 | 3122 | - debian/rules: install ufw profile. | ||
2336 | 3123 | - debian/slapd.ufw.profile: add ufw profile. | ||
2337 | 3124 | + Enable nssoverlay: | ||
2338 | 3125 | - debian/patches/nssov-build, debian/series, debian/rules: | ||
2339 | 3126 | Apply, build and package the nss overlay. | ||
2340 | 3127 | - debian/schema/extra/misc.ldif: add ldif file for the misc schema | ||
2341 | 3128 | which defines rfc822MailMember (required by the nss overlay). | ||
2342 | 3129 | + debian/rules, debian/schema/extra/: | ||
2343 | 3130 | Fix configure rule to supports extra schemas shipped as part | ||
2344 | 3131 | of the debian/schema/ directory. | ||
2345 | 3132 | + debian/rules, debian/slapd.py: Add apport hook. (LP: #610544) | ||
2346 | 3133 | + debian/slapd.init.ldif: don't set olcRootDN since it's not defined in | ||
2347 | 3134 | neither the default DIT nor via an Authn mapping. | ||
2348 | 3135 | + debian/slapd.scripts-common: adjust minimum version that triggers a | ||
2349 | 3136 | database upgrade. Upgrade from maverick shouldn't trigger database | ||
2350 | 3137 | upgrade (which would happen with the version used in Debian). | ||
2351 | 3138 | + debian/slapd.scripts-common: add slapcat_opts to local variables. | ||
2352 | 3139 | Remove unused variable new_conf. | ||
2353 | 3140 | + debian/slapd.script-common: Fix package reconfiguration. | ||
2354 | 3141 | - Fix backup directory naming for multiple reconfiguration. | ||
2355 | 3142 | + debian/slapd.default, debian/slapd.README.Debian: | ||
2356 | 3143 | use the new configuration style. | ||
2357 | 3144 | |||
2358 | 3145 | -- Mathias Gug <mathiaz@ubuntu.com> Fri, 12 Nov 2010 15:19:07 -0500 | ||
2359 | 3146 | |||
2360 | 1069 | openldap (2.4.23-6) unstable; urgency=high | 3147 | openldap (2.4.23-6) unstable; urgency=high |
2361 | 1070 | 3148 | ||
2362 | 1071 | * Check for an empty directory to prevent an rm -f /*. (Closes: #597704) | 3149 | * Check for an empty directory to prevent an rm -f /*. (Closes: #597704) |
2363 | @@ -1188,6 +3266,80 @@ openldap (2.4.23-1) unstable; urgency=low | |||
2364 | 1188 | 3266 | ||
2365 | 1189 | -- Matthijs Mohlmann <matthijs@cacholong.nl> Mon, 12 Jul 2010 13:25:00 +0200 | 3267 | -- Matthijs Mohlmann <matthijs@cacholong.nl> Mon, 12 Jul 2010 13:25:00 +0200 |
2366 | 1190 | 3268 | ||
2367 | 3269 | openldap (2.4.23-0ubuntu4) natty; urgency=low | ||
2368 | 3270 | |||
2369 | 3271 | * debian/slapd.templates: amended typo in slapd/move_old_database | ||
2370 | 3272 | (LP: #666028) | ||
2371 | 3273 | |||
2372 | 3274 | -- James Page <james.page@canonical.com> Mon, 08 Nov 2010 10:00:58 +0000 | ||
2373 | 3275 | |||
2374 | 3276 | openldap (2.4.23-0ubuntu3.2) maverick-proposed; urgency=low | ||
2375 | 3277 | |||
2376 | 3278 | * debian/slapd.templates: re-add slapd/move_old_database template as it's | ||
2377 | 3279 | used during the package upgrade. Thanks to James Page for pointing it. | ||
2378 | 3280 | * debian/slapd.config: restore debconf question slapd/move_old_database. | ||
2379 | 3281 | |||
2380 | 3282 | -- Mathias Gug <mathiaz@ubuntu.com> Thu, 14 Oct 2010 16:56:38 -0400 | ||
2381 | 3283 | |||
2382 | 3284 | openldap (2.4.23-0ubuntu3.1) maverick-proposed; urgency=low | ||
2383 | 3285 | |||
2384 | 3286 | [ James Page ] | ||
2385 | 3287 | * Fixed install/upgrade process to dump/restore databases due | ||
2386 | 3288 | to uplift to libdb4.8-dev (LP: #658227) | ||
2387 | 3289 | |||
2388 | 3290 | -- Mathias Gug <mathiaz@ubuntu.com> Thu, 14 Oct 2010 14:50:49 -0400 | ||
2389 | 3291 | |||
2390 | 3292 | openldap (2.4.23-0ubuntu3) maverick; urgency=low | ||
2391 | 3293 | |||
2392 | 3294 | * debian/rules: move dh_apparmor before dh_installinit | ||
2393 | 3295 | |||
2394 | 3296 | -- Jamie Strandboge <jamie@ubuntu.com> Fri, 06 Aug 2010 17:34:21 -0500 | ||
2395 | 3297 | |||
2396 | 3298 | openldap (2.4.23-0ubuntu2) maverick; urgency=low | ||
2397 | 3299 | |||
2398 | 3300 | * convert to using dh_apparmor: | ||
2399 | 3301 | - debian/rules, debian/slapd.post{inst,rm}: use dh_apparmor | ||
2400 | 3302 | - debian/control: Build-Depends on debhelper 7.4.20ubuntu5 | ||
2401 | 3303 | * debian/apparmor-profile: use local include | ||
2402 | 3304 | |||
2403 | 3305 | -- Jamie Strandboge <jamie@ubuntu.com> Fri, 06 Aug 2010 15:08:55 -0500 | ||
2404 | 3306 | |||
2405 | 3307 | openldap (2.4.23-0ubuntu1) maverick; urgency=low | ||
2406 | 3308 | |||
2407 | 3309 | * New release, features include: | ||
2408 | 3310 | + Fixed libldap to return server's error code (ITS#6569) | ||
2409 | 3311 | + Fixed libldap memleaks (ITS#6568) | ||
2410 | 3312 | + Fixed liblutil off-by-one with delta (ITS#6541) | ||
2411 | 3313 | + Fixed slapd acls with glued databases (ITS#6468) | ||
2412 | 3314 | + Fixed slapd syncrepl rid logging (ITS#6533) | ||
2413 | 3315 | + Fixed slapd modrdn handling of invalid values (ITS#6570) | ||
2414 | 3316 | + Fixed slapd-bdb hasSubordinates computation (ITS#6549) | ||
2415 | 3317 | + Fixed slapd-bdb to use memcpy instead for strcpy (ITS#6474) | ||
2416 | 3318 | + Fixed slapd-bdb entry cache delete failure (ITS#6577) | ||
2417 | 3319 | + Fixed slapd-ldap to return control responses (ITS#6530) | ||
2418 | 3320 | + Fixed slapo-ppolicy to use Debug (ITS#6566) | ||
2419 | 3321 | + Fixed slapo-refint to zero out freed DN vals (ITS#6572) | ||
2420 | 3322 | + Fixed slapo-rwm to use Debug (ITS#6566) | ||
2421 | 3323 | + Fixed slapo-sssvlv to use Debug (ITS#6566) | ||
2422 | 3324 | + Fixed slapo-syncprov lost deletes in refresh phase (ITS#6555) | ||
2423 | 3325 | + Fixed slapo-valsort to use Debug (ITS#6566) | ||
2424 | 3326 | + Fixed contrib/nssov network.c missing patch (ITS#6562) | ||
2425 | 3327 | + Fixed test043 attribute sorting (ITS#6553) | ||
2426 | 3328 | + slapd-config(5) note default rootdn (ITS#6546) | ||
2427 | 3329 | * Rebased patches debian/patches/dropped nssov-build | ||
2428 | 3330 | * Resynchronize with Debian: | ||
2429 | 3331 | + debian/control: | ||
2430 | 3332 | - Bump standards-version to 3.9.0 | ||
2431 | 3333 | - Use libdb4.8-dev (LP: #572489) | ||
2432 | 3334 | + Added debian/patches/issue-6534-patch | ||
2433 | 3335 | + Added debian/patches/ldap-conf-tls-cacertdir | ||
2434 | 3336 | * Add ufw support, thanks to PatRiehecky (LP: #423246) | ||
2435 | 3337 | |||
2436 | 3338 | [Adam Sommer] | ||
2437 | 3339 | * debian/rules, debian/slapd.py: Add apport hook. (LP: #610544) | ||
2438 | 3340 | |||
2439 | 3341 | -- Chuck Short <zulcss@ubuntu.com> Wed, 28 Jul 2010 11:35:16 -0400 | ||
2440 | 3342 | |||
2441 | 1191 | openldap (2.4.21-1) unstable; urgency=low | 3343 | openldap (2.4.21-1) unstable; urgency=low |
2442 | 1192 | 3344 | ||
2443 | 1193 | [ Steve Langasek ] | 3345 | [ Steve Langasek ] |
2444 | @@ -1219,6 +3371,79 @@ openldap (2.4.21-1) unstable; urgency=low | |||
2445 | 1219 | 3371 | ||
2446 | 1220 | -- Matthijs Mohlmann <matthijs@cacholong.nl> Thu, 22 Apr 2010 23:40:30 +0200 | 3372 | -- Matthijs Mohlmann <matthijs@cacholong.nl> Thu, 22 Apr 2010 23:40:30 +0200 |
2447 | 1221 | 3373 | ||
2448 | 3374 | openldap (2.4.21-0ubuntu5) lucid; urgency=low | ||
2449 | 3375 | |||
2450 | 3376 | * Fix local root connection access: replace olcAuthzRegexp mapping to | ||
2451 | 3377 | cn=localroot,cn=config with using the SASL dn directly in olcAccess. | ||
2452 | 3378 | Makes upgrades much simpler and robust (LP: #563829). | ||
2453 | 3379 | |||
2454 | 3380 | -- Mathias Gug <mathiaz@ubuntu.com> Fri, 23 Apr 2010 00:23:31 -0400 | ||
2455 | 3381 | |||
2456 | 3382 | openldap (2.4.21-0ubuntu4) lucid; urgency=low | ||
2457 | 3383 | |||
2458 | 3384 | [ Simon Olofsson ] | ||
2459 | 3385 | * debian/slapd.postinst: | ||
2460 | 3386 | - Show a message after successful migration (LP: #538848) | ||
2461 | 3387 | |||
2462 | 3388 | [ Jorgen Rosink ] | ||
2463 | 3389 | * debian/slapd.init: add simple status checking with LSB compatible exit | ||
2464 | 3390 | codes (LP: #562377) | ||
2465 | 3391 | * debian/slapd.init.ldif: | ||
2466 | 3392 | - remove admin user in default config database (LP: #556176) | ||
2467 | 3393 | - in default config, add olcAccess entries giving access to controls | ||
2468 | 3394 | available and cn=subschema (LP: #427842) | ||
2469 | 3395 | |||
2470 | 3396 | [ Scott Moser ] | ||
2471 | 3397 | * debian/slapd.scripts-common: Do not create /nonexistent directory | ||
2472 | 3398 | for openldap user's home (LP: #556176) | ||
2473 | 3399 | * debian/slapd.postinst: fix cn=config olcAccess migration (LP: #559070) | ||
2474 | 3400 | |||
2475 | 3401 | -- Scott Moser <smoser@ubuntu.com> Mon, 12 Apr 2010 16:16:47 -0400 | ||
2476 | 3402 | |||
2477 | 3403 | openldap (2.4.21-0ubuntu3) lucid; urgency=low | ||
2478 | 3404 | |||
2479 | 3405 | * debian/slapd.postinst, debian/slapd.scripts-common: Upgrade databases | ||
2480 | 3406 | before trying to convert to slapd.d, to avoid upgrade failure from hardy | ||
2481 | 3407 | (LP: #536958) | ||
2482 | 3408 | * debian/slapd.postinst: Add a {1} numeric index to olcAccess entry in | ||
2483 | 3409 | olcDatabase={0}config.ldif to avoid upgrade failures (LP: #538516, #526230) | ||
2484 | 3410 | |||
2485 | 3411 | -- Thierry Carrez <thierry.carrez@ubuntu.com> Mon, 29 Mar 2010 13:31:47 +0200 | ||
2486 | 3412 | |||
2487 | 3413 | openldap (2.4.21-0ubuntu2) lucid; urgency=low | ||
2488 | 3414 | |||
2489 | 3415 | * debian/apparmor-profile: Update apparmor profile. (LP: #508190) | ||
2490 | 3416 | |||
2491 | 3417 | -- Chuck Short <zulcss@ubuntu.com> Tue, 09 Mar 2010 13:33:35 -0500 | ||
2492 | 3418 | |||
2493 | 3419 | openldap (2.4.21-0ubuntu1) lucid; urgency=low | ||
2494 | 3420 | |||
2495 | 3421 | * New upstream release. | ||
2496 | 3422 | * debian/rules, debian/schema/extra/: | ||
2497 | 3423 | Fix get-orig-source rule to supports extra schemas shipped as part of the | ||
2498 | 3424 | debian/schema/ directory. | ||
2499 | 3425 | |||
2500 | 3426 | -- Mathias Gug <mathiaz@ubuntu.com> Thu, 18 Feb 2010 00:58:13 -0500 | ||
2501 | 3427 | |||
2502 | 3428 | openldap (2.4.18-0ubuntu2) lucid; urgency=low | ||
2503 | 3429 | |||
2504 | 3430 | * debian/patches/gssapi.diff, thanks to Jerry Carter (Likewise): | ||
2505 | 3431 | - Add --with-gssapi support | ||
2506 | 3432 | - Make guess_service_principal() more robust when determining principal | ||
2507 | 3433 | * Enable GSSAPI support (LP: #495418): | ||
2508 | 3434 | - debian/configure.options: Configure with --with-gssapi | ||
2509 | 3435 | - debian/control: Added libkrb5-dev as a build depend | ||
2510 | 3436 | |||
2511 | 3437 | -- Thierry Carrez <thierry.carrez@ubuntu.com> Fri, 11 Dec 2009 11:31:11 +0100 | ||
2512 | 3438 | |||
2513 | 3439 | openldap (2.4.18-0ubuntu1) karmic; urgency=low | ||
2514 | 3440 | |||
2515 | 3441 | * New upstream release: (LP: #419515): | ||
2516 | 3442 | + pcache overlay supports disconnected mode. | ||
2517 | 3443 | * Fix nss overlay load (LP: #417163). | ||
2518 | 3444 | |||
2519 | 3445 | -- Mathias Gug <mathiaz@ubuntu.com> Mon, 07 Sep 2009 13:41:10 -0400 | ||
2520 | 3446 | |||
2521 | 1222 | openldap (2.4.17-2.1) unstable; urgency=high | 3447 | openldap (2.4.17-2.1) unstable; urgency=high |
2522 | 1223 | 3448 | ||
2523 | 1224 | * Non-maintainer upload by the Security Team. | 3449 | * Non-maintainer upload by the Security Team. |
2524 | @@ -1245,6 +3470,108 @@ openldap (2.4.17-2) unstable; urgency=low | |||
2525 | 1245 | 3470 | ||
2526 | 1246 | -- Steve Langasek <vorlon@debian.org> Tue, 22 Sep 2009 20:06:34 -0700 | 3471 | -- Steve Langasek <vorlon@debian.org> Tue, 22 Sep 2009 20:06:34 -0700 |
2527 | 1247 | 3472 | ||
2528 | 3473 | openldap (2.4.17-1ubuntu3) karmic; urgency=low | ||
2529 | 3474 | |||
2530 | 3475 | * Install a minimal slapd configuration instead of creating a default | ||
2531 | 3476 | database with a default DIT: | ||
2532 | 3477 | + Move openldap user home from /var/lib/ldap to /nonexistent. | ||
2533 | 3478 | + Remove all code and templates dealing with the default database and DIT | ||
2534 | 3479 | creation. | ||
2535 | 3480 | + Add an Authz map from root user (UID=0) to cn=localroot,cn=config and | ||
2536 | 3481 | grant all access to the latter in the cn=config database as well as the | ||
2537 | 3482 | default backend configuration. | ||
2538 | 3483 | * Add cn=localroot,cn=config authz mapping on upgrades. | ||
2539 | 3484 | |||
2540 | 3485 | -- Mathias Gug <mathiaz@ubuntu.com> Tue, 11 Aug 2009 14:48:56 -0400 | ||
2541 | 3486 | |||
2542 | 3487 | openldap (2.4.17-1ubuntu2) karmic; urgency=low | ||
2543 | 3488 | |||
2544 | 3489 | [ Thierry Carrez ] | ||
2545 | 3490 | * debian/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support | ||
2546 | 3491 | in the openldap library, as required by Likewise-Open (LP: #390579) | ||
2547 | 3492 | |||
2548 | 3493 | [ Mathias Gug ] | ||
2549 | 3494 | * debian/patches/its6077-uniqueness-overlay: fixes some issues with the | ||
2550 | 3495 | uniqueness overlay. | ||
2551 | 3496 | * debian/patches/its6220-writetimeout-directive: fixes a problem with the | ||
2552 | 3497 | writetimeout directive being in effect even if it wasn't set, | ||
2553 | 3498 | closing connections incorrectly. | ||
2554 | 3499 | * debian/patches/its6222-dncachesize-parameter: fixes the behavior of the | ||
2555 | 3500 | dncachesize parameter that was added in RE24, so that if it is set to | ||
2556 | 3501 | "0" (now the default), it has an unlimited DN cache (RE23 always | ||
2557 | 3502 | had an unlimited DN cache). | ||
2558 | 3503 | |||
2559 | 3504 | -- Mathias Gug <mathiaz@ubuntu.com> Fri, 31 Jul 2009 13:43:46 -0400 | ||
2560 | 3505 | |||
2561 | 3506 | openldap (2.4.17-1ubuntu1) karmic; urgency=low | ||
2562 | 3507 | |||
2563 | 3508 | [ Steve Langasek ] | ||
2564 | 3509 | * Fix up the lintian warnings: | ||
2565 | 3510 | - add missing misc-depends on all packages | ||
2566 | 3511 | - slapd, libldap-2.4-2-dbg sections changed to 'debug' to match archive | ||
2567 | 3512 | overrides | ||
2568 | 3513 | - bump Standards-Version to 3.8.2, no changes required. | ||
2569 | 3514 | |||
2570 | 3515 | [ Mathias Gug ] | ||
2571 | 3516 | * Resynchronise with Debian. Remaining changes: | ||
2572 | 3517 | - AppArmor support: | ||
2573 | 3518 | - debian/apparmor-profile: add AppArmor profile | ||
2574 | 3519 | - updated debian/slapd.README.Debian for note on AppArmor | ||
2575 | 3520 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
2576 | 3521 | - debian/slapd.postrm: remove symlink in force-complain/ on purge | ||
2577 | 3522 | - debian/rules: install apparmor profile. | ||
2578 | 3523 | - Don't use local statement in config script as it fails if /bin/sh | ||
2579 | 3524 | points to bash. | ||
2580 | 3525 | - debian/slapd.postinst, debian/slapd.script-common: set correct | ||
2581 | 3526 | ownership and permissions on /var/lib/ldap, /etc/ldap/slapd.d (group | ||
2582 | 3527 | readable) and /var/run/slapd (world readable). | ||
2583 | 3528 | - Enable nssoverlay: | ||
2584 | 3529 | - debian/patches/nssov-build, debian/rules: Build and package the nss | ||
2585 | 3530 | overlay. | ||
2586 | 3531 | - debian/schema/misc.ldif: add ldif file for the misc schema which | ||
2587 | 3532 | defines rfc822MailMember (required by the nss overlay). | ||
2588 | 3533 | - debian/{control,rules}: enable PIE hardening | ||
2589 | 3534 | - Use cn=config as the default configuration backend instead of | ||
2590 | 3535 | slapd.conf. Migrate slapd.conf file to /etc/ldap/slapd.d/ on upgrade | ||
2591 | 3536 | asking the end user to enter a new password to control the access to | ||
2592 | 3537 | the cn=config tree. | ||
2593 | 3538 | - debian/slapd.postinst: create /var/run/slapd before updating its | ||
2594 | 3539 | permissions. | ||
2595 | 3540 | - debian/slapd.init: Correctly set slapd config backend option even if | ||
2596 | 3541 | the pidfile is configured in slapd default file. | ||
2597 | 3542 | * Dropped: | ||
2598 | 3543 | - Merged in Debian: | ||
2599 | 3544 | - Update priority of libldap-2.4-2 to match the archive override. | ||
2600 | 3545 | - Add the missing ldapexop and ldapurl tools to ldap-utils, as well as | ||
2601 | 3546 | the ldapurl(1) manpage. | ||
2602 | 3547 | - Bump build-dependency on debhelper to 6 instead of 5, since that's | ||
2603 | 3548 | what we're using. | ||
2604 | 3549 | - Set the default SLAPD_SERVICES to ldap:/// ldapi:///, instead of using | ||
2605 | 3550 | the built-in default of ldap:/// only. | ||
2606 | 3551 | - Fixed in upstream release: | ||
2607 | 3552 | - debian/patches/fix-ldap_back_entry_get_rwa.patch: fix test-0034 | ||
2608 | 3553 | failure when built with PIE. | ||
2609 | 3554 | - debian/patches/gnutls-enable-v1-ca-certs: Enable V1 CA certs to be | ||
2610 | 3555 | trusted. | ||
2611 | 3556 | - Update Apparmor profile support: don't support upgrade from pre-hardy | ||
2612 | 3557 | systems: | ||
2613 | 3558 | - debian/slapd.postinst: Reload AA profile on configuration | ||
2614 | 3559 | - debian/control: Recommends apparmor >= 2.1+1075-0ubuntu6 | ||
2615 | 3560 | - debian/control: Conflicts with apparmor-profiles << | ||
2616 | 3561 | 2.1+1075-0ubuntu4 to make sure that if earlier version of | ||
2617 | 3562 | apparmor-profiles gets installed it won't overwrite our profile. | ||
2618 | 3563 | - follow ApparmorProfileMigration and force apparmor complain mode on | ||
2619 | 3564 | some upgrades | ||
2620 | 3565 | - debian/slapd.preinst: create symlink for force-complain on | ||
2621 | 3566 | pre-feisty upgrades, upgrades where apparmor-profiles profile is | ||
2622 | 3567 | unchanged (ie non-enforcing) and upgrades where apparmor profile | ||
2623 | 3568 | does not exist. | ||
2624 | 3569 | - debian/patches/autogen.sh: no longer needed with karmic libtool. | ||
2625 | 3570 | - Call libtoolize with the --install option to install | ||
2626 | 3571 | config.{guess,sub} files. | ||
2627 | 3572 | |||
2628 | 3573 | -- Mathias Gug <mathiaz@ubuntu.com> Thu, 30 Jul 2009 16:42:58 -0400 | ||
2629 | 3574 | |||
2630 | 1248 | openldap (2.4.17-1) unstable; urgency=low | 3575 | openldap (2.4.17-1) unstable; urgency=low |
2631 | 1249 | 3576 | ||
2632 | 1250 | * New upstream version. | 3577 | * New upstream version. |
2633 | @@ -1267,6 +3594,153 @@ openldap (2.4.17-1) unstable; urgency=low | |||
2634 | 1267 | 3594 | ||
2635 | 1268 | -- Steve Langasek <vorlon@debian.org> Tue, 28 Jul 2009 10:17:15 -0700 | 3595 | -- Steve Langasek <vorlon@debian.org> Tue, 28 Jul 2009 10:17:15 -0700 |
2636 | 1269 | 3596 | ||
2637 | 3597 | openldap (2.4.15-1.1ubuntu1) karmic; urgency=low | ||
2638 | 3598 | |||
2639 | 3599 | * Resynchronise with Debian. Remaining changes: | ||
2640 | 3600 | - AppArmor support: | ||
2641 | 3601 | - debian/apparmor-profile: add AppArmor profile | ||
2642 | 3602 | - debian/slapd.postinst: Reload AA profile on configuration | ||
2643 | 3603 | - updated debian/slapd.README.Debian for note on AppArmor | ||
2644 | 3604 | - debian/control: Recommends apparmor >= 2.1+1075-0ubuntu6 | ||
2645 | 3605 | - debian/control: Conflicts with apparmor-profiles << | ||
2646 | 3606 | 2.1+1075-0ubuntu4 to make sure that if earlier version of | ||
2647 | 3607 | apparmor-profiles gets installed it won't overwrite our profile. | ||
2648 | 3608 | - follow ApparmorProfileMigration and force apparmor complain mode on | ||
2649 | 3609 | some upgrades | ||
2650 | 3610 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
2651 | 3611 | - debian/slapd.preinst: create symlink for force-complain on | ||
2652 | 3612 | pre-feisty upgrades, upgrades where apparmor-profiles profile is | ||
2653 | 3613 | unchanged (ie non-enforcing) and upgrades where apparmor profile | ||
2654 | 3614 | does not exist. | ||
2655 | 3615 | - debian/slapd.postrm: remove symlink in force-complain/ on purge | ||
2656 | 3616 | - debian/patches/autogen.sh: | ||
2657 | 3617 | - Call libtoolize with the --install option to install | ||
2658 | 3618 | config.{guess,sub} files. | ||
2659 | 3619 | - Don't use local statement in config script as it fails if /bin/sh | ||
2660 | 3620 | points to bash. | ||
2661 | 3621 | - debian/slapd.postinst, debian/slapd.script-common: set correct | ||
2662 | 3622 | ownership and permissions on /var/lib/ldap, /etc/ldap/slapd.d (group | ||
2663 | 3623 | readable) and /var/run/slapd (world readable). | ||
2664 | 3624 | - Enable nssoverlay: | ||
2665 | 3625 | - debian/patches/nssov-build, debian/rules: Build and package the nss | ||
2666 | 3626 | overlay. | ||
2667 | 3627 | - debian/schema/misc.ldif: add ldif file for the misc schema which | ||
2668 | 3628 | defines rfc822MailMember (required by the nss overlay). | ||
2669 | 3629 | - debian/{control,rules}: enable PIE hardening | ||
2670 | 3630 | - Use cn=config as the default configuration backend instead of | ||
2671 | 3631 | slapd.conf. Migrate slapd.conf file to /etc/ldap/slapd.d/ on upgrade | ||
2672 | 3632 | asking the end user to enter a new password to control the access to | ||
2673 | 3633 | the cn=config tree. | ||
2674 | 3634 | - Update priority of libldap-2.4-2 to match the archive override. | ||
2675 | 3635 | - Add the missing ldapexop and ldapurl tools to ldap-utils, as well as | ||
2676 | 3636 | the ldapurl(1) manpage. | ||
2677 | 3637 | - Bump build-dependency on debhelper to 6 instead of 5, since that's | ||
2678 | 3638 | what we're using. | ||
2679 | 3639 | - Set the default SLAPD_SERVICES to ldap:/// ldapi:///, instead of using | ||
2680 | 3640 | the built-in default of ldap:/// only. | ||
2681 | 3641 | - debian/patches/fix-ldap_back_entry_get_rwa.patch: fix test-0034 | ||
2682 | 3642 | failure when built with PIE. | ||
2683 | 3643 | - debian/patches/gnutls-enable-v1-ca-certs: Enable V1 CA certs to be | ||
2684 | 3644 | trusted. | ||
2685 | 3645 | - debian/slapd.postinst: create /var/run/slapd before updating its | ||
2686 | 3646 | permissions. | ||
2687 | 3647 | - debian/slapd.init: Correctly set slapd config backend option even if | ||
2688 | 3648 | the pidfile is configured in slapd default file. | ||
2689 | 3649 | * Drop patch to avoid the test suite on hppa, as hppa is EOL. | ||
2690 | 3650 | |||
2691 | 3651 | -- Colin Watson <cjwatson@ubuntu.com> Wed, 24 Jun 2009 10:45:20 +0100 | ||
2692 | 3652 | |||
2693 | 3653 | openldap (2.4.15-1.1) unstable; urgency=low | ||
2694 | 3654 | |||
2695 | 3655 | * Non-maintainer upload. | ||
2696 | 3656 | * Change libltdl3-dev Build-Depends to libltdl-dev | libltdl3-dev | ||
2697 | 3657 | (Closes: #522965) | ||
2698 | 3658 | |||
2699 | 3659 | -- Kurt Roeckx <kurt@roeckx.be> Sun, 19 Apr 2009 18:24:32 +0200 | ||
2700 | 3660 | |||
2701 | 3661 | openldap (2.4.15-1ubuntu3) jaunty; urgency=low | ||
2702 | 3662 | |||
2703 | 3663 | * No-change rebuild to fix lpia shared library dependencies. | ||
2704 | 3664 | |||
2705 | 3665 | -- Colin Watson <cjwatson@ubuntu.com> Thu, 19 Mar 2009 09:52:40 +0000 | ||
2706 | 3666 | |||
2707 | 3667 | openldap (2.4.15-1ubuntu2) jaunty; urgency=low | ||
2708 | 3668 | |||
2709 | 3669 | * debian/slapd.postinst: create /var/run/slapd before updating its | ||
2710 | 3670 | permissions (LP: #298928). | ||
2711 | 3671 | * debian/slapd.init: Correclty set slapd config backend option even if the | ||
2712 | 3672 | pidfile is configured in slapd default file (LP: #292364). | ||
2713 | 3673 | * debian/apparmor-profile: support multiple databases to be stored under | ||
2714 | 3674 | /var/lib/ldap/. (LP: #286614). | ||
2715 | 3675 | |||
2716 | 3676 | -- Mathias Gug <mathiaz@ubuntu.com> Fri, 13 Mar 2009 13:56:12 -0400 | ||
2717 | 3677 | |||
2718 | 3678 | openldap (2.4.15-1ubuntu1) jaunty; urgency=low | ||
2719 | 3679 | |||
2720 | 3680 | [ Steve Langasek ] | ||
2721 | 3681 | * Update priority of libldap-2.4-2 to match the archive override. | ||
2722 | 3682 | * Add the missing ldapexop and ldapurl tools to ldap-utils, as well as the | ||
2723 | 3683 | ldapurl(1) manpage. Thanks to Peter Marschall for the patch. | ||
2724 | 3684 | Closes: #496749. | ||
2725 | 3685 | * Bump build-dependency on debhelper to 6 instead of 5, since that's | ||
2726 | 3686 | what we're using. Closes: #498116. | ||
2727 | 3687 | * Set the default SLAPD_SERVICES to ldap:/// ldapi:///, instead of using | ||
2728 | 3688 | the built-in default of ldap:/// only. | ||
2729 | 3689 | |||
2730 | 3690 | [ Mathias Gug ] | ||
2731 | 3691 | * Merge from debian unstable, remaining changes: | ||
2732 | 3692 | - Modify Maintainer value to match the DebianMaintainerField | ||
2733 | 3693 | speficication. | ||
2734 | 3694 | - AppArmor support: | ||
2735 | 3695 | - debian/apparmor-profile: add AppArmor profile | ||
2736 | 3696 | - debian/slapd.postinst: Reload AA profile on configuration | ||
2737 | 3697 | - updated debian/slapd.README.Debian for note on AppArmor | ||
2738 | 3698 | - debian/control: Recommends apparmor >= 2.1+1075-0ubuntu6 | ||
2739 | 3699 | - debian/control: Conflicts with apparmor-profiles << 2.1+1075-0ubuntu4 | ||
2740 | 3700 | to make sure that if earlier version of apparmour-profiles gets | ||
2741 | 3701 | installed it won't overwrite our profile. | ||
2742 | 3702 | - follow ApparmorProfileMigration and force apparmor compalin mode on | ||
2743 | 3703 | some upgrades (LP: #203529) | ||
2744 | 3704 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
2745 | 3705 | - debian/slapd.preinst: create symlink for force-complain on pre-feisty | ||
2746 | 3706 | upgrades, upgrades where apparmor-profiles profile is unchanged (ie | ||
2747 | 3707 | non-enforcing) and upgrades where apparmor profile does not exist. | ||
2748 | 3708 | - debian/slapd.postrm: remove symlink in force-complain/ on purge | ||
2749 | 3709 | - debian/control: | ||
2750 | 3710 | - Build-depend on libltdl7-dev rather then libltdl3-dev. | ||
2751 | 3711 | - debian/patches/autogen.sh: | ||
2752 | 3712 | - Call libtoolize with the --install option to install config.{guess,sub} | ||
2753 | 3713 | files. | ||
2754 | 3714 | - Don't use local statement in config script as it fails if /bin/sh | ||
2755 | 3715 | points to bash (LP: #286063). | ||
2756 | 3716 | - Disable the testsuite on hppa. Allows building of packages on this | ||
2757 | 3717 | architecture again, once this package is in the archive. | ||
2758 | 3718 | LP: #288908. | ||
2759 | 3719 | - debian/slapd.postinst, debian/slapd.script-common: set correct ownership | ||
2760 | 3720 | and permissions on /var/lib/ldap, /etc/ldap/slapd.d (group readable) and | ||
2761 | 3721 | /var/run/slapd (world readable). (LP: #257667). | ||
2762 | 3722 | - Enable nssoverlay: | ||
2763 | 3723 | - debian/patches/nssov-build, debian/rules: Build and package | ||
2764 | 3724 | the nss overlay. | ||
2765 | 3725 | - debian/schema/misc.ldif: add ldif file for the misc schema | ||
2766 | 3726 | which defines rfc822MailMember (required by the nss overlay). | ||
2767 | 3727 | - debian/{control,rules}: enable PIE hardening | ||
2768 | 3728 | - Use cn=config as the default configuration backend instead of | ||
2769 | 3729 | slapd.conf. Migrate slapd.conf file to /etc/ldap/slapd.d/ on upgrade | ||
2770 | 3730 | asking the end user to enter a new password to control the access to the | ||
2771 | 3731 | cn=config tree. | ||
2772 | 3732 | * Dropped: | ||
2773 | 3733 | - debian/patches/corrupt-contextCSN: The contextCSN can get corrupted at | ||
2774 | 3734 | times. (ITS: #5947) Fixed in new upstream version 2.4.15. | ||
2775 | 3735 | - debian/patches/fix-ucred-libc due to changes how newer glibc handle | ||
2776 | 3736 | the ucred struct now. Implemented in Debian. | ||
2777 | 3737 | * debian/patches/fix-ldap_back_entry_get_rwa.patch: fix test-0034 failure | ||
2778 | 3738 | when built with PIE. | ||
2779 | 3739 | * debian/patches/gnutls-enable-v1-ca-certs: Enable V1 CA certs to be | ||
2780 | 3740 | trusted (LP: #305264). | ||
2781 | 3741 | |||
2782 | 3742 | -- Mathias Gug <mathiaz@ubuntu.com> Fri, 06 Mar 2009 17:34:21 -0500 | ||
2783 | 3743 | |||
2784 | 1270 | openldap (2.4.15-1) unstable; urgency=low | 3744 | openldap (2.4.15-1) unstable; urgency=low |
2785 | 1271 | 3745 | ||
2786 | 1272 | * New upstream version | 3746 | * New upstream version |
2787 | @@ -1284,6 +3758,69 @@ openldap (2.4.15-1) unstable; urgency=low | |||
2788 | 1284 | 3758 | ||
2789 | 1285 | -- Steve Langasek <vorlon@debian.org> Tue, 24 Feb 2009 14:27:35 -0800 | 3759 | -- Steve Langasek <vorlon@debian.org> Tue, 24 Feb 2009 14:27:35 -0800 |
2790 | 1286 | 3760 | ||
2791 | 3761 | openldap (2.4.14-0ubuntu1) jaunty; urgency=low | ||
2792 | 3762 | |||
2793 | 3763 | [ Steve Langasek ] | ||
2794 | 3764 | * New upstream version | ||
2795 | 3765 | - Fixes a bug with the pcache overlay not returning cached entries | ||
2796 | 3766 | (closes: #497697) | ||
2797 | 3767 | - Update evolution-ntlm patch to apply to current Makefiles. | ||
2798 | 3768 | - (tentatively) drop gnutls-ciphers, since this bug was reported to be | ||
2799 | 3769 | fixed upstream in 2.4.8. The fix applied in 2.4.8 didn't match the | ||
2800 | 3770 | patch from the bug report, so this should be watched for regressions. | ||
2801 | 3771 | * Build against db4.7 instead of db4.2 at last! Closes: #421946. | ||
2802 | 3772 | * Build with --disable-ndb, to avoid a misbuild when libmysqlclient is | ||
2803 | 3773 | installed in the build environment. | ||
2804 | 3774 | * New patch, no-crlcheck-for-gnutls, to fix a build failure when using | ||
2805 | 3775 | --with-tls=gnutls. | ||
2806 | 3776 | |||
2807 | 3777 | [ Mathias Gug ] | ||
2808 | 3778 | * Merge from debian unstable, remaining changes: | ||
2809 | 3779 | - debian/apparmor-profile: add AppArmor profile | ||
2810 | 3780 | - debian/slapd.postinst: Reload AA profile on configuration | ||
2811 | 3781 | - updated debian/slapd.README.Debian for note on AppArmor | ||
2812 | 3782 | - debian/control: Recommends apparmor >= 2.1+1075-0ubuntu6 | ||
2813 | 3783 | - debian/control: Conflicts with apparmor-profiles << 2.1+1075-0ubuntu4 | ||
2814 | 3784 | to make sure that if earlier version of apparmour-profiles gets | ||
2815 | 3785 | installed it won't overwrite our profile. | ||
2816 | 3786 | - Modify Maintainer value to match the DebianMaintainerField | ||
2817 | 3787 | speficication. | ||
2818 | 3788 | - follow ApparmorProfileMigration and force apparmor compalin mode on | ||
2819 | 3789 | some upgrades (LP: #203529) | ||
2820 | 3790 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
2821 | 3791 | - debian/slapd.preinst: create symlink for force-complain on pre-feisty | ||
2822 | 3792 | upgrades, upgrades where apparmor-profiles profile is unchanged (ie | ||
2823 | 3793 | non-enforcing) and upgrades where apparmor profile does not exist. | ||
2824 | 3794 | - debian/slapd.postrm: remove symlink in force-complain/ on purge | ||
2825 | 3795 | - debian/patches/fix-ucred-libc due to changes how newer glibc handle | ||
2826 | 3796 | the ucred struct now. | ||
2827 | 3797 | - debian/control: | ||
2828 | 3798 | - Build-depend on libltdl7-dev rather then libltdl3-dev. | ||
2829 | 3799 | - debian/patches/autogen.sh: | ||
2830 | 3800 | - Call libtoolize with the --install option to install config.{guess,sub} | ||
2831 | 3801 | files. | ||
2832 | 3802 | - Don't use local statement in config script as it fails if /bin/sh | ||
2833 | 3803 | points to bash (LP: #286063). | ||
2834 | 3804 | - Disable the testsuite on hppa. Allows building of packages on this | ||
2835 | 3805 | architecture again, once this package is in the archive. | ||
2836 | 3806 | LP: #288908. | ||
2837 | 3807 | - debian/slapd.postinst, debian/slapd.script-common: set correct ownership | ||
2838 | 3808 | and permissions on /var/lib/ldap, /etc/ldap/slapd.d (group readable) and | ||
2839 | 3809 | /var/run/slapd (world readable). (LP: #257667). | ||
2840 | 3810 | - debian/patches/nssov-build, debian/rules: | ||
2841 | 3811 | Build and package the nss overlay. | ||
2842 | 3812 | debian/schema/misc.ldif: add ldif file for the misc schema, which defines | ||
2843 | 3813 | rfc822MailMember (required by the nss overlay). | ||
2844 | 3814 | - debian/{control,rules}: enable PIE hardening | ||
2845 | 3815 | - Use cn=config as the default configuration backend instead of | ||
2846 | 3816 | slapd.conf. Migrate slapd.conf file to /etc/ldap/slapd.d/ on upgrade | ||
2847 | 3817 | asking the end user to enter a new password to control the access to the | ||
2848 | 3818 | cn=config tree. | ||
2849 | 3819 | * debian/patches/corrupt-contextCSN: The contextCSN can get corrupted at | ||
2850 | 3820 | times. (ITS: #5947) | ||
2851 | 3821 | |||
2852 | 3822 | -- Mathias Gug <mathiaz@ubuntu.com> Wed, 18 Feb 2009 18:44:00 -0500 | ||
2853 | 3823 | |||
2854 | 1287 | openldap (2.4.11-1) unstable; urgency=low | 3824 | openldap (2.4.11-1) unstable; urgency=low |
2855 | 1288 | 3825 | ||
2856 | 1289 | * New upstream version (closes: #499560). | 3826 | * New upstream version (closes: #499560). |
2857 | @@ -1306,6 +3843,110 @@ openldap (2.4.11-1) unstable; urgency=low | |||
2858 | 1306 | 3843 | ||
2859 | 1307 | -- Steve Langasek <vorlon@debian.org> Sat, 11 Oct 2008 01:53:55 -0700 | 3844 | -- Steve Langasek <vorlon@debian.org> Sat, 11 Oct 2008 01:53:55 -0700 |
2860 | 1308 | 3845 | ||
2861 | 3846 | openldap (2.4.11-0ubuntu7) jaunty; urgency=low | ||
2862 | 3847 | |||
2863 | 3848 | * Don't use local statement in config script as it fails if /bin/sh | ||
2864 | 3849 | points to bash (LP: #286063). | ||
2865 | 3850 | |||
2866 | 3851 | -- Mathias Gug <mathiaz@ubuntu.com> Tue, 04 Nov 2008 20:03:46 -0500 | ||
2867 | 3852 | |||
2868 | 3853 | openldap (2.4.11-0ubuntu6) intrepid; urgency=low | ||
2869 | 3854 | |||
2870 | 3855 | * Disable the testsuite on hppa. Allows building of packages on this | ||
2871 | 3856 | architecture again, once this package is in the archive. | ||
2872 | 3857 | LP: #288908. | ||
2873 | 3858 | |||
2874 | 3859 | -- Matthias Klose <doko@ubuntu.com> Fri, 24 Oct 2008 23:22:33 +0200 | ||
2875 | 3860 | |||
2876 | 3861 | openldap (2.4.11-0ubuntu5) intrepid; urgency=low | ||
2877 | 3862 | |||
2878 | 3863 | * Don't set admin passwords in ldif files if adminpw is empty. | ||
2879 | 3864 | (LP: #273988 - LP: #276606). | ||
2880 | 3865 | |||
2881 | 3866 | -- Mathias Gug <mathiaz@ubuntu.com> Mon, 13 Oct 2008 19:31:15 -0400 | ||
2882 | 3867 | |||
2883 | 3868 | openldap (2.4.11-0ubuntu4) intrepid; urgency=low | ||
2884 | 3869 | |||
2885 | 3870 | * debian/slapd.postinst, debian/slapd.script-common: set correct ownership | ||
2886 | 3871 | and permissions on /var/lib/ldap, /etc/ldap/slapd.d (group readable) and | ||
2887 | 3872 | /var/run/slapd (world readable). (LP: #257667). | ||
2888 | 3873 | * debian/slapd.script-common: | ||
2889 | 3874 | - Fix package reconfiguration: | ||
2890 | 3875 | + Remove slapd.d/ directory if it already exists when creating a new | ||
2891 | 3876 | configuration. | ||
2892 | 3877 | + Fix backup directory naming for multiple reconfiguration. | ||
2893 | 3878 | |||
2894 | 3879 | -- Mathias Gug <mathiaz@ubuntu.com> Wed, 24 Sep 2008 21:01:42 -0400 | ||
2895 | 3880 | |||
2896 | 3881 | openldap (2.4.11-0ubuntu3) intrepid; urgency=low | ||
2897 | 3882 | |||
2898 | 3883 | * debian/patches/nssov-build, debian/rules: | ||
2899 | 3884 | Build and package the nss overlay. | ||
2900 | 3885 | * debian/schema/misc.ldif: add ldif file for the misc schema, which defines | ||
2901 | 3886 | rfc822MailMember (required by the nss overlay). | ||
2902 | 3887 | |||
2903 | 3888 | -- Mathias Gug <mathiaz@ubuntu.com> Tue, 26 Aug 2008 18:42:54 -0400 | ||
2904 | 3889 | |||
2905 | 3890 | openldap (2.4.11-0ubuntu2) intrepid; urgency=low | ||
2906 | 3891 | |||
2907 | 3892 | * debian/{control,rules}: enable PIE hardening | ||
2908 | 3893 | |||
2909 | 3894 | -- Kees Cook <kees@ubuntu.com> Wed, 20 Aug 2008 15:47:01 -0700 | ||
2910 | 3895 | |||
2911 | 3896 | openldap (2.4.11-0ubuntu1) intrepid; urgency=low | ||
2912 | 3897 | |||
2913 | 3898 | * New upstream version: | ||
2914 | 3899 | - Mainly bug fixes. | ||
2915 | 3900 | - New nss slapd overlay (not compiled by default). | ||
2916 | 3901 | * Use cn=config as the default configuration backend instead of | ||
2917 | 3902 | slapd.conf. Migrate slapd.conf file to /etc/ldap/slapd.d/ on upgrade | ||
2918 | 3903 | asking the end user to enter a new password to control the access to the | ||
2919 | 3904 | cn=config tree. | ||
2920 | 3905 | |||
2921 | 3906 | -- Mathias Gug <mathiaz@ubuntu.com> Mon, 11 Aug 2008 20:26:05 -0400 | ||
2922 | 3907 | |||
2923 | 3908 | openldap (2.4.10-3ubuntu1) intrepid; urgency=low | ||
2924 | 3909 | |||
2925 | 3910 | [ Mathias Gug ] | ||
2926 | 3911 | * Merge from debian unstable, remaining changes: | ||
2927 | 3912 | - debian/apparmor-profile: add AppArmor profile | ||
2928 | 3913 | - debian/slapd.postinst: Reload AA profile on configuration | ||
2929 | 3914 | - updated debian/slapd.README.Debian for note on AppArmor | ||
2930 | 3915 | - debian/control: Recommends apparmor >= 2.1+1075-0ubuntu6 | ||
2931 | 3916 | - debian/control: Conflicts with apparmor-profiles << 2.1+1075-0ubuntu4 | ||
2932 | 3917 | to make sure that if earlier version of apparmour-profiles gets | ||
2933 | 3918 | installed it won't overwrite our profile. | ||
2934 | 3919 | - Modify Maintainer value to match the DebianMaintainerField | ||
2935 | 3920 | speficication. | ||
2936 | 3921 | - follow ApparmorProfileMigration and force apparmor compalin mode on | ||
2937 | 3922 | some upgrades (LP: #203529) | ||
2938 | 3923 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
2939 | 3924 | - debian/slapd.preinst: create symlink for force-complain on pre-feisty | ||
2940 | 3925 | upgrades, upgrades where apparmor-profiles profile is unchanged (ie | ||
2941 | 3926 | non-enforcing) and upgrades where apparmor profile does not exist. | ||
2942 | 3927 | - debian/slapd.postrm: remove symlink in force-complain/ on purge | ||
2943 | 3928 | - debian/patches/fix-ucred-libc due to changes how newer glibc handle | ||
2944 | 3929 | the ucred struct now. | ||
2945 | 3930 | - debian/patches/fix-unique-overlay-assertion.patch: | ||
2946 | 3931 | Fix another assertion error in unique overlay (LP: #243337). | ||
2947 | 3932 | Backport from head. | ||
2948 | 3933 | * Dropped - implemented in Debian: | ||
2949 | 3934 | - debian/patches/fix-gnutls-key-strength.patch: | ||
2950 | 3935 | Fix slapd handling of ssf using gnutls. (LP: #244925). | ||
2951 | 3936 | - debian/control: | ||
2952 | 3937 | Add time as build dependency: needed by make test. | ||
2953 | 3938 | * debian/control: | ||
2954 | 3939 | - Build-depend on libltdl7-dev rather then libltdl3-dev. | ||
2955 | 3940 | * debian/patches/autogen.sh: | ||
2956 | 3941 | - Call libtoolize with the --install option to install config.{guess,sub} | ||
2957 | 3942 | files. | ||
2958 | 3943 | |||
2959 | 3944 | [ Jamie Strandboge ] | ||
2960 | 3945 | * adjust apparmor profile to allow gssapi (LP: #229252) | ||
2961 | 3946 | * adjust apparmor profile to allow cnconfig (LP: #243525) | ||
2962 | 3947 | |||
2963 | 3948 | -- Mathias Gug <mathiaz@ubuntu.com> Wed, 30 Jul 2008 19:46:02 -0400 | ||
2964 | 3949 | |||
2965 | 1309 | openldap (2.4.10-3) unstable; urgency=low | 3950 | openldap (2.4.10-3) unstable; urgency=low |
2966 | 1310 | 3951 | ||
2967 | 1311 | [ Steve Langasek ] | 3952 | [ Steve Langasek ] |
2968 | @@ -1339,6 +3980,40 @@ openldap (2.4.10-3) unstable; urgency=low | |||
2969 | 1339 | 3980 | ||
2970 | 1340 | -- Steve Langasek <vorlon@debian.org> Mon, 28 Jul 2008 15:26:06 -0700 | 3981 | -- Steve Langasek <vorlon@debian.org> Mon, 28 Jul 2008 15:26:06 -0700 |
2971 | 1341 | 3982 | ||
2972 | 3983 | openldap (2.4.10-2ubuntu1) intrepid; urgency=low | ||
2973 | 3984 | |||
2974 | 3985 | * Merge from debian unstable, remaining changes: | ||
2975 | 3986 | - debian/apparmor-profile: add AppArmor profile | ||
2976 | 3987 | - debian/slapd.postinst: Reload AA profile on configuration | ||
2977 | 3988 | - updated debian/slapd.README.Debian for note on AppArmor | ||
2978 | 3989 | - debian/control: Recommends apparmor >= 2.1+1075-0ubuntu6 | ||
2979 | 3990 | - debian/control: Conflicts with apparmor-profiles << 2.1+1075-0ubuntu4 | ||
2980 | 3991 | to make sure that if earlier version of apparmour-profiles gets | ||
2981 | 3992 | installed it won't overwrite our profile. | ||
2982 | 3993 | - Modify Maintainer value to match the DebianMaintainerField | ||
2983 | 3994 | speficication. | ||
2984 | 3995 | - follow ApparmorProfileMigration and force apparmor compalin mode on | ||
2985 | 3996 | some upgrades (LP: #203529) | ||
2986 | 3997 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
2987 | 3998 | - debian/slapd.preinst: create symlink for force-complain on pre-feisty | ||
2988 | 3999 | upgrades, upgrades where apparmor-profiles profile is unchanged (ie | ||
2989 | 4000 | non-enforcing) and upgrades where apparmor profile does not exist. | ||
2990 | 4001 | - debian/slapd.postrm: remove symlink in force-complain/ on purge | ||
2991 | 4002 | - debian/patches/fix-ucred-libc due to changes how newer glibc handle | ||
2992 | 4003 | the ucred struct now. | ||
2993 | 4004 | - debian/patches/fix-unique-overlay-assertion.patch: | ||
2994 | 4005 | Fix another assertion error in unique overlay (LP: #243337). | ||
2995 | 4006 | Backport from head. | ||
2996 | 4007 | - debian/patches/fix-gnutls-key-strength.patch: | ||
2997 | 4008 | Fix slapd handling of ssf using gnutls. (LP: #244925). | ||
2998 | 4009 | - debian/control: | ||
2999 | 4010 | Add time as build dependency: needed by make test. | ||
3000 | 4011 | * Dropped - implemented in Debian: | ||
3001 | 4012 | - debian/rules: | ||
3002 | 4013 | Support debuild nocheck option: don't run tests if nocheck is set. | ||
3003 | 4014 | |||
3004 | 4015 | -- Mathias Gug <mathiaz@ubuntu.com> Thu, 10 Jul 2008 14:45:49 -0400 | ||
3005 | 4016 | |||
3006 | 1342 | openldap (2.4.10-2) unstable; urgency=low | 4017 | openldap (2.4.10-2) unstable; urgency=low |
3007 | 1343 | 4018 | ||
3008 | 1344 | * Support DEB_BUILD_OPTIONS=nocheck to disable running the test suite at | 4019 | * Support DEB_BUILD_OPTIONS=nocheck to disable running the test suite at |
3009 | @@ -1353,6 +4028,54 @@ openldap (2.4.10-2) unstable; urgency=low | |||
3010 | 1353 | 4028 | ||
3011 | 1354 | -- Steve Langasek <vorlon@debian.org> Sun, 06 Jul 2008 22:03:32 -0700 | 4029 | -- Steve Langasek <vorlon@debian.org> Sun, 06 Jul 2008 22:03:32 -0700 |
3012 | 1355 | 4030 | ||
3013 | 4031 | openldap2.3 (2.4.10-1ubuntu1) intrepid; urgency=low | ||
3014 | 4032 | |||
3015 | 4033 | * Merge from debian unstable, remaining changes: | ||
3016 | 4034 | - debian/apparmor-profile: add AppArmor profile | ||
3017 | 4035 | - debian/slapd.postinst: Reload AA profile on configuration | ||
3018 | 4036 | - updated debian/slapd.README.Debian for note on AppArmor | ||
3019 | 4037 | - debian/control: Recommends apparmor >= 2.1+1075-0ubuntu6 | ||
3020 | 4038 | - debian/control: Conflicts with apparmor-profiles << 2.1+1075-0ubuntu4 | ||
3021 | 4039 | to make sure that if earlier version of apparmour-profiles gets | ||
3022 | 4040 | installed it won't overwrite our profile. | ||
3023 | 4041 | - Modify Maintainer value to match the DebianMaintainerField | ||
3024 | 4042 | speficication. | ||
3025 | 4043 | - follow ApparmorProfileMigration and force apparmor compalin mode on | ||
3026 | 4044 | some upgrades (LP: #203529) | ||
3027 | 4045 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
3028 | 4046 | - debian/slapd.preinst: create symlink for force-complain on pre-feisty | ||
3029 | 4047 | upgrades, upgrades where apparmor-profiles profile is unchanged (ie | ||
3030 | 4048 | non-enforcing) and upgrades where apparmor profile does not exist. | ||
3031 | 4049 | - debian/slapd.postrm: remove symlink in force-complain/ on purge | ||
3032 | 4050 | - debian/patches/fix-ucred-libc due to changes how newer glibc handle | ||
3033 | 4051 | the ucred struct now. | ||
3034 | 4052 | - debian/patches/fix-unique-overlay-assertion.patch: | ||
3035 | 4053 | Fix another assertion error in unique overlay (LP: #243337). | ||
3036 | 4054 | Backport from head. | ||
3037 | 4055 | * debian/control: | ||
3038 | 4056 | - add time as build dependency: needed by make test. | ||
3039 | 4057 | * debian/rules: | ||
3040 | 4058 | - support debuild nocheck option: don't run tests if nocheck is set. | ||
3041 | 4059 | * debian/patches/fix-gnutls-key-strength.patch: | ||
3042 | 4060 | - fix slapd handling of ssf using gnutls. (LP: #244925). | ||
3043 | 4061 | * Dropped - accepted in Debian: | ||
3044 | 4062 | - debian/rules, debian/slapd.links: use hard links to slapd instead of | ||
3045 | 4063 | symlinks for slap* so these applications aren't confined by apparmor | ||
3046 | 4064 | (LP: #203898) | ||
3047 | 4065 | * Dropped - fixed in new upstream release: | ||
3048 | 4066 | - debian/patches/fix-assertion-io.patch: Fixes ber_flush2 assertion. | ||
3049 | 4067 | (LP: #215904) | ||
3050 | 4068 | - debian/patches/fix-dnpretty-assertion.patch: Fix dnPrettyNormal assertion | ||
3051 | 4069 | error. (LP: #234196) | ||
3052 | 4070 | - dropped debian/patches/fix-notify-crasher.patch: Fix modify timestamp crashes. | ||
3053 | 4071 | (LP: #220724) | ||
3054 | 4072 | - debian/patches/fix-syncrepl-oops: Fixes segmentation fault when using | ||
3055 | 4073 | syncrepl. (LP: #227178) | ||
3056 | 4074 | - dropped debian/patches/SECURITY_CVE-2008-0658.patch. Already applied | ||
3057 | 4075 | upstream. | ||
3058 | 4076 | |||
3059 | 4077 | -- Mathias Gug <mathiaz@ubuntu.com> Thu, 03 Jul 2008 14:15:08 -0400 | ||
3060 | 4078 | |||
3061 | 1356 | openldap2.3 (2.4.10-1) unstable; urgency=low | 4079 | openldap2.3 (2.4.10-1) unstable; urgency=low |
3062 | 1357 | 4080 | ||
3063 | 1358 | [ Steve Langasek ] | 4081 | [ Steve Langasek ] |
3064 | @@ -1377,6 +4100,64 @@ openldap2.3 (2.4.10-1) unstable; urgency=low | |||
3065 | 1377 | 4100 | ||
3066 | 1378 | -- Steve Langasek <vorlon@debian.org> Mon, 30 Jun 2008 04:28:34 -0700 | 4101 | -- Steve Langasek <vorlon@debian.org> Mon, 30 Jun 2008 04:28:34 -0700 |
3067 | 1379 | 4102 | ||
3068 | 4103 | openldap2.3 (2.4.9-1ubuntu4) intrepid; urgency=low | ||
3069 | 4104 | |||
3070 | 4105 | * debian/patches/fix-unique-overlay-assertion.patch: | ||
3071 | 4106 | - Fix another assertion error in unique overlay, backported from head. | ||
3072 | 4107 | (LP: #243337) Note: This patch will still be needed when moved to 2.4.10 | ||
3073 | 4108 | |||
3074 | 4109 | -- Chuck Short <zulcss@ubuntu.com> Mon, 30 Jun 2008 18:49:52 +0000 | ||
3075 | 4110 | |||
3076 | 4111 | openldap2.3 (2.4.9-1ubuntu3) intrepid; urgency=low | ||
3077 | 4112 | |||
3078 | 4113 | * Drop spurious dependency on hiemdal-dev. Caused by an aborted attempt to | ||
3079 | 4114 | include the smbk5pwd overlay. | ||
3080 | 4115 | |||
3081 | 4116 | -- Chuck Short <zulcss@ubuntu.com> Wed, 11 Jun 2008 21:25:40 +0000 | ||
3082 | 4117 | |||
3083 | 4118 | openldap2.3 (2.4.9-1ubuntu2) intrepid; urgency=low | ||
3084 | 4119 | |||
3085 | 4120 | * Rebuild for perl 5.10 transition (LP: #230016) | ||
3086 | 4121 | * debian/patches/fix-syncrepl-oops: Fixes segmentation fault when using | ||
3087 | 4122 | syncrepl. (LP: #227178) | ||
3088 | 4123 | |||
3089 | 4124 | -- Chuck Short <zulcss@ubuntu.com> Mon, 09 Jun 2008 14:56:40 +0000 | ||
3090 | 4125 | |||
3091 | 4126 | openldap2.3 (2.4.9-1ubuntu1) intrepid; urgency=low | ||
3092 | 4127 | |||
3093 | 4128 | * Merge from debian unstable, remaining changes: | ||
3094 | 4129 | - debian/apparmor-profile: add AppArmor profile | ||
3095 | 4130 | - debian/slapd.postinst: Reload AA profile on configuration | ||
3096 | 4131 | - updated debian/slapd.README.Debian for note on AppArmor | ||
3097 | 4132 | - debian/control: Recommends apparmor >= 2.1+1075-0ubuntu6 | ||
3098 | 4133 | - debian/control: Conflicts with apparmor-profiles << 2.1+1075-0ubuntu4 | ||
3099 | 4134 | to make sure that if earlier version of apparmour-profiles gets | ||
3100 | 4135 | installed it won't overwrite our profile. | ||
3101 | 4136 | - Modify Maintainer value to match the DebianMaintainerField | ||
3102 | 4137 | speficication. | ||
3103 | 4138 | - follow ApparmorProfileMigration and force apparmor compalin mode on | ||
3104 | 4139 | some upgrades (LP: #203529) | ||
3105 | 4140 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
3106 | 4141 | - debian/slapd.preinst: create symlink for force-complain on pre-feisty | ||
3107 | 4142 | upgrades, upgrades where apparmor-profiles profile is unchanged (ie | ||
3108 | 4143 | non-enforcing) and upgrades where apparmor profile does not exist. | ||
3109 | 4144 | - debian/slapd.postrm: remove symlink in force-complain/ on purge | ||
3110 | 4145 | - debian/rules, debian/slapd.links: use hard links to slapd instead of | ||
3111 | 4146 | symlinks for slap* so these applications aren't confined by apparmor | ||
3112 | 4147 | (LP: #203898) | ||
3113 | 4148 | - debian/patches/fix-assertion-io.patch: Fixes ber_flush2 assertion. | ||
3114 | 4149 | (LP: #215904) | ||
3115 | 4150 | - debian/patches/fix-dnpretty-assertion.patch: Fix dnPrettyNormal assertion | ||
3116 | 4151 | error. (LP: #234196) | ||
3117 | 4152 | - dropped debian/patches/fix-notify-crasher.patch: Fix modify timestamp crashes. | ||
3118 | 4153 | (LP: #220724) | ||
3119 | 4154 | - dropped debian/patches/SECURITY_CVE-2008-0658.patch. Already applied | ||
3120 | 4155 | upstream. | ||
3121 | 4156 | * Added debian/patches/fix-ucred-libc due to changes how newer glibc handle | ||
3122 | 4157 | the ucred struct now. | ||
3123 | 4158 | |||
3124 | 4159 | -- Chuck Short <zulcss@ubuntu.com> Fri, 30 May 2008 17:09:53 +0100 | ||
3125 | 4160 | |||
3126 | 1380 | openldap2.3 (2.4.9-1) unstable; urgency=low | 4161 | openldap2.3 (2.4.9-1) unstable; urgency=low |
3127 | 1381 | 4162 | ||
3128 | 1382 | [ Updated debconf translations ] | 4163 | [ Updated debconf translations ] |
3129 | @@ -1447,6 +4228,51 @@ openldap2.3 (2.4.7-6.1) unstable; urgency=high | |||
3130 | 1447 | 4228 | ||
3131 | 1448 | -- Nico Golde <nion@debian.org> Tue, 04 Mar 2008 14:34:44 +0100 | 4229 | -- Nico Golde <nion@debian.org> Tue, 04 Mar 2008 14:34:44 +0100 |
3132 | 1449 | 4230 | ||
3133 | 4231 | openldap2.3 (2.4.7-6ubuntu3) hardy; urgency=low | ||
3134 | 4232 | |||
3135 | 4233 | * remove apparmor-profile workaround for Launchpad #202161 (it's now fixed | ||
3136 | 4234 | in klibc) | ||
3137 | 4235 | |||
3138 | 4236 | -- Jamie Strandboge <jamie@ubuntu.com> Mon, 07 Apr 2008 16:09:38 -0400 | ||
3139 | 4237 | |||
3140 | 4238 | openldap2.3 (2.4.7-6ubuntu2) hardy; urgency=low | ||
3141 | 4239 | |||
3142 | 4240 | * apparmor-profile workaround for Launchpad #202161 | ||
3143 | 4241 | * follow ApparmorProfileMigration and force apparmor complain mode on some | ||
3144 | 4242 | upgrades (LP: #203529) | ||
3145 | 4243 | - debian/control: Recommends apparmor >= 2.1+1075-0ubuntu6 | ||
3146 | 4244 | - debian/slapd.dirs: add etc/apparmor.d/force-complain | ||
3147 | 4245 | - debian/slapd.preinst: create symlink for force-complain/ on pre-feisty | ||
3148 | 4246 | upgrades, upgrades where apparmor-profiles profile is unchanged (ie | ||
3149 | 4247 | non-enforcing) and upgrades where apparmor profile does not exist | ||
3150 | 4248 | - debian/slapd.postrm: remove symlink in force-complain/ on purge | ||
3151 | 4249 | * debian/rules, debian/slapd.links: use hard links to slapd instead of | ||
3152 | 4250 | symlinks for slap* so these applications aren't confined by apparmor | ||
3153 | 4251 | (LP: #203898) | ||
3154 | 4252 | |||
3155 | 4253 | -- Jamie Strandboge <jamie@ubuntu.com> Tue, 18 Mar 2008 13:53:23 -0400 | ||
3156 | 4254 | |||
3157 | 4255 | openldap2.3 (2.4.7-6ubuntu1) hardy; urgency=low | ||
3158 | 4256 | |||
3159 | 4257 | * Merge from Debian unstable, remaining changes: | ||
3160 | 4258 | + debian/patches/SECURITY_CVE-2008-0658.patch (LP: #197077) | ||
3161 | 4259 | slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 | ||
3162 | 4260 | allows remote authenticated users to cause a denial of service (daemon | ||
3163 | 4261 | crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) | ||
3164 | 4262 | control, a related issue to CVE-2007-6698. | ||
3165 | 4263 | + debian/apparmor-profile: add AppArmor profile | ||
3166 | 4264 | + debian/slapd.postinst: Reload AA profile on configuration | ||
3167 | 4265 | + updated debian/slapd.README.Debian for note on AppArmor | ||
3168 | 4266 | + debian/control: Replaces apparmor-profiles << 2.1+1075-0ubuntu4 as we | ||
3169 | 4267 | should now take control | ||
3170 | 4268 | + debian/control: Conflicts with apparmor-profiles << 2.1+1075-0ubuntu4 | ||
3171 | 4269 | to make sure that if earlier version of apparmor-profiles gets | ||
3172 | 4270 | installed it won't overwrite our profile | ||
3173 | 4271 | + Modify Maintainer value to match the DebianMaintainerField | ||
3174 | 4272 | specification. | ||
3175 | 4273 | |||
3176 | 4274 | -- Steve Langasek <steve.langasek@ubuntu.com> Tue, 04 Mar 2008 01:59:51 +0000 | ||
3177 | 4275 | |||
3178 | 1450 | openldap2.3 (2.4.7-6) unstable; urgency=low | 4276 | openldap2.3 (2.4.7-6) unstable; urgency=low |
3179 | 1451 | 4277 | ||
3180 | 1452 | [ Updated debconf translations ] | 4278 | [ Updated debconf translations ] |
3181 | @@ -1492,6 +4318,37 @@ openldap2.3 (2.4.7-6) unstable; urgency=low | |||
3182 | 1492 | 4318 | ||
3183 | 1493 | -- Steve Langasek <vorlon@debian.org> Thu, 28 Feb 2008 22:15:17 -0800 | 4319 | -- Steve Langasek <vorlon@debian.org> Thu, 28 Feb 2008 22:15:17 -0800 |
3184 | 1494 | 4320 | ||
3185 | 4321 | openldap2.3 (2.4.7-5ubuntu2) hardy; urgency=low | ||
3186 | 4322 | |||
3187 | 4323 | * SECURITY UPDATE: | ||
3188 | 4324 | + debian/patches/SECURITY_CVE-2008-0658.patch (LP: #197077) | ||
3189 | 4325 | slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 | ||
3190 | 4326 | allows remote authenticated users to cause a denial of service (daemon crash) | ||
3191 | 4327 | via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related | ||
3192 | 4328 | issue to CVE-2007-6698. | ||
3193 | 4329 | |||
3194 | 4330 | * References | ||
3195 | 4331 | - http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0658 | ||
3196 | 4332 | - http://www.openldap.org/its/index.cgi/Software%20Bugs?id=5358 | ||
3197 | 4333 | |||
3198 | 4334 | -- Emanuele Gentili <emgent@emanuele-gentili.com> Sun, 02 Mar 2008 16:34:30 +0100 | ||
3199 | 4335 | |||
3200 | 4336 | openldap2.3 (2.4.7-5ubuntu1) hardy; urgency=low | ||
3201 | 4337 | |||
3202 | 4338 | * add AppArmor profile | ||
3203 | 4339 | + debian/apparmor-profile | ||
3204 | 4340 | + debian/slapd.postinst: Reload AA profile on configuration | ||
3205 | 4341 | * updated debian/slapd.README.Debian for note on AppArmor | ||
3206 | 4342 | * debian/control: Replaces apparmor-profiles << 2.1+1075-0ubuntu4 as we | ||
3207 | 4343 | should now take control | ||
3208 | 4344 | * debian/control: Conflicts with apparmor-profiles << 2.1+1075-0ubuntu4 | ||
3209 | 4345 | to make sure that if earlier version of apparmor-profiles gets installed | ||
3210 | 4346 | it won't overwrite our profile | ||
3211 | 4347 | * Modify Maintainer value to match the DebianMaintainerField | ||
3212 | 4348 | specification. | ||
3213 | 4349 | |||
3214 | 4350 | -- Jamie Strandboge <jamie@ubuntu.com> Wed, 13 Feb 2008 17:15:41 +0000 | ||
3215 | 4351 | |||
3216 | 1495 | openldap2.3 (2.4.7-5) unstable; urgency=low | 4352 | openldap2.3 (2.4.7-5) unstable; urgency=low |
3217 | 1496 | 4353 | ||
3218 | 1497 | [ Updated debconf translations ] | 4354 | [ Updated debconf translations ] |
3219 | diff --git a/debian/control b/debian/control | |||
3220 | index 263cc9e..7a3b0c8 100644 | |||
3221 | --- a/debian/control | |||
3222 | +++ b/debian/control | |||
3223 | @@ -1,11 +1,13 @@ | |||
3224 | 1 | Source: openldap | 1 | Source: openldap |
3225 | 2 | Section: net | 2 | Section: net |
3226 | 3 | Priority: optional | 3 | Priority: optional |
3228 | 4 | Maintainer: Debian OpenLDAP Maintainers <pkg-openldap-devel@lists.alioth.debian.org> | 4 | Maintainer: Ubuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com> |
3229 | 5 | XSBC-Original-Maintainer: Debian OpenLDAP Maintainers <pkg-openldap-devel@lists.alioth.debian.org> | ||
3230 | 5 | Uploaders: Steve Langasek <vorlon@debian.org>, | 6 | Uploaders: Steve Langasek <vorlon@debian.org>, |
3231 | 6 | Torsten Landschoff <torsten@debian.org>, | 7 | Torsten Landschoff <torsten@debian.org>, |
3232 | 7 | Ryan Tandy <ryan@nardis.ca> | 8 | Ryan Tandy <ryan@nardis.ca> |
3233 | 8 | Build-Depends: debhelper-compat (= 12), | 9 | Build-Depends: debhelper-compat (= 12), |
3234 | 10 | dh-apparmor, | ||
3235 | 9 | dpkg-dev (>= 1.17.14), | 11 | dpkg-dev (>= 1.17.14), |
3236 | 10 | groff-base, | 12 | groff-base, |
3237 | 11 | heimdal-multidev (>= 7.4.0.dfsg.1-1~) <!pkg.openldap.noslapd>, | 13 | heimdal-multidev (>= 7.4.0.dfsg.1-1~) <!pkg.openldap.noslapd>, |
3238 | @@ -35,7 +37,7 @@ Depends: ${shlibs:Depends}, libldap-2.5-0 (= ${binary:Version}), | |||
3239 | 35 | coreutils (>= 4.5.1-1), psmisc, perl:any (>> 5.8.0) | libmime-base64-perl, | 37 | coreutils (>= 4.5.1-1), psmisc, perl:any (>> 5.8.0) | libmime-base64-perl, |
3240 | 36 | adduser, lsb-base (>= 3.2-13), ${perl:Depends}, ${misc:Depends} | 38 | adduser, lsb-base (>= 3.2-13), ${perl:Depends}, ${misc:Depends} |
3241 | 37 | Recommends: ldap-utils | 39 | Recommends: ldap-utils |
3243 | 38 | Suggests: libsasl2-modules, | 40 | Suggests: libsasl2-modules, ufw, |
3244 | 39 | libsasl2-modules-gssapi-mit | libsasl2-modules-gssapi-heimdal | 41 | libsasl2-modules-gssapi-mit | libsasl2-modules-gssapi-heimdal |
3245 | 40 | Conflicts: umich-ldapd, ldap-server, libltdl3 (= 1.5.4-1) | 42 | Conflicts: umich-ldapd, ldap-server, libltdl3 (= 1.5.4-1) |
3246 | 41 | Replaces: libldap2, ldap-utils (<< 2.2.23-3) | 43 | Replaces: libldap2, ldap-utils (<< 2.2.23-3) |
3247 | diff --git a/debian/rules b/debian/rules | |||
3248 | index cc0a583..3a80b0d 100755 | |||
3249 | --- a/debian/rules | |||
3250 | +++ b/debian/rules | |||
3251 | @@ -15,7 +15,7 @@ export DEB_BUILD_MAINT_OPTIONS := hardening=+all | |||
3252 | 15 | export AUTOMAKE = true | 15 | export AUTOMAKE = true |
3253 | 16 | 16 | ||
3254 | 17 | # Expose maintainer address to build/mkversion (see debian/patches/set-maintainer-name) | 17 | # Expose maintainer address to build/mkversion (see debian/patches/set-maintainer-name) |
3256 | 18 | export DEB_MAINTAINER := $(shell sed -ne 's/Maintainer:\s\+//p' debian/control) | 18 | export DEB_MAINTAINER := $(shell sed -ne 's/^Maintainer:\s\+//p' debian/control) |
3257 | 19 | 19 | ||
3258 | 20 | # Expose DEB_VERSION to build/version.sh (see debian/patches/debian-version) | 20 | # Expose DEB_VERSION to build/version.sh (see debian/patches/debian-version) |
3259 | 21 | export DEB_VERSION | 21 | export DEB_VERSION |
3260 | @@ -157,6 +157,22 @@ endif | |||
3261 | 157 | find $(installdir)/usr/share/man -name \*.8 \ | 157 | find $(installdir)/usr/share/man -name \*.8 \ |
3262 | 158 | | xargs perl -pi -e 's#(\.TH \w+ 8)C#$$1#' | 158 | | xargs perl -pi -e 's#(\.TH \w+ 8)C#$$1#' |
3263 | 159 | 159 | ||
3264 | 160 | ifeq ($(filter stage1,$(DEB_BUILD_PROFILES)),) | ||
3265 | 161 | override_dh_install-arch: | ||
3266 | 162 | dh_install | ||
3267 | 163 | |||
3268 | 164 | # install AppArmor profile | ||
3269 | 165 | install -D -m 644 $(CURDIR)/debian/apparmor-profile $(CURDIR)/debian/slapd/etc/apparmor.d/usr.sbin.slapd | ||
3270 | 166 | |||
3271 | 167 | # install Apport hook | ||
3272 | 168 | install -D -m 644 $(CURDIR)/debian/slapd.py $(CURDIR)/debian/slapd/usr/share/apport/package-hooks/slapd.py | ||
3273 | 169 | |||
3274 | 170 | # install ufw profile | ||
3275 | 171 | install -D -m 644 $(CURDIR)/debian/slapd.ufw.profile $(CURDIR)/debian/slapd/etc/ufw/applications.d/slapd | ||
3276 | 172 | |||
3277 | 173 | dh_apparmor -pslapd --profile-name=usr.sbin.slapd | ||
3278 | 174 | endif | ||
3279 | 175 | |||
3280 | 160 | override_dh_installinit: | 176 | override_dh_installinit: |
3281 | 161 | dh_installinit --no-restart-after-upgrade --error-handler=ignore_init_failure -- "defaults 19 80" | 177 | dh_installinit --no-restart-after-upgrade --error-handler=ignore_init_failure -- "defaults 19 80" |
3282 | 162 | 178 | ||
3283 | diff --git a/debian/slapd.README.Debian b/debian/slapd.README.Debian | |||
3284 | index ff7d66b..a4f3f55 100644 | |||
3285 | --- a/debian/slapd.README.Debian | |||
3286 | +++ b/debian/slapd.README.Debian | |||
3287 | @@ -252,6 +252,17 @@ Modifications Compared to Upstream | |||
3288 | 252 | 252 | ||
3289 | 253 | -- Russ Allbery <rra@debian.org>, Thu, 14 Feb 2008 18:47:07 -0800 | 253 | -- Russ Allbery <rra@debian.org>, Thu, 14 Feb 2008 18:47:07 -0800 |
3290 | 254 | 254 | ||
3291 | 255 | Apparmor Profile | ||
3292 | 256 | ---------------- | ||
3293 | 257 | |||
3294 | 258 | If your system uses AppArmor, please note that the shipped enforcing profile | ||
3295 | 259 | works with the default installation, and changes in your configuration may | ||
3296 | 260 | require changes to the installed apparmor profile. Please see | ||
3297 | 261 | https://wiki.ubuntu.com/DebuggingApparmor before filing a bug against this | ||
3298 | 262 | software. | ||
3299 | 263 | |||
3300 | 264 | -- Jamie Strandboge <jamie@ubuntu.com>, Mon, 4 Feb 2008 21:18:21 -0500 | ||
3301 | 265 | |||
3302 | 255 | Migrating your installation to OpenLDAP 2.5.x | 266 | Migrating your installation to OpenLDAP 2.5.x |
3303 | 256 | 267 | ||
3304 | 257 | OpenLDAP 2.5 is a major new release and includes several incompatible | 268 | OpenLDAP 2.5 is a major new release and includes several incompatible |
3305 | diff --git a/debian/slapd.py b/debian/slapd.py | |||
3306 | 258 | new file mode 100644 | 269 | new file mode 100644 |
3307 | index 0000000..b1aed25 | |||
3308 | --- /dev/null | |||
3309 | +++ b/debian/slapd.py | |||
3310 | @@ -0,0 +1,51 @@ | |||
3311 | 1 | #!/usr/bin/python3 | ||
3312 | 2 | |||
3313 | 3 | '''apport hook for slapd | ||
3314 | 4 | |||
3315 | 5 | (c) 2010 Adam Sommer. | ||
3316 | 6 | Author: Adam Sommer <asommer@ubuntu.com> | ||
3317 | 7 | |||
3318 | 8 | This program is free software; you can redistribute it and/or modify it | ||
3319 | 9 | under the terms of the GNU General Public License as published by the | ||
3320 | 10 | Free Software Foundation; either version 2 of the License, or (at your | ||
3321 | 11 | option) any later version. See http://www.gnu.org/copyleft/gpl.html for | ||
3322 | 12 | the full text of the license. | ||
3323 | 13 | ''' | ||
3324 | 14 | |||
3325 | 15 | from apport.hookutils import * | ||
3326 | 16 | import os | ||
3327 | 17 | |||
3328 | 18 | # Scrub olcRootPW attribute and credentials strings if necessary. | ||
3329 | 19 | def scrub_pass_strings(config): | ||
3330 | 20 | olcrootpw_regex = re.compile('olcRootPW:.*') | ||
3331 | 21 | olcrootpw_string = olcrootpw_regex.search(config) | ||
3332 | 22 | if olcrootpw_string: | ||
3333 | 23 | config = config.replace(olcrootpw_string.group(0), 'olcRootPW: @@APPORTREPLACED@@') | ||
3334 | 24 | |||
3335 | 25 | credentials_regex = re.compile('credentials=.* ') | ||
3336 | 26 | credentials_string = credentials_regex.search(config) | ||
3337 | 27 | if credentials_string: | ||
3338 | 28 | config = config.replace(credentials_string.group(0), 'credentials=@@APPORTREPLACED@@ ') | ||
3339 | 29 | |||
3340 | 30 | return config | ||
3341 | 31 | |||
3342 | 32 | def add_info(report, ui): | ||
3343 | 33 | response = ui.yesno("The contents of your /etc/ldap/slapd.d directory " | ||
3344 | 34 | "may help developers diagnose your bug more " | ||
3345 | 35 | "quickly. However, it may contain sensitive " | ||
3346 | 36 | "information. Do you want to include it in your " | ||
3347 | 37 | "bug report?") | ||
3348 | 38 | |||
3349 | 39 | if response == None: # user cancelled | ||
3350 | 40 | raise StopIteration | ||
3351 | 41 | |||
3352 | 42 | elif response == True: | ||
3353 | 43 | # Get the cn=config tree. | ||
3354 | 44 | cn_config = root_command_output(['/usr/bin/ldapsearch', '-Q', '-LLL', '-Y EXTERNAL', '-H ldapi:///', '-b cn=config']) | ||
3355 | 45 | report['CNConfig'] = scrub_pass_strings(cn_config) | ||
3356 | 46 | |||
3357 | 47 | # Get slapd messages from /var/log/syslog | ||
3358 | 48 | slapd_re = re.compile('slapd', re.IGNORECASE) | ||
3359 | 49 | report['SysLog'] = recent_syslog(slapd_re) | ||
3360 | 50 | |||
3361 | 51 | attach_mac_events(report, '/usr/sbin/slapd') | ||
3362 | diff --git a/debian/slapd.ufw.profile b/debian/slapd.ufw.profile | |||
3363 | 0 | new file mode 100644 | 52 | new file mode 100644 |
3364 | index 0000000..3c4f676 | |||
3365 | --- /dev/null | |||
3366 | +++ b/debian/slapd.ufw.profile | |||
3367 | @@ -0,0 +1,9 @@ | |||
3368 | 1 | [OpenLDAP LDAP] | ||
3369 | 2 | title=OpenLDAP with TLS | ||
3370 | 3 | description=OpenLDAP is a free, fast, lightweight LDAP server | ||
3371 | 4 | ports=389/tcp | ||
3372 | 5 | |||
3373 | 6 | [OpenLDAP LDAPS] | ||
3374 | 7 | title=OpenLDAP over SSL | ||
3375 | 8 | description=OpenLDAP is a free, fast, lightweight LDAP server | ||
3376 | 9 | ports=636/tcp |
Thanks for the review, Athos.
Uploaded:
$ git push pkg upload/ 2.5.6+dfsg- 1_exp1ubuntu1 launchpad. net/ubuntu/ +source/ openldap 2.5.6+dfsg- 1_exp1ubuntu1 -> upload/ 2.5.6+dfsg- 1_exp1ubuntu1
Enumerating objects: 41, done.
Counting objects: 100% (41/41), done.
Delta compression using up to 8 threads
Compressing objects: 100% (35/35), done.
Writing objects: 100% (35/35), 22.40 KiB | 1.60 MiB/s, done.
Total 35 (delta 24), reused 2 (delta 0)
To ssh://git.
* [new tag] upload/
$ dput openldap_ 2.5.6+dfsg- 1~exp1ubuntu1_ source. changes work/openldap/ openldap_ 2.5.6+dfsg- 1~exp1ubuntu1_ source. changes: Valid signature from 106DA1C8C3CBBF14 work/openldap/ openldap_ 2.5.6+dfsg- 1~exp1ubuntu1. dsc: Valid signature from 106DA1C8C3CBBF14 2.5.6+dfsg- 1~exp1ubuntu1. dsc: done. 2.5.6+dfsg. orig.tar. gz: done. 2.5.6+dfsg- 1~exp1ubuntu1. debian. tar.xz: done. 2.5.6+dfsg- 1~exp1ubuntu1_ source. buildinfo: done. 2.5.6+dfsg- 1~exp1ubuntu1_ source. changes: done.
Trying to upload package to ubuntu
Checking signature on .changes
gpg: /home/sergio/
Checking signature on .dsc
gpg: /home/sergio/
Package includes an .orig.tar.gz file although the debian revision suggests
that it might not be required. Multiple uploads of the .orig.tar.gz may be
rejected by the upload queue management software.
Uploading to ubuntu (via ftp to upload.ubuntu.com):
Uploading openldap_
Uploading openldap_
Uploading openldap_
Uploading openldap_
Uploading openldap_
Successfully uploaded packages.