a3548c3... by Mattia Rizzolo on 2017-04-10

Import patches-unapplied version 4.4.3-3ubuntu2 to ubuntu/zesty-proposed

Imported using git-ubuntu import.

Changelog parent: 257f4f9ce8d8aeb77df0a4dd1cfc08f26cecaf8c

New changelog entries:
  * No-change rebuild against ldns2.

257f4f9... by Timo Aaltonen on 2017-02-16

Import patches-unapplied version 4.4.3-3ubuntu1 to ubuntu/zesty-proposed

Imported using git-ubuntu import.

Changelog parent: 35c0252abc8a836f95ceb9690ed5deb748059c14

New changelog entries:
  * fix-is-running.diff: Add a third argument to is_running() in

35c0252... by Timo Aaltonen on 2017-02-16

Import patches-unapplied version 4.4.3-3 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: 39896bbd0fa78f27da2e79e69ee91cd526dc9956

New changelog entries:
  * client.postinst: Fix logfile location.

39896bb... by Timo Aaltonen on 2017-01-27

Import patches-unapplied version 4.4.3-2 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: 83b0f7f970bf4500e3d2a6e8804e1da554e5f4fc

New changelog entries:
  * control: Fix python-ipatests to depend on python-sss instead of

83b0f7f... by Timo Aaltonen on 2017-01-14

Import patches-unapplied version 4.4.3-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: e137a3036039e72d85f14d7aa4c60fe98a743caa

New changelog entries:
  * New upstream release. (Closes: #848762)
  * configure-apache-from-installer.diff: Dropped, upstream.
  * fix-cve-2016-5404.diff: Dropped, upstream.
  * patches: Refreshed.
  * work-around-apache-fail.diff: Dropped, apache supports systemd now
    so this should not be needed.
  * watch: Use https url.
  * client.postinst: Use update_ipa_nssdb(), which also removes remnants
    from /etc/pki/nssdb.
  * control: Bump depends on slapi-nis to 0.56.1.
  * control: Add python-custodia and python-requests to ipalib depends.
  * control: Use python-netifaces instead of iproute.
  * control: Add python-sssdconfig to python-ipatests depends.
  * control: Bump depends on 389-ds-base to, upstream #5396
  * control: Bump bind9-dyndb-ldap depends to 10, upstream #2008.
  * control: Add python-libsss-nss-idmap to build-depends.
  * control: Bump depends on sssd to 1.14.0.
  * install: Updated.
  * platform:
    - drop variables that were commented out
    - add some comments to tasks.py
    - migrate some services to use systemd
    - add & update some paths
    - add some stub services (LP: #1653245)
  * control: Add krb5-otp to server depends. (LP: #1640732)
  * control: Demote ntp to Recommends so that lxc containers can be
    enrolled without it. (LP: #1630911)

e137a30... by Timo Aaltonen on 2016-12-02

Import patches-unapplied version 4.3.2-5 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 01c324fd9182f9b8e2807b5dc6fb0207dd29af6e

New changelog entries:
  * fix-cve-2016-5404.diff: Fix permission check bypass (Closes: #835131)
    - CVE-2016-5404
  * ipa-kdb-support-dal-version-5-and-6.diff: Support mit-krb5 1.15.
    (Closes: #844114)

01c324f... by Timo Aaltonen on 2016-12-01

Import patches-unapplied version 4.3.2-4 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 330f89e1919a40fadbfa358bc7727c550922ef0d

New changelog entries:
  * freeipa-client.post*: Use /var/log/ipaclient-upgrade.log instead of
    ipaupgrade.log, and remove it on purge. (Closes: #842071)
  * control: Bump dependency on libapache2-mod-auth-gssapi to verify
    upstream bug #5653 is resolved.
  * platform: Add Debian mapping for rpcgssd and rpcidmapd service
    files. (LP: #1645201)

330f89e... by Timo Aaltonen on 2016-10-05

Import patches-unapplied version 4.3.2-3 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 57c5ab0f2e4d2818a14f88d4da54f2327d4f4870

New changelog entries:
  * rules: Add a check to override_dh_fixperms so that chmod is not run
    on arch-indep build where the targets don't exist. (Closes: #839844)

57c5ab0... by Timo Aaltonen on 2016-10-04

Import patches-unapplied version 4.3.2-2 to debian/sid

Imported using git-ubuntu import.

Changelog parent: ec36ae145c14372894e248f1e2d1dc231c7fa7e8

New changelog entries:
  * copyright: Since ffb9a09a0d all original code should be GPL-3+, so
    drop some exceptions.
  * control: Add libnss-sss, libpam-sss and libsss-sudo to client depends
    to ensure they get installed. (LP: #1600513)
  * fix-ipa-otpd-service.diff: Use correct path for ipa-otpd. (LP:
  * add-debian-platform.diff: Fix libsofthsm2.so install path.
  * control: Bump dep on softhsm2 due to changed lib install path.
  * tests: Add simple autopkgtest to check that ipa-server-install

ec36ae1... by Timo Aaltonen on 2016-09-14

Import patches-unapplied version 4.3.2-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: 5aed73dab7e4446e394ca8bef8dcb71db09ebd9a

New changelog entries:
  * New upstream release.
  * copyright, missing-sources, README.source: Exclude minified javascript
    that the runtime does not need. Add unminified versions of others,
    update copyright to match. (Closes: #787593)
  * source/lintian-overrides: Document minified javascript issues.
  * control: python-ipalib can be arch:all now.
  * New upstream release. (Closes: #781607, #786411) (LP: #1449304)
    - drop no-test-lang.diff, obsolete
  * fix-match-hostname.diff, control: Drop the patch and python-openssl
    deps, not needed anymore
  * rules, platform, server.dirs, server.install:
    Add support for DNSSEC.
  * control, rules: Add support for kdcproxy.
  * control, server: Migrate to mod-auth-gssapi.
  * control, rules, fix-ipa-conf.diff: Add support for custodia.
  * control:
    - Add python-cryptography to build-deps and python-freeipa deps.
    - Add libp11-kit-dev to build-deps, p11-kit to server deps.
    - Depend on python-gssapi instead of python-kerberos/-krbV.
    - Add libini-config-dev and python-dbus to build-deps, replace wget
      with curl.
    - Bump libkrb5-dev build-dep.
    - Add pki-base to build-deps and pki-kra to server deps, bump pki-ca
    - Drop python-m2crypto from deps, obsolete.
    - Bump sssd deps to 1.13.1.
    - Add python-six to build-deps and python-freeipa deps.
    - Split python stuff from server, client, tests to python-
      ipa{server,client,tests}, rename python-freeipa to match and move
      translations to freeipa-common. Mark them Arch:all where possible,
      and add Breaks/Replaces.
    - Add oddjob to server and oddjob-mkhomedir to client deps.
    - Add python-setuptools to python-ipalib deps.
    - Bump 389-ds-base* deps.
    - Bump server and python-ipaserver dependency on python-ldap to 2.4.22
      to fix a bug on ipa-server-upgrade.
    - Add pki-tools to python-ipaserver deps.
    - Add zip to python-ipaserver depends.
    - Add python-systemd to server depends.
    - Add opendnssec to freeipa-server-dns depends.
    - Add python-cffi to python-ipalib depends.
    - Bump dep on bind9-dyndb-ldap.
    - Bump certmonger dependency to version that has helpers in the correct
  * patches:
    - prefix.patch: Fix ipalib install too.
    - Drop bits of platform.diff and other patches that are now upstream.
    - fix-kdcproxy-paths.diff: Fix paths in kdcproxy configs.
    - fix-oddjobs.diff: Fix paths and uids in oddjob configs.
    - fix-replicainstall.diff: Use ldap instead of ldaps for conncheck.
    - fix-dnssec-services.diff: Debianize ipa-dnskeysyncd & ipa-ods-
      exporter units.
    - create-sysconfig-ods.diff: Create an empty file for opendnssec
      daemons, until opendnssec itself is fixed.
    - purge-firefox-extension.diff: Clean obsolete kerberosauth.xpi.
    - enable-mod-nss-during-setup.diff: Split from platform.diff, call
      a2enmod/a2dismod from httpinstance.py.
    - fix-memcached.diff: Split from platform.diff, debianize memcached
      conf & unit.
    - hack-libarch.diff: Don't use fedora libpaths.
  * add-debian-platform.diff:
    - Update paths.py to include all variables, comment out ones we don't
    - Use systemwide certificate store; put ipa-ca.crt in
      /usr/local/share/ca-certificates, and run update-ca-certificates
    - Map smb service to smbd (LP: #1543230)
    - Don't ship /var/cache/bind/data, fix named.conf a bit.
    - Use DebianNoService() for dbus. (LP: #1564981)
    - Add more constants
  * Split freeipa-server-dns from freeipa-server, add -dns to -server
  * server.postinst: Use ipa-server-upgrade.
  * admintools: Use the new location for bash completions.
  * rules: Remove obsolete configure.jar, preferences.html.
  * platform: Fix ipautil.run stdout handling, add support for systemd.
  * server.postinst, tmpfile: Create state directories for
  * rules, server.install: Install scripts under /usr/lib instead of
    multiarch path to avoid hacking the code too much.
  * fix-ipa-otpd-install.diff, rules, server.install: Put ipa-otpd in
    /usr/lib/ipa instead of directly under multiarch lib path.
  * control, server*.install: Move dirsrv plugins from server-trust-ad
    to server, needed on upgrades even if trust-ad isn't set up.
  * server: Enable mod_proxy_ajp and mod_proxy_http on postinst, disable
    on postrm.
  * rules: Add SKIP_API_VERSION_CHECK, and adjust directories to clean.
  * rules: Don't enable systemd units on install.
  * client: Don't create /etc/pki/nssdb on postinst, it's not used
  * platform.diff, rules, server.install: Drop generate-rndc-key.sh, bind
    already generates the keyfile.