Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

pam_krb5-2.3.13-11.1.3 RPM for i586

From OpenSuSE 12.1 for i586

Name: pam_krb5 Distribution: openSUSE 12.1
Version: 2.3.13 Vendor: openSUSE
Release: 11.1.3 Build date: Sat Oct 29 19:33:35 2011
Group: Productivity/Networking/Security Build host: build31
Size: 400542 Source RPM: pam_krb5-2.3.13-11.1.3.src.rpm
Summary: PAM Module for Kerberos Authentication
This PAM module supports authentication against a Kerberos KDC. It also
supports updating your Kerberos password.




BSD3c(or similar) ; LGPLv2.0+


* Tue Aug 23 2011
  - disable checks during build. Does not work reliable in the
* Sun Aug 21 2011
  - update to version 2.3.13
    * don't bother creating a v5 ccache in "external" mode
    * add a "trace" option to enable libkrb5 tracing, if available
    * avoid trying to get password-change creds twice
    * use an in-memory ccache when obtaining tokens using v5 creds
    * turn off creds==session in "sshd"
    * add a "validate_user_user" option to control trying to perform
      user-to-user authentication to validate TGTs when a keytab is not
    * add an "ignore_k5login" option to control whether or not the module
      will use the krb5_kuserok() function to perform additional
      authorization checks
    * turn on validation by default - verify_ap_req_nofail controls how we
      treat errors reading keytab files now
    * add an "always_allow_localname" option when we can use
      krb5_aname_to_localname() to second-guess the krb5_kuserok() check
    * prefer krb5_change_password() to krb5_set_password()
* Tue Mar 01 2011
  - make pam_sm_setcred less verbose (bnc#641008)
* Fri Nov 19 2010
  - remove autoreconf call - breaks more than it helps
* Mon Mar 22 2010
  - update to version 2.3.11
    * create credentials before trying to look up the location of
      the user's home directory via krb5_kuserok()
* Thu Mar 04 2010
  - update to version 2.3.10-3
    * add a "chpw_prompt" option
    * add a "multiple_ccaches" option
    * fine-tune the logic for selecting which key we use for
      validating credentials
    * fixes
* Mon Feb 01 2010
  - package baselibs.conf
* Tue Nov 03 2009
  - updated patches to apply with fuzz=0
* Mon Jul 27 2009
  - version 2.3.7
    * when refreshing credentials, store the new creds in the default
      ccache if $KRB5CCNAME isn't set.
    * prefer a "host" key, if one is found, when validating TGTs
* Wed Jun 24 2009
  - Supplement pam-32bit/pam-64bit in baselibs.conf (bnc#354164).
* Mon Jun 15 2009
  - compile fixes for krb5 1.7
* Mon Jun 08 2009
  - update to version 2.3.5
    * make prompting behavior for non-existent accounts and users who
      just press enter match up with those who aren't/don't (#502602,
* Wed May 20 2009
  - update to version 2.3.4
    * don't request password-changing credentials using the same options
      we use for ticket-granting tickets
    * close a couple of open pipes to defunct processes, fix a couple
      of debug messages
    * fix ccache permissions bypass when the "existing_ticket" option is
      used (CVE-2008-3825, which affects 2.2.0-2.2.25, 2.3.0, and 2.3.1)
  - obsolete a lot of patches.



Generated by rpm2html 1.8.1

Fabrice Bellet, Mon Jul 10 03:42:25 2017