<feed xmlns='http://www.w3.org/2005/Atom'>
<title>sssd.git/src/providers/krb5, branch nonroot-libcap</title>
<subtitle>sssd with jhrozek's patches</subtitle>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/'/>
<entry>
<title>UTIL: Move become_user outside krb5 tree</title>
<updated>2014-10-07T11:48:04+00:00</updated>
<author>
<name>Jakub Hrozek</name>
<email>jhrozek@redhat.com</email>
</author>
<published>2014-07-26T10:46:26+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=21983497ff98e34e34f8a626fd0bba24831fd1b4'/>
<id>21983497ff98e34e34f8a626fd0bba24831fd1b4</id>
<content type='text'>
In order for several other SSSD processes to run as a non-root user, we
need to move the functions to become another user to a shared space in
our source tree.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
In order for several other SSSD processes to run as a non-root user, we
need to move the functions to become another user to a shared space in
our source tree.
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix debug messages - trailing '.'</title>
<updated>2014-09-29T16:15:01+00:00</updated>
<author>
<name>Pavel Reichl</name>
<email>preichl@redhat.com</email>
</author>
<published>2014-09-27T11:06:44+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=c683b8d730f4ec838244147d70a0275d53459aa5'/>
<id>c683b8d730f4ec838244147d70a0275d53459aa5</id>
<content type='text'>
Fix debug messages where '\n' was wrongly followed by '.'.

Reviewed-by: Lukáš Slebodník &lt;lslebodn@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Fix debug messages where '\n' was wrongly followed by '.'.

Reviewed-by: Lukáš Slebodník &lt;lslebodn@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>UTIL: rename find_subdomain_by_name</title>
<updated>2014-07-22T07:40:08+00:00</updated>
<author>
<name>Pavel Reichl</name>
<email>preichl@redhat.com</email>
</author>
<published>2014-07-21T07:06:23+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=db18dda869bc6c52a41797b2066cf121cf10f49c'/>
<id>db18dda869bc6c52a41797b2066cf121cf10f49c</id>
<content type='text'>
The function was named "find_subdomain" yet it could find both main
domain and subdomain.

sed 's/find_subdomain_by_name/find_domain_by_name/' -i `find . -name "*.[ch]"`

Reviewed-by: Jakub Hrozek &lt;jhrozek@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The function was named "find_subdomain" yet it could find both main
domain and subdomain.

sed 's/find_subdomain_by_name/find_domain_by_name/' -i `find . -name "*.[ch]"`

Reviewed-by: Jakub Hrozek &lt;jhrozek@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>KRB5: add missing debug-to-stderr option to krb5_child</title>
<updated>2014-07-20T19:26:19+00:00</updated>
<author>
<name>Sumit Bose</name>
<email>sbose@redhat.com</email>
</author>
<published>2014-07-18T20:34:23+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=ee4ba51f2fcfc8d8b807c3de6eaac554281165d2'/>
<id>ee4ba51f2fcfc8d8b807c3de6eaac554281165d2</id>
<content type='text'>
Without this option krb5_child cannot be run in interactive mode.

Reviewed-by: Jakub Hrozek &lt;jhrozek@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Without this option krb5_child cannot be run in interactive mode.

Reviewed-by: Jakub Hrozek &lt;jhrozek@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>KRB5: Go offline in case of generic error</title>
<updated>2014-04-17T20:18:44+00:00</updated>
<author>
<name>Pavel Reichl</name>
<email>preichl@redhat.com</email>
</author>
<published>2014-04-17T12:31:17+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=dd3398f8cc5a80cd99546bfe9c500589b78a96f1'/>
<id>dd3398f8cc5a80cd99546bfe9c500589b78a96f1</id>
<content type='text'>
Resolves:
https://fedorahosted.org/sssd/ticket/2313
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Resolves:
https://fedorahosted.org/sssd/ticket/2313
</pre>
</div>
</content>
</entry>
<entry>
<title>KRB: do not check ccache directory for GID</title>
<updated>2014-04-17T08:31:14+00:00</updated>
<author>
<name>Pavel Reichl</name>
<email>reichl.pavel@gmail.com</email>
</author>
<published>2014-04-15T15:31:49+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=26ce47cc3e2003c30bae8206c3085f0814c9a842'/>
<id>26ce47cc3e2003c30bae8206c3085f0814c9a842</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>krb5_child: Fix use after free in debug message</title>
<updated>2014-04-08T12:12:23+00:00</updated>
<author>
<name>Lukas Slebodnik</name>
<email>lslebodn@redhat.com</email>
</author>
<published>2014-04-08T08:56:22+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=47bc2d6639c41da1e5bac37eb4af3559bbc0e10e'/>
<id>47bc2d6639c41da1e5bac37eb4af3559bbc0e10e</id>
<content type='text'>
debug_prg_name is used in debug_fn and it was allocated under
talloc context "kr". The variable "kr" was removed before the last debug
messages in function main. It is very little change that it will be overridden.
It is possible to see this issue with exported environment variable
TALLOC_FREE_FILL=255

Reviewed-by: Sumit Bose &lt;sbose@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
debug_prg_name is used in debug_fn and it was allocated under
talloc context "kr". The variable "kr" was removed before the last debug
messages in function main. It is very little change that it will be overridden.
It is possible to see this issue with exported environment variable
TALLOC_FREE_FILL=255

Reviewed-by: Sumit Bose &lt;sbose@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>krb5_child: Remove unused krb5_context from set_changepw_options</title>
<updated>2014-04-07T15:46:10+00:00</updated>
<author>
<name>Lukas Slebodnik</name>
<email>lslebodn@redhat.com</email>
</author>
<published>2014-04-05T09:26:59+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=d2ea839a907ba6ee1fe44027d67b11b02593fc99'/>
<id>d2ea839a907ba6ee1fe44027d67b11b02593fc99</id>
<content type='text'>
Reviewed-by: Pavel Reichl &lt;preichl@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Reviewed-by: Pavel Reichl &lt;preichl@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>KRB5: Do not attempt to get a TGT after a password change using OTP</title>
<updated>2014-03-26T08:56:23+00:00</updated>
<author>
<name>Jakub Hrozek</name>
<email>jhrozek@redhat.com</email>
</author>
<published>2014-03-18T15:48:11+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=3983d81f461a4f17736a516eb595f54df4bf4336'/>
<id>3983d81f461a4f17736a516eb595f54df4bf4336</id>
<content type='text'>
https://fedorahosted.org/sssd/ticket/2271

The current krb5_child code attempts to get a TGT for the convenience of
the user using the new password after a password change operation.
However, an OTP should never be used twice, which means we can't perform
the kinit operation after chpass is finished. Instead, we only print a
PAM information instructing the user to log out and back in manually.

Reviewed-by: Alexander Bokovoy &lt;abokovoy@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
https://fedorahosted.org/sssd/ticket/2271

The current krb5_child code attempts to get a TGT for the convenience of
the user using the new password after a password change operation.
However, an OTP should never be used twice, which means we can't perform
the kinit operation after chpass is finished. Instead, we only print a
PAM information instructing the user to log out and back in manually.

Reviewed-by: Alexander Bokovoy &lt;abokovoy@redhat.com&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>krb5-child: add revert_changepw_options()</title>
<updated>2014-03-21T22:06:26+00:00</updated>
<author>
<name>Sumit Bose</name>
<email>sbose@redhat.com</email>
</author>
<published>2014-03-21T15:16:23+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/jhrozek/public_git/sssd.git/commit/?id=6bbff437dcea7e56d71cf119d1391be7264dfaf0'/>
<id>6bbff437dcea7e56d71cf119d1391be7264dfaf0</id>
<content type='text'>
After changing the Kerberos password krb5-child will try to get a fresh
TGT with the new password. This patch tries to make sure the right gic
options are used.

Resolves: https://fedorahosted.org/sssd/ticket/2289

Reviewed-by: Jakub Hrozek &lt;jhrozek@redhat.com&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
After changing the Kerberos password krb5-child will try to get a fresh
TGT with the new password. This patch tries to make sure the right gic
options are used.

Resolves: https://fedorahosted.org/sssd/ticket/2289

Reviewed-by: Jakub Hrozek &lt;jhrozek@redhat.com&gt;
</pre>
</div>
</content>
</entry>
</feed>
