summaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
* Send the correct enumeration requestsssd-1.8.0-26.el6Jakub Hrozek2012-05-101-1/+1
| | | | https://fedorahosted.org/sssd/ticket/1329
* Special-case LDAP_SIZELIMIT_EXCEEDEDJakub Hrozek2012-05-101-4/+9
| | | | | | | | | | | | Previous version of the SSSD did not abort the async LDAP search operation on errors. In cases where the request ended in progress, such as when the paging was very strictly limited, the old versions at least returned partial data. This patch special-cases the LDAP_SIZELIMIT_EXCEEDED error to avoid a user-visible regression. https://fedorahosted.org/sssd/ticket/1322
* Read sysdb attribute name, not LDAP attribute map nameJakub Hrozek2012-05-101-2/+2
| | | | https://fedorahosted.org/sssd/ticket/1320
* Lowercase group members in case-insensitive domainsJakub Hrozek2012-04-301-1/+7
| | | | https://fedorahosted.org/sssd/ticket/1312
* AUTOFS: fix copy-and-paste bug in the autofs clientJakub Hrozek2012-04-201-1/+1
|
* sdap_check_aliases must not error when detects the same userJakub Hrozek2012-04-201-13/+31
| | | | https://fedorahosted.org/sssd/ticket/1307
* Get the RootDSE after binding if not successfull beforeJakub Hrozek2012-04-201-26/+104
| | | | https://fedorahosted.org/sssd/ticket/1258
* Add umask before mkstemp() call in SSH responderJan Zeleny2012-04-091-0/+3
|
* Only free returned values on successJakub Hrozek2012-04-091-3/+3
| | | | https://fedorahosted.org/sssd/ticket/1237
* Fixed uninitialized pointer in SSH authorized keys clientJan Zeleny2012-04-091-1/+1
|
* Fixed uninitialized pointer in SSH known host proxyJan Zeleny2012-04-091-1/+1
|
* Autofs: operate on contents of double-pointer, not addressJakub Hrozek2012-04-091-3/+3
| | | | https://fedorahosted.org/sssd/ticket/1234
* Catch cases where D-Bus connection is NULLJakub Hrozek2012-04-092-0/+24
| | | | https://fedorahosted.org/sssd/ticket/1270
* Fix regression in SSSDConfig.pyJakub Hrozek2012-04-091-1/+1
| | | | https://fedorahosted.org/sssd/ticket/1291
* Make the string_equal() function publicsssd-1.8.0-20.el6Jakub Hrozek2012-03-303-13/+14
|
* Return correct resolv_status on resolver timeoutJakub Hrozek2012-03-304-24/+95
| | | | https://fedorahosted.org/sssd/ticket/1274
* Save alias of the primary name, tooJakub Hrozek2012-03-302-11/+23
|
* Fix off-by-one error in principal selectionJakub Hrozek2012-03-301-3/+3
| | | | https://fedorahosted.org/sssd/ticket/1269
* Support lookup of services with case-insensitive protocolJakub Hrozek2012-03-304-58/+75
| | | | | | | | | | Add sss_get_cased_name_list utility function LDAP services: Save lowercased protocol names in case-insensitive domains https://fedorahosted.org/sssd/ticket/1260 Proxy services: Save lowercased protocol names and aliases in case-insensitive domains
* NSS: Look for services with correct case when cache is updatedJakub Hrozek2012-03-301-7/+7
| | | | https://fedorahosted.org/sssd/ticket/1259
* Start SSSD earlier and stop it laterStephen Gallagher2012-03-211-1/+1
| | | | | | | | SSSD needs to be started before NFS-related processes or they will mount with the username 'nobody' if they would have otherwise used LDAP accounts. https://fedorahosted.org/sssd/ticket/1273
* Fix uninitialized variablesssd-1.8.0-17.el6Jakub Hrozek2012-03-201-1/+1
|
* SSH: Fix infinite loop in sss_ssh_knownhostsproxyJan Cholasta2012-03-201-6/+9
| | | | https://fedorahosted.org/sssd/ticket/1268
* LDAP: Errors retrieving the RootDSE should not be fatalsssd-1.8.0-16.el6Stephen Gallagher2012-03-161-15/+8
| | | | | | | | If we can't reach the RootDSE, let's just proceed as if it's unavailable with reasonable defaults. If we fail later on, that's fine. Fixes https://fedorahosted.org/sssd/ticket/1257
* SYSDB: Save only lowercased aliases in case-insensitive domainsStephen Gallagher2012-03-161-19/+28
| | | | https://fedorahosted.org/sssd/ticket/1253
* SSH: Canonicalize host name and do reverse DNS lookupJan Cholasta2012-03-168-101/+101
| | | | | | | | | | | SSH: Allow clients to explicitly specify host alias This change removes the need to canonicalize host names on the responder side - the relevant code was removed. SSH: Canonicalize host name and do reverse DNS lookup in sss_ssh_knownhostsproxy https://fedorahosted.org/sssd/ticket/1245
* Save original name into the in-memory cacheJakub Hrozek2012-03-161-1/+1
|
* IPA: Initialize hbac_ctx to NULLsssd-1.8.0-15.el6Stephen Gallagher2012-03-121-1/+1
|
* Update translations for RHEL 6.3Stephen Gallagher2012-03-1246-465/+20979
| | | | | | | | Include new manpages in translations Updating translations for SSSD 1.8.1 Fix validation errors in translations
* Handle errors from lookup_netgr_step gracefullyJakub Hrozek2012-03-121-3/+10
|
* Fix netgroup error handlingsssd-1.8.0-12.el6Jakub Hrozek2012-03-091-20/+65
| | | | | | https://fedorahosted.org/sssd/ticket/1242 Handle empty elements in proxy netgroups:
* PROXY: Create fake user entries for group lookupsStephen Gallagher2012-03-091-3/+85
|
* Fix nested groups processingJakub Hrozek2012-03-091-27/+61
| | | | | | | Instead of keeping the number of parent groups in "state" and having to reset the count when moving to another group on the same level, keep track of the all groups on a particular level along with their parents and parent count.
* DP: Reorganize memory hierarchy of requestsStephen Gallagher2012-03-091-24/+108
| | | | | | | | | | | | | This function alters the memory hierarchy of the be_req to ensure memory safety during shutdown. It creates a spy on the be_cli object so that it will free the be_req if the client is freed. It is generally allocated atop the private data context for the appropriate back-end against which it is being filed. https://fedorahosted.org/sssd/ticket/1226
* Search netgroups by alias, tooJakub Hrozek2012-03-092-3/+5
| | | | https://fedorahosted.org/sssd/ticket/1228
* Hide --debug option in sss_debuglevelPavel Březina2012-03-091-1/+1
| | | | https://fedorahosted.org/sssd/ticket/1224
* IPA: Fix segfault with srchost functionality enabledStephen Gallagher2012-03-091-1/+1
| | | | https://fedorahosted.org/sssd/ticket/1215
* Only do one cycle when resolving a serverJakub Hrozek2012-03-097-59/+132
|
* IPA: Check nsAccountLock during PAM_ACCT_MGMTStephen Gallagher2012-03-097-13/+87
| | | | https://fedorahosted.org/sssd/ticket/1227
* Use the correct hash table for pending requestsSimo Sorce2012-03-097-10/+14
| | | | | | | | | | | | | The function that handled pending requests on reconnect was checking an orphaned global variable that was never used, redenring the whole function uselsess. This fixes a very nasty bug that was causing requests for which we never received an answer for (for example because the backend failed and was restarted) to be never removed and therefore causing a black hole effect for any other request of the same type. Fixes: https://fedorahosted.org/sssd/ticket/1229
* Handle cases where UID is -1Stephen Gallagher2012-03-011-6/+1
| | | | | | | Also removes an unnecessary range check (since it's already handled by strtoint32() https://fedorahosted.org/sssd/ticket/1216
* IPA: Set the DNS discovery domain to match ipa_domainStephen Gallagher2012-03-015-8/+17
| | | | https://fedorahosted.org/sssd/ticket/1217
* RHEL6: Add debug level upgrade scriptStephen Gallagher2012-02-282-0/+101
|
* Updating translations for SSSD 1.8.0 releasesssd-1_8_0Stephen Gallagher2012-02-2856-2745/+63872
|
* Update version to 1.8.0Stephen Gallagher2012-02-281-1/+1
|
* PAM: Don't send PAM_SYSTEM_INFO message if module unsetStephen Gallagher2012-02-271-7/+3
| | | | | | | | We now have a session module that is only available for the IPA provider. We should not be logging noisily that other providers do not have the session provider configured. https://fedorahosted.org/sssd/ticket/1211
* SSH: Update sss_ssh_knownhostsproxy manual pageJan Cholasta2012-02-271-15/+4
|
* SSH: Remove unused --file option of sss_ssh_knownhostsproxyJan Cholasta2012-02-271-5/+0
|
* SSH: Replace blocking getaddrinfo call in the responder with asynchronous ↵Jan Cholasta2012-02-274-27/+59
| | | | resolver code
* SSH: Use fchmod instead of chmod on known_hosts fileJan Cholasta2012-02-271-8/+4
|