<feed xmlns='http://www.w3.org/2005/Atom'>
<title>sssd2.git/src, branch 1-1-0</title>
<subtitle>System Security Services Daemon [okos' clone]</subtitle>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/okos/public_git/sssd2.git/'/>
<entry>
<title>Treat a zero-length password as a failure</title>
<updated>2010-08-24T16:44:56+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2010-08-18T16:57:43+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/okos/public_git/sssd2.git/commit/?id=2448114d633cd144482fb8e1bcf14c82a5ec7eb8'/>
<id>2448114d633cd144482fb8e1bcf14c82a5ec7eb8</id>
<content type='text'>
Some LDAP servers allow binding with blank passwords. We should
not allow a blank password to authenticate the SSSD.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Some LDAP servers allow binding with blank passwords. We should
not allow a blank password to authenticate the SSSD.
</pre>
</div>
</content>
</entry>
<entry>
<title>Update translation files for 1.1.1 release</title>
<updated>2010-04-01T14:17:21+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2010-04-01T14:13:23+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/okos/public_git/sssd2.git/commit/?id=b55cec93ae9432a6fce50c50e3ed3e2c975da134'/>
<id>b55cec93ae9432a6fce50c50e3ed3e2c975da134</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Do not revert options to defaults in SSSDConfig.get_domain()</title>
<updated>2010-03-31T13:34:20+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2010-03-31T13:10:55+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/okos/public_git/sssd2.git/commit/?id=5e12d81215f2a7e49ce61a9513c6624cc1afa1ad'/>
<id>5e12d81215f2a7e49ce61a9513c6624cc1afa1ad</id>
<content type='text'>
There was a faulty check in get_domain() that led to the
*_provider options being re-added, sometimes after options related
to them had already been set. If those options had a default
value, they would be overwritten by the default.

Fixes: https://fedorahosted.org/sssd/ticket/441
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
There was a faulty check in get_domain() that led to the
*_provider options being re-added, sometimes after options related
to them had already been set. If those options had a default
value, they would be overwritten by the default.

Fixes: https://fedorahosted.org/sssd/ticket/441
</pre>
</div>
</content>
</entry>
<entry>
<title>Add regression test for https://fedorahosted.org/sssd/ticket/441</title>
<updated>2010-03-31T13:34:20+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2010-03-31T13:12:58+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/okos/public_git/sssd2.git/commit/?id=fc8a12ac4c0eb7fe68f7f289cc69703459a79f58'/>
<id>fc8a12ac4c0eb7fe68f7f289cc69703459a79f58</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Allow arbitrary-length PAM messages</title>
<updated>2010-03-25T20:02:19+00:00</updated>
<author>
<name>Stephen Gallagher</name>
<email>sgallagh@redhat.com</email>
</author>
<published>2010-03-23T20:35:49+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/okos/public_git/sssd2.git/commit/?id=f5397172fca9935c5f0867d7c13d71d29dc92c42'/>
<id>f5397172fca9935c5f0867d7c13d71d29dc92c42</id>
<content type='text'>
The PAM standard allows for messages of any length to be returned
to the client. We were discarding all messages of length greater
than 255. This patch dynamically allocates the message buffers so
we can pass the complete message.

This resolves https://fedorahosted.org/sssd/ticket/432
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The PAM standard allows for messages of any length to be returned
to the client. We were discarding all messages of length greater
than 255. This patch dynamically allocates the message buffers so
we can pass the complete message.

This resolves https://fedorahosted.org/sssd/ticket/432
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix LDAP search paths for IPA HBAC</title>
<updated>2010-03-25T16:14:03+00:00</updated>
<author>
<name>Sumit Bose</name>
<email>sbose@redhat.com</email>
</author>
<published>2010-03-25T15:21:12+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/okos/public_git/sssd2.git/commit/?id=01498c6bc57e8e137ef57fed9acffedccfa03e93'/>
<id>01498c6bc57e8e137ef57fed9acffedccfa03e93</id>
<content type='text'>
- use domain_to_basedn() to construct LDAP search paths for IPA HBAC
- move domain_to_basedn() to a separate file to simplify the build of
  a test
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
- use domain_to_basedn() to construct LDAP search paths for IPA HBAC
- move domain_to_basedn() to a separate file to simplify the build of
  a test
</pre>
</div>
</content>
</entry>
<entry>
<title>Add krb5_kpasswd to IPA provider</title>
<updated>2010-03-25T16:14:03+00:00</updated>
<author>
<name>Eugene Indenbom</name>
<email>eindenbom@gmail.com</email>
</author>
<published>2010-03-25T14:27:01+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/okos/public_git/sssd2.git/commit/?id=27ca4bb27bead02dc155099f45c9b2669b064a16'/>
<id>27ca4bb27bead02dc155099f45c9b2669b064a16</id>
<content type='text'>
The krb5 options were out of sync, causing a runtime abort.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The krb5 options were out of sync, causing a runtime abort.
</pre>
</div>
</content>
</entry>
<entry>
<title>Regression test against RHBZ #576856</title>
<updated>2010-03-25T16:14:03+00:00</updated>
<author>
<name>Jakub Hrozek</name>
<email>jhrozek@redhat.com</email>
</author>
<published>2010-03-25T14:10:56+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/okos/public_git/sssd2.git/commit/?id=a47382e30b86fb90495de5bab04690f215980ec4'/>
<id>a47382e30b86fb90495de5bab04690f215980ec4</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Set LDAP_OPT_RESTART for ldap_sasl_interactive_bind_s()</title>
<updated>2010-03-25T16:14:03+00:00</updated>
<author>
<name>Sumit Bose</name>
<email>sbose@redhat.com</email>
</author>
<published>2010-03-23T16:01:59+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/okos/public_git/sssd2.git/commit/?id=6e8f828c84334c43500311ddcdb4341d87cdd71f'/>
<id>6e8f828c84334c43500311ddcdb4341d87cdd71f</id>
<content type='text'>
This option is needed for the rare case where a poll() call during
ldap_sasl_interactive_bind_s() is interrupted by a signal.
LDAP_OPT_RESTART enables the handling of the EINTR error instead of
returning an error.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This option is needed for the rare case where a poll() call during
ldap_sasl_interactive_bind_s() is interrupted by a signal.
LDAP_OPT_RESTART enables the handling of the EINTR error instead of
returning an error.
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix kinit after password change</title>
<updated>2010-03-25T16:14:02+00:00</updated>
<author>
<name>Sumit Bose</name>
<email>sbose@redhat.com</email>
</author>
<published>2010-03-23T15:34:31+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/okos/public_git/sssd2.git/commit/?id=1fafd0ab7e7c136ccc4fda54e6d2e0f947e28713'/>
<id>1fafd0ab7e7c136ccc4fda54e6d2e0f947e28713</id>
<content type='text'>
In an environment with slave KDCs and a central server where password
changes are allowed the request for a new TGT immediately after the
password change should be made against this server, because the slave
server might not know the new password.

To achieve this the Kerberos localtor plugin now returns the address of
the kpasswd server as master_kdc.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
In an environment with slave KDCs and a central server where password
changes are allowed the request for a new TGT immediately after the
password change should be made against this server, because the slave
server might not know the new password.

To achieve this the Kerberos localtor plugin now returns the address of
the kpasswd server as master_kdc.
</pre>
</div>
</content>
</entry>
</feed>
