Skip to content

HTTPS clone URL

Subversion checkout URL

You can clone with HTTPS or Subversion.

Download ZIP
branch: tags/krb5-1-5-…
Commits on Aug 24, 2006
  1. tag krb5-1.5.1

    tlyu authored
    git-svn-id: svn://anonsvn.mit.edu/krb5/tags/krb5-1-5-1-final@18526 dc483132-0cff-0310-8789-dd5450dbe970
  2. krb5-1.5.1

    tlyu authored
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18525 dc483132-0cff-0310-8789-dd5450dbe970
  3. make depend

    tlyu authored
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18524 dc483132-0cff-0310-8789-dd5450dbe970
  4. update for krb5-1.5.1

    tlyu authored
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18523 dc483132-0cff-0310-8789-dd5450dbe970
  5. bump

    tlyu authored
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18522 dc483132-0cff-0310-8789-dd5450dbe970
Commits on Aug 23, 2006
  1. ticket: 4172

    tlyu authored
    pull up r18499 from trunk
    
     r18499@cathode-dark-space:  jaltman | 2006-08-23 12:33:58 -0400
     ticket: 4172
     
     	Update auxiliary version number for NetIDMgr
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18511 dc483132-0cff-0310-8789-dd5450dbe970
  2. ticket: 4172

    tlyu authored
    pull up r18498 from trunk
    
     r18498@cathode-dark-space:  jaltman | 2006-08-22 22:28:05 -0400
     ticket: 4172
     
     	* install NetIDMgr plug-in sample as part of SDK
     	* install netidmgr.exe (win2000 version)
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18510 dc483132-0cff-0310-8789-dd5450dbe970
  3. ticket: 4172

    tlyu authored
    pull up r18497 from trunk
    
     r18497@cathode-dark-space:  jaltman | 2006-08-22 22:18:00 -0400
     ticket: 4172
     
     	* newcredwnd.c - erase the password field on error
               during new credential acquisition
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18509 dc483132-0cff-0310-8789-dd5450dbe970
  4. ticket: 4172

    tlyu authored
    pull up r18496 from trunk
    
     r18496@cathode-dark-space:  jaltman | 2006-08-22 22:17:12 -0400
     ticket: 4172
     
     	* Fix auto-registration of plug-in modules 
       	  if there is no plug-in list specified
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18508 dc483132-0cff-0310-8789-dd5450dbe970
  5. ticket: 4172

    tlyu authored
    pull up r18495 from trunk
    
     r18495@cathode-dark-space:  jaltman | 2006-08-22 22:15:52 -0400
     ticket: 4172
     
     	* Makefile - do not etag the Win2000 version of 
               the NetIDMgr.exe
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18507 dc483132-0cff-0310-8789-dd5450dbe970
  6. ticket: 4172

    tlyu authored
    pull up r18494 from trunk
    
     r18494@cathode-dark-space:  jaltman | 2006-08-22 18:12:15 -0400
     ticket: new
     subject: improvements to netidmgr dialogs
     
       	* ensure that buttons are disabled while
               actions are in process
     
       	* allow plug-ins to specify italic text
     
       	* fix some documentation
     
     	* reformat langres.rc 
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18506 dc483132-0cff-0310-8789-dd5450dbe970
Commits on Aug 22, 2006
  1. ticket: 4168

    tlyu authored
    version_fixed: 1.5.1
    
    pull up r18475 from trunk
    
     r18475@cathode-dark-space:  tlyu | 2006-08-21 16:31:51 -0400
     ticket: new
     subject: clean up mkrel patchlevel.h editing etc.
     tags: pullup
     target_version: 1.5.1
     
     	* src/util/mkrel: Be more careful editing KRB5_RELDATE.  Delete
     	'$ac_config_fragdir' autoconf droppings.
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18492 dc483132-0cff-0310-8789-dd5450dbe970
  2. ticket: 4147

    tlyu authored
    pull up r18464 from trunk
    
     r18464@cathode-dark-space:  jaltman | 2006-08-16 21:21:00 -0400
     ticket: new
     subject: NetIDMgr Credential Provider Sample Code and Documentation
     tags: pullup
     
        This commit provides a template for a Network Identity Manager
        Credential Provider.  It doesn't provide any real functionality
        but it does provide all of the functions that need to be specified
        and filled in as part of the process of producing a NetIdMgr plug-in.
     
        This code should be pulled up to 1.4.x for inclusion in the KFW 3.1
        SDK as well as to 1.5.x.  
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18491 dc483132-0cff-0310-8789-dd5450dbe970
Commits on Aug 16, 2006
  1. krb5-1.5.1-beta1-postrelease

    tlyu authored
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18453 dc483132-0cff-0310-8789-dd5450dbe970
  2. krb5-1.5.1-beta1

    tlyu authored
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18451 dc483132-0cff-0310-8789-dd5450dbe970
  3. update for krb5-1.5.1-beta1

    tlyu authored
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18450 dc483132-0cff-0310-8789-dd5450dbe970
Commits on Aug 15, 2006
  1. ticket: 4137

    tlyu authored
    pull up r18438 from trunk
    
     r18438@cathode-dark-space:  tlyu | 2006-08-15 15:27:08 -0400
     ticket: 4137
     
     	* src/clients/ksu/main.c (sweep_up): Don't check return value of
     	krb5_seteuid(0), as it is not harmful for it to fail, and it will
     	fail after setuid(target_user).  Correct error message.
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18439 dc483132-0cff-0310-8789-dd5450dbe970
Commits on Aug 9, 2006
  1. ticket: 3956

    tlyu authored
    version_fixed: 1.5.1
    
    	* src/lib/gssapi/mechglue/Makefile.in (OBJS): Adjust to account
    	for g_utils.c removal.
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18427 dc483132-0cff-0310-8789-dd5450dbe970
  2. ticket: 3956

    tlyu authored
    version_fixed: 1.5.1
    
    pull up r18259 from trunk
    
     r18259@cathode-dark-space:  jaltman | 2006-06-28 21:48:31 -0400
     ticket: new
     subject: gssapi compilation errors on Windows
     tags: pullup
     
     src/Makefile.in:  generate lib/gssapi/spnego/Makefile
     
     src/lib/gssapi/Makefile.in: build mechglue and spnego
     
     src/lib/gssapi/krb5/init_sec_context.c: do not include 
     kdc only symbols on windows
     
     src/lib/gssapi/mechglue/g_utils.c: no strings.h on Windows
     
     src/lib/gssapi/mechglue/Makefile.in: construct mechglue.lst
     
     src/lib/gssapi/spnego/Makefile.in: construct spnego.lst
     
     src/lib/gssapi/spnego/spnego_mech.c: k5-int.h must be 
     included before krb5.h in order to prevent mixed definitions
     of time_t on windows
     
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18426 dc483132-0cff-0310-8789-dd5450dbe970
Commits on Aug 8, 2006
  1. ticket: 4125

    tlyu authored
    version_fixed: 1.5.1
    
    pull up r18420 from trunk
    
     r18420@cathode-dark-space:  tlyu | 2006-08-08 15:26:40 -0400
     ticket: new
     subject: fix MITKRB5-SA-2006-001: multiple local privilege escalation vulnerabilities
     target_version: 1.5.1
     tags: pullup
     
     	* src/appl/gssftp/ftpd/ftpd.c (getdatasock, passive):
     	* src/appl/bsd/v4rcp.c (main):
     	* src/appl/bsd/krcp.c (main):
     	* src/appl/bsd/krshd.c (doit):
     	* src/appl/bsd/login.c (main): 
     	* src/clients/ksu/main.c (sweep_up):
     	* src/lib/krb4/kuserok.c (kuserok): Check return values from
     	setuid() and related functions to avoid privilege escalation
     	vulnerabilities.  Fixes MITKRB5-SA-2006-001. [CVE-2006-3083,
     	VU#580124, CVE-2006-3084, VU#401660]
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18421 dc483132-0cff-0310-8789-dd5450dbe970
  2. ticket: 4063

    tlyu authored
    version_fixed: 1.5.1
    
    	* src/lib/gssapi/krb5/accept_sec_context.c
    	(krb5_gss_accept_sec_context): Apply single fix from ticket
    	#4057.
    
    	* src/lib/gssapi/mechglue/g_glue.c
    	(gssint_convert_name_to_union_name): Fix up merge botch.
    
    	* src/lib/gssapi/mechglue/mglueP.h: Fix up struct name differences
    	between trunk and 1.5-branch.
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18419 dc483132-0cff-0310-8789-dd5450dbe970
  3. ticket: 4063

    tlyu authored
    version_fixed: 1.5.1
    
    pull up r18417 from trunk
    
     r18417@cathode-dark-space:  tlyu | 2006-08-07 19:33:39 -0400
     ticket: 4063
     tags: pullup
     
     	* src/lib/gssapi/mechglue/mglueP.h: Add loopback field to opaque
     	structs of gss_ctx_id_t, gss_name_t, gss_cred_id_t to catch some
     	application programming errors.  Add new macro GSSINT_CHK_LOOP()
     	which returns non-zero if loopback field doesn't point to itself.
     
     	* src/lib/gssapi/mechglue/g_accept_sec_context.c
     	(gss_accept_sec_context):
     	* src/lib/gssapi/mechglue/g_acquire_cred.c (gss_add_cred) 
     	(gss_acquire_cred):
     	* src/lib/gssapi/mechglue/g_delete_sec_context.c
     	(gss_delete_sec_context):
     	* src/lib/gssapi/mechglue/g_glue.c
     	(gssint_convert_name_to_union_name):
     	* src/lib/gssapi/mechglue/g_imp_name.c (gss_import_name):
     	* src/lib/gssapi/mechglue/g_imp_sec_context.c
     	(gss_import_sec_context):
     	* src/lib/gssapi/mechglue/g_init_sec_context.c
     	(gss_init_sec_context): Set loopback pointers.
     
     	* src/lib/gssapi/mechglue/g_delete_sec_context.c
     	(gss_delete_sec_context):
     	* src/lib/gssapi/mechglue/g_rel_cred.c (gss_release_cred):
     	* src/lib/gssapi/mechglue/g_rel_name.c (gss_release_name): Call
     	GSSINT_CHK_LOOP() to validate loopback pointer.
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18418 dc483132-0cff-0310-8789-dd5450dbe970
Commits on Aug 7, 2006
  1. ticket: 4088

    tlyu authored
    version_fixed: 1.5.1
    
    pull up r18397 from trunk
    
     r18397@cathode-dark-space:  tlyu | 2006-08-01 17:09:43 -0400
     ticket: 4088
     status: open
     
     	* src/lib/gssapi/mechglue/g_initialize.c (gss_release_oid): Call
     	gssint_initialize_library to ensure mutex is initialized.
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18409 dc483132-0cff-0310-8789-dd5450dbe970
  2. ticket: 3904

    tlyu authored
    version_fixed: 1.5.1
    
    pull up r18404 from trunk
    
     r18404@cathode-dark-space:  tlyu | 2006-08-02 16:51:50 -0400
     ticket: 3904
     tags: pullup
     
     Apply patch from Michael Calmer to fix some uninitialized variables.
     
     	* src/appl/gssftp/ftpd/ftpd.c (auth_data): Initialize stat_maj,
     	accept_maj, acquire_maj.
     
     	* src/appl/telnet/libtelnet/kerberos5.c (kerberos5_send):
     	Intialize rdata.
     
     	* src/kdc/do_tgs_req.c (process_tgs_req): Initialize magic and
     	tr_contents.magic.
     
     	* src/lib/krb5/asn.1/krb5_decode.c (decode_krb5_safe_with_body):
     	Initialize tmpbody.magic.
     
     	* src/plugins/kdb/db2/libdb2/hash/dbm.c (kdb2_fetch) 
     	(kdb2_firstkey, kdb2_nextkey): Initialize dsize.
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18408 dc483132-0cff-0310-8789-dd5450dbe970
Commits on Aug 2, 2006
  1. ticket: 4037

    tlyu authored
    version_fixed: 1.5.1
    
    pull up r18350 from trunk
    
     r18350@cathode-dark-space:  raeburn | 2006-07-21 13:49:07 -0400
     ticket: new
     subject: respect LDFLAGS in NetBSD build
     target: 1.5.1
     tags: pullup
     
     An LDFLAGS setting at configure time is ignored in parts of the build.
     
     * shlib.conf (*-*-netbsd*): Use $(CC) for LDCOMBINE, and include $(LDFLAGS).
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18403 dc483132-0cff-0310-8789-dd5450dbe970
  2. ticket: 4036

    tlyu authored
    version_fixed: 1.5.1
    
    pull up r18352 from trunk
    
     r18352@cathode-dark-space:  raeburn | 2006-07-21 15:03:02 -0400
     ticket: 4036
     
     * aclocal.m4 (KRB5_LIB_AUX): Disallow --enable-profiled and --disable-shared
     options as well.  Don't generate help messages for these options.
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18402 dc483132-0cff-0310-8789-dd5450dbe970
  3. ticket: 4036

    tlyu authored
    version_fixed: 1.5.1
    
    pull up r18348 from trunk
    
     r18348@cathode-dark-space:  raeburn | 2006-07-21 13:41:43 -0400
     ticket: new
     subject: reject configure option for static libraries
     target_version: 1.5.1
     tags: pullup
     
     We shouldn't accept --enable-static at configure time when we know
     it's not going to work at build time.
     
     * aclocal.m4 (KRB5_LIB_AUX): Error out if --enable-static.
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18401 dc483132-0cff-0310-8789-dd5450dbe970
Commits on Aug 1, 2006
  1. ticket: 4012

    tlyu authored
    version_fixed: 1.5.1
    
    pull up r18330 from trunk
    
     r18330@cathode-dark-space:  tlyu | 2006-07-17 12:39:35 -0400
     ticket: new
     target_version: 1.5.1
     tags: pullup
     subject: reverse test for copy_oid_set in lib/gssapi/krb5/indicate_mechs.c
     
     	* src/lib/gssapi/krb5/indicate_mechs.c: Reverse sense of test,
     	since gssint_copy_oid_set() returns 0 on success.
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18400 dc483132-0cff-0310-8789-dd5450dbe970
  2. ticket: 3998

    tlyu authored
    version_fixed: 1.5.1
    
    pull up r18328 from trunk
    
     r18328@cathode-dark-space:  rra | 2006-07-12 18:17:34 -0400
     Ticket: new
     Subject: Document add_entry in ktutil man page
     Version_Reported: 1.3.6
     Target_Version: 1.5.2
     Tags: pullup
     
     Apply patch from Mike Dopheide to document ktutil add_entry in the man
     page and fix some other spelling errors in the ktutil man page.
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18399 dc483132-0cff-0310-8789-dd5450dbe970
  3. ticket: 3971

    tlyu authored
    version_fixed: 1.5.5
    
    pull up r18331 from trunk
    
     r18331@cathode-dark-space:  raeburn | 2006-07-17 13:55:54 -0400
     ticket: 3971
     target_version: 1.5.1
     tags: pullup
     
     (KRB5_AC_FIND_DLOPEN): Use AC_SEARCH_LIBS.
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18398 dc483132-0cff-0310-8789-dd5450dbe970
Commits on Jul 25, 2006
  1. ticket: 4053

    tlyu authored
    pull up r18387 from trunk
    
     r18387@cathode-dark-space:  jaltman | 2006-07-25 09:59:30 -0400
     ticket: new
     subject: Windows - fix kfwlogon for Windows 2000
     tags: pullup
     
         Windows 2000 does not support the ability to generate SIDs
         from symbolic names.
     
         Add more debugging and error condition checks.
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18389 dc483132-0cff-0310-8789-dd5450dbe970
  2. ticket: 4048

    tlyu authored
    pull up r18379 from trunk
    
     r18379@cathode-dark-space:  jaltman | 2006-07-24 02:58:23 -0400
     ticket: new
     subject: Windows Integrated Login Fixes for KFW 3.1
     tags: pullup
     component: windows
     
         KFW integrated login was failing when the user is 
         not a power user or administrator.  This was occurring 
         because the temporary file ccache was being created in
         a directory the user could not read.  While fixing this
         it was noticed that the ACLs on the ccache were too broad.
         Instead of applying a fix to the FILE: krb5_ccache 
         implementation it was decided that simply applying a new
         set of ACLs (SYSTEM and "user" with no inheritance) to 
         the file immediately after the krb5_cc_initialize() call
         would close the broadest security issues.  
     
         The file is initially created in the SYSTEM %TEMP% directory
         with "SYSTEM" ACL only.  Then it is moved to the user's %TEMP%
         directory with "SYSTEM" and "user" ACLs.  Finally, after
         copying the credentials to the API: ccache, the file is deleted.
         
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18386 dc483132-0cff-0310-8789-dd5450dbe970
Commits on Jul 22, 2006
  1. ticket: 4028

    tlyu authored
    pull up r18344 from trunk
    
     r18344@cathode-dark-space:  jaltman | 2006-07-19 18:36:00 -0400
     ticket: new
     subject: Windows NetIDMgr post-1.5 branch commits
     
     The following patch updates the NetIDMgr:
     
      * allow plug-ins to be marked "do not unload" in order
        to support DLLs that create threads that are not
        properly cleaned up as part of library unload.
     
      * allow plug-ins to be marked "disabled"
     
      * Additional changes to deal with Microsoft's efforts
        to deprecate all of the str C runtime functions.
     
      * Improvements to Manifest processing in the build
        system
     
      * Addition of Tooltip support to the Toolbar.  Dragging
        the mouse over toolbar buttons displays textual 
        descriptions.
     
      * Correct the behavior of the New Credentials Dialog
        to disable the "Ok" button after it has been pressed.
     
      * Add support to allow plugin configuration data to 
        be distributed as part of transforms to the MSI
        installer.
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18375 dc483132-0cff-0310-8789-dd5450dbe970
  2. ticket: 4033

    tlyu authored
    pull up r18345 from trunk
    
     r18345@cathode-dark-space:  jaltman | 2006-07-20 23:12:00 -0400
     ticket: new 
     subject: Windows NetIDMgr documentation
     
     NetIDMgr 1.1 documentation for KFW 3.1 release
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18373 dc483132-0cff-0310-8789-dd5450dbe970
  3. ticket: 4032

    tlyu authored
    pull up r18346 from trunk
    
     r18346@cathode-dark-space:  jaltman | 2006-07-21 09:48:37 -0400
     ticket: new
     subject: Windows - kfw 3.1 msi deployment guide updates
     
     	documentation updates for the kfw 3.1 msi deployment guide.
     
     
    
    
    
    git-svn-id: svn://anonsvn.mit.edu/krb5/branches/krb5-1-5@18371 dc483132-0cff-0310-8789-dd5450dbe970
Something went wrong with that request. Please try again.