Changelog for
openldap24-servers-2.4.32-2.ius.centos6.i686.rpm :
* Wed Dec 05 2012 Jeffrey Ness
2.4.32-2.ius- Adding in needed Conflicts
* Wed Aug 15 2012 Jeffrey Ness 2.4.32-1.ius- Porting to IUS from Enterprise Linux 6- Latest sources
* Mon May 07 2012 Jan Vcelak 2.4.23-26- fix: MozNSS CA cert dir does not work together with PEM CA cert file (#818844)- fix: memory leak: def_urlpre is not freed (#816168)- fix update: Default SSL certificate bundle is not found by openldap library (#742023)
* Wed May 02 2012 Jan Vcelak 2.4.23-25- fix update: Default SSL certificate bundle is not found by openldap library (#742023)
* Mon Apr 30 2012 Jan Vcelak 2.4.23-24- fix update: Default SSL certificate bundle is not found by openldap library (#742023)- fix: memberof overlay on the frontend database causes server segfault (#730745)
* Fri Apr 20 2012 Jan Vcelak 2.4.23-23- security fix: CVE-2012-1164: assertion failure by processing search queries requesting only attributes for particular entry (#813162)
* Tue Apr 10 2012 Jan Vcelak 2.4.23-22- fix: libraries leak memory when following referrals (#807363)
* Thu Mar 01 2012 Jan Vcelak 2.4.23-21- fix: ldapsearch crashes with invalid parameters (#743781)- fix: replication (syncrepl) with TLS causes segfault (#783445)- fix: openldap server in MirrorMode sometimes fails to resync via syncrepl (#784211)- use portreserve to reserve LDAPS port (636/tcp+udp) (#790687)- fix: missing options in manual pages of client tools (#745470)- fix: SASL_NOCANON option missing in ldap.conf manual page (#732916)- fix: slapd segfaults when certificate key cannot be loaded (#796808)- Jan Synáček + fix: overlay constraint with count option work bad with modify operation (#742163) + fix: Default SSL certificate bundle is not found by openldap library (#742023) + fix: Duplicate close() calls in OpenLDAP (#784203)
* Tue Oct 04 2011 Jan Vcelak 2.4.23-20- new feature update: honor priority/weight with ldap_domain2hostlist (#730311)- fix regression: openldap built without tcp_wrappers (#742592)
* Tue Sep 13 2011 Jan Vcelak 2.4.23-19- fix: SSL_ForceHandshake function is not thread safe (#709407)
* Fri Aug 26 2011 Jan Vcelak 2.4.23-18- fix: overlay refint option refint_nothing doesn\'t function correctly (#725479)- fix: Unwanted slash printed when installing openldap-servers (#732001)- manpage fix: TLS options in documentation are not valid for MozNSS (#684810)- fix: NSS_Init
* functions are not thread safe (#731168)- manpage fix: errors in manual page slapo-unique (#723521) - new feature: honor priority/weight with ldap_domain2hostlist (#730311)
* Mon Aug 15 2011 Jan Vcelak 2.4.23-17- fix: strict aliasing warnings during package build (#723487)- add partial RELRO support for libraries (#723999)- fix: incorrect behavior of allow/try options of VerifyCert and TLS_REQCERT (#729095)- fix: memleak - free the return of tlsm_find_and_verify_cert_key (#729087)- fix: TLS_REQCERT=never ignored when the certificate is expired (#722959)- fix: matching wildcard hostnames in certificate Subject field does not work (#726984)- fix: OpenLDAP server segfaults when using back-sql (#727533)- fix: conversion of constraint overlay settings to cn=config is incorrect (#722923)- fix: DDS overlay tolerance parametr doesn\'t function and breakes default TTL (#723514)
* Mon Jul 18 2011 Jan Vcelak 2.4.23-16- fix: memleak in tlsm_auth_cert_handler (#717738)- fix: segmentation fault of client tool when LDIF input file is not terminated by a new line character (#698921)- fix: segmentation fault of client tool when input line in LDIF file is splitted but indented incorrectly (#701227)- fix: server scriptlets require initscripts package (#712358)- enable ldapi:/// interface by default- set cn=config management ACLs for root user, SASL external schema (#712494)- fix: ldapsearch fails if no CA certificate is available (#713525)
* Wed Apr 13 2011 Jan Vcelak 2.4.23-15- fix: rpm -V fail when upgrading with openldap-devel installed (#693716) (remove devel
*.so symlinks from /lib and leave them in /usr/lib)
* Fri Mar 18 2011 Jan Vcelak 2.4.23-14- fix update: openldap startup script ignores ulimit settings (#679356)- fix update: openldap-servers upgrade hangs or do not upgrade the database (#685119)
* Mon Mar 14 2011 Jan Vcelak 2.4.23-13- fix update: openldap can\'t use TLS after a fork() (#671553)- fix: possible NULL pointer dereferences in NSS non-blocking patch (#684035)- fix: move libldif to /lib for consistency (#548475)- fix: openldap-servers upgrade hangs or do not upgrade the database (#685119)
* Tue Mar 01 2011 Jan Vcelak 2.4.23-12- fix: security - DoS when submitting special MODRDN request (#680975)
* Mon Feb 28 2011 Jan Vcelak 2.4.23-11- fix: CVE-2011-1024 ppolicy forwarded bind failure messages cause success- fix: CVE-2011-1025 rootpw is not verified for ndb backend- fix: openldap startup script ignores ulimit settings (#679356)- fix: add symlinks into /usr/lib
*/ (#680139)
* Mon Feb 21 2011 Jan Vcelak 2.4.23-10- fix: add symlinks for libraries moved in 2.4.23-5 to allow building packages which require these libraries in the old location (#678105)
* Wed Feb 02 2011 Jan Vcelak 2.4.23-9- fix update: openldap can\'t use TLS after a fork() (#671553)
* Tue Jan 25 2011 Jan Vcelak 2.4.23-8- fix: openldap can\'t use TLS after a fork() (#671553)
* Thu Jan 20 2011 Jan Vcelak 2.4.23-7- fix: some server certificates refused with inadequate type error (#669846)- fix: default encryption strength dropped in switch to using NSS (#669845)
* Thu Jan 13 2011 Jan Vcelak 2.4.23-6- fix update: openldap-devel symlinks to libraries were not moved correctly (#548475)
* Thu Jan 13 2011 Jan Vcelak 2.4.23-5- initscript: slaptest with \'-u\' to skip database opening (#613966)- removed slurpd options from sysconfig/ldap- fix: verification of self issued certificates (#667795)- fix: move libraries from /usr/lib to /lib (#548475)
* Sat Dec 04 2010 Jan Vcelak 2.4.23-4- rebase to 2.4.23 (Fedora 14) (#644077)- uses Mozilla NSS instead of OpenSSL for TLS/SSL- added LDIF (ldif.h) to the public API- removed embeded Berkeley DB- removed autofs schema (use up-to-date version from autofs package instead)- removed compat-openldap subpackage (use separate package instead)- fixes: ldapsearch -Z hangs server if starttls fails (#652823)- fixes: improve SSL/TLS log messages (#652819)- fixes: crash when TLS_CACERTDIR contains a subdirectory (#652817)- fixes: TLS_CACERTDIR takes precedence over TLS_CACERT (#652816)- fixes: openldap should ignore files not in the openssl c_hash format in cacertdir (#652814)- fixes: slapd init script gets stuck in an infinite loop (#644399)- fixes: Remove lastmod.la from default slapd.conf.bak (#630637)- fixes: Mozilla NSS - delay token auth until needed (#616558)- fixes: Mozilla NSS - support use of self signed CA certs as server certs (#616554)
* Fri Jun 25 2010 Jan Zeleny - 2.4.19-15- fixed regression caused by tls accept patch (#608112)
* Tue Jun 22 2010 Jan Zeleny - 2.4.19-14- fixed segfault issue in modrdn (#606369)
* Fri Jun 18 2010 Jan Vcelak 2.4.19-13- implementation of ulimit settings for slapd (#602458)
* Wed May 26 2010 Jan Zeleny - 2.4.19-12- updated man pages - only slaptest can convert configuration schema (#584787)- openldap compiled with -fno-strict-aliasing (#596193)
* Thu May 06 2010 Jan Zeleny - 2.4.19-11- added compat package
* Tue Apr 27 2010 Jan Zeleny - 2.4.19-10- updated overlay list in config file (#586143)- config dir slapd.d added to package payload (#585276)- init script now creates only symlink, not harldink, in /var/run (#584870)
* Mon Apr 19 2010 Jan Zeleny - 2.4.19-9- fixed broken link /usr/sbin/slapschema (#583568)- removed some static libraries from openldap-devel (#583575)
* Fri Apr 16 2010 Jan Zeleny - 2.4.19-8- updated spec file - clean files generated by configuration conversion (#582327)
* Mon Mar 22 2010 Jan Zeleny - 2.4.19-7- updated usage line in init script- changed return code when calling init script with bad arguments
* Mon Mar 22 2010 Jan Zeleny - 2.4.19-6- fixed segfault when using hdb backend (#575403)
* Fri Mar 19 2010 Jan Zeleny - 2.4.19-5- minor corrections of init script (fedora bugs #571235, #570057, #573804)
* Wed Feb 10 2010 Jan Zeleny - 2.4.19-4- removed syncprov.la from config file (#563472)
* Wed Feb 03 2010 Jan Zeleny - 2.4.19-3- updated post scriptlet (#561352)
* Mon Nov 23 2009 Jan Zeleny - 2.4.19-2- minor changes in init script
* Wed Nov 18 2009 Jan Zeleny - 2.4.19-1- fixed tls connection accepting when TLSVerifyClient = allow- /etc/openldap/ldap.conf removed from files owned by openldap-servers- minor changes in spec file to supress warnings- some changes in init script, so it would be possible to use it when using old configuration style- rebased openldap to 2.4.19- rebased bdb to 4.8.24
* Wed Oct 07 2009 Jan Zeleny 2.4.18-5- updated smbk5pwd patch to be linked with libldap (#526500)
* Wed Sep 30 2009 Jan Zeleny 2.4.18-4- buffer overflow patch from upstream- added /etc/openldap/slapd.d and /etc/openldap/slapd.conf.bak to files owned by openldap-servers
* Thu Sep 24 2009 Jan Zeleny 2.4.18-3- cleanup of previous patch fixing buffer overflow
* Tue Sep 22 2009 Jan Zeleny 2.4.18-2- changed configuration approach. Instead od slapd.conf slapd is using slapd.d directory now- fix of some issues caused by renaming of init script- fix of buffer overflow issue in ldif.c pointed out by new glibc
* Fri Sep 18 2009 Jan Zeleny 2.4.18-1- rebase of openldap to 2.4.18
* Wed Sep 16 2009 Jan Zeleny 2.4.16-7- updated documentation (hashing the cacert dir)
* Wed Sep 16 2009 Jan Zeleny 2.4.16-6- updated init script to be LSB-compliant (#523434)- init script renamed to slapd
* Thu Aug 27 2009 Tomas Mraz - 2.4.16-5- rebuilt with new openssl
* Tue Aug 25 2009 Jan Zeleny 2.4.16-4- updated %pre script to correctly install openldap group
* Sat Jul 25 2009 Fedora Release Engineering - 2.4.16-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
* Wed Jul 01 2009 Jan Zeleny 2.4.16-1- rebase of openldap to 2.4.16- fixed minor issue in spec file (output looking interactive when installing servers)
* Tue Jun 09 2009 Jan Zeleny 2.4.15-4- added $SLAPD_URLS variable to init script (#504504)
* Thu Apr 09 2009 Jan Zeleny 2.4.15-3- extended previous patch (#481310) to remove options cfMP from some client tools- correction of patch setugid (#494330)
* Thu Mar 26 2009 Jan Zeleny 2.4.15-2- removed -f option from some client tools (#481310)
* Wed Feb 25 2009 Jan Safranek 2.4.15-1- new upstream release
* Tue Feb 17 2009 Jan Safranek 2.4.14-1- new upstream release- upgraded to db-4.7.25
* Sat Jan 17 2009 Tomas Mraz 2.4.12-3- rebuild with new openssl
* Mon Dec 15 2008 Caolán McNamara 2.4.12-2- rebuild for libltdl, i.e. copy config.sub|guess from new location
* Wed Oct 15 2008 Jan Safranek 2.4.12-1- new upstream release
* Mon Oct 13 2008 Jan Safranek 2.4.11-3- add SLAPD_SHUTDOWN_TIMEOUT to /etc/sysconfig/ldap, allowing admins to set non-default slapd shutdown timeout- add checkpoint to default slapd.conf file (#458679)
* Mon Sep 01 2008 Jan Safranek 2.4.11-2- provide ldif2ldbm functionality for migrationtools- rediff all patches to get rid of patch fuzz
* Mon Jul 21 2008 Jan Safranek 2.4.11-1- new upstream release- apply official bdb-4.6.21 patches
* Wed Jul 02 2008 Jan Safranek 2.4.10-2- fix CVE-2008-2952 (#453728)
* Thu Jun 12 2008 Jan Safranek 2.4.10-1- new upstream release
* Wed May 28 2008 Jan Safranek 2.4.9-5- use /sbin/nologin as shell of ldap user (#447919)
* Tue May 13 2008 Jan Safranek 2.4.9-4- new upstream release- removed unnecessary MigrationTools patches
* Thu Apr 10 2008 Jan Safranek 2.4.8-4- bdb upgraded to 4.6.21- reworked upgrade logic again to run db_upgrade when bdb version changes
* Wed Mar 05 2008 Jan Safranek 2.4.8-3- reworked the upgrade logic, slapcat/slapadd of the whole database is needed only if minor version changes (2.3.x -> 2.4.y)- do not try to save database in LDIF format, if openldap-servers package is being removed (it\'s up to the admin to do so manually)
* Thu Feb 28 2008 Jan Safranek 2.4.8-2- migration tools carved out to standalone package \"migrationtools\" (#236697)
* Fri Feb 22 2008 Jan Safranek 2.4.8-1- new upstream release
* Fri Feb 08 2008 Jan Safranek 2.4.7-7- fix CVE-2008-0658 (#432014)
* Mon Jan 28 2008 Jan Safranek 2.4.7-6- init script fixes
* Mon Jan 28 2008 Jan Safranek 2.4.7-5- init script made LSB-compliant (#247012)
* Fri Jan 25 2008 Jan Safranek 2.4.7-4- fixed rpmlint warnings and errors - /etc/openldap/schema/README moved to /usr/share/doc/openldap
* Tue Jan 22 2008 Jan Safranek 2.4.7-3- obsoleting compat-openldap properly again :)
* Tue Jan 22 2008 Jan Safranek 2.4.7-2- obsoleting compat-openldap properly (#429591)
* Mon Jan 14 2008 Jan Safranek 2.4.7-1- new upstream version (openldap-2.4.7)