Changelog for
pam-devel-1.1.8-23.el7.x86_64.rpm :
Tue Aug 6 14:00:00 2019 Tomáš Mráz
1.1.8-23
- pam_get_authtok_verify: ensure no double verification happens
- manual page fixes for pam_tty_audit and pam_wheel
- pam_unix: lower the excessive maximum number of closed fd descriptors
when spawning handlers
- pam_loginuid: do not prevent login in unprivileged containers
Fri Nov 3 13:00:00 2017 Tomáš Mráz 1.1.8-22
- pam_mkhomedir: do not fail creating parent dir if in /
Thu Nov 2 13:00:00 2017 Tomáš Mráz 1.1.8-21
- pam(8) Manual page missing space fix (#1382302)
Mon Oct 9 14:00:00 2017 Tomáš Mráz 1.1.8-20
- pam_tty_audit: add support for uid range matching
Fri Sep 8 14:00:00 2017 Tomáš Mráz 1.1.8-19
- pam_access: (group) match syntax is prioritized over networkAATTnetgroup
match (#1358881), add support for additional /etc/security/access.d/
*.conf
files, improve documentation (#1421735)
- pam_lastlog: fix pt_BR translation (#1185697)
- pam_faillock: support admin_group with users equivalent to root in
faillock handling (#1285550)
Tue Jul 19 14:00:00 2016 Tomáš Mráz 1.1.8-18
- pam_succeed_if: fix handling of large uids, tty, and rhost
Mon May 30 14:00:00 2016 Tomáš Mráz 1.1.8-17
- fix pam_fail_delay() manual page (#1130053)
Thu Apr 28 14:00:00 2016 Tomáš Mráz 1.1.8-15
- pam_faillock: support permanent locking of user with
unlock_time=never option
Fri Apr 22 14:00:00 2016 Tomáš Mráz 1.1.8-14
- pam_unix: add no_pass_expiry option for ignoring password
expiration in crond and sshd with public key authentication
- add manual page for environment(5) (#1110257)
- pam_loginuid: log if auditd not detected
- always ignore audit error when -EPERM is returned (#1287800)
- pam_lastlog: fix possible NULL dereference when localtime fails (#1313537)
Tue Aug 4 14:00:00 2015 Tomáš Mráz 1.1.8-13
- fix CVE-2015-3238 - DoS due to blocking pipe with very long password
Fri Oct 17 14:00:00 2014 Tomáš Mráz 1.1.8-12
- use USER_MGMT type for auditing in the pam_tally2 and faillock
apps (#1151576)
Thu Sep 11 14:00:00 2014 Tomáš Mráz 1.1.8-11
- be tolerant to corrupted opasswd file
- audit the module names that granted access
- pam_userdb: correct the example in man page (#1078784)
- pam_limits: check whether the utmp login entry is valid (#1080023)
- pam_console_apply: do not print error if console.perms.d is empty
- pam_limits: nofile refers to open file descriptors (#1111220)
- apply PIE and full RELRO to all binaries built
Mon Aug 25 14:00:00 2014 Tomáš Mráz 1.1.8-10
- pam_lastlog: fix uninitialized access of parts of lastlog structure
Mon Mar 31 14:00:00 2014 Tomáš Mráz 1.1.8-9
- fix CVE-2014-2583: potential path traversal issue in pam_timestamp
- pam_pwhistory: call the helper if SELinux enabled
Tue Mar 11 13:00:00 2014 Tomáš Mráz 1.1.8-8
- fix CVE-2013-7041: use case sensitive comparison in pam_userdb
Mon Mar 10 13:00:00 2014 Tomáš Mráz 1.1.8-7
- rename the 90-nproc.conf to 20-nproc.conf (#1071618)
- canonicalize user name in pam_selinux (#1071010)
Fri Jan 31 13:00:00 2014 Tomáš Mráz 1.1.8-6
- refresh the pam-redhat tarball
Fri Jan 24 13:00:00 2014 Daniel Mach - 1.1.8-5
- Mass rebuild 2014-01-24
Wed Jan 15 13:00:00 2014 Tomáš Mráz 1.1.8-4
- rebuild with -O3 on ppc64 architecture
Fri Dec 27 13:00:00 2013 Daniel Mach - 1.1.8-3
- Mass rebuild 2013-12-27
Tue Dec 3 13:00:00 2013 Tomáš Mráz 1.1.8-2
- updated translations
Mon Oct 14 14:00:00 2013 Tomáš Mráz 1.1.8-1
- new upstream release
Sat Oct 5 14:00:00 2013 Tomáš Mráz 1.1.7-4
- pam_tty_audit: proper initialization of the tty_audit_status struct
Mon Sep 30 14:00:00 2013 Tomáš Mráz 1.1.7-2
- add \"local_users_only\" to pam_pwquality in default configuration
Fri Sep 13 14:00:00 2013 Tomáš Mráz 1.1.7-1
- new upstream release
Wed Aug 7 14:00:00 2013 Tomáš Mráz 1.1.6-14
- use links instead of w3m to create txt documentation
- recognize login session in pam_sepermit to prevent gdm from locking (#969174)
- add support for disabling password logging in pam_tty_audit
Thu Jul 11 14:00:00 2013 Tomáš Mráz 1.1.6-13
- add auditing of SELinux policy violation in pam_rootok (#965723)
- add SELinux helper to pam_pwhistory
Wed Jun 12 14:00:00 2013 Tomáš Mráz 1.1.6-12
- lastlog must be updated also for su
Tue May 7 14:00:00 2013 Tomáš Mráz 1.1.6-11
- the default isadir is more correct
Wed Apr 24 14:00:00 2013 Tomáš Mráz 1.1.6-10
- pam_unix: do not fail with bad ld.so.preload
Fri Mar 22 13:00:00 2013 Tomáš Mráz 1.1.6-9
- do not fail if btmp file is corrupted (#906852)
- fix strict aliasing warnings in build
- UsrMove
- use authtok_type with pam_pwquality in system-auth
- remove manual_context handling from pam_selinux (#876976)
- other minor specfile cleanups
Tue Mar 19 13:00:00 2013 Tomáš Mráz 1.1.6-8
- check NULL return from crypt() calls (#915316)
Thu Mar 14 13:00:00 2013 Tomáš Mráz 1.1.6-7
- add workaround for low nproc limit for confined root user (#432903)
Thu Feb 21 13:00:00 2013 Karsten Hopp 1.1.6-6
- add support for ppc64p7 arch (Power7 optimized)
Thu Feb 14 13:00:00 2013 Fedora Release Engineering - 1.1.6-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
Tue Jan 22 13:00:00 2013 Tomas Mraz 1.1.6-4
- fix build with current autotools
Mon Oct 15 14:00:00 2012 Tomas Mraz 1.1.6-3
- add support for tmpfs mount options in pam_namespace
Mon Sep 3 14:00:00 2012 Tomas Mraz 1.1.6-2
- link setuid binaries with full relro (#853158)
- add rhost and tty to auditing data in modules (#677664)
Fri Aug 17 14:00:00 2012 Tomas Mraz - 1.1.6-1
- new upstream release
Thu Aug 9 14:00:00 2012 Tomas Mraz - 1.1.5-9
- make the pam_lastlog module in postlogin \'optional\' (#846843)
Mon Aug 6 14:00:00 2012 Tomas Mraz - 1.1.5-8
- fix build failure in pam_unix
- add display of previous bad login attempts to postlogin.pamd
- put the tmpfiles.d config to /usr/lib and rename it to pam.conf
- build against libdb-5
Wed May 9 14:00:00 2012 Tomas Mraz 1.1.5-7
- add inactive account lock out functionality to pam_lastlog
- fix pam_unix remember user name matching
- add gecoscheck and maxclassrepeat functionality to pam_cracklib
- correctly check for crypt() returning NULL in pam_unix
- pam_unix - do not fallback to MD5 on password change
if requested algorithm not supported by crypt() (#818741)
- install empty directories
Wed May 9 14:00:00 2012 Tomas Mraz 1.1.5-6
- add pam_systemd to session modules
Tue Jan 31 13:00:00 2012 Tomas Mraz 1.1.5-5
- fix pam_namespace leaking the protect mounts to parent namespace (#755216)
Fri Jan 13 13:00:00 2012 Fedora Release Engineering - 1.1.5-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
Wed Dec 21 13:00:00 2011 Tomas Mraz 1.1.5-3
- add a note to limits.conf (#754285)
Thu Nov 24 13:00:00 2011 Tomas Mraz 1.1.5-2
- use pam_pwquality instead of pam_cracklib
Thu Nov 24 13:00:00 2011 Tomas Mraz 1.1.5-1
- upgrade to new upstream release
Thu Aug 25 14:00:00 2011 Tomas Mraz 1.1.4-4
- fix dereference in pam_env
- fix wrong parse of userAATThost pattern in pam_access (#732081)
Sat Jul 23 14:00:00 2011 Ville Skyttä - 1.1.4-3
- Rebuild to fix trailing slashes in provided dirs added by rpm 4.9.1.
Fri Jul 15 14:00:00 2011 Tomas Mraz 1.1.4-2
- clear supplementary groups in pam_console handler execution
Mon Jun 27 14:00:00 2011 Tomas Mraz 1.1.4-1
- upgrade to new upstream release
Tue Jun 7 14:00:00 2011 Tomas Mraz 1.1.3-10
- detect the shared / and make the polydir mounts private based on that
- fix memory leak and other small errors in pam_namespace
Thu Jun 2 14:00:00 2011 Tomas Mraz 1.1.3-9
- add support for explicit marking of the polydir mount private (#623522)
Tue Feb 8 13:00:00 2011 Fedora Release Engineering - 1.1.3-8
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
Wed Dec 22 13:00:00 2010 Tomas Mraz 1.1.3-7
- add postlogin common PAM configuration file (#665059)
Tue Dec 14 13:00:00 2010 Tomas Mraz 1.1.3-6
- include patches recently submitted and applied to upstream CVS
Thu Nov 25 13:00:00 2010 Tomas Mraz 1.1.3-5
- add config for autocreation of subdirectories in /var/run (#656655)
- automatically enable kernel console in pam_securetty
Wed Nov 10 13:00:00 2010 Tomas Mraz 1.1.3-4
- fix memory leak in pam_faillock
Wed Nov 10 13:00:00 2010 Tomas Mraz 1.1.3-3
- fix segfault in faillock utility
- remove some cases where the information of existence of
an user account could be leaked by the pam_faillock,
document the remaining case
Fri Nov 5 13:00:00 2010 Tomas Mraz 1.1.3-2
- fix a mistake in the abstract X-socket connect
- make pam_faillock work with screensaver
Mon Nov 1 13:00:00 2010 Tomas Mraz 1.1.3-1
- upgrade to new upstream release fixing CVE-2010-3316 CVE-2010-3435
CVE-2010-3853
- try to connect to an abstract X-socket first to verify we are
at real console (#647191)
Wed Sep 29 14:00:00 2010 jkeating - 1.1.2-2
- Rebuilt for gcc bug 634757
Mon Sep 20 14:00:00 2010 Tomas Mraz 1.1.2-1
- add pam_faillock module implementing temporary account lock out based
on authentication failures during a specified interval
- do not build some auxiliary tools that are not installed that require
flex-static to build
- upgrade to new upstream release
Thu Jul 15 14:00:00 2010 Tomas Mraz 1.1.1-5
- do not overwrite tallylog with empty file on upgrade
Mon Feb 15 13:00:00 2010 Tomas Mraz 1.1.1-4
- change the default password hash to sha512
Fri Jan 22 13:00:00 2010 Tomas Mraz 1.1.1-3
- fix wrong prompt when pam_get_authtok is used for new password
Mon Jan 18 13:00:00 2010 Tomas Mraz 1.1.1-2
- fix build with disabled audit and SELinux (#556211, #556212)
Thu Dec 17 13:00:00 2009 Tomas Mraz 1.1.1-1
- new upstream version with minor changes
Mon Nov 2 13:00:00 2009 Tomas Mraz 1.1.0-7
- pam_console: fix memory corruption when executing handlers (patch by
Stas Sergeev) and a few more fixes in the handler execution code (#532302)
Thu Oct 29 13:00:00 2009 Tomas Mraz 1.1.0-6
- pam_xauth: set the approprate context when creating .xauth files (#531530)
Tue Sep 1 14:00:00 2009 Tomas Mraz 1.1.0-5
- do not change permissions with pam_console_apply
- drop obsolete pam_tally module and the faillog file (#461258)
Wed Aug 19 14:00:00 2009 Tomas Mraz 1.1.0-4
- rebuild with new libaudit
Mon Jul 27 14:00:00 2009 Tomas Mraz 1.1.0-3
- fix for pam_cracklib from upstream
Sat Jul 25 14:00:00 2009 Fedora Release Engineering - 1.1.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
Tue Jun 23 14:00:00 2009 Tomas Mraz 1.1.0-1
- update to new upstream version
Wed May 13 14:00:00 2009 Tomas Mraz 1.0.92-1
- update to new upstream version
Fri Apr 10 14:00:00 2009 Tomas Mraz 1.0.91-6
- add password-auth, fingerprint-auth, and smartcard-auth
for applications which can use them namely gdm (#494874)
patch by Ray Strode
Thu Mar 26 13:00:00 2009 Tomas Mraz 1.0.91-5
- replace also other std descriptors (#491471)
Tue Mar 17 13:00:00 2009 Tomas Mraz 1.0.91-3
- we must replace the stdin when execing the helper (#490644)
Mon Mar 16 13:00:00 2009 Tomas Mraz 1.0.91-2
- do not close stdout/err when execing the helpers (#488147)
Mon Mar 9 13:00:00 2009 Tomas Mraz 1.0.91-1
- upgrade to new upstream release
Fri Feb 27 13:00:00 2009 Tomas Mraz 1.0.90-4
- fix parsing of config files containing non-ASCII characters
- fix CVE-2009-0579 (mininimum days for password change ignored) (#487216)
- pam_access: improve handling of hostname resolution
Thu Feb 26 13:00:00 2009 Fedora Release Engineering - 1.0.90-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
Mon Jan 19 13:00:00 2009 Tomas Mraz 1.0.90-2
- add helper to pam_mkhomedir for proper SELinux confinement (#476784)
Tue Dec 16 13:00:00 2008 Tomas Mraz 1.0.90-1
- upgrade to new upstream release
- add --disable-prelude (#466242)
Tue Sep 23 14:00:00 2008 Tomas Mraz 1.0.2-2
- new password quality checks in pam_cracklib
- report failed logins from btmp in pam_lastlog
- allow larger groups in modutil functions
- fix leaked file descriptor in pam_tally
Mon Sep 8 14:00:00 2008 Tomas Mraz 1.0.2-1
- pam_loginuid: uids are unsigned (#460241)
- new minor upstream release
- use external db4
- drop tests for not pulling in libpthread (as NPTL should
be safe)
Wed Jul 9 14:00:00 2008 Tomas Mraz 1.0.1-5
- update internal db4
Wed May 21 14:00:00 2008 Tomas Mraz 1.0.1-4
- pam_namespace: allow safe creation of directories owned by user (#437116)
- pam_unix: fix multiple error prompts on password change (#443872)
Tue May 20 14:00:00 2008 Tomas Mraz 1.0.1-3
- pam_selinux: add env_params option which will be used by OpenSSH
- fix build with new autoconf
Tue Apr 22 14:00:00 2008 Tomas Mraz 1.0.1-2
- pam_selinux: restore execcon properly (#443667)
Fri Apr 18 14:00:00 2008 Tomas Mraz 1.0.1-1
- upgrade to new upstream release (one bugfix only)
- fix pam_sepermit use in screensavers
Mon Apr 7 14:00:00 2008 Tomas Mraz 1.0.0-2
- fix regression in pam_set_item
Fri Apr 4 14:00:00 2008 Tomas Mraz 1.0.0-1
- upgrade to new upstream release (bugfix only)
Thu Mar 20 13:00:00 2008 Tomas Mraz 0.99.10.0-4
- pam_namespace: fix problem with level polyinst (#438264)
- pam_namespace: improve override checking for umount
- pam_selinux: fix syslogging a context after free() (#438338)
Thu Feb 28 13:00:00 2008 Tomas Mraz 0.99.10.0-3
- update pam-redhat module tarball
- update internal db4
Fri Feb 22 13:00:00 2008 Tomas Mraz 0.99.10.0-2
- if shadow is readable for an user do not prevent him from
authenticating any user with unix_chkpwd (#433459)
- call audit from unix_chkpwd when appropriate
Fri Feb 15 13:00:00 2008 Tomas Mraz 0.99.10.0-1
- new upstream release
- add default soft limit for nproc of 1024 to prevent
accidental fork bombs (#432903)
Mon Feb 4 13:00:00 2008 Tomas Mraz 0.99.8.1-18
- allow the package to build without SELinux and audit support (#431415)
- macro usage cleanup
Mon Jan 28 13:00:00 2008 Tomas Mraz 0.99.8.1-17
- test for setkeycreatecon correctly
- add exclusive login mode of operation to pam_selinux_permit (original
patch by Dan Walsh)
Tue Jan 22 13:00:00 2008 Tomas Mraz 0.99.8.1-16
- add auditing to pam_access, pam_limits, and pam_time
- moved sanity testing code to check script
Mon Jan 14 13:00:00 2008 Tomas Mraz 0.99.8.1-15
- merge review fixes (#226228)
Tue Jan 8 13:00:00 2008 Tomas Mraz 0.99.8.1-14
- support for sha256 and sha512 password hashes
- account expiry checks moved to unix_chkpwd helper
Wed Jan 2 13:00:00 2008 Tomas Mraz 0.99.8.1-13
- wildcard match support in pam_tty_audit (by Miloslav Trmač)
Thu Nov 29 13:00:00 2007 Tomas Mraz 0.99.8.1-12
- add pam_tty_audit module (#244352) - written by Miloslav Trmač
Wed Nov 7 13:00:00 2007 Tomas Mraz 0.99.8.1-11
- add substack support
Tue Sep 25 14:00:00 2007 Tomas Mraz 0.99.8.1-10
- update db4 to 4.6.19 (#274661)
Fri Sep 21 14:00:00 2007 Tomas Mraz 0.99.8.1-9
- do not preserve contexts when copying skel and other namespace.init
fixes (#298941)
- do not free memory sent to putenv (#231698)
Wed Sep 19 14:00:00 2007 Tomas Mraz 0.99.8.1-8
- add pam_selinux_permit module
- pam_succeed_if: fix in operator (#295151)
Tue Sep 18 14:00:00 2007 Tomas Mraz 0.99.8.1-7
- when SELinux enabled always run the helper binary instead of
direct shadow access (#293181)
Fri Aug 24 14:00:00 2007 Tomas Mraz 0.99.8.1-6
- do not ask for blank password when SELinux confined (#254044)
- initialize homedirs in namespace init script (original patch by dwalsh)
Wed Aug 22 14:00:00 2007 Tomas Mraz 0.99.8.1-5
- most devices are now handled by HAL and not pam_console (patch by davidz)
- license tag fix
- multifunction scanner device support (#251468)
Mon Aug 13 14:00:00 2007 Tomas Mraz 0.99.8.1-4
- fix auth regression when uid != 0 from previous build (#251804)
Mon Aug 6 14:00:00 2007 Tomas Mraz 0.99.8.1-3
- updated db4 to 4.6.18 (#249740)
- added user and new instance parameters to namespace init
- document the new features of pam_namespace
- do not log an audit error when uid != 0 (#249870)
Wed Jul 25 14:00:00 2007 Jeremy Katz - 0.99.8.1-2
- rebuild for toolchain bug
Mon Jul 23 14:00:00 2007 Tomas Mraz 0.99.8.1-1
- upgrade to latest upstream version
- add some firewire devices to default console perms (#240770)
Thu Apr 26 14:00:00 2007 Tomas Mraz 0.99.7.1-6
- pam_namespace: better document behavior on failure (#237249)
- pam_unix: split out passwd change to a new helper binary (#236316)
- pam_namespace: add support for temporary logons (#241226)
Fri Apr 13 14:00:00 2007 Tomas Mraz 0.99.7.1-5
- pam_selinux: improve context change auditing (#234781)
- pam_namespace: fix parsing config file with unknown users (#234513)
Fri Mar 23 13:00:00 2007 Tomas Mraz 0.99.7.1-4
- pam_console: always decrement use count (#230823)
- pam_namespace: use raw context for poly dir name (#227345)
- pam_namespace: truncate long poly dir name (append hash) (#230120)
- we don\'t patch any po files anymore
Wed Feb 21 13:00:00 2007 Tomas Mraz 0.99.7.1-3
- correctly relabel tty in the default case (#229542)
- pam_unix: cleanup of bigcrypt support
- pam_unix: allow modification of \'
*\' passwords to root
Tue Feb 6 13:00:00 2007 Tomas Mraz 0.99.7.1-2
- more X displays as consoles (#227462)
Wed Jan 24 13:00:00 2007 Tomas Mraz 0.99.7.1-1
- upgrade to new upstream version resolving CVE-2007-0003
- pam_namespace: unmount poly dir for override users
Mon Jan 22 13:00:00 2007 Tomas Mraz 0.99.7.0-2
- add back min salt length requirement which was erroneously removed
upstream (CVE-2007-0003)
Fri Jan 19 13:00:00 2007 Tomas Mraz 0.99.7.0-1
- upgrade to new upstream version
- drop pam_stack module as it is obsolete
- some changes to silence rpmlint
Tue Jan 16 13:00:00 2007 Tomas Mraz 0.99.6.2-8
- properly include /var/log/faillog and tallylog as ghosts
and create them in post script (#209646)
- update gmo files as we patch some po files (#218271)
- add use_current_range option to pam_selinux (#220487)
- improve the role selection in pam_selinux
- remove shortcut on Password: in ja locale (#218271)
- revert to old euid and not ruid when setting euid in pam_keyinit (#219486)
- rename selinux-namespace patch to namespace-level
Fri Dec 1 13:00:00 2006 Dan Walsh 0.99.6.2-7
- fix selection of role
Fri Dec 1 13:00:00 2006 Dan Walsh 0.99.6.2-6
- add possibility to pam_namespace to only change MLS component
- Resolves: Bug #216184
Thu Nov 30 13:00:00 2006 Tomas Mraz 0.99.6.2-5
- add select-context option to pam_selinux (#213812)
- autoreconf won\'t work with autoconf-2.61 as configure.in is not yet adjusted
for it
Mon Nov 13 13:00:00 2006 Tomas Mraz 0.99.6.2-4
- update internal db4 to 4.5.20 version
- move setgid before setuid in pam_keyinit (#212329)
- make username check in pam_unix consistent with useradd (#212153)
Tue Oct 24 14:00:00 2006 Tomas Mraz 0.99.6.2-3.3
- don\'t overflow a buffer in pam_namespace (#211989)
Mon Oct 16 14:00:00 2006 Tomas Mraz 0.99.6.2-3.2
- /var/log/faillog and tallylog must be config(noreplace)
Fri Oct 13 14:00:00 2006 Tomas Mraz 0.99.6.2-3.1
- preserve effective uid in namespace.init script (LSPP for newrole)
- include /var/log/faillog and tallylog to filelist (#209646)
- add ids to .xml docs so the generated html is always the same (#210569)
Thu Sep 28 14:00:00 2006 Tomas Mraz 0.99.6.2-3
- add pam_namespace option no_unmount_on_close, required for newrole
Mon Sep 4 14:00:00 2006 Tomas Mraz 0.99.6.2-2
- silence pam_succeed_if in default system-auth (#205067)
- round the pam_timestamp_check sleep up to wake up at the start of the
wallclock second (#205068)
Thu Aug 31 14:00:00 2006 Tomas Mraz 0.99.6.2-1
- upgrade to new upstream version, as there are mostly bugfixes except
improved documentation
- add support for session and password service for pam_access and
pam_succeed_if
- system-auth: skip session pam_unix for crond service
Thu Aug 10 14:00:00 2006 Dan Walsh 0.99.5.0-8
- Add new setkeycreatecon call to pam_selinux to make sure keyring has correct context
Thu Aug 10 14:00:00 2006 Tomas Mraz 0.99.5.0-7
- revoke keyrings properly when pam_keyinit called as root (#201048)
- pam_succeed_if should return PAM_USER_UNKNOWN when getpwnam fails (#197748)
Wed Aug 2 14:00:00 2006 Tomas Mraz 0.99.5.0-6
- revoke keyrings properly when pam_keyinit called more than once (#201048)
patch by David Howells
Fri Jul 21 14:00:00 2006 Tomas Mraz 0.99.5.0-5
- don\'t log pam_keyinit debug messages by default (#199783)
Fri Jul 21 14:00:00 2006 Tomas Mraz 0.99.5.0-4
- drop ainit from console.handlers (#199561)
Mon Jul 17 14:00:00 2006 Tomas Mraz 0.99.5.0-3
- don\'t report error in pam_selinux for nonexistent tty (#188722)
- add pam_keyinit to the default system-auth file (#198623)
Wed Jul 12 14:00:00 2006 Jesse Keating - 0.99.5.0-2.1
- rebuild
Mon Jul 3 14:00:00 2006 Tomas Mraz 0.99.5.0-2
- fixed network match in pam_access (patch by Dan Yefimov)
Fri Jun 30 14:00:00 2006 Tomas Mraz 0.99.5.0-1
- updated to a new upstream release
- added service as value to be matched and list matching to
pam_succeed_if
- namespace.init was missing from EXTRA_DIST
Thu Jun 8 14:00:00 2006 Tomas Mraz 0.99.4.0-5
- updated pam_namespace with latest patch by Janak Desai
- merged pam_namespace patches
- added buildrequires libtool
- fixed a few rpmlint warnings
Wed May 24 14:00:00 2006 Tomas Mraz 0.99.4.0-4
- actually don\'t link to libssl as it is not used (#191915)
Wed May 17 14:00:00 2006 Tomas Mraz 0.99.4.0-3
- use md5 implementation from pam_unix in pam_namespace
- pam_namespace should call setexeccon only when selinux is enabled
Tue May 16 14:00:00 2006 Tomas Mraz 0.99.4.0-2
- pam_console_apply shouldn\'t access /var when called with -r (#191401)
- actually apply the large-uid patch
- don\'t build hmactest in pam_timestamp so openssl-devel is not required
- add missing buildrequires (#191915)
Wed May 10 14:00:00 2006 Tomas Mraz 0.99.4.0-1
- upgrade to new upstream version
- make pam_console_apply not dependent on glib
- support large uids in pam_tally, pam_tally2
Thu May 4 14:00:00 2006 Tomas Mraz 0.99.3.0-5
- the namespace instance init script is now in /etc/security (#190148)
- pam_namespace: added missing braces (#190026)
- pam_tally(2): never call fclose twice on the same FILE (from upstream)
Wed Apr 26 14:00:00 2006 Tomas Mraz 0.99.3.0-4
- fixed console device class for irda (#189966)
- make pam_console_apply fail gracefully when a class is missing
Tue Apr 25 14:00:00 2006 Tomas Mraz 0.99.3.0-3
- added pam_namespace module written by Janak Desai (per-user /tmp
support)
- new pam-redhat modules version
Fri Feb 24 13:00:00 2006 Tomas Mraz 0.99.3.0-2
- added try_first_pass option to pam_cracklib
- use try_first_pass for pam_unix and pam_cracklib in
system-auth (#182350)
Fri Feb 10 13:00:00 2006 Jesse Keating - 0.99.3.0-1.2
- bump again for double-long bug on ppc(64)
Tue Feb 7 13:00:00 2006 Jesse Keating - 0.99.3.0-1.1
- rebuilt for new gcc4.1 snapshot and glibc changes
Fri Feb 3 13:00:00 2006 Tomas Mraz 0.99.3.0-1
- new upstream version
- updated db4 to 4.3.29
- added module pam_tally2 with auditing support
- added manual pages for system-auth and config-util (#179584)
Tue Jan 3 13:00:00 2006 Tomas Mraz 0.99.2.1-3
- remove \'initscripts\' dependency (#176508)
- update pam-redhat modules, merged patches
Fri Dec 16 13:00:00 2005 Tomas Mraz 0.99.2.1-2
- fix dangling symlinks in -devel (#175929)
- link libaudit only where necessary
- actually compile in audit support
Thu Dec 15 13:00:00 2005 Tomas Mraz 0.99.2.1-1
- support netgroup matching in pam_succeed_if
- upgrade to new release
- drop pam_pwdb as it was obsolete long ago
- we don\'t build static libraries anymore
Fri Dec 9 13:00:00 2005 Jesse Keating
- rebuilt
Tue Nov 15 13:00:00 2005 Tomas Mraz 0.80-14
- pam_stack is deprecated - log its usage
Wed Oct 26 14:00:00 2005 Tomas Mraz 0.80-13
- fixed CAN-2005-2977 unix_chkpwd should skip user verification only if
run as root (#168181)
- link pam_loginuid to libaudit
- support no tty in pam_access (#170467)
- updated audit patch (by Steve Grubb)
- the previous pam_selinux change was not applied properly
- pam_xauth: look for the xauth binary in multiple directories (#171164)
Wed Oct 26 14:00:00 2005 Dan Walsh 0.80-12
- Eliminate multiple in pam_selinux
Fri Oct 14 14:00:00 2005 Dan Walsh 0.80-11
- Eliminate fail over for getseuserbyname call
Thu Oct 13 14:00:00 2005 Dan Walsh 0.80-10
- Add getseuserbyname call for SELinux MCS/MLS policy
Tue Oct 4 14:00:00 2005 Tomas Mraz
- pam_console manpage fixes (#169373)
Fri Sep 30 14:00:00 2005 Tomas Mraz 0.80-9
- don\'t include ps and pdf docs (#168823)
- new common config file for configuration utilities
- remove glib2 dependency (#166979)
Tue Sep 20 14:00:00 2005 Tomas Mraz 0.80-8
- process limit values other than RLIMIT_NICE correctly (#168790)
- pam_unix: always honor nis flag on password change (by Aaron Hope)
Wed Aug 24 14:00:00 2005 Tomas Mraz 0.80-7
- don\'t fail in audit code when audit is not compiled in
on the newest kernels (#166422)
Mon Aug 1 14:00:00 2005 Tomas Mraz 0.80-6
- add option to pam_loginuid to require auditd
Fri Jul 29 14:00:00 2005 Tomas Mraz 0.80-5
- fix NULL dereference in pam_userdb (#164418)
Tue Jul 26 14:00:00 2005 Tomas Mraz 0.80-4
- fix 64bit bug in pam_pwdb
- don\'t crash in pam_unix if pam_get_data fail
Fri Jul 22 14:00:00 2005 Tomas Mraz 0.80-3
- more pam_selinux permissive fixes (Dan Walsh)
- make binaries PIE (#158938)
Mon Jul 18 14:00:00 2005 Tomas Mraz 0.80-2
- fixed module tests so the pam doesn\'t require itself to build (#163502)
- added buildprereq for building the documentation (#163503)
- relaxed permissions of binaries (u+w)
Thu Jul 14 14:00:00 2005 Tomas Mraz 0.80-1
- upgrade to new upstream sources
- removed obsolete patches
- pam_selinux module shouldn\'t fail on broken configs unless
policy is set to enforcing (Dan Walsh)
Tue Jun 21 14:00:00 2005 Tomas Mraz 0.79-11
- update pam audit patch
- add support for new limits in kernel-2.6.12 (#157050)
Thu Jun 9 14:00:00 2005 Tomas Mraz 0.79-10
- add the Requires dependency on audit-libs (#159885)
- pam_loginuid shouldn\'t report error when /proc/self/loginuid
is missing (#159974)
Fri May 20 14:00:00 2005 Tomas Mraz 0.79-9
- update the pam audit patch to support newest audit library,
audit also pam_setcred calls (Steve Grubb)
- don\'t use the audit_fd as global static variable
- don\'t unset the XAUTHORITY when target user is root
Mon May 2 14:00:00 2005 Tomas Mraz 0.79-8
- pam_console: support loading .perms files in the console.perms.d (#156069)
Tue Apr 26 14:00:00 2005 Tomas Mraz 0.79-7
- pam_xauth: unset the XAUTHORITY variable on error, fix
potential memory leaks
- modify path to IDE floppy devices in console.perms (#155560)
Sat Apr 16 14:00:00 2005 Steve Grubb 0.79-6
- Adjusted pam audit patch to make exception for ECONNREFUSED
Tue Apr 12 14:00:00 2005 Tomas Mraz 0.79-5
- added auditing patch by Steve Grubb
- added cleanup patches for bugs found by Steve Grubb
- don\'t clear the shadow option of pam_unix if nis option used
Fri Apr 8 14:00:00 2005 Tomas Mraz 0.79-4
- #150537 - flush input first then write the prompt
Thu Apr 7 14:00:00 2005 Tomas Mraz 0.79-3
- make pam_unix LSB 2.0 compliant even when SELinux enabled
- #88127 - change both local and NIS passwords to keep them in sync,
also fix a regression in passwd functionality on NIS master server
Tue Apr 5 14:00:00 2005 Tomas Mraz
- #153711 fix wrong logging in pam_selinux when restoring tty label
Sun Apr 3 14:00:00 2005 Tomas Mraz 0.79-2
- fix NULL deref in pam_tally when it\'s used in account phase
Thu Mar 31 14:00:00 2005 Tomas Mraz 0.79-1
- upgrade to the new upstream release
- moved pam_loginuid to pam-redhat repository
Wed Mar 23 13:00:00 2005 Tomas Mraz 0.78-9
- fix wrong logging in pam_console handlers
- add executing ainit handler for alsa sound dmix
- #147879, #112777 - change permissions for dri devices
Fri Mar 18 13:00:00 2005 Tomas Mraz 0.78-8
- remove ownership and permissions handling from pam_console call
pam_console_apply as a handler instead
Mon Mar 14 13:00:00 2005 Tomas Mraz 0.78-7
- add pam_loginuid module for setting the the login uid for auditing purposes
(by Steve Grubb)
Thu Mar 10 13:00:00 2005 Tomas Mraz 0.78-6
- add functionality for running handler executables from pam_console
when console lock was obtained/lost
- removed patches merged to pam-redhat
Tue Mar 1 13:00:00 2005 Tomas Mraz 0.78-5
- echo why tests failed when rebuilding
- fixed some warnings and errors in pam_console for gcc4 build
- improved parsing pam_console config file
Mon Feb 21 13:00:00 2005 Tomas Mraz
- don\'t log garbage in pam_console_apply (#147879)
Tue Jan 18 13:00:00 2005 Tomas Mraz
- don\'t require exact db4 version only conflict with incompatible one
Wed Jan 12 13:00:00 2005 Tomas Mraz 0.78-4
- updated pam-redhat from elvis CVS
- removed obsolete patches
Mon Jan 3 13:00:00 2005 Jeff Johnson 0.78-3
- depend on db-4.3.27, not db-4.3.21.
Thu Nov 25 13:00:00 2004 Tomas Mraz 0.78-2
- add argument to pam_console_apply to restrict its work to specified files
Tue Nov 23 13:00:00 2004 Tomas Mraz 0.78-1
- update to Linux-PAM-0.78
- #140451 parse passwd entries correctly and test for failure
- #137802 allow using pam_console for authentication
Fri Nov 12 13:00:00 2004 Jeff Johnson 0.77-67
- rebuild against db-4.3.21.
Thu Nov 11 13:00:00 2004 Tomas Mraz 0.77-66
- #77646 log failures when renaming the files when changing password
- Log failure on missing /etc/security/opasswd when remember option is present
Wed Nov 10 13:00:00 2004 Tomas Mraz
- #87628 pam_timestamp remembers authorization after logout
- #116956 fixed memory leaks in pam_stack
Wed Oct 20 14:00:00 2004 Tomas Mraz 0.77-65
- #74062 modify the pwd-lock patch to remove NIS passwd changing deadlock
Wed Oct 20 14:00:00 2004 Tomas Mraz 0.77-64
- #134941 pam_console should check X11 socket only on login
Tue Oct 19 14:00:00 2004 Tomas Mraz 0.77-63
- Fix checking of group %group syntax in pam_limits
- Drop fencepost patch as it was already fixed
by upstream change from 0.75 to 0.77
- Fix brokenshadow patch
Mon Oct 11 14:00:00 2004 Tomas Mraz 0.77-62
- Added bluetooth, raw1394 and flash to console.perms
- pam_console manpage fix
Mon Oct 11 14:00:00 2004 Tomas Mraz 0.77-61
- #129328 pam_env shouldn\'t abort on missing /etc/environment
- #126985 pam_stack should always copy the conversation function
- #127524 add /etc/security/opasswd to files
Tue Sep 28 14:00:00 2004 Phil Knirsch 0.77-60
- Drop last patch again, fixed now correctly elsewhere
Thu Sep 23 14:00:00 2004 Phil Knirsch 0.77-59
- Fixed bug in pam_env where wrong initializer was used
Fri Sep 17 14:00:00 2004 Dan Walsh 0.77-58
- rebuild selinux patch using checkPasswdAccess
Mon Sep 13 14:00:00 2004 Jindrich Novy
- rebuilt
Mon Sep 13 14:00:00 2004 Tomas Mraz 0.77-56
- #75454 fixed locking when changing password
- #127054
- #125653 removed unnecessary getgrouplist call
- #124979 added quiet option to pam_succeed_if
Mon Aug 30 14:00:00 2004 Warren Togami 0.77-55
- #126024 /dev/pmu console perms
Wed Aug 4 14:00:00 2004 Dan Walsh 0.77-54
- Move pam_console.lock to /var/run/console/
Thu Jul 29 14:00:00 2004 Dan Walsh 0.77-53
- Close fd[1] before pam_modutilread so that unix_verify will complete
Tue Jul 27 14:00:00 2004 Alan Cox 0.77-52
- First chunk of Steve Grubb\'s resource leak and other fixes
Tue Jul 27 14:00:00 2004 Alan Cox 0.77-51
- Fixed build testing of modules
- Fixed dependancies
Tue Jul 20 14:00:00 2004 Dan Walsh 0.77-50
- Change unix_chkpwd to return pam error codes
Sat Jul 10 14:00:00 2004 Alan Cox
- Fixed the pam glib2 dependancy issue
Mon Jun 21 14:00:00 2004 Alan Cox
- Fixed the pam_limits fencepost error (#79989) since nobody seems to
be doing it
Tue Jun 15 14:00:00 2004 Elliot Lee
- rebuilt
Wed Jun 9 14:00:00 2004 Dan Walsh 0.77-45
- Add requires libselinux > 1.8
Thu Jun 3 14:00:00 2004 Dan Walsh 0.77-44
- Add MLS Support to selinux patch
Wed Jun 2 14:00:00 2004 Dan Walsh 0.77-43
- Modify pam_selinux to use open and close param
Fri May 28 14:00:00 2004 Dan Walsh 0.77-42
- Split pam module into two parts open and close
Tue May 18 14:00:00 2004 Phil Knirsch 0.77-41
- Fixed 64bit segfault in pam_succeed_if module.
Wed Apr 14 14:00:00 2004 Dan Walsh 0.77-40
- Apply changes from audit.
Mon Apr 12 14:00:00 2004 Dan Walsh 0.77-39
- Change to only report failure on relabel if debug
Wed Mar 3 13:00:00 2004 Dan Walsh 0.77-38
- Fix error handling of pam_unix
Tue Mar 2 13:00:00 2004 Elliot Lee
- rebuilt
Thu Feb 26 13:00:00 2004 Dan Walsh 0.77-36
- fix tty handling
Thu Feb 26 13:00:00 2004 Dan Walsh 0.77-35
- remove tty closing and opening from pam_selinux, it does not work.
Fri Feb 13 13:00:00 2004 Elliot Lee
- rebuilt
Thu Feb 12 13:00:00 2004 Nalin Dahyabhai
- pam_unix: also log successful password changes when using shadowed passwords
Tue Feb 10 13:00:00 2004 Dan Walsh 0.77-33
- close and reopen terminal after changing context.
Thu Feb 5 13:00:00 2004 Dan Walsh 0.77-32
- Check for valid tty
Tue Feb 3 13:00:00 2004 Dan Walsh 0.77-31
- Check for multiple > 1
Mon Feb 2 13:00:00 2004 Dan Walsh 0.77-30
- fix is_selinux_enabled call for pam_rootok
Wed Jan 28 13:00:00 2004 Dan Walsh 0.77-29
- More fixes to pam_selinux,pam_rootok
Wed Jan 28 13:00:00 2004 Dan Walsh 0.77-28
- turn on selinux
Wed Jan 28 13:00:00 2004 Dan Walsh 0.77-27
- Fix rootok check.
Mon Jan 26 13:00:00 2004 Dan Walsh 0.77-26
- fix is_selinux_enabled call
Sun Jan 25 13:00:00 2004 Dan Walsh 0.77-25
- Check if ROOTOK for SELinux
Thu Jan 15 13:00:00 2004 Dan Walsh 0.77-24
- Fix tty handling for pts in pam_selinux
Thu Jan 15 13:00:00 2004 Dan Walsh 0.77-23
- Need to add qualifier context for sudo situation
Thu Jan 15 13:00:00 2004 Dan Walsh 0.77-22