|
|
|
|
Changelog for pam-devel-0.77-66.2.3.rhfc3.ccrma.i386.rpm :
* Tue May 10 2005 Fernando Lopez-Lezcano 0.77-66.2.3- build for Planet CCRMA- added limits.skel patch to enable access to realtime privileges to all users (same as current default behavior in Planet CCRMA for the realtime lsm configuration) - \"lock all memory\" is \"4Gbytes\", max realtime priority is 100, niceness is -10 (which was not, I think, part of the realtime lsm at all) * Sat Apr 30 2005 Jody McIntyre 0.77-66.2.2- Updated RT limits patch to convert nice values in limits.conf to the expected rlimit values.- Set default RT and nice rlimits to 0 for non-audio users. * Wed Apr 27 2005 Jody McIntyre 0.77-66.2.1- pam_limits.patch: add RT/nice rlimit settings.- enable_audio_rt.patch: enable RT privileges for audio group in limits.conf. * Fri Jan 21 2005 Tomas Mraz 0.77-66.2- #115309 prefer changing local password instead of NIS one for local users- Fix PAM_IGNORE return value handling and correct the grubb_leak patch to fix #143750 * Wed Dec 08 2004 Tomas Mraz 0.77-66.1- add argument to pam_console_apply to restrict its work to specified files- #140451 parse passwd entries correctly and test for failure * Thu Nov 11 2004 Tomas Mraz 0.77-66- #77646 log failures when renaming the files when changing password- Log failure on missing /etc/security/opasswd when remember option is present * Wed Nov 10 2004 Tomas Mraz - #87628 pam_timestamp remembers authorization after logout- #116956 fixed memory leaks in pam_stack * Thu Oct 21 2004 Tomas Mraz 0.77-65- #74062 modify the pwd-lock patch to remove NIS passwd changing deadlock * Thu Oct 21 2004 Tomas Mraz 0.77-64- #134941 pam_console should check X11 socket only on login * Wed Oct 20 2004 Tomas Mraz 0.77-63- Fix checking of group Development/Debug syntax in pam_limits- Drop fencepost patch as it was already fixed by upstream change from 0.75 to 0.77- Fix brokenshadow patch * Tue Oct 12 2004 Tomas Mraz 0.77-62- Added bluetooth, raw1394 and flash to console.perms- pam_console manpage fix * Tue Oct 12 2004 Tomas Mraz 0.77-61- #129328 pam_env shouldn\'t abort on missing /etc/environment- #126985 pam_stack should always copy the conversation function - #127524 add /etc/security/opasswd to files * Wed Sep 29 2004 Phil Knirsch 0.77-60- Drop last patch again, fixed now correctly elsewhere * Fri Sep 24 2004 Phil Knirsch 0.77-59- Fixed bug in pam_env where wrong initializer was used * Sat Sep 18 2004 Dan Walsh 0.77-58- rebuild selinux patch using checkPasswdAccess * Tue Sep 14 2004 Jindrich Novy - rebuilt * Tue Sep 14 2004 Tomas Mraz 0.77-56- #75454 fixed locking when changing password- #127054 - #125653 removed unnecessary getgrouplist call- #124979 added quiet option to pam_succeed_if * Tue Aug 31 2004 Warren Togami 0.77-55- #126024 /dev/pmu console perms * Thu Aug 05 2004 Dan Walsh 0.77-54- Move pam_console.lock to /var/run/console/ * Fri Jul 30 2004 Dan Walsh 0.77-53- Close fd[1] before pam_modutilread so that unix_verify will complete * Wed Jul 28 2004 Alan Cox 0.77-52- First chunk of Steve Grubb\'s resource leak and other fixes * Wed Jul 28 2004 Alan Cox 0.77-51- Fixed build testing of modules- Fixed dependancies * Wed Jul 21 2004 Dan Walsh 0.77-50- Change unix_chkpwd to return pam error codes * Sun Jul 11 2004 Alan Cox - Fixed the pam glib2 dependancy issue * Tue Jun 22 2004 Alan Cox - Fixed the pam_limits fencepost error (#79989) since nobody seems to be doing it * Wed Jun 16 2004 Elliot Lee - rebuilt * Thu Jun 10 2004 Dan Walsh 0.77-45- Add requires libselinux > 1.8 * Fri Jun 04 2004 Dan Walsh 0.77-44- Add MLS Support to selinux patch * Thu Jun 03 2004 Dan Walsh 0.77-43- Modify pam_selinux to use open and close param * Sat May 29 2004 Dan Walsh 0.77-42- Split pam module into two parts open and close * Wed May 19 2004 Phil Knirsch 0.77-41- Fixed 64bit segfault in pam_succeed_if module. * Thu Apr 15 2004 Dan Walsh 0.77-40- Apply changes from audit. * Tue Apr 13 2004 Dan Walsh 0.77-39- Change to only report failure on relabel if debug * Wed Mar 03 2004 Dan Walsh 0.77-38- Fix error handling of pam_unix * Tue Mar 02 2004 Elliot Lee - rebuilt * Thu Feb 26 2004 Dan Walsh 0.77-36- fix tty handling * Thu Feb 26 2004 Dan Walsh 0.77-35- remove tty closing and opening from pam_selinux, it does not work. * Fri Feb 13 2004 Elliot Lee - rebuilt * Thu Feb 12 2004 Nalin Dahyabhai - pam_unix: also log successful password changes when using shadowed passwords * Tue Feb 10 2004 Dan Walsh 0.77-33- close and reopen terminal after changing context. * Thu Feb 05 2004 Dan Walsh 0.77-32- Check for valid tty * Tue Feb 03 2004 Dan Walsh 0.77-31- Check for multiple > 1 * Mon Feb 02 2004 Dan Walsh 0.77-30- fix is_selinux_enabled call for pam_rootok * Wed Jan 28 2004 Dan Walsh 0.77-29- More fixes to pam_selinux,pam_rootok * Wed Jan 28 2004 Dan Walsh 0.77-28- turn on selinux * Wed Jan 28 2004 Dan Walsh 0.77-27- Fix rootok check. * Mon Jan 26 2004 Dan Walsh 0.77-26- fix is_selinux_enabled call * Sun Jan 25 2004 Dan Walsh 0.77-25- Check if ROOTOK for SELinux * Thu Jan 15 2004 Dan Walsh 0.77-24- Fix tty handling for pts in pam_selinux * Thu Jan 15 2004 Dan Walsh 0.77-23- Need to add qualifier context for sudo situation * Thu Jan 15 2004 Dan Walsh 0.77-22- Fix pam_selinux to use prevcon instead of pam_user so it will work for su. * Fri Dec 12 2003 Bill Nottingham 0.77-21.sel- add alsa devs to console.perms * Thu Dec 11 2003 Jeff Johnson 0.77-20.sel- rebuild with db-4.2.52.- build db4 in build_unix, not dist. * Wed Nov 26 2003 Dan Walsh 0.77-19.sel- Change unix_chkpwd to handle unix_passwd and unix_acct- This eliminates the need for pam modules to have read/write access to /etc/shadow. * Thu Nov 20 2003 Dan Walsh 0.77-18.sel- Cleanup unix_chkpwd * Mon Nov 03 2003 Dan Walsh 0.77-17.sel- Fix tty handling - Add back multiple handling * Mon Oct 27 2003 Dan Walsh 0.77-16.sel- Remove Multiple from man page of pam_selinux * Fri Oct 24 2003 Nalin Dahyabhai 0.77-15- don\'t install _pam_aconf.h -- apps don\'t use it, other PAM headers which are installed don\'t use it, and its contents may be different for arches on a multilib system- check for linkage problems in modules at %install-time (kill #107093 dead)- add buildprereq on flex (#101563) * Thu Oct 23 2003 Nalin Dahyabhai - make pam_pwdb.so link with libnsl again so that it loads (#107093)- remove now-bogus buildprereq on db4-devel (we use a bundled copy for pam_userdb to avoid symbol collisions with other db libraries in apps) * Tue Oct 21 2003 Dan Walsh 0.77-14.sel- Add Russell Coker patch to handle /dev/pty * Sat Oct 18 2003 Dan Walsh 0.77-13.sel- Turn on Selinux * Sat Oct 18 2003 Dan Walsh 0.77-12- Fix pam_timestamp to work when 0 seconds have elapsed * Tue Oct 07 2003 Dan Walsh 0.77-11- Turn off selinux * Fri Sep 26 2003 Dan Walsh 0.77-10.sel- Turn on Selinux and remove multiple choice of context. * Thu Sep 25 2003 Dan Walsh 0.77-10- Turn off selinux * Thu Sep 25 2003 Dan Walsh 0.77-9.sel- Add Russell\'s patch to check password * Thu Sep 18 2003 Dan Walsh 0.77-8.sel- handle ttys correctly in pam_selinux * Sat Sep 06 2003 Dan Walsh 0.77-7.sel- Clean up memory problems and fix tty handling. * Tue Jul 29 2003 Dan Walsh 0.77-6- Add manual context selection to pam_selinux * Tue Jul 29 2003 Dan Walsh 0.77-5- Add pam_selinux * Tue Jul 29 2003 Dan Walsh 0.77-4- Add SELinux support * Fri Jul 25 2003 Nalin Dahyabhai 0.77-3- pam_postgresok: add- pam_xauth: add \"targetuser\" argument * Wed Jul 23 2003 Nalin Dahyabhai - pam_succeed_if: fix thinko in argument parsing which would walk past the end of the argument list * Thu Jul 10 2003 Nalin Dahyabhai 0.77-2- reapply: - set handler for SIGCHLD to SIG_DFL around *_chkpwd, not SIG_IGN * Tue Jul 08 2003 Nalin Dahyabhai 0.77-1- pam_timestamp: fail if the key file doesn\'t contain enough data * Fri Jul 04 2003 Nalin Dahyabhai 0.77-0- update to 0.77 upstream release - pam_limits: limits now affect root as well - pam_nologin: returns PAM_IGNORE instead of PAM_SUCCESS unless \"successok\" is given as an argument - pam_userdb: correctly return PAM_AUTH_ERR instead of PAM_USER_UNKNOWN when invoked with the \"key_only\" argument and the database has an entry of the form \"user-\"- use a bundled libdb for pam_userdb.so because the system copy uses threads, and demand-loading a shared library which uses threads into an application which doesn\'t is a Very Bad Idea * Fri Jul 04 2003 Nalin Dahyabhai - pam_timestamp: use a message authentication code to validate timestamp files * Tue Jul 01 2003 Nalin Dahyabhai 0.75-48.1- rebuild * Tue Jun 10 2003 Nalin Dahyabhai 0.75-49- modify calls to getlogin() to check the directory of the current TTY before searching for an entry in the utmp/utmpx file (#98020, #98826, CAN-2003-0388) * Thu Jun 05 2003 Elliot Lee - rebuilt * Mon Feb 10 2003 Bill Nottingham 0.75-48- set handler for SIGCHLD to SIG_DFL around *_chkpwd, not SIG_IGN * Wed Jan 22 2003 Tim Powers 0.75-47- rebuilt * Tue Dec 17 2002 Nalin Dahyabhai 0.75-46- pam_xauth: reintroduce ACL support, per the original white paper- pam_xauth: default root\'s export ACL to none instead of everyone * Mon Dec 02 2002 Nalin Dahyabhai 0.75-45- create /lib/security, even if it isn\'t /%{_lib}/security, because we can\'t locate /lib/security/$ISA without it (noted by Arnd Bergmann)- clear out the duplicate docs directory created during %install * Thu Nov 21 2002 Nalin Dahyabhai 0.75-44- fix syntax errors in pam_console\'s yacc parser which newer bison chokes on- forcibly set FAKEROOT at make install time * Wed Oct 23 2002 Nalin Dahyabhai 0.75-43- patch to interpret $ISA in case the fist module load attempt fails- use $ISA in default configs * Sat Oct 05 2002 Elliot Lee 0.75-42- Since cracklib-dicts location will not be correctly detected without that package being installed, add buildreq for cracklib-dicts.- Add patch57: makes configure use $LIBNAME when searching for cracklib dicts, and error out if not found. * Fri Sep 13 2002 Than Ngo 0.75-41.1- Fixed pam config files * Thu Sep 12 2002 Than Ngo 0.75-41- Added fix to install libs in correct directory on 64bit machine * Sat Aug 03 2002 Nalin Dahyabhai 0.75-40- pam_timestamp_check: check that stdio descriptors are open before we\'re invoked- add missing chroot.conf * Tue Jul 30 2002 Nalin Dahyabhai 0.75-39- pam_timestamp: sundry fixes, use \"unknown\" as the tty when none is found * Fri Jun 28 2002 Nalin Dahyabhai 0.75-38- pam_timestamp_check: be as smart about figuring out the tty as the module is * Thu Jun 20 2002 Nalin Dahyabhai 0.75-37- pam_timestamp_check: remove extra unlink() call spotted by Havoc * Tue Jun 18 2002 Nalin Dahyabhai 0.75-36- pam_timestamp: chown intermediate directories when creating them- pam_timestamp_check: add -d flag to poll * Fri May 24 2002 Nalin Dahyabhai 0.75-35- pam_timestamp: add some sanity checks- pam_timestamp_check: add * Thu May 23 2002 Nalin Dahyabhai 0.75-34- pam_timestamp: add a \'verbose\' option * Fri May 17 2002 Nalin Dahyabhai 0.75-33- rebuild with db4- just bundle install-sh into the source package * Wed Apr 10 2002 Nalin Dahyabhai 0.75-32- pam_unix: be more compatible with AIX-style shadowing (#19236) * Thu Mar 28 2002 Nalin Dahyabhai 0.75-31- libpam_misc: fix possible infinite loop in misc_conv (#62195)- pam_xauth: fix cases where DISPLAY is \"localhost:screen\" and the xauth key is actually stored using the system\'s hostname (#61524) * Mon Mar 25 2002 Nalin Dahyabhai 0.75-30- rebuild * Mon Mar 25 2002 Nalin Dahyabhai 0.75-29- rebuild * Mon Mar 11 2002 Nalin Dahyabhai 0.75-28- include the pwdb config file * Fri Mar 01 2002 Nalin Dahyabhai 0.75-27- adjust the pwdb-static patch to build pam_radius correctly (#59408) * Fri Mar 01 2002 Nalin Dahyabhai 0.75-26- change the db4-devel build dependency to db3-devel * Thu Feb 21 2002 Nalin Dahyabhai 0.75-25- rebuild * Fri Feb 08 2002 Nalin Dahyabhai 0.75-24- pam_unix: log successful password changes- remove pam_timestamp * Thu Feb 07 2002 Nalin Dahyabhai 0.75-23- fix pwdb embedding- add pam_timestamp * Thu Jan 31 2002 Nalin Dahyabhai 0.75-22- swallow up pwdb 0.61.1 for building pam_pwdb * Wed Jan 23 2002 Nalin Dahyabhai 0.75-21- pam_userdb: build with db4 instead of db3 * Thu Nov 22 2001 Nalin Dahyabhai 0.75-20- pam_stack: fix some memory leaks (reported by Fernando Trias)- pam_chroot: integrate Owl patch to report the more common causes of failures * Fri Nov 09 2001 Nalin Dahyabhai 0.75-19- fix a bug in the getpwnam_r wrapper which sometimes resulted in false positives for non-existent users * Wed Nov 07 2001 Nalin Dahyabhai 0.75-18- include libpamc in the pam package (#55651) * Fri Nov 02 2001 Nalin Dahyabhai 0.75-17- pam_xauth: don\'t free a string after passing it to putenv() * Thu Oct 25 2001 Nalin Dahyabhai 0.75-16- pam_xauth: always return PAM_SUCCESS or PAM_SESSION_ERR instead of PAM_IGNORE, matching the previous behavior (libpam treats PAM_IGNORE from a single module in a stack as a session error, leading to false error messages if we just return PAM_IGNORE for all cases) * Tue Oct 23 2001 Nalin Dahyabhai 0.75-15- reorder patches so that the reentrancy patch is applied last -- we never came to a consensus on how to guard against the bugs in calling applications which this sort of change addresses, and having them last allows for dropping in a better strategy for addressing this later on * Tue Oct 16 2001 Nalin Dahyabhai - pam_rhosts: allow \"+hostname\" as a synonym for \"hostname\" to jive better with the hosts.equiv(5) man page- use the automake install-sh instead of the autoconf install-sh, which disappeared somewhere between 2.50 and now * Tue Oct 09 2001 Nalin Dahyabhai - add pwdb as a buildprereq * Sat Oct 06 2001 Nalin Dahyabhai - pam_tally: don\'t try to read past the end of faillog -- it probably contains garbage, which if written into the file later on will confuse /usr/bin/faillog * Fri Oct 05 2001 Nalin Dahyabhai - pam_limits: don\'t just return if the user is root -- we\'ll want to set the priority (it could be negative to elevate root\'s sessions)- pam_issue: fix off-by-one error allocating space for the prompt string * Thu Oct 04 2001 Nalin Dahyabhai - pam_mkhomedir: recurse into subdirectories properly- pam_mkhomedir: handle symlinks- pam_mkhomedir: skip over special items in the skeleton directory * Wed Oct 03 2001 Nalin Dahyabhai - add cracklib as a buildprereq- pam_wheel: don\'t ignore out if the user is attempting to switch to a unprivileged user (this lets pam_wheel do its thing when users attempt to get to system accounts or accounts of other unprivileged users) * Sat Sep 29 2001 Nalin Dahyabhai - pam_xauth: close a possible DoS due to use of dotlock-style locking in world-writable directories by relocating the temporary file to the target user\'s home directory- general: include headers local to this tree using relative paths so that system headers for PAM won\'t be pulled in, in case include paths don\'t take care of it * Fri Sep 28 2001 Nalin Dahyabhai - pam_xauth: rewrite to skip refcounting and just use a temporary file created using mkstemp() in /tmp * Wed Sep 26 2001 Nalin Dahyabhai - pam_userdb: fix the key_only flag so that the null-terminator of the user-password string isn\'t expected to be part of the key in the db file, matching the behavior of db_load 3.2.9 * Tue Sep 25 2001 Nalin Dahyabhai - pam_unix: use crypt() instead of bigcrypt() when salted field is less than the critical size which lets us know it was generated with bigcrypt()- use a wrapper to handle ERANGE errors when calling get....._r functions: defining PAM_GETPWNAM_R and such (for getpwnam, getpwuid, getgrnam, getgrgid, and getspnam) before including _pam_macros.h will cause them to be implemented as static functions, similar to how defining PAM_SM_xxx is used to control whether or not PAM declares prototypes for certain functions * Tue Sep 25 2001 Nalin Dahyabhai 0.75-14- pam_unix: argh, compare entire pruned salt string with crypted result, always * Sun Sep 09 2001 Bill Nottingham 0.75-13- ship /lib/lib{pam,pam_misc}.so for legacy package builds * Fri Sep 07 2001 Nalin Dahyabhai 0.75-12- noreplace configuration files in /etc/security- pam_console: update pam_console_apply and man pages to reflect /var/lock -> /var/run move * Thu Sep 06 2001 Nalin Dahyabhai 0.75-11- pam_unix: fix the fix for #42394 * Wed Sep 05 2001 Nalin Dahyabhai - modules: use getpwnam_r and friends instead of non-reentrant versions- pam_console: clear generated .c and .h files in \"clean\" makefile target * Fri Aug 31 2001 Nalin Dahyabhai - pam_stack: perform deep copy of conversation structures- include the static libpam in the -devel subpackage (#52321)- move development .so and .a files to %{_libdir}- pam_unix: don\'t barf on empty passwords (#51846)- pam_unix: redo compatibility with \"hash,age\" data wrt bigcrypt (#42394)- console.perms: add usb camera, scanner, and rio devices (#15528)- pam_cracklib: initialize all options properly (#49613) * Thu Aug 23 2001 Nalin Dahyabhai - pam_limits: don\'t rule out negative priorities * Tue Aug 14 2001 Nalin Dahyabhai 0.75-10- pam_xauth: fix errors due to uninitialized data structure (fix from Tse Huong Choo)- pam_xauth: random cleanups- pam_console: use /var/run/console instead of /var/lock/console at install-time- pam_unix: fix preserving of permissions on files which are manipulated * Sat Aug 11 2001 Bill Nottingham - fix segfault in pam_securetty * Fri Aug 10 2001 Nalin Dahyabhai - pam_console: use /var/run/console instead of /var/lock/console for lock files- pam_issue: read the right number of bytes from the file * Tue Jul 10 2001 Nalin Dahyabhai - pam_wheel: don\'t error out if the group has no members, but is the user\'s primary GID (reported by David Vos)- pam_unix: preserve permissions on files which are manipulated (#43706)- pam_securetty: check if the user is the superuser before checking the tty, thereby allowing regular users access to services which don\'t set the PAM_TTY item (#39247)- pam_access: define NIS and link with libnsl (#36864) * Fri Jul 06 2001 Nalin Dahyabhai - link libpam_misc against libpam * Wed Jul 04 2001 Nalin Dahyabhai - pam_chroot: chdir() before chroot() * Sat Jun 30 2001 Nalin Dahyabhai - pam_console: fix logic bug when changing permissions on single file and/or lists of files- pam_console: return the proper error code (reported and patches for both from Frederic Crozat)- change deprecated Copyright: tag in .spec file to License: * Tue Jun 26 2001 Nalin Dahyabhai - console.perms: change js * to js[0-9] *- include pam_aconf.h in more modules (patches from Harald Welte) * Fri May 25 2001 Nalin Dahyabhai - console.perms: add apm_bios to the list of devices the console owner can use- console.perms: add beep to the list of sound devices * Tue May 08 2001 Nalin Dahyabhai - link pam_console_apply statically with libglib (#38891) * Tue May 01 2001 Nalin Dahyabhai - pam_access: compare IP addresses with the terminating \".\", as documented (patch from Carlo Marcelo Arenas Belon, I think) (#16505) * Tue Apr 24 2001 Nalin Dahyabhai - merge up to 0.75- pam_unix: temporarily ignore SIGCHLD while running the helper- pam_pwdb: temporarily ignore SIGCHLD while running the helper- pam_dispatch: default to uncached behavior if the cached chain is empty * Sat Apr 07 2001 Nalin Dahyabhai - correct speling errors in various debug messages and doc files (#33494) * Fri Apr 06 2001 Nalin Dahyabhai - prereq sed, fileutils (used in %post) * Thu Apr 05 2001 Nalin Dahyabhai - remove /dev/dri from console.perms -- XFree86 munges it, so it\'s outside of our control (reminder from Daryll Strauss)- add /dev/3dfx to console.perms * Fri Mar 23 2001 Nalin Dahyabhai - pam_wheel: make \'trust\' and \'deny\' work together correctly- pam_wheel: also check the user\'s primary gid- pam_group: also initialize groups when called with PAM_REINITIALIZE_CRED * Tue Mar 20 2001 Nalin Dahyabhai - mention pam_console_apply in the see also section of the pam_console man pages * Fri Mar 16 2001 Nalin Dahyabhai - console.perms: /dev/vc/ * should be a regexp, not a glob (thanks to Charles Lopes) * Mon Mar 12 2001 Nalin Dahyabhai - console.perms: /dev/cdroms/ * should belong to the user, from Douglas Gilbert via Tim Waugh * Thu Mar 08 2001 Nalin Dahyabhai - pam_console_apply: muck with devices even if the mount point doesn\'t exist * Wed Mar 07 2001 Nalin Dahyabhai - pam_console: error out on undefined classes in pam_console config file- console.perms: actually change the permissions on the new device classes- pam_console: add an fstab= argument, and -f and -c flags to pam_console_apply- pam_console: use g_log instead of g_critical when bailing out- console.perms: logins on /dev/vc/ * are also console logins, from Douglas Gilbert via Tim Waugh * Tue Mar 06 2001 Nalin Dahyabhai - add pam_console_apply- /dev/pilot\'s usually a serial port (or a USB serial port), so revert its group to \'uucp\' instead of \'tty\' in console.perms- change pam_console\'s behavior wrt directories -- directories which are mount points according to /etc/fstab are taken to be synonymous with their device special nodes, and directories which are not mount points are ignored * Tue Feb 27 2001 Nalin Dahyabhai - handle errors fork()ing in pam_xauth- make the \"other\" config noreplace * Mon Feb 26 2001 Nalin Dahyabhai - user should own the /dev/video directory, not the non-existent /dev/v4l- tweak pam_limits doc * Wed Feb 21 2001 Nalin Dahyabhai - own /etc/security- be more descriptive when logging messages from pam_limits- pam_listfile: remove some debugging code (#28346) * Mon Feb 19 2001 Nalin Dahyabhai - pam_lastlog: don\'t pass NULL to logwtmp() * Fri Feb 16 2001 Nalin Dahyabhai - pam_listfile: fix argument parser (#27773)- pam_lastlog: link to libutil * Tue Feb 13 2001 Nalin Dahyabhai - pam_limits: change the documented default config file to reflect the defaults- pam_limits: you should be able to log in a total of maxlogins times, not (maxlogins - 1)- handle group limits on maxlogins correctly (#25690) * Mon Feb 12 2001 Nalin Dahyabhai - change the pam_xauth default maximum \"system user\" ID from 499 to 99 (#26343) * Wed Feb 07 2001 Nalin Dahyabhai - refresh the default system-auth file, pam_access is out * Mon Feb 05 2001 Nalin Dahyabhai - actually time out when attempting to lckpwdf() (#25889)- include time.h in pam_issue (#25923)- update the default system-auth to the one generated by authconfig 4.1.1- handle getpw??? and getgr??? failures more gracefully (#26115)- get rid of some extraneous {set,end}{pw,gr}ent() calls * Tue Jan 30 2001 Nalin Dahyabhai - overhaul pam_stack to account for abstraction libpam now provides * Tue Jan 23 2001 Nalin Dahyabhai - remove pam_radius at request of author * Mon Jan 22 2001 Nalin Dahyabhai - merge to 0.74- make console.perms match perms set by MAKEDEV, and add some devfs device names- add \'sed\' to the buildprereq list (#24666) * Sun Jan 21 2001 Matt Wilson - added \"exit 0\" to the end of the %pre script * Fri Jan 19 2001 Nalin Dahyabhai - self-hosting fix from Guy Streeter * Wed Jan 17 2001 Nalin Dahyabhai - use gcc for LD_L to pull in intrinsic stuff on ia64 * Fri Jan 12 2001 Nalin Dahyabhai - take another whack at compatibility with \"hash,age\" data in pam_unix (#21603) * Wed Jan 10 2001 Nalin Dahyabhai - make the -devel subpackage unconditional * Tue Jan 09 2001 Nalin Dahyabhai - merge/update to 0.73 * Mon Dec 18 2000 Nalin Dahyabhai - refresh from CVS -- some weird stuff crept into pam_unix * Tue Dec 12 2000 Nalin Dahyabhai - fix handling of \"nis\" when changing passwords by adding the checks for the data source to the password-updating module in pam_unix- add the original copyright for pam_access (fix from Michael Gerdts) * Thu Nov 30 2000 Nalin Dahyabhai - redo similar() using a distance algorithm and drop the default dif_ok to 5- readd -devel * Wed Nov 29 2000 Nalin Dahyabhai - fix similar() function in pam_cracklib (#14740)- fix example in access.conf (#21467)- add conditional compilation for building for 6.2 (for pam_userdb)- tweak post to not use USESHADOW any more * Tue Nov 28 2000 Nalin Dahyabhai - make EINVAL setting lock limits in pam_limits non-fatal, because it\'s a 2.4ism * Tue Nov 21 2000 Nalin Dahyabhai - revert to DB 3.1, which is what we were supposed to be using from the get-go * Mon Nov 20 2000 Nalin Dahyabhai - add RLIMIT_LOCKS to pam_limits (patch from Jes Sorensen) (#20542)- link pam_userdb to Berkeley DB 2.x to match 6.2\'s setup correctly * Mon Nov 06 2000 Matt Wilson - remove prereq on sh-utils, test ([) is built in to bash * Fri Oct 20 2000 Nalin Dahyabhai - fix the pam_userdb module breaking * Thu Oct 19 2000 Nalin Dahyabhai - fix pam_unix likeauth argument for authenticate(),setcred(),setcred() * Wed Oct 18 2000 Nalin Dahyabhai - tweak pre script to be called in all upgrade cases- get pam_unix to only care about the significant pieces of passwords it checks- add /usr/include/db1/db.h as a build prereq to pull in the right include files, no matter whether they\'re in glibc-devel or db1-devel- pam_userdb.c: include db1/db.h instead of db.h * Thu Oct 12 2000 Nalin Dahyabhai - add BuildPrereq for bison (suggested by Bryan Stillwell) * Sat Oct 07 2000 Nalin Dahyabhai - patch from Dmitry V. Levin to have pam_stack propagate the PAM fail_delay- roll back the README for pam_xauth to actually be the right one- tweak pam_stack to use the parent\'s service name when calling the substack * Thu Oct 05 2000 Nalin Dahyabhai - create /etc/sysconfig/authconfig at install-time if upgrading * Tue Oct 03 2000 Nalin Dahyabhai - modify the files list to make sure #16456 stays fixed- make pam_stack track PAM_AUTHTOK and PAM_OLDAUTHTOK items- add pam_chroot module- self-hosting fixes from the -devel split- update generated docs in the tree * Wed Sep 13 2000 Nalin Dahyabhai - split off a -devel subpackage- install the developer man pages * Mon Sep 11 2000 Bill Nottingham - build libraries before modules * Thu Sep 07 2000 Nalin Dahyabhai - fix problems when looking for headers in /usr/include (#17236)- clean up a couple of compile warnings * Wed Aug 23 2000 Nalin Dahyabhai - give users /dev/cdrom * instead of /dev/cdrom in console.perms (#16768)- add nvidia control files to console.perms * Wed Aug 23 2000 Bill Nottingham - add DRI devices to console.perms (#16731) * Fri Aug 18 2000 Nalin Dahyabhai - move pam_filter modules to /lib/security/pam_filter (#16111)- add pam_tally\'s application to allow counts to be reset (#16456)- move README files to the txts subdirectory * Tue Aug 15 2000 Nalin Dahyabhai - add a postun that runs ldconfig- clean up logging in pam_xauth * Sat Aug 05 2000 Nalin Dahyabhai - make the tarball include the release number in its name * Tue Aug 01 2000 Nalin Dahyabhai - add a broken_shadow option to pam_unix- add all module README files to the documentation list (#16456) * Wed Jul 26 2000 Nalin Dahyabhai - fix pam_stack debug and losing-track-of-the-result bug * Tue Jul 25 2000 Nalin Dahyabhai - rework pam_console\'s usage of syslog to actually be sane (#14646) * Sun Jul 23 2000 Nalin Dahyabhai - take the LOG_ERR flag off of some of pam_console\'s new messages * Sat Jul 22 2000 Nalin Dahyabhai - add pam_localuser * Thu Jul 13 2000 Nalin Dahyabhai - need to make pam_console\'s checking a little stronger- only pass data up from pam_stack if the parent didn\'t already define it * Thu Jul 13 2000 Prospector - automatic rebuild * Wed Jul 12 2000 Nalin Dahyabhai - make pam_console\'s extra checks disableable- simplify extra check to just check if the device owner is root- add a debug log when pam_stack comes across a NULL item- have pam_stack hand items up to the parent from the child * Tue Jul 04 2000 Nalin Dahyabhai - fix installation of pam_xauth man pages (#12417)- forcibly strip helpers (#12430)- try to make pam_console a little more discriminating * Tue Jun 20 2000 Nalin Dahyabhai - symlink libpam.so to libpam.so.0.77, and likewise for libpam_misc- reverse order of checks in _unix_getpwnam for pam_unix * Thu Jun 15 2000 Preston Brown - include gpmctl in pam_console * Tue Jun 06 2000 Nalin Dahyabhai - add MANDIR definition and use it when installing man pages * Tue Jun 06 2000 Preston Brown - handle scanner and cdwriter devices in pam_console * Sun Jun 04 2000 Nalin Dahyabhai - add account management wrappers for pam_listfile, pam_nologin, pam_securetty, pam_shells, and pam_wheel * Fri Jun 02 2000 Nalin Dahyabhai - add system-auth control file- let gethostname() call in pam_access.c be implicitly declared to avoid conflicting types if unistd.c declares it * Tue May 16 2000 Nalin Dahyabhai - fix problems compiling on Red Hat Linux 5.x (bug #11005) * Thu Apr 27 2000 Bill Nottingham - fix size assumptions in pam_(pwdb|unix) md5 code * Mon Mar 20 2000 Nalin Dahyabhai - Add new pam_stack module.- Install pwdb_chkpwd and unix_chkpwd as the current user for non-root builds * Sat Feb 05 2000 Nalin Dahyabhai - Fix pam_xauth bug #6191. * Thu Feb 03 2000 Elliot Lee - Add a patch to accept \'pts/N\' in /etc/securetty as a match for tty \'5\' (which is what other pieces of the system think it is). Fixes bug #7641. * Mon Jan 31 2000 Nalin Dahyabhai - argh, turn off gratuitous debugging * Wed Jan 19 2000 Nalin Dahyabhai - update to 0.72- fix pam_unix password-changing bug- fix pam_unix\'s cracklib support- change package URL * Mon Jan 03 2000 Cristian Gafton - don\'t allow \'/\' on service_name * Fri Oct 22 1999 Cristian Gafton - enhance the pam_userdb module some more * Sat Sep 25 1999 Cristian Gafton - add documenatation * Wed Sep 22 1999 Michael K. Johnson - a tiny change to pam_console to make it not loose track of console users * Tue Sep 21 1999 Michael K. Johnson - a few fixes to pam_xauth to make it more robust * Thu Jul 15 1999 Michael K. Johnson - pam_console: added to manage /dev/console * Fri Jul 02 1999 Michael K. Johnson - pam_xauth: New refcounting implementation based on idea from Stephen Tweedie * Sun Apr 18 1999 Michael K. Johnson - added video4linux devices to /etc/security/console.perms * Sat Apr 17 1999 Michael K. Johnson - added joystick lines to /etc/security/console.perms * Fri Apr 16 1999 Michael K. Johnson - fixed a couple segfaults in pam_xauth uncovered by yesterday\'s fix... * Thu Apr 15 1999 Cristian Gafton - use gcc -shared to link the shared libs * Thu Apr 15 1999 Michael K. Johnson - many bug fixes in pam_xauth- pam_console can now handle broken applications that do not set the PAM_TTY item. * Wed Apr 14 1999 Michael K. Johnson - fixed glob/regexp confusion in pam_console, added kbd and fixed fb devices- added pam_xauth module * Sun Apr 11 1999 Cristian Gafton - pam_lastlog does wtmp handling now * Fri Apr 09 1999 Michael K. Johnson - added option parsing to pam_console- added framebuffer devices to default console.perms settings * Thu Apr 08 1999 Cristian Gafton - fixed empty passwd handling in pam_pwdb * Tue Mar 30 1999 Michael K. Johnson - changed /dev/cdrom default user permissions back to 0600 in console.perms because some cdrom players open O_RDWR. * Fri Mar 26 1999 Michael K. Johnson - added /dev/jaz and /dev/zip to console.perms * Thu Mar 25 1999 Michael K. Johnson - changed the default user permissions for /dev/cdrom to 0400 in console.perms * Fri Mar 19 1999 Michael K. Johnson - fixed a few bugs in pam_console * Thu Mar 18 1999 Michael K. Johnson - pam_console authentication working- added /etc/security/console.apps directory * Mon Mar 15 1999 Michael K. Johnson - added pam_console files to filelist * Fri Feb 12 1999 Cristian Gafton - upgraded to 0.66, some source cleanups * Mon Dec 28 1998 Cristian Gafton - add patch from Savochkin Andrey Vladimirovich for umask security risk * Fri Dec 18 1998 Cristian Gafton - upgrade to ver 0.65- build the package out of internal CVS server | |