|
|
|
|
Changelog for openldap-servers-2.4.40-16.el6.i686.rpm :
* Tue Dec 06 2016 Matus Honek - 2.4.40-16- NSS: re-register NSS_Shutdown callback (#1071520) * Wed Nov 30 2016 Matus Honek - 2.4.40-15- ITS#8337 fix missing olcDbChecksum config attr (#1397961)- ITS#8003 fix off-by-one in LDIF length (#1397949) * Tue Nov 08 2016 Matus Honek - 2.4.40-14- NSS: use a hex number for some ciphersuite definitions (#1372357)- NSS: fix OpenLDAP crash in NSS shutdown handling (#1373222)- fix: rpm -V openldap-servers complains after a clean install (#1263220) * Tue Nov 01 2016 Matus Honek - 2.4.40-13- NSS: fix setting olcTLSProtocolMin (#1249092)- fix slapd crash in do_search (sc_writewait) (#1340861)- NSS: fix parsing code (#1372349) + refactor ciphers-related patches + fix cipherstring parsing- NSS: fix cipher suites\' definitions (#1372357) + fix some ciphers\' flags + add new ciphers to match the current NSS + add PSK and CHACHA20POLY1305 cipher strings * Mon Mar 21 2016 Matúš Honěk - 2.4.40-12- fix regression: Including AESGCM ciphers in DEFAULT cipher string breaks SSF (#1300701) * Tue Mar 08 2016 Matúš Honěk - 2.4.40-11- fix: OpenLDAP doesn\'t use sane (or default) cipher order (#1300701) + Add support for TLSv1.2, and SHA256 and SHA384 ciphers + Use what NSS considers default for DEFAULT cipher string. + Drop unnecessary hardcoded cipher suites\' default flags + Update with TLSv1.2 ciphers- revert: check_password minPoints parameter useless (#1255063) * Wed Jan 20 2016 Matúš Honěk - 2.4.40-10- fix: update description in slapd.conf for NSS database related options (#1131094)- fix: check_password minPoints parameter useless (#1255063) * Wed Jan 20 2016 Matúš Honěk - 2.4.40-9- fix: Bad log levels in check_password module (#1255046)- [rfe] add informational message about database backup when openldap is updated (#1261651)- fix: id_query option is not available after rebasing openldap to 2.4.39 (#1288545)- fix: We can\'t search expected entries from LDAP server (#1212283) * Tue Jan 19 2016 Matúš Honěk - 2.4.40-8- fix: slapd crash in do_search (#1257543)- Fix: Cannot build the package after libtool rebase (#1296129) * Tue Sep 29 2015 Matúš Honěk - 2.4.40-7- fix: regression: deadlock during SSL_ForceHandshake when getting connection to replica (#1263477) + apply (and modify a little) the patch from commit 1eeaeeb7 * Thu Sep 17 2015 Matúš Honěk - 2.4.40-6- CVE-2015-6908 openldap: ber_get_next denial of service vulnerability (#1263172) * Thu May 21 2015 Jan Synáček - 2.4.40-5- fix: nslcd segfaults due to incorrect mutex initialization (#1144294) * Tue Mar 24 2015 Jan Synáček - 2.4.40-4- fix: Updating openldap deletes database if slapd.conf is used (#1193519) * Fri Mar 20 2015 Jan Synáček - 2.4.40-3- fix: ppc64: slaptest segfault in openldap-2.4.40 (#1202696) * Mon Mar 09 2015 Jan Synáček - 2.4.40-2- fix: bring back accidentaly removed patch (#1147983) * Mon Mar 02 2015 Jan Synáček - 2.4.40-1- rebase to 2.4.40 (#1147983) * Wed Feb 25 2015 Jan Synáček - 2.4.39-11- fix: make /etc/openldap/check_password.conf readable by ldap (#1155390) * Mon Feb 02 2015 Jan Synáček - 2.4.39-10- revert previous patch (#1172296)- fix: crash in ldap_domain2hostlist when processing SRV record (#1164369)- support TLS 1.1 and later (#1160467)- enhancement: add ppolicy-check-password (#1155390) * Mon Jan 05 2015 Jan Synáček - 2.4.39-9- fix: prevent freed memory reuse (#1172296) * Wed Jun 18 2014 Jan Synáček - 2.4.39-8- fix: provide a shim libldif.so (#1110382) * Wed Jun 04 2014 Jan Synáček - 2.4.39-7- fix: remove correct tmp file when generating server cert (#1102083) * Tue Apr 22 2014 Jan Synáček - 2.4.39-6- remove unapplied patches * Tue Apr 22 2014 Jan Synáček - 2.4.39-5- fix: TLS_REQCERT documentation in client manpage (#1027796) * Thu Mar 27 2014 Jan Synáček - 2.4.39-4- review %configure and remove nonexistent options * Mon Mar 24 2014 Jan Synáček - 2.4.39-3- add another missing patch forgotten during the rebase- fix: enable dynamic linking - unresolved symbols in the smbk5pwd module * Tue Mar 18 2014 Jan Synáček - 2.4.39-2- add missing patches that were removed by mistake during the rebase * Thu Mar 13 2014 Jan Synáček - 2.4.39-1- rebase to 2.4.39 (#923680) + drop a lot of upstreamed patches, backport the rest + compile in mdb + remove automatic slapd.conf -> slapd-config conversion * Thu Jan 23 2014 Jan Synáček - 2.4.23-35- fix: segfault on certain queries with rwm overlay (#1003038) * Tue Jan 21 2014 Jan Synáček - 2.4.23-34- fix: deadlock during SSL_ForceHandshake (#996373) + revert nss-handshake-threadsafe.patch * Tue Feb 26 2013 Jan Synáček 2.4.23-32- fix: segfault in syncprov overlay (#910241)- fix: NSS related resource leak (#929358) * Wed Oct 31 2012 Jan Vcelak 2.4.23-31- fix update: libldap does not load PEM certificate if certdb is used as TLS_CACERTDIR (#859858) * Fri Oct 12 2012 Jan Vcelak 2.4.23-30- fix: slapd with rwm overlay segfault following ldapmodify (#864913) * Tue Sep 25 2012 Jan Vcelak 2.4.23-29- fix: invalid order of TLS shutdown operations (#818572)- fix: TLS error messages overwriting in tlsm_verify_cert() (#828787)- fix: reading pin from file can make all TLS connections hang (#829319)- fix: replication with TLS does not work (#707599)- fix: some TLS ciphers cannot be enabled (#852339)- fix: connection hangs after fallback to second server when certificate hostname verification fails (#843056)- fix: not all certificates in OpenSSL compatible CA certificate directory format are loaded (#811468)- fix: MozNSS certificate database in SQL format cannot be used (#857390)- fix: libldap does not load PEM certificate if certdb is used as TLS_CACERTDIR (#859858)- fix: do not send IPv6 DNS queries when IPv6 is disabled on the host (#835012)- fix: modification of olcSyncrepl attribute takes server out of MirrorMode (#821848) * Tue Jul 31 2012 Jan Vcelak 2.4.23-28- CVE-2012-2668 (#825875) + cipher suite selection by name can be ignored + default cipher suite is always selected * Mon Jul 30 2012 Jan Vcelak 2.4.23-27- fix: smbk5pwd module computes invalid LM hashes (#820278) * Mon May 07 2012 Jan Vcelak 2.4.23-26- fix: MozNSS CA cert dir does not work together with PEM CA cert file (#818844)- fix: memory leak: def_urlpre is not freed (#816168)- fix update: Default SSL certificate bundle is not found by openldap library (#742023) * Wed May 02 2012 Jan Vcelak 2.4.23-25- fix update: Default SSL certificate bundle is not found by openldap library (#742023) * Mon Apr 30 2012 Jan Vcelak 2.4.23-24- fix update: Default SSL certificate bundle is not found by openldap library (#742023)- fix: memberof overlay on the frontend database causes server segfault (#730745) * Fri Apr 20 2012 Jan Vcelak 2.4.23-23- security fix: CVE-2012-1164: assertion failure by processing search queries requesting only attributes for particular entry (#813162) * Tue Apr 10 2012 Jan Vcelak 2.4.23-22- fix: libraries leak memory when following referrals (#807363) * Thu Mar 01 2012 Jan Vcelak 2.4.23-21- fix: ldapsearch crashes with invalid parameters (#743781)- fix: replication (syncrepl) with TLS causes segfault (#783445)- fix: openldap server in MirrorMode sometimes fails to resync via syncrepl (#784211)- use portreserve to reserve LDAPS port (636/tcp+udp) (#790687)- fix: missing options in manual pages of client tools (#745470)- fix: SASL_NOCANON option missing in ldap.conf manual page (#732916)- fix: slapd segfaults when certificate key cannot be loaded (#796808)- Jan Synáček + fix: overlay constraint with count option work bad with modify operation (#742163) + fix: Default SSL certificate bundle is not found by openldap library (#742023) + fix: Duplicate close() calls in OpenLDAP (#784203) * Tue Oct 04 2011 Jan Vcelak 2.4.23-20- new feature update: honor priority/weight with ldap_domain2hostlist (#730311)- fix regression: openldap built without tcp_wrappers (#742592) * Tue Sep 13 2011 Jan Vcelak 2.4.23-19- fix: SSL_ForceHandshake function is not thread safe (#709407) * Fri Aug 26 2011 Jan Vcelak 2.4.23-18- fix: overlay refint option refint_nothing doesn\'t function correctly (#725479)- fix: Unwanted slash printed when installing openldap-servers (#732001)- manpage fix: TLS options in documentation are not valid for MozNSS (#684810)- fix: NSS_Init * functions are not thread safe (#731168)- manpage fix: errors in manual page slapo-unique (#723521) - new feature: honor priority/weight with ldap_domain2hostlist (#730311) * Mon Aug 15 2011 Jan Vcelak 2.4.23-17- fix: strict aliasing warnings during package build (#723487)- add partial RELRO support for libraries (#723999)- fix: incorrect behavior of allow/try options of VerifyCert and TLS_REQCERT (#729095)- fix: memleak - free the return of tlsm_find_and_verify_cert_key (#729087)- fix: TLS_REQCERT=never ignored when the certificate is expired (#722959)- fix: matching wildcard hostnames in certificate Subject field does not work (#726984)- fix: OpenLDAP server segfaults when using back-sql (#727533)- fix: conversion of constraint overlay settings to cn=config is incorrect (#722923)- fix: DDS overlay tolerance parametr doesn\'t function and breakes default TTL (#723514) * Mon Jul 18 2011 Jan Vcelak 2.4.23-16- fix: memleak in tlsm_auth_cert_handler (#717738)- fix: segmentation fault of client tool when LDIF input file is not terminated by a new line character (#698921)- fix: segmentation fault of client tool when input line in LDIF file is splitted but indented incorrectly (#701227)- fix: server scriptlets require initscripts package (#712358)- enable ldapi:/// interface by default- set cn=config management ACLs for root user, SASL external schema (#712494)- fix: ldapsearch fails if no CA certificate is available (#713525) * Wed Apr 13 2011 Jan Vcelak 2.4.23-15- fix: rpm -V fail when upgrading with openldap-devel installed (#693716) (remove devel *.so symlinks from /lib and leave them in /usr/lib) * Fri Mar 18 2011 Jan Vcelak 2.4.23-14- fix update: openldap startup script ignores ulimit settings (#679356)- fix update: openldap-servers upgrade hangs or do not upgrade the database (#685119) * Mon Mar 14 2011 Jan Vcelak 2.4.23-13- fix update: openldap can\'t use TLS after a fork() (#671553)- fix: possible NULL pointer dereferences in NSS non-blocking patch (#684035)- fix: move libldif to /lib for consistency (#548475)- fix: openldap-servers upgrade hangs or do not upgrade the database (#685119) * Tue Mar 01 2011 Jan Vcelak 2.4.23-12- fix: security - DoS when submitting special MODRDN request (#680975) * Mon Feb 28 2011 Jan Vcelak 2.4.23-11- fix: CVE-2011-1024 ppolicy forwarded bind failure messages cause success- fix: CVE-2011-1025 rootpw is not verified for ndb backend- fix: openldap startup script ignores ulimit settings (#679356)- fix: add symlinks into /usr/lib */ (#680139) * Mon Feb 21 2011 Jan Vcelak 2.4.23-10- fix: add symlinks for libraries moved in 2.4.23-5 to allow building packages which require these libraries in the old location (#678105) * Wed Feb 02 2011 Jan Vcelak 2.4.23-9- fix update: openldap can\'t use TLS after a fork() (#671553) * Tue Jan 25 2011 Jan Vcelak 2.4.23-8- fix: openldap can\'t use TLS after a fork() (#671553) * Thu Jan 20 2011 Jan Vcelak 2.4.23-7- fix: some server certificates refused with inadequate type error (#669846)- fix: default encryption strength dropped in switch to using NSS (#669845) * Thu Jan 13 2011 Jan Vcelak 2.4.23-6- fix update: openldap-devel symlinks to libraries were not moved correctly (#548475) * Thu Jan 13 2011 Jan Vcelak 2.4.23-5- initscript: slaptest with \'-u\' to skip database opening (#613966)- removed slurpd options from sysconfig/ldap- fix: verification of self issued certificates (#667795)- fix: move libraries from /usr/lib to /lib (#548475) * Sat Dec 04 2010 Jan Vcelak 2.4.23-4- rebase to 2.4.23 (Fedora 14) (#644077)- uses Mozilla NSS instead of OpenSSL for TLS/SSL- added LDIF (ldif.h) to the public API- removed embeded Berkeley DB- removed autofs schema (use up-to-date version from autofs package instead)- removed compat-openldap subpackage (use separate package instead)- fixes: ldapsearch -Z hangs server if starttls fails (#652823)- fixes: improve SSL/TLS log messages (#652819)- fixes: crash when TLS_CACERTDIR contains a subdirectory (#652817)- fixes: TLS_CACERTDIR takes precedence over TLS_CACERT (#652816)- fixes: openldap should ignore files not in the openssl c_hash format in cacertdir (#652814)- fixes: slapd init script gets stuck in an infinite loop (#644399)- fixes: Remove lastmod.la from default slapd.conf.bak (#630637)- fixes: Mozilla NSS - delay token auth until needed (#616558)- fixes: Mozilla NSS - support use of self signed CA certs as server certs (#616554) * Fri Jun 25 2010 Jan Zeleny - 2.4.19-15- fixed regression caused by tls accept patch (#608112) * Tue Jun 22 2010 Jan Zeleny - 2.4.19-14- fixed segfault issue in modrdn (#606369) * Fri Jun 18 2010 Jan Vcelak 2.4.19-13- implementation of ulimit settings for slapd (#602458) * Wed May 26 2010 Jan Zeleny - 2.4.19-12- updated man pages - only slaptest can convert configuration schema (#584787)- openldap compiled with -fno-strict-aliasing (#596193) * Thu May 06 2010 Jan Zeleny - 2.4.19-11- added compat package * Tue Apr 27 2010 Jan Zeleny - 2.4.19-10- updated overlay list in config file (#586143)- config dir slapd.d added to package payload (#585276)- init script now creates only symlink, not harldink, in /var/run (#584870) * Mon Apr 19 2010 Jan Zeleny - 2.4.19-9- fixed broken link /usr/sbin/slapschema (#583568)- removed some static libraries from openldap-devel (#583575) * Fri Apr 16 2010 Jan Zeleny - 2.4.19-8- updated spec file - clean files generated by configuration conversion (#582327) * Mon Mar 22 2010 Jan Zeleny - 2.4.19-7- updated usage line in init script- changed return code when calling init script with bad arguments * Mon Mar 22 2010 Jan Zeleny - 2.4.19-6- fixed segfault when using hdb backend (#575403) * Fri Mar 19 2010 Jan Zeleny - 2.4.19-5- minor corrections of init script (fedora bugs #571235, #570057, #573804) * Wed Feb 10 2010 Jan Zeleny - 2.4.19-4- removed syncprov.la from config file (#563472) * Wed Feb 03 2010 Jan Zeleny - 2.4.19-3- updated post scriptlet (#561352) * Mon Nov 23 2009 Jan Zeleny - 2.4.19-2- minor changes in init script * Wed Nov 18 2009 Jan Zeleny - 2.4.19-1- fixed tls connection accepting when TLSVerifyClient = allow- /etc/openldap/ldap.conf removed from files owned by openldap-servers- minor changes in spec file to supress warnings- some changes in init script, so it would be possible to use it when using old configuration style- rebased openldap to 2.4.19- rebased bdb to 4.8.24 * Wed Oct 07 2009 Jan Zeleny 2.4.18-5- updated smbk5pwd patch to be linked with libldap (#526500) * Wed Sep 30 2009 Jan Zeleny 2.4.18-4- buffer overflow patch from upstream- added /etc/openldap/slapd.d and /etc/openldap/slapd.conf.bak to files owned by openldap-servers * Thu Sep 24 2009 Jan Zeleny 2.4.18-3- cleanup of previous patch fixing buffer overflow * Tue Sep 22 2009 Jan Zeleny 2.4.18-2- changed configuration approach. Instead od slapd.conf slapd is using slapd.d directory now- fix of some issues caused by renaming of init script- fix of buffer overflow issue in ldif.c pointed out by new glibc * Fri Sep 18 2009 Jan Zeleny 2.4.18-1- rebase of openldap to 2.4.18 * Wed Sep 16 2009 Jan Zeleny 2.4.16-7- updated documentation (hashing the cacert dir) * Wed Sep 16 2009 Jan Zeleny 2.4.16-6- updated init script to be LSB-compliant (#523434)- init script renamed to slapd * Thu Aug 27 2009 Tomas Mraz - 2.4.16-5- rebuilt with new openssl * Tue Aug 25 2009 Jan Zeleny 2.4.16-4- updated %pre script to correctly install openldap group * Sat Jul 25 2009 Fedora Release Engineering - 2.4.16-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Wed Jul 01 2009 Jan Zeleny 2.4.16-1- rebase of openldap to 2.4.16- fixed minor issue in spec file (output looking interactive when installing servers) * Tue Jun 09 2009 Jan Zeleny 2.4.15-4- added $SLAPD_URLS variable to init script (#504504) * Thu Apr 09 2009 Jan Zeleny 2.4.15-3- extended previous patch (#481310) to remove options cfMP from some client tools- correction of patch setugid (#494330) * Thu Mar 26 2009 Jan Zeleny 2.4.15-2- removed -f option from some client tools (#481310) * Wed Feb 25 2009 Jan Safranek 2.4.15-1- new upstream release * Tue Feb 17 2009 Jan Safranek 2.4.14-1- new upstream release- upgraded to db-4.7.25 * Sat Jan 17 2009 Tomas Mraz 2.4.12-3- rebuild with new openssl * Mon Dec 15 2008 Caolán McNamara 2.4.12-2- rebuild for libltdl, i.e. copy config.sub|guess from new location * Wed Oct 15 2008 Jan Safranek 2.4.12-1- new upstream release * Mon Oct 13 2008 Jan Safranek 2.4.11-3- add SLAPD_SHUTDOWN_TIMEOUT to /etc/sysconfig/ldap, allowing admins to set non-default slapd shutdown timeout- add checkpoint to default slapd.conf file (#458679) * Mon Sep 01 2008 Jan Safranek 2.4.11-2- provide ldif2ldbm functionality for migrationtools- rediff all patches to get rid of patch fuzz * Mon Jul 21 2008 Jan Safranek 2.4.11-1- new upstream release- apply official bdb-4.6.21 patches * Wed Jul 02 2008 Jan Safranek 2.4.10-2- fix CVE-2008-2952 (#453728) * Thu Jun 12 2008 Jan Safranek 2.4.10-1- new upstream release * Wed May 28 2008 Jan Safranek 2.4.9-5- use /sbin/nologin as shell of ldap user (#447919) * Tue May 13 2008 Jan Safranek 2.4.9-4- new upstream release- removed unnecessary MigrationTools patches * Thu Apr 10 2008 Jan Safranek 2.4.8-4- bdb upgraded to 4.6.21- reworked upgrade logic again to run db_upgrade when bdb version changes * Wed Mar 05 2008 Jan Safranek 2.4.8-3- reworked the upgrade logic, slapcat/slapadd of the whole database is needed only if minor version changes (2.3.x -> 2.4.y)- do not try to save database in LDIF format, if openldap-servers package is being removed (it\'s up to the admin to do so manually) * Thu Feb 28 2008 Jan Safranek 2.4.8-2- migration tools carved out to standalone package \"migrationtools\" (#236697) * Fri Feb 22 2008 Jan Safranek 2.4.8-1- new upstream release * Fri Feb 08 2008 Jan Safranek 2.4.7-7- fix CVE-2008-0658 (#432014) * Mon Jan 28 2008 Jan Safranek 2.4.7-6- init script fixes * Mon Jan 28 2008 Jan Safranek 2.4.7-5- init script made LSB-compliant (#247012) * Fri Jan 25 2008 Jan Safranek 2.4.7-4- fixed rpmlint warnings and errors - /etc/openldap/schema/README moved to /usr/share/doc/openldap * Tue Jan 22 2008 Jan Safranek 2.4.7-3- obsoleting compat-openldap properly again :) * Tue Jan 22 2008 Jan Safranek 2.4.7-2- obsoleting compat-openldap properly (#429591) * Mon Jan 14 2008 Jan Safranek 2.4.7-1- new upstream version (openldap-2.4.7) * Mon Dec 03 2007 Jan Safranek 2.4.6-1- new upstream version (openldap-2.4)- deprecating compat- package * Mon Nov 05 2007 Jan Safranek 2.3.39-1- new upstream release * Tue Oct 23 2007 Jan Safranek 2.3.38-4- fixed multilib issues - all platform independent files have the same content now (#342791) * Thu Oct 04 2007 Jan Safranek 2.3.38-3- BDB downgraded back to 4.4.20 because 4.6.18 is not supported by openldap (#314821) * Mon Sep 17 2007 Jan Safranek 2.3.38-2- skeleton /etc/sysconfig/ldap added- new SLAPD_LDAP option to turn off listening on ldap:/// (#292591)- fixed checking of SSL (#292611)- fixed upgrade with empty database * Thu Sep 06 2007 Jan Safranek 2.3.38-1- new upstream version- added images to the guide.html (#273581) * Wed Aug 22 2007 Jan Safranek 2.3.37-3- just rebuild * Thu Aug 02 2007 Jan Safranek 2.3.37-2- do not use specific automake and autoconf- do not distinguish between NPTL and non-NPTL platforms, we have NPTL everywhere- db-4.6.18 integrated- updated openldap-servers License: field to reference BDB license * Tue Jul 31 2007 Jan Safranek 2.3.37-1- new upstream version * Fri Jul 20 2007 Jan Safranek 2.3.34-7- MigrationTools-47 integrated * Wed Jul 04 2007 Jan Safranek 2.3.34-6- fix compat-slapcat compilation. Now it can be found in /usr/lib/compat-openldap/slapcat, because the tool checks argv[0] (#246581) * Fri Jun 29 2007 Jan Safranek 2.3.34-5- smbk5pwd added (#220895)- correctly distribute modules between servers and servers-sql packages * Mon Jun 25 2007 Jan Safranek 2.3.34-4- Fix initscript return codes (#242667)- Provide overlays (as modules; #246036, #245896)- Add available modules to config file * Tue May 22 2007 Jan Safranek 2.3.34-3- do not create script in /tmp on startup (bz#188298)- add compat-slapcat to openldap-compat (bz#179378)- do not import ddp services with migrate_services.pl (bz#201183)- sort the hosts by adders, preventing duplicities in migrate *nis *.pl (bz#201540)- start slupd for each replicated database (bz#210155)- add ldconfig to devel post/postun (bz#240253)- include misc.schema in default slapd.conf (bz#147805) * Mon Apr 23 2007 Jan Safranek 2.3.34-2- slapadd during package update is now quiet (bz#224581)- use _localstatedir instead of var/ during build (bz#220970)- bind-libbind-devel removed from BuildRequires (bz#216851)- slaptest is now quiet during service ldap start, if there is no error/warning (bz#143697)- libldap_r.so now links with pthread (bz#198226)- do not strip binaries to produce correct .debuginfo packages (bz#152516) * Mon Feb 19 2007 Jay Fenlason 2.3.34-1- New upstream release- Upgrade the scripts for migrating the database so that they might actually work.- change bind-libbind-devel to bind-devel in BuildPreReq * Mon Dec 04 2006 Thomas Woerner 2.3.30-1.1- tcp_wrappers has a new devel and libs sub package, therefore changing build requirement for tcp_wrappers to tcp_wrappers-devel * Wed Nov 15 2006 Jay Fenlason 2.3.30-1- New upstream version * Wed Oct 25 2006 Jay Fenlason 2.3.28-1- New upstream version * Sun Oct 01 2006 Jesse Keating - 2.3.27-4- rebuilt for unwind info generation, broken in gcc-4.1.1-21 * Mon Sep 18 2006 Jay Fenlason 2.3.27-3- Include --enable-multimaster to close bz#185821: adding slapd_multimaster to the configure options- Upgade guide.html to the correct one for openladp-2.3.27, closing bz#190383: openldap 2.3 packages contain the administrator\'s guide for 2.2- Remove the quotes from around the slaptestflags in ldap.init This closes one part of bz#204593: service ldap fails after having added entries to ldap- include __db. * in the list of files to check ownership of in ldap.init, as suggested in bz#199322: RFE: perform cleanup in ldap.init * Fri Aug 25 2006 Jay Fenlason 2.3.27-2- New upstream release- Include the gethostbyname_r patch so that nss_ldap won\'t hang on recursive attemts to ldap_initialize. * Wed Jul 12 2006 Jesse Keating - 2.3.24-2.1- rebuild * Wed Jun 07 2006 Jay Fenlason 2.3.24-2- New upstream version * Thu Apr 27 2006 Jay Fenlason 2.3.21-2- Upgrade to 2.3.21- Add two upstream patches for db-4.4.20 * Mon Feb 13 2006 Jay Fenlason 2.3.19-4- Re-fix ldap.init * Fri Feb 10 2006 Jesse Keating - 2.3.19-3.1- bump again for double-long bug on ppc(64) * Thu Feb 09 2006 Jay Fenlason 2.3.19-3- Modify the ldap.init script to call runuser correctly. * Tue Feb 07 2006 Jesse Keating - 2.3.19-2.1- rebuilt for new gcc4.1 snapshot and glibc changes * Tue Jan 10 2006 Jay Fenlason 2.3.19-2- Upgrade to 2.3.19, which upstream now considers stable- Modify the -config.patch, ldap.init, and this spec file to put the pid file and args file in an ldap-owned openldap subdirectory under /var/run.- Move back_sql * out of _sbindir/openldap , which requires hand-moving slapd and slurpd to _sbindir, and recreating symlinks by hand.- Retire openldap-2.3.11-ads.patch, which went upstream.- Update the ldap.init script to run slaptest as the ldap user rather than as root. This solves bz#150172 Startup failure after database problem- Add to the servers post and preun scriptlets so that on preun, the database is slapcatted to /var/lib/ldap/upgrade.ldif and the database files are saved to /var/lib/ldap/rpmorig. On post, if /var/lib/ldap/upgrade.ldif exists, it is slapadded. This means that on upgrades from 2.3.16-2 to higher versions, the database files may be automatically upgraded. Unfortunatly, because of the changes to the preun scriptlet, users have to do the slapcat, etc by hand when upgrading to 2.3.16-2. Also note that the /var/lib/ldap/rpmorig files need to be removed by hand because automatically removing your emergency fallback files is a bad idea.- Upgrade internal bdb to db-4.4.20. For a clean upgrade, this will require that users slapcat their databases into a temp file, move /var/lib/ldap someplace safe, upgrade the openldap rpms, then slapadd the temp file. * Fri Dec 09 2005 Jesse Keating - rebuilt * Mon Nov 21 2005 Jay Fenlason 2.3.11-3- Remove Requires: cyrus-sasl and cyrus-sasl-md5 from openldap- and compat-openldap- to close bz#173313 Remove exlicit \'Requires: cyrus-sasl\" + \'Requires: cyrus-sasl-md5\' * Thu Nov 10 2005 Jay Fenlason 2.3.11-2- Upgrade to 2.3.11, which upstream now considers stable.- Switch compat-openldap to 2.2.29- remove references to nss_ldap_build from the spec file- remove references to 2.0 and 2.1 from the spec file.- reorganize the build() function slightly in the spec file to limit the number of redundant and conflicting options passedto configure.- Remove the attempt to hardlink ldapmodify and ldapadd together, since the current make install make ldapadd a symlink to ldapmodify.- Include the -ads patches to allow SASL binds to an Active Directory server to work. Nalin wrote the patch, based on my broken first attempt. * Thu Nov 10 2005 Tomas Mraz 2.2.29-3- rebuilt against new openssl * Mon Oct 10 2005 Jay Fenlason 2.2.29-2- New upstream version. * Thu Sep 29 2005 Jay Fenlason 2.2.28-2- Upgrade to nev upstream version. This makes the 2.2. *-hop patch obsolete. * Mon Aug 22 2005 Jay Fenlason 2.2.26-2- Move the slapd.pem file to /etc/pki/tls/certs and edit the -config patch to match to close bz#143393 Creates certificates + keys at an insecure/bad place- also use _sysconfdir instead of hard-coding /etc * Thu Aug 11 2005 Jay Fenlason - Add the tls-fix-connection-test patch to close bz#161991 openldap password disclosure issue- add the hop patches to prevent infinite looping when chasing referrals. OpenLDAP ITS #3578 * Fri Aug 05 2005 Nalin Dahyabhai - fix typo in ldap.init (call $klist instead of klist, from Charles Lopes) * Thu May 19 2005 Nalin Dahyabhai 2.2.26-1- run slaptest with the -u flag if no id2entry db files are found, because you can\'t check for read-write access to a non-existent database (#156787)- add _sysconfdir/openldap/cacerts, which authconfig sets as the TLS_CACERTDIR path in /etc/openldap/ldap.conf now- use a temporary wrapper script to launch slapd, in case we have arguments with embedded whitespace (#158111) * Wed May 04 2005 Nalin Dahyabhai - update to 2.2.26 (stable 20050429)- enable the lmpasswd scheme- print a warning if slaptest fails, slaptest -u succeeds, and one of the directories listed as the storage location for a given suffix in slapd.conf contains a readable file named __db.001 (#118678) * Tue Apr 26 2005 Nalin Dahyabhai 2.2.25-1- update to 2.2.25 (release) * Tue Apr 26 2005 Nalin Dahyabhai 2.2.24-1- update to 2.2.24 (stable 20050318)- export KRB5_KTNAME in the init script, in case it was set in the sysconfig file but not exported * Tue Mar 01 2005 Nalin Dahyabhai 2.2.23-4- prefer libresolv to libbind * Tue Mar 01 2005 Nalin Dahyabhai 2.2.23-3- add bind-libbind-devel and libtool-ltdl-devel buildprereqs * Tue Mar 01 2005 Tomas Mraz 2.2.23-2- rebuild with openssl-0.9.7e * Mon Jan 31 2005 Nalin Dahyabhai 2.2.23-1- update to 2.2.23 (stable-20050125)- update notes on upgrading from earlier versions- drop slapcat variations for 2.0/2.1, which choke on 2.2\'s config files * Tue Jan 04 2005 Nalin Dahyabhai 2.2.20-1- update to 2.2.20 (stable-20050103)- warn about unreadable krb5 keytab files containing \"ldap\" keys- warn about unreadable TLS-related files- own a ref to subdirectories which we create under _libdir/tls * Tue Nov 02 2004 Nalin Dahyabhai 2.2.17-0- rebuild * Thu Sep 30 2004 Nalin Dahyabhai - update to 2.2.17 (stable-20040923) (#135188)- move nptl libraries into arch-specific subdirectories on x86 boxes- require a newer glibc which can provide nptl libpthread on i486/i586 * Tue Aug 24 2004 Nalin Dahyabhai - move slapd startup to earlier in the boot sequence (#103160)- update to 2.2.15 (stable-20040822)- change version number on compat-openldap to include the non-compat version from which it\'s compiled, otherwise would have to start 2.2.15 at release 3 so that it upgrades correctly * Thu Aug 19 2004 Nalin Dahyabhai 2.2.13-2- build a separate, static set of libraries for openldap-devel with the non-standard ntlm bind patch applied, for use by the evolution-connector package (#125579), and installing them under evolution_connector_prefix)- provide openldap-evolution-devel = version-release in openldap-devel so that evolution-connector\'s source package can require a version of openldap-devel which provides what it wants * Mon Jul 26 2004 Nalin Dahyabhai - update administrator guide * Wed Jun 16 2004 Nalin Dahyabhai 2.2.13-1- add compat-openldap subpackage- default to bdb, as upstream does, gambling that we\'re only going to be on systems with nptl now * Tue Jun 15 2004 Nalin Dahyabhai 2.2.13-0- preliminary 2.2.13 update- move ucdata to the -servers subpackage where it belongs * Tue Jun 15 2004 Nalin Dahyabhai 2.1.30-1- build experimental sql backend as a loadable module * Tue Jun 15 2004 Elliot Lee - rebuilt * Tue May 18 2004 Nalin Dahyabhai 2.1.30-0- update to 2.1.30 * Thu May 13 2004 Thomas Woerner 2.1.29-3- removed rpath- added pie patch: slapd and slurpd are now pie- requires libtool >= 1.5.6-2 (PIC libltdl.a) * Fri Apr 16 2004 Nalin Dahyabhai 2.1.29-2- move rfc documentation from main to -devel (#121025) * Wed Apr 14 2004 Nalin Dahyabhai 2.1.29-1- rebuild * Tue Apr 06 2004 Nalin Dahyabhai 2.1.29-0- update to 2.1.29 (stable 20040329) * Mon Mar 29 2004 Nalin Dahyabhai - don\'t build servers with --with-kpasswd, that option hasn\'t been recognized since 2.1.23 * Tue Mar 02 2004 Elliot Lee 2.1.25-5.1- rebuilt * Mon Feb 23 2004 Tim Waugh 2.1.25-5- Use \':\' instead of \'.\' as separator for chown. * Fri Feb 13 2004 Elliot Lee - rebuilt * Tue Feb 10 2004 Nalin Dahyabhai 2.1.25-4- remove \'reload\' from the init script -- it never worked as intended (#115310) * Wed Feb 04 2004 Nalin Dahyabhai 2.1.25-3- commit that last fix correctly this time * Tue Feb 03 2004 Nalin Dahyabhai 2.1.25-2- fix incorrect use of find when attempting to detect a common permissions error in the init script (#114866) * Fri Jan 16 2004 Nalin Dahyabhai - add bug fix patch for DB 4.2.52 * Thu Jan 08 2004 Nalin Dahyabhai 2.1.25-1- change logging facility used from daemon to local4 (#112730, reversing #11047) BEHAVIOR CHANGE - SHOULD BE MENTIONED IN THE RELEASE NOTES. * Wed Jan 07 2004 Nalin Dahyabhai - incorporate fix for logic quasi-bug in slapd\'s SASL auxprop code (Dave Jones) * Thu Dec 18 2003 Nalin Dahyabhai - update to 2.1.25, now marked STABLE * Thu Dec 11 2003 Jeff Johnson 2.1.22-9- update to db-4.2.52. * Thu Oct 23 2003 Nalin Dahyabhai 2.1.22-8- add another section to the ABI note for the TLS libdb so that it\'s marked as not needing an executable stack (from Arjan Van de Ven) * Thu Oct 16 2003 Nalin Dahyabhai 2.1.22-7- force bundled libdb to not use O_DIRECT by making it forget that we have it * Wed Oct 15 2003 Nalin Dahyabhai - build bundled libdb for slapd dynamically to make the package smaller, among other things- on tls-capable arches, build libdb both with and without shared posix mutexes, otherwise just without- disable posix mutexes unconditionally for db 4.0, which shouldn\'t need them for the migration cases where it\'s used- update to MigrationTools 45 * Thu Sep 25 2003 Jeff Johnson 2.1.22-6.1- upgrade db-4.1.25 to db-4.2.42. * Fri Sep 12 2003 Nalin Dahyabhai 2.1.22-6- drop rfc822-MailMember.schema, merged into upstream misc.schema at some point * Wed Aug 27 2003 Nalin Dahyabhai - actually require newer libtool, as was intended back in 2.1.22-0, noted as missed by Jim Richardson * Fri Jul 25 2003 Nalin Dahyabhai 2.1.22-5- enable rlookups, they don\'t cost anything unless also enabled in slapd\'s configuration file * Tue Jul 22 2003 Nalin Dahyabhai 2.1.22-4- rebuild * Thu Jul 17 2003 Nalin Dahyabhai 2.1.22-3- rebuild * Wed Jul 16 2003 Nalin Dahyabhai 2.1.22-2- rebuild * Tue Jul 15 2003 Nalin Dahyabhai 2.1.22-1- build * Mon Jul 14 2003 Nalin Dahyabhai 2.1.22-0- 2.1.22 now badged stable- be more aggressive in what we index by default- use/require libtool 1.5 * Mon Jun 30 2003 Nalin Dahyabhai - update to 2.1.22 * Wed Jun 04 2003 Elliot Lee - rebuilt * Tue Jun 03 2003 Nalin Dahyabhai 2.1.21-1- update to 2.1.21- enable ldap, meta, monitor, null, rewrite in slapd * Mon May 19 2003 Nalin Dahyabhai 2.1.20-1- update to 2.1.20 * Thu May 08 2003 Nalin Dahyabhai 2.1.19-1- update to 2.1.19 * Mon May 05 2003 Nalin Dahyabhai 2.1.17-1- switch to db with crypto * Fri May 02 2003 Nalin Dahyabhai - install the db utils for the bundled libdb as %{_sbindir}/slapd_db_ *- install slapcat/slapadd from 2.0.x for migration purposes * Wed Apr 30 2003 Nalin Dahyabhai - update to 2.1.17- disable the shell backend, not expected to work well with threads- drop the kerberosSecurityObject schema, the krbName attribute it contains is only used if slapd is built with v2 kbind support * Mon Feb 10 2003 Nalin Dahyabhai 2.0.27-8- back down to db 4.0.x, which 2.0.x can compile with in ldbm-over-db setups- tweak SuSE patch to fix a few copy-paste errors and a NULL dereference * Wed Jan 22 2003 Tim Powers - rebuilt * Tue Jan 07 2003 Nalin Dahyabhai 2.0.27-6- rebuild * Mon Dec 16 2002 Nalin Dahyabhai 2.0.27-5- rebuild * Fri Dec 13 2002 Nalin Dahyabhai 2.0.27-4- check for setgid as well * Thu Dec 12 2002 Nalin Dahyabhai 2.0.27-3- rebuild * Thu Dec 12 2002 Nalin Dahyabhai - incorporate fixes from SuSE\'s security audit, except for fixes to ITS 1963, 1936, 2007, 2009, which were included in 2.0.26.- add two more patches for db 4.1.24 from sleepycat\'s updates page- use openssl pkgconfig data, if any is available * Mon Nov 11 2002 Nalin Dahyabhai 2.0.27-2- add patches for db 4.1.24 from sleepycat\'s updates page * Mon Nov 04 2002 Nalin Dahyabhai - add a sample TLSCACertificateFile directive to the default slapd.conf * Tue Sep 24 2002 Nalin Dahyabhai 2.0.27-1- update to 2.0.27 * Fri Sep 20 2002 Nalin Dahyabhai 2.0.26-1- update to 2.0.26, db 4.1.24.NC * Fri Sep 13 2002 Nalin Dahyabhai 2.0.25-2- change LD_FLAGS to refer to /usr/kerberos/_libdir instead of /usr/kerberos/lib, which might not be right on some arches * Mon Aug 26 2002 Nalin Dahyabhai 2.0.25-1- update to 2.0.25 \"stable\", ldbm-over-gdbm (putting off migration of LDBM slapd databases until we move to 2.1.x)- use %{_smp_mflags} when running make- update to MigrationTools 44- enable dynamic module support in slapd * Thu May 16 2002 Nalin Dahyabhai 2.0.23-5- rebuild in new environment * Wed Feb 20 2002 Nalin Dahyabhai 2.0.23-3- use the gdbm backend again * Mon Feb 18 2002 Nalin Dahyabhai 2.0.23-2- make slapd.conf read/write by root, read by ldap * Sun Feb 17 2002 Nalin Dahyabhai - fix corner case in sendbuf fix- 2.0.23 now marked \"stable\" * Tue Feb 12 2002 Nalin Dahyabhai 2.0.23-1- update to 2.0.23 * Fri Feb 08 2002 Nalin Dahyabhai 2.0.22-2- switch to an internalized Berkeley DB as the ldbm back-end (NOTE: this breaks access to existing on-disk directory data)- add slapcat/slapadd with gdbm for migration purposes- remove Kerberos dependency in client libs (the direct Kerberos dependency is used by the server for checking {kerberos} passwords) * Fri Feb 01 2002 Nalin Dahyabhai 2.0.22-1- update to 2.0.22 * Sat Jan 26 2002 Florian La Roche 2.0.21-5- prereq chkconfig for server subpackage * Fri Jan 25 2002 Nalin Dahyabhai 2.0.21-4- update migration tools to version 40 * Wed Jan 23 2002 Nalin Dahyabhai 2.0.21-3- free ride through the build system * Wed Jan 16 2002 Nalin Dahyabhai 2.0.21-2- update to 2.0.21, now earmarked as STABLE * Wed Jan 16 2002 Nalin Dahyabhai 2.0.20-2- temporarily disable optimizations for ia64 arches- specify pthreads at configure-time instead of letting configure guess * Mon Jan 14 2002 Nalin Dahyabhai - and one for Raw Hide * Mon Jan 14 2002 Nalin Dahyabhai 2.0.20-0.7- build for RHL 7/7.1 * Mon Jan 14 2002 Nalin Dahyabhai 2.0.20-1- update to 2.0.20 (security errata) * Thu Dec 20 2001 Nalin Dahyabhai 2.0.19-1- update to 2.0.19 * Tue Nov 06 2001 Nalin Dahyabhai 2.0.18-2- fix the commented-out replication example in slapd.conf * Fri Oct 26 2001 Nalin Dahyabhai 2.0.18-1- update to 2.0.18 * Mon Oct 15 2001 Nalin Dahyabhai 2.0.17-1- update to 2.0.17 * Wed Oct 10 2001 Nalin Dahyabhai - disable kbind support (deprecated, and I suspect unused)- configure with --with-kerberos=k5only instead of --with-kerberos=k5- build slapd with threads * Thu Sep 27 2001 Nalin Dahyabhai 2.0.15-2- rebuild, 2.0.15 is now designated stable * Fri Sep 21 2001 Nalin Dahyabhai 2.0.15-1- update to 2.0.15 * Mon Sep 10 2001 Nalin Dahyabhai 2.0.14-1- update to 2.0.14 * Fri Aug 31 2001 Nalin Dahyabhai 2.0.12-1- update to 2.0.12 to pull in fixes for setting of default TLS options, among other things- update to migration tools 39- drop tls patch, which was fixed better in this release * Tue Aug 21 2001 Nalin Dahyabhai 2.0.11-13- install saucer correctly * Thu Aug 16 2001 Nalin Dahyabhai - try to fix ldap_set_options not being able to set global options related to TLS correctly | |