mblaha / rpms / krb5

Forked from rpms/krb5 11 months ago
Clone

0b340d0 New upstream version (1.21)

Authored and Committed by jrische a year ago
24 files changed. 768 lines added. 2176 lines removed.
.gitignore
file modified
+2 -0
0001-downstream-ksu-pam-integration.patch
file modified
+5 -5
0002-downstream-SELinux-integration.patch
file modified
+19 -19
0003-downstream-fix-debuginfo-with-y.tab.c.patch
file modified
+2 -2
0004-downstream-Remove-3des-support.patch
file modified
+88 -84
0005-downstream-FIPS-with-PRNG-and-RADIUS-and-MD4.patch
file modified
+4 -4
0006-downstream-Allow-krad-UDP-TCP-localhost-connection-w.patch
file modified
+3 -4
0007-Add-configure-variable-for-default-PKCS-11-module.patch
file removed
-201
0007-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch
file renamed
+2 -2
0008-Set-reasonable-supportedCMSTypes-in-PKINIT.patch
file removed
-159
0008-downstream-Include-missing-OpenSSL-FIPS-header.patch0014-downstream-Include-missing-OpenSSL-FIPS-header.patch
file renamed
+2 -2
0009-Simplify-plugin-loading-code.patch
file removed
-622
0009-downstream-Do-not-set-root-as-ksu-file-owner.patch0015-downstream-Do-not-set-root-as-ksu-file-owner.patch
file renamed
+2 -2
0010-Update-error-checking-for-OpenSSL-CMS_verify.patch
file removed
-48
0010-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch
file renamed
+2 -2
0011-downstream-Allow-to-set-PAC-ticket-signature-as-opti.patch
file added
+279
0011-downstream-Catch-SHA-1-digest-disallowed-error-for-P.patch
file removed
-28
0012-Add-and-use-ts_interval-helper.patch
file removed
-239
0012-downstream-Make-PKINIT-CMS-SHA-1-signature-verificat.patch
file added
+47
0013-Enable-PKINIT-if-at-least-one-group-is-available.patch
file added
+218
0017-Add-PAC-full-checksums.patch
file removed
-672
krb5-tests
file modified
+4 -1
krb5.spec
file modified
+87 -78
sources
file modified
+2 -2
    New upstream version (1.21)
    
    Do not disable PKINIT if some of the well-known DH groups are unavailable
      Resolves: rhbz#2214297
    Make PKINIT CMS SHA-1 signature verification available in FIPS mode
      Resolves: rhbz#2214300
    Allow to set PAC ticket signature as optional
      Resolves: rhbz#2181311
    Add support for MS-PAC extended KDC signature (CVE-2022-37967)
      Resolves: rhbz#2166001
    Fix syntax error in aclocal.m4
      Resolves: rhbz#2143306
    
    Signed-off-by: Julien Rische <jrische@redhat.com>
    
        
file modified
+2 -0
0007-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch 0013-downstream-Make-tests-compatible-with-sssd_krb5_loca.patch
file renamed
+2 -2
0008-downstream-Include-missing-OpenSSL-FIPS-header.patch 0014-downstream-Include-missing-OpenSSL-FIPS-header.patch
file renamed
+2 -2
0009-downstream-Do-not-set-root-as-ksu-file-owner.patch 0015-downstream-Do-not-set-root-as-ksu-file-owner.patch
file renamed
+2 -2
0010-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch 0016-downstream-Allow-KRB5KDF-MD5-and-MD4-in-FIPS-mode.patch
file renamed
+2 -2
file modified
+4 -1
file modified
+87 -78
file modified
+2 -2