summaryrefslogtreecommitdiff
path: root/usr/src/lib/gss_mechs
AgeCommit message (Collapse)AuthorFilesLines
2009-12-286885561 Unable to verify PAC server's signature in Windows 2008 domain w/ ↵Shawn Emery1-4/+10
2003 domain functional level
2009-11-096899293 Use of uninitialized variable in krb5_sname_to_principal on error pathMark Phalan1-2/+3
2009-11-096898348 'idmapd' core reported with thread 'ad_disc_get_DomainController'Mark Phalan1-1/+1
2009-11-106565115 Bug in krb5_get_credentials_core() functionMark Phalan1-6/+16
2009-11-126885980 Need case-insensitive keytab lookups for MS interopShawn Emery6-26/+120
6885387 gsskrb5_extract_authz_data_from_sec_context() fails with service ticket sent by Windows 7 client 6858400 kclient cant join Windows AD domain if hostname is 20 characters or longer 6867203 Solaris acceptors fail in Windows 2000 environment 6868908 Solaris acceptors should have returned KRB5KRB_AP_ERR_MODIFIED for Microsoft interoperability 6867208 Windows client cannot recover from KRB5KRB_AP_ERR_SKEW error
2009-10-126887388 New SPNEGO features for CIFS are DOAGlenn Barry1-23/+23
6888759 EXPORT_SRC build broken after push of CR 6808598
2009-09-21PSARC 2009/418 Kerberos V5 PAC APIGlenn Barry33-4607/+8867
6283931 SPNEGO needs to follow latest RFC 6808598 krb5 APIs needed to create and parse PAC data 6817447 libgss and various mechs are hiding both the real minor_status and the error token
2009-07-296864230 hiho, hiho, it'ch chtime for CH to gojmcp1-1/+0
Portions contributed by Rich Lowe
2009-06-026802931 krb5 nfs allows access to shares without credentials by symlinking ↵Peter Shoults1-3/+4
to someone else's cred cache 6840235 Some slight changes need to be made to gssd_getuid.c to be more readable
2009-05-196822062 multiple vulnerabilities in SPNEGO, ASN.1 decoder (CVE-2009-0847, ↵Peter Shoults3-44/+44
CVE-2009-0845, CVE-2009-0844) 6822066 ASN.1 decoder frees uninitialized pointer (CVE-2009-0846)
2009-02-266801333 mech_krb5 is using deprecated libresolv functions which are not MT safe1-1/+2
2009-02-116777148 idmap fails to auto-discover AD due to ldap_sasl_bind failure6-9/+172
2009-02-106798660 Cadmium .NOT file processing problem with CWD relative file pathsAli Bahrami8-63/+121
Contributed by Richard Lowe 6785284 Mapfile versioning rules need to be more visible to gatelings 6800164 Standard file exclusion mechanism needed for Cadmium tools
2008-12-116782682 krb5_recvauth() should return NULL for auth_context on failure1-1/+3
2009-01-14PSARC 2008/778 asprintf, vasprintfRoger A. Faulkner1-2/+3
4508459 Solaris should have asprintf() and vasprintf() functions
2008-10-296704459 assert defined in k5-thread.h produces number of false positives1-2/+2
2008-10-276756312 krb5int_pbkdf2_hmac_sha1() should not call C_DestroyObject() after ↵1-7/+6
C_GenerateKey() fails
2008-10-246756928 Kerberos incorrectly displays the error message "krb5 conf file not ↵1-5/+4
configured"
2008-10-24PSARC/2008/631 Kerberos PKINITMark Phalan194-5098/+11521
PSARC/2008/358 removal of kadm5.keytab 6698059 Resync with mit 1.6.3 (pkinit) 6749302 pam_krb5 auth fails with key table entry not found
2008-09-08Contributed by Palle Lyckegaard <palle@lyckegaard.dk>John Sonnenschein4-28/+16
4930079 many Makefiles redefine "CP", causing problems for incrementals
2008-09-046736781 Memory leak in mech_krb5.so.1 when obtaining FQHN for comparison to ↵Peter Shoults1-20/+20
host principal
2008-06-066523785 kerberos unseal from buggy client causes a coresemery1-1/+2
6663377 krb5int_dns_init() doesn't initialize __res_state structure 6704617 kclient needs cleanup and occasionally hangs during join when a DC is down within the domain
2008-05-276692336 ktkt_warnd(1M) client code should be a librarygtb1-0/+2
2008-05-026683064 check_rtime could do with some spring cleaningrie1-3/+5
2008-05-016516568 Warning messages still being displayed on krb ccache ownershipgtb3-30/+109
6574888 Principals using delegated credentials are not being registered with ktkt_warnd for auto-renewal 6689008 kwarn_add_warning should not output errors to stderr
2008-04-136245750 kadmin "Bad encryption type" error should state the enctypemp1537395-15/+151
6658621 Configuration checks for kerberos daemons should be done by the daemons themselves 6658624 Missing error strings for new kerberos DB error types 6658627 kpropd should use its executable name and not the full path when logging error messages 6658631 error messages in kerberos deamons need cleanup 6664832 various memleaks in krb libs --HG-- rename : usr/src/cmd/krb5/kadmin/server/svc-kdc.master => deleted_files/usr/src/cmd/krb5/kadmin/server/svc-kdc.master rename : usr/src/cmd/krb5/krb5kdc/svc-kdc => deleted_files/usr/src/cmd/krb5/krb5kdc/svc-kdc rename : usr/src/cmd/krb5/slave/svc-kdc.slave => deleted_files/usr/src/cmd/krb5/slave/svc-kdc.slave rename : usr/src/cmd/svc/shell/krb_include.sh => deleted_files/usr/src/cmd/svc/shell/krb_include.sh
2008-01-256604635 kdb ldap integration removed rev/recurse kdb5_util dumpswillf1-2/+4
6620943 ktadd fails for principal with history when using ldap plugin
2008-01-146634436 XFFLAG should be updated.rie5-7/+17
2008-01-146644742 kadmind cores when using an 'afs3' salt and password > 8 charsmp1537392-11/+23
6647708 Cannot create des keys with afs3 salt
2007-12-136621129 generic_gss_release_oid() should check for oid == NULL before ↵mp1537391-8/+19
dereferencing
2007-11-29PSARC 2007/597 Kerberos NULL replay cacheps574223-3/+96
6355106 rcache should include the "none" type --HG-- rename : deleted_files/usr/src/lib/gss_mechs/mech_krb5/krb5/rcache/rc_none.c => usr/src/lib/gss_mechs/mech_krb5/krb5/rcache/rc_none.c
2007-10-19backout 6355106: breaks buildsuha4-96/+4
--HG-- rename : usr/src/lib/gss_mechs/mech_krb5/krb5/rcache/rc_none.c => deleted_files/usr/src/lib/gss_mechs/mech_krb5/krb5/rcache/rc_none.c
2007-10-196355106 rcache should include the "none" typeps574224-4/+96
2007-09-166573019 mit 1.4 sub-glue layer resync (fix cstyle)gtb1-1/+21
2007-09-146573019 mit 1.4 sub-glue layer resyncgtb47-1920/+4436
--HG-- rename : usr/src/lib/gss_mechs/mech_krb5/mech/k5mech.c => deleted_files/usr/src/lib/gss_mechs/mech_krb5/mech/k5mech.c
2007-08-306467709 spnego_gss_inquire_cred() can recurse indefinitely causing crashwyllys2-365/+379
2007-08-29PSARC/2006/277 Support for Kerberos Records in LDAP Directorywillf25-302/+2232
6399903 Support for Kerberos Records in LDAP Directory 6520554 MIT bug #5427 with krb5_kt_get_name() 6597851 dmake lint in usr/src/lib/gss_mechs/mech_krb5 broken --HG-- rename : usr/src/lib/gss_mechs/mech_krb5/include/krb5/kdb_dbm.h => deleted_files/usr/src/lib/gss_mechs/mech_krb5/include/krb5/kdb_dbm.h rename : usr/src/lib/krb5/kadm5/srv/adb_free.c => deleted_files/usr/src/lib/krb5/kadm5/srv/adb_free.c rename : usr/src/lib/krb5/kdb/fetch_mkey.c => deleted_files/usr/src/lib/krb5/kdb/fetch_mkey.c rename : usr/src/lib/krb5/kdb/kdb_dbm.c => deleted_files/usr/src/lib/krb5/kdb/kdb_dbm.c rename : usr/src/lib/krb5/kdb/kdb_hdr.h => deleted_files/usr/src/lib/krb5/kdb/kdb_hdr.h rename : usr/src/lib/krb5/kdb/setup_mkey.c => deleted_files/usr/src/lib/krb5/kdb/setup_mkey.c rename : usr/src/lib/krb5/kdb/store_mkey.c => deleted_files/usr/src/lib/krb5/kdb/store_mkey.c rename : usr/src/lib/krb5/kdb/verify_mky.c => deleted_files/usr/src/lib/krb5/kdb/verify_mky.c rename : usr/src/lib/krb5/kdb/kdb_kt.h => usr/src/lib/gss_mechs/mech_krb5/include/kdb_kt.h rename : usr/src/lib/krb5/kadm5/adb_err.h => usr/src/lib/krb5/kdb/adb_err.h rename : usr/src/lib/krb5/kadm5/srv/adb_openclose.c => usr/src/lib/krb5/plugins/kdb/db2/adb_openclose.c rename : usr/src/lib/krb5/kadm5/srv/adb_policy.c => usr/src/lib/krb5/plugins/kdb/db2/adb_policy.c rename : usr/src/lib/krb5/kdb/kdb_compat.h => usr/src/lib/krb5/plugins/kdb/db2/kdb_compat.h rename : usr/src/lib/krb5/kdb/kdb_db2.c => usr/src/lib/krb5/plugins/kdb/db2/kdb_db2.c rename : usr/src/lib/krb5/kdb/kdb_db2.h => usr/src/lib/krb5/plugins/kdb/db2/kdb_db2.h rename : usr/src/lib/krb5/kdb/kdb_xdr.c => usr/src/lib/krb5/plugins/kdb/db2/kdb_xdr.c rename : usr/src/lib/krb5/db2/Makefile => usr/src/lib/krb5/plugins/kdb/db2/libdb2/Makefile rename : usr/src/lib/krb5/db2/Makefile.com => usr/src/lib/krb5/plugins/kdb/db2/libdb2/Makefile.com rename : usr/src/lib/krb5/db2/README.db2 => usr/src/lib/krb5/plugins/kdb/db2/libdb2/README.db2 rename : usr/src/lib/krb5/db2/btree/bt_close.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_close.c rename : usr/src/lib/krb5/db2/btree/bt_conv.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_conv.c rename : usr/src/lib/krb5/db2/btree/bt_debug.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_debug.c rename : usr/src/lib/krb5/db2/btree/bt_delete.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_delete.c rename : usr/src/lib/krb5/db2/btree/bt_get.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_get.c rename : usr/src/lib/krb5/db2/btree/bt_open.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_open.c rename : usr/src/lib/krb5/db2/btree/bt_overflow.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_overflow.c rename : usr/src/lib/krb5/db2/btree/bt_page.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_page.c rename : usr/src/lib/krb5/db2/btree/bt_put.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_put.c rename : usr/src/lib/krb5/db2/btree/bt_search.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_search.c rename : usr/src/lib/krb5/db2/btree/bt_seq.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_seq.c rename : usr/src/lib/krb5/db2/btree/bt_split.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_split.c rename : usr/src/lib/krb5/db2/btree/bt_utils.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/bt_utils.c rename : usr/src/lib/krb5/db2/btree/btree.h => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/btree.h rename : usr/src/lib/krb5/db2/btree/extern.h => usr/src/lib/krb5/plugins/kdb/db2/libdb2/btree/extern.h rename : usr/src/lib/krb5/db2/db/db.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/db/db.c rename : usr/src/lib/krb5/db2/hash/dbm.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/hash/dbm.c rename : usr/src/lib/krb5/db2/hash/extern.h => usr/src/lib/krb5/plugins/kdb/db2/libdb2/hash/extern.h rename : usr/src/lib/krb5/db2/hash/hash.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/hash/hash.c rename : usr/src/lib/krb5/db2/hash/hash.h => usr/src/lib/krb5/plugins/kdb/db2/libdb2/hash/hash.h rename : usr/src/lib/krb5/db2/hash/hash_bigkey.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/hash/hash_bigkey.c rename : usr/src/lib/krb5/db2/hash/hash_func.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/hash/hash_func.c rename : usr/src/lib/krb5/db2/hash/hash_log2.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/hash/hash_log2.c rename : usr/src/lib/krb5/db2/hash/hash_page.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/hash/hash_page.c rename : usr/src/lib/krb5/db2/hash/hsearch.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/hash/hsearch.c rename : usr/src/lib/krb5/db2/hash/page.h => usr/src/lib/krb5/plugins/kdb/db2/libdb2/hash/page.h rename : usr/src/lib/krb5/db2/hash/search.h => usr/src/lib/krb5/plugins/kdb/db2/libdb2/hash/search.h rename : usr/src/lib/krb5/db2/i386/Makefile => usr/src/lib/krb5/plugins/kdb/db2/libdb2/i386/Makefile rename : usr/src/lib/krb5/db2/include/db-int.h => usr/src/lib/krb5/plugins/kdb/db2/libdb2/include/db-int.h rename : usr/src/lib/krb5/db2/include/db-ndbm.h => usr/src/lib/krb5/plugins/kdb/db2/libdb2/include/db-ndbm.h rename : usr/src/lib/krb5/db2/include/db-queue.h => usr/src/lib/krb5/plugins/kdb/db2/libdb2/include/db-queue.h rename : usr/src/lib/krb5/db2/mapfile-vers => usr/src/lib/krb5/plugins/kdb/db2/libdb2/mapfile-vers rename : usr/src/lib/krb5/db2/mpool/mpool.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/mpool/mpool.c rename : usr/src/lib/krb5/db2/mpool/mpool.h => usr/src/lib/krb5/plugins/kdb/db2/libdb2/mpool/mpool.h rename : usr/src/lib/krb5/db2/recno/extern.h => usr/src/lib/krb5/plugins/kdb/db2/libdb2/recno/extern.h rename : usr/src/lib/krb5/db2/recno/rec_close.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/recno/rec_close.c rename : usr/src/lib/krb5/db2/recno/rec_delete.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/recno/rec_delete.c rename : usr/src/lib/krb5/db2/recno/rec_get.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/recno/rec_get.c rename : usr/src/lib/krb5/db2/recno/rec_open.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/recno/rec_open.c rename : usr/src/lib/krb5/db2/recno/rec_put.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/recno/rec_put.c rename : usr/src/lib/krb5/db2/recno/rec_search.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/recno/rec_search.c rename : usr/src/lib/krb5/db2/recno/rec_seq.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/recno/rec_seq.c rename : usr/src/lib/krb5/db2/recno/rec_utils.c => usr/src/lib/krb5/plugins/kdb/db2/libdb2/recno/rec_utils.c rename : usr/src/lib/krb5/db2/recno/recno.h => usr/src/lib/krb5/plugins/kdb/db2/libdb2/recno/recno.h rename : usr/src/lib/krb5/db2/sparc/Makefile => usr/src/lib/krb5/plugins/kdb/db2/libdb2/sparc/Makefile
2007-08-06PSARC/2006/690 Kerberos client configuration improvementsmp15373910-779/+1989
6496710 enable dns_lookup_kdc by default 6499339 krb zero conf needs better realm lookup logic 6523887 krb should support client side referrals 6528391 krb5.conf should not be delivered in a misconfigured state
2007-07-096550530 pam_krb5_migrate's expire_pw expires the Kerberos password too lateonnv_69semery1-2/+18
6557188 included pam_krb5 doesn't function correctly as 'auth required' in pam.conf 6559678 kpasswd returns "KDC reply did not match expectations" when using Heimdal server 6564714 Option "-m" doesn't work for kadmind. 6564718 kdb5_util dump doesn't create a "dump ok" file if the master key is not available 6570434 libkadm5srv should be smarter in figuring out the enc type of the master key in the stash file 6575452 kdb5_util should be more robust after CF providers have failed
2007-05-176455532 OSNet cleanup required in preparation for direct bindingsrie5-8/+91
--HG-- rename : usr/src/cmd/bnu/strecpy.c => deleted_files/usr/src/cmd/bnu/strecpy.c rename : usr/src/cmd/fs.d/ufs/mount/realpath.c => deleted_files/usr/src/cmd/fs.d/ufs/mount/realpath.c rename : usr/src/cmd/lp/lib/lp/tinames.c => deleted_files/usr/src/cmd/lp/lib/lp/tinames.c rename : usr/src/cmd/sgs/crle/common/mapfile-vers => deleted_files/usr/src/cmd/sgs/crle/common/mapfile-vers rename : usr/src/cmd/sgs/elfdump/common/mapfile-vers => deleted_files/usr/src/cmd/sgs/elfdump/common/mapfile-vers rename : usr/src/cmd/sgs/ldd/common/mapfile-vers => deleted_files/usr/src/cmd/sgs/ldd/common/mapfile-vers rename : usr/src/cmd/sgs/moe/common/mapfile-vers => deleted_files/usr/src/cmd/sgs/moe/common/mapfile-vers rename : usr/src/cmd/sgs/pvs/common/mapfile-vers => deleted_files/usr/src/cmd/sgs/pvs/common/mapfile-vers rename : usr/src/lib/libsocket/amd64/byteorder.s => deleted_files/usr/src/lib/libsocket/amd64/byteorder.s rename : usr/src/lib/libsocket/i386/byteorder.s => deleted_files/usr/src/lib/libsocket/i386/byteorder.s rename : usr/src/cmd/sgs/ld/common/mapfile-vers => usr/src/cmd/sgs/ld/common/mapfile-intf rename : usr/src/cmd/sgs/mapfiles/Makefile => usr/src/common/mapfiles/Makefile rename : usr/src/cmd/sgs/mapfiles/amd64/Makefile => usr/src/common/mapfiles/amd64/Makefile rename : usr/src/cmd/sgs/mapfiles/amd64/map.above4G => usr/src/common/mapfiles/amd64/map.above4G rename : usr/src/cmd/sgs/mapfiles/amd64/map.below4G => usr/src/common/mapfiles/amd64/map.below4G rename : usr/src/cmd/sgs/mapfiles/common/Makefile => usr/src/common/mapfiles/common/Makefile rename : usr/src/cmd/mapfile_bssalign => usr/src/common/mapfiles/common/map.bssalign rename : usr/src/cmd/mapfile_execdata => usr/src/common/mapfiles/common/map.execdata rename : usr/src/lib/common/mapfile-filter => usr/src/common/mapfiles/common/map.filter rename : usr/src/cmd/mapfile_noexstk => usr/src/common/mapfiles/common/map.noexstk rename : usr/src/cmd/sgs/mapfiles/i386/Makefile => usr/src/common/mapfiles/i386/Makefile rename : usr/src/cmd/sgs/mapfiles/i386/map.default => usr/src/common/mapfiles/i386/map.default rename : usr/src/cmd/mapfile_noexdata => usr/src/common/mapfiles/i386/map.noexdata rename : usr/src/cmd/sgs/mapfiles/i386/map.pagealign => usr/src/common/mapfiles/i386/map.pagealign rename : usr/src/cmd/sgs/mapfiles/sparc/Makefile => usr/src/common/mapfiles/sparc/Makefile rename : usr/src/cmd/sgs/mapfiles/sparc/map.default => usr/src/common/mapfiles/sparc/map.default rename : usr/src/cmd/sgs/mapfiles/sparc/map.pagealign => usr/src/common/mapfiles/sparc/map.pagealign rename : usr/src/cmd/sgs/mapfiles/sparcv9/Makefile => usr/src/common/mapfiles/sparcv9/Makefile rename : usr/src/cmd/sgs/mapfiles/sparcv9/map.above4G => usr/src/common/mapfiles/sparcv9/map.above4G rename : usr/src/cmd/sgs/mapfiles/sparcv9/map.below4G => usr/src/common/mapfiles/sparcv9/map.below4G rename : usr/src/lib/libsocket/inet/byteorder.c => usr/src/lib/libc/sparc/gen/byteorder.c
2007-05-156440682 mech_krb5 should make fewer calls to PKCS#11 for AESwillf1-2/+2
6549922 krb build broken when -DDEBUG used
2007-05-036455242 nightly should be able to preserve all proto areas from a single build.kupfer2-0/+236
6467531 nightly(1) needs option to generate OpenSolaris delivery --HG-- rename : usr/src/pkgdefs/SUNWftpu/copyright => usr/src/cmd/cmd-inet/usr.sbin/in.ftpd/LICENSE
2007-04-176543658 krb5_set_default_tgs_enctypes: referenced symbol not foundgtb1-0/+7
2007-02-136394510 error table is out of whacksemery4-48/+107
6497698 krb5kdc(1) should also provide password expiration information 6497703 pam_krb5(5) should interpret the key expiration field to display expiration warning information 6514446 pam_dhkeys prompts for secure RPC password when neither LOCAL or DES credentials exist 6515558 Pre-s10 client's keytab file are generated incorrectly when auth princ == target princ 6523684 Memory rcache function doesn't acquire the right locks
2007-01-084854431 krb5_gss_acquire_cred() does not implement correct GSS_C_NO_NAME ↵mp1537393-43/+40
semantics 6290693 krb mech isn't doing the right thing in regards to gss_delete_sec_context and the output token 6491792 gss_unwrap() is causing duplicate token detection to fail for subsequent calls to gss_unwrap()
2007-01-086225779 kadmin.local -q listprincs should not output warnings to stdoutmp1537391-0/+10
6251822 klist will core dump if KRB5CCNAME is set to empty string("export KRB5CCNAME=") 6396614 kadmin's Usage output is incomplete, missing [-w password]] 6460287 kadmin should use pager for listpols
2006-10-236367849 kdb5_util will core dump if krb5.conf doesn't contain default_realm ↵mp1537391-1/+2
info. 6415909 kadmin hangs when authenticating with an admin principal which contains '\@' 6419447 HAVE_ACCESS should be defined for prof_file.c
2006-10-176471429 clients using SET_CHANGE do not log the change to kadmin.logsemery1-1/+1
6474547 After setting SET_CHANGE kpasswd returns false positives 6478028 pam_krb5's password management should not be prompting for old or for new passwords 6478031 Typo in krb change pw too soon message
2006-10-07PSARC 2006/424 Kerberos 1.4 KDC Resyncmp1537396-126/+110
6406993 kdc and client resync with MIT 1.4
2006-08-246311077 Enabling ON compilation with Sun Studio 11 (Venus)petede3-4/+6