<feed xmlns='http://www.w3.org/2005/Atom'>
<title>pkgsrc/security/sudo/options.mk, branch pkgsrc_2008Q2</title>
<subtitle>[no description]</subtitle>
<id>https://git.osdyson.ru/mirror/pkgsrc/atom?h=pkgsrc_2008Q2</id>
<link rel='self' href='https://git.osdyson.ru/mirror/pkgsrc/atom?h=pkgsrc_2008Q2'/>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/'/>
<updated>2008-03-11T15:52:51Z</updated>
<entry>
<title>Update sudo package to 1.6.9p14.</title>
<updated>2008-03-11T15:52:51Z</updated>
<author>
<name>taca</name>
<email>taca</email>
</author>
<published>2008-03-11T15:52:51Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=488f4f2e96ffece02bead6a12adc75bfef47f097'/>
<id>urn:sha1:488f4f2e96ffece02bead6a12adc75bfef47f097</id>
<content type='text'>
pkgsrc changes:

- Explict to depends security/heimdal package when kerberos option is
  specified.  PR pkg/37999 should be fixed.

Change:

646) Sudo will now set the nproc resource limit to unlimited on Linux
     systems to work around Linux's setuid() resource limit semantics.
     On PAM systems the resource limits will be reset by pam_limits.so
     before the command is executed.

647) SELinux support that can be used to implement role based access
     control (RBAC).  A role and (optional) type may be specified
     in sudoers or on the command line.  These are then used in the
     security context that the command is run as.

648) Fixed a Kerberos 5 compilation problem with MIT Kerberos.

Sudo 1.6.9p13 released.

649) Fixed an invalid assumption in the PAM conversation function
     introduced in version 1.6.9p9.  The conversation function may
     be called for non-password reading purposes as well.

650) Fixed freeing an uninitialized pointer in -l mode, introduced in
     version 1.6.9p13.

651) Check /etc/sudoers after LDAP even if the user was found in LDAP.
     This allows Defaults options in /etc/sudoers to take effect.

652) Add missing checks for enforcing mode in SELinux RBAC mode.

Sudo 1.6.9p14 released.
</content>
</entry>
<entry>
<title>PKG_OPTIONS_OPTIONAL_GROUPS/PKG_OPTIONS_NONEMPTY_SETS have their respective</title>
<updated>2007-09-26T05:47:46Z</updated>
<author>
<name>bjs</name>
<email>bjs</email>
</author>
<published>2007-09-26T05:47:46Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=1dd639a347270d4e498135a4cae3a5c43dc1c243'/>
<id>urn:sha1:1dd639a347270d4e498135a4cae3a5c43dc1c243</id>
<content type='text'>
options added to PKG_SUPPORTED_OPTIONS automagically.  Duplicate options
removed.
</content>
</entry>
<entry>
<title>Update sudo package to 1.6.9p4.</title>
<updated>2007-08-18T15:09:11Z</updated>
<author>
<name>taca</name>
<email>taca</email>
</author>
<published>2007-08-18T15:09:11Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=ebd3413f0a6b7543bf007ddcf5db5c36c1ced2d0'/>
<id>urn:sha1:ebd3413f0a6b7543bf007ddcf5db5c36c1ced2d0</id>
<content type='text'>
pkgsrc change:

Make these options mutual exclusive: kerberos pam skey.
(Really, combinations of kerberos and pam, pam and skey are conflicts.)

CHANGES:

609) Worked around a bug ins some PAM implementations that caused a crash
     when no tty was present.

610) Fixed a crash on some platforms in the error logging function.

611) Documentation improvements.

Sudo 1.6.9p1 released.

612) Fixed updating of the saved environment when the environ pointer
     gets changed out from underneath us.

Sudo 1.6.9p2 released.

613) Fixed a bug related to supplemental group matching introduced
     in 1.6.9.

Sudo 1.6.9p3 released.

614) Added IPv6 support from YOSHIFUJI Hideaki.

615) Fixed sudo_noexec installation path.

616) Fixed a K&amp;R compilation error.

Sudo 1.6.9p4 released.
</content>
</entry>
<entry>
<title>Update sudo to 1.6.9.  We don't take the new default of PAM and no other</title>
<updated>2007-07-23T16:38:36Z</updated>
<author>
<name>tls</name>
<email>tls</email>
</author>
<published>2007-07-23T16:38:36Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=b383956e20f2de9b532dddf82da9f6f4205c25c4'/>
<id>urn:sha1:b383956e20f2de9b532dddf82da9f6f4205c25c4</id>
<content type='text'>
authentication; that can be enabled by adding pam to the package options
if users desire.
</content>
</entry>
<entry>
<title>The databases/openldap package has been split in -client and -server component</title>
<updated>2006-05-31T18:22:23Z</updated>
<author>
<name>ghen</name>
<email>ghen</email>
</author>
<published>2006-05-31T18:22:23Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=6a34cac762bbf82e27b9e03d66f87e4ef2add238'/>
<id>urn:sha1:6a34cac762bbf82e27b9e03d66f87e4ef2add238</id>
<content type='text'>
packages.  Convert LDAP-based applications to depend on openldap-client, and
bump PKGREVISION for those that depend on it by default.
</content>
</entry>
<entry>
<title>check for  /usr/include/skey.h on NetBSD - in case dist with MKSKEY=no</title>
<updated>2005-08-22T10:20:33Z</updated>
<author>
<name>abs</name>
<email>abs</email>
</author>
<published>2005-08-22T10:20:33Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=9c8e9544f4f8e2cb27fd91064fd7cfa49e8bf16f'/>
<id>urn:sha1:9c8e9544f4f8e2cb27fd91064fd7cfa49e8bf16f</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Update PKG_OPTIONS variable "PAM" to "pam".</title>
<updated>2005-06-22T10:30:12Z</updated>
<author>
<name>taca</name>
<email>taca</email>
</author>
<published>2005-06-22T10:30:12Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=3231cce5141b3ddf9469fde3124a1f99bbdf7ad3'/>
<id>urn:sha1:3231cce5141b3ddf9469fde3124a1f99bbdf7ad3</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Packages have no business modifying PKG_DEFAULT_OPTIONS -- it's a</title>
<updated>2005-05-31T10:01:36Z</updated>
<author>
<name>dillo</name>
<email>dillo</email>
</author>
<published>2005-05-31T10:01:36Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=3d75323aa5391188ab027b2688faacf8286ace0c'/>
<id>urn:sha1:3d75323aa5391188ab027b2688faacf8286ace0c</id>
<content type='text'>
user settable variable.  Set PKG_SUGGESTED_OPTIONS instead.  Also,
make use of PKG_OPTIONS_LEGACY_VARS.

Reviewed by wiz.
</content>
</entry>
<entry>
<title>Create a pam.buildlink3.mk file that is used by PAM-using packages.</title>
<updated>2005-01-14T05:15:39Z</updated>
<author>
<name>jlam</name>
<email>jlam</email>
</author>
<published>2005-01-14T05:15:39Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=e7b0a8edd99fc8377a8c8877bd0b5aea28fe5479'/>
<id>urn:sha1:e7b0a8edd99fc8377a8c8877bd0b5aea28fe5479</id>
<content type='text'>
It includes the correct buildlink3.mk file from either Linux-PAM
(security/PAM) or OpenPAM (security/openpam) and eventually will
support solaris-pam.  pam.buildlink3.mk will:

	* set PAMBASE to the base directory of the PAM files;
	* set PAM_TYPE to the PAM implementation used.

There are two variables that can be used to tweak the selection of
the PAM implementation:

PAM_DEFAULT is a user-settable variable whose value is the default
	PAM implementation to use.

PAM_ACCEPTED is a package-settable list of PAM implementations
	that may be used by the package.

Modify most packages that include PAM/buildlink3.mk to include
pam.buildlink3.mk instead.
</content>
</entry>
<entry>
<title>Allow building sudo without S/Key support on NetBSD.  Patch from</title>
<updated>2004-12-22T04:36:32Z</updated>
<author>
<name>jlam</name>
<email>jlam</email>
</author>
<published>2004-12-22T04:36:32Z</published>
<link rel='alternate' type='text/html' href='https://git.osdyson.ru/mirror/pkgsrc/commit/?id=c49b38644de6c44c74c9e9b5253de2fe991cb83d'/>
<id>urn:sha1:c49b38644de6c44c74c9e9b5253de2fe991cb83d</id>
<content type='text'>
PR pkg/28743 by Jukka Salmi with minor changes by me.
</content>
</entry>
</feed>
