summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Collapse)AuthorFilesLines
2006-10-17Update p5-Authen-SASL to 2.10.obache2-7/+7
Patch provided by Martin Wilke via PR 34396. Modify to avoid interaction when buildling. Authen-SASL 2.10 -- Sat Mar 25 13:11:47 CST 2006 Enhancements * Added Authen::SASL::Perl::GSSAPI * Added error method to Authen::SASL to obtain error from last connection Bug Fixes * Authen::SASL::Perl::DIGEST_MD5 - Fixed response to server to pass digest-uri - Correct un-escaping behaviour when reading the challenge, - check for required fields (according to the RFC), - allow for qop not to be sent from the server (according to the RFC), - add a callback for the realm. Authen-SASL 2.09 -- Tue Apr 26 06:55:10 CDT 2005 Enhancements * authname support in Authen::SASL::Perl::DIGEST_MD5 * flexible plugin selection in Authen::SASL using import() i.e. use Authen::SASL qw(Authen::SASL::Cyrus); * new documentation for - Authen::SASL::Perl::ANONYMOUS - Authen::SASL::Perl::CRAM_MD5 - Authen::SASL::Perl::EXTERNAL - Authen::SASL::Perl::LOGIN - Authen::SASL::Perl::PLAIN - Authen::SASL::Perl * updates in the tests Authen-SASL 2.08 -- Tue May 25 11:24:21 BST 2004 Bug Fixes * Fix the handling of qop in Digest-MD5 Authen-SASL 2.07 -- Sat Apr 10 09:06:21 BST 2004 Bug Fixes * Fixed test bug if Digest::HMAC_MD5 was not installed * Fixed order of values sent in the PLAIN mechanism Enhancements * Added support in the framework for server-side plugins 2003-11-01 18:48 Graham Barr * lib/Authen/SASL.pm: Release 2.06 2003-10-21 19:59 Graham Barr * MANIFEST, lib/Authen/SASL/Perl.pm, lib/Authen/SASL/Perl/ANONYMOUS.pm, lib/Authen/SASL/Perl/CRAM_MD5.pm, lib/Authen/SASL/Perl/DIGEST_MD5.pm, lib/Authen/SASL/Perl/EXTERNAL.pm, lib/Authen/SASL/Perl/LOGIN.pm, lib/Authen/SASL/Perl/PLAIN.pm, t/order.t: Add ordering so we always pich the best of the available methods instead of just the first 2003-10-17 22:12 Graham Barr * lib/Authen/SASL.pm: Release 2.05 2003-10-17 22:06 Graham Barr * MANIFEST, Makefile.PL: use Module::Install to generate Makefile and add SIGNATURE and META.yml 2003-10-17 21:19 Graham Barr * lib/Authen/SASL/Perl/DIGEST_MD5.pm: Fix typo 2003-10-17 21:17 Graham Barr * lib/Authen/SASL/: Perl.pm, Perl/DIGEST_MD5.pm: Don't call die in DIGEST_MD5, but call set_error and return an empty list 2003-10-17 21:16 Graham Barr * lib/Authen/SASL.pod: Update docs to reflect that client_start and client_step return an emtpy list on error
2006-10-17HTTP download URLs for HTTP-only sites.dsainty1-2/+4
2006-10-16nb1: Put conf and pid files back where they belong after the 4.15 update.tv3-2/+17
(PKG_SYSCONFDIR already includes "stunnel" by default, so avoid the package adding another and making $PREFIX/etc/stunnel/stunnel/stunnel.conf; the pidfile does not normally belong under $PREFIX as $PREFIX/var/run is not normally cleaned/checked by OS-supplied processes.)
2006-10-16Make pkglint happy.martti1-2/+1
2006-10-16Added yaficmartti1-1/+2
2006-10-16yafic is Yet Another File Integrity Checker, similar to programs likemartti4-0/+28
Tripwire and AIDE.
2006-10-16Updated security/keychain to 2.6.6martti2-6/+6
* keychain 2.6.6 (08 Sep 2006) 08 Sep 2006; Aron Griffis <agriffis@gentoo.org>: Make --lockwait -1 mean forever. Previously 0 meant forever but was undocumented. Add more locking regression tests #137981 * keychain 2.6.5 (08 Sep 2006) 08 Sep 2006; Aron Griffis <agriffis@gentoo.org>: Break out of loop when empty lockfile can't be removed #127471. Add locking regression tests: 100_lock_stale 101_lock_held 102_lock_empty 103_lock_empty_cant_remove * keychain 2.6.4 (08 Sep 2006) 08 Sep 2006; Aron Griffis <agriffis@gentoo.org>: Add validinherit function so that validity of SSH_AUTH_SOCK and friends can be validated from startagent rather than up front. The advantage is that warning messages aren't emitted unnecessarily when --inherit *-once. Fix --eval for fish, and add new testcases: 053_start_with_--eval_ksh 054_start_with_--eval_fish 055_start_with_--eval_csh * keychain 2.6.3 (07 Sep 2006) 07 Sep 2006; Aron Griffis <agriffis@gentoo.org>: Support fish: http://roo.no-ip.org/fish/ Thanks to Ilkka Poutanen for the patch.
2006-10-14Update stunnel to 4.15.obache5-53/+50
Patch provided by Shaun Amott via PR 34436, take maintainership. And define USE_LIBTOOL, regen patch with mkpatches.
2006-10-14Update MASTER_SITES and/or HOMEPAGE, from Sergey Svishchev.wiz1-2/+2
2006-10-14Fixed "test ==".rillig3-1/+29
2006-10-14Fixed "test ==" and pkglint warnings.rillig5-37/+69
2006-10-13Update security/caff to 0.4.8tonio2-7/+7
Changelog: * gpglist: do not die with with-fingerprint (Closes: #382019). * gpg-key2ps: add --list-key to gpg call (works around #382794). * caff: when set, use $ENV{'GNUPGHOME'} to find secring.gpg. Suggested by Gerfried Fuchs.
2006-10-13Add an HTTP download URL for when outbound FTP isn't available.dsainty1-2/+3
2006-10-12Fix dependency. No cookie for shannonjr.joerg1-2/+2
2006-10-11Latest pinentry has new GTK+-2 Pinentry option. Enable or disableshannonjr3-4/+15
according to build options.
2006-10-11Remove patch-ab, patch-ac, and patch-ad because they are no longer needed.shannonjr3-40/+0
2006-10-11Update to 0.7.2shannonjr4-9/+12
2006-10-11adjust comment explaining how this should be separate packages rathergdt1-5/+6
than options.
2006-10-11Update to 0.9.10. Changes:shannonjr2-6/+6
- Only export symbol starting with preludedb_. - Verbose error reporting in case of libpreludedb initialization failure.
2006-10-11Update to 0.9.11. Changes:shannonjr4-40/+8
- Hook class comparison function. Accept NULL, equal, not equal operator. - Introduce better error checking in the idmef-class API, which is now considered public and might be used by external application. Rename error code to reflect the API. - Change to the way IDMEF listed element are handled. Specifying negative number as the position of the element from the low level API now allow to position the element at the specified (reversed) index. Using the high level API a negative index permit to address a list of element backward (replace an element). - Build fixes for SWIG > 1.3.27. - Modify idmef_value_match() so that it always unroll listed value (do it for both val1 and val2. Remove assertion, and let idmef_value_type_compare() return an error code in case there is an issue. - Handle path using IDMEF_LIST_APPEND or IDMEF_LIST_PREPEND as path using an undefined list index on idmef_path_get() call. - Make criteria parser accept (*) list index. - Implement comparison function for all IDMEF object.
2006-10-11Update to 0.9.3. Changes:shannonjr2-7/+7
* Portability fixes. * Pth is not anymore linked by means of weak symbol tricks. It is now required to link to the pth version of libassuan. New aufoconf macros are provided to to check for this. The pth version is only build if Pth is available. * configure does now check that descriptor passing is available. A way to check at runtime for this is also provided
2006-10-11Remove patches/patch-aa. It's no longer needed.shannonjr1-12/+0
2006-10-11Update to 1.9.92. Changes:shannonjr2-9/+8
* New "relax" flag for trustlist.txt to allow root CA certificates without BasicContraints. * [gpg2] Removed the -k PGP 2 compatibility hack. -k is now an alias for --list-keys. * [gpg2] Print a warning if "-sat" is used instead of "--clearsign". * Regular man pages for most tools are now build directly from the Texinfo source. * Included translations from gnupg 1.4.5. * The gpg code from 1.4.5 has been fully merged into this release. The configure option --enable-gpg is still required to build this gpg part. For production use of OpenPGP the gpg version 1.4.5 is still recommended. Note, that gpg will be installed under the name gpg2 to allow coexisting with an 1.4.x gpg. * API change in gpg-agent's pkdecrypt command. Thus an older gpgsm may not be used with the current gpg-agent. * The scdaemon will now call a script on reader status changes. * gpgsm now allows file descriptor passing for "INPUT", "OUTPUT" and "MESSAGE". * The gpgsm server may now output a key listing to the output file handle. This needs to be enabled using "OPTION list-to-output=1". * The --output option of gpgsm has now an effect on list-keys. * New gpgsm commands --dump-chain and list-chain. * gpg-connect-agent has new options to utilize descriptor passing. * A global trustlist may now be used. See doc/examples/trustlist.txt. * When creating a new pubring.kbx keybox common certificates are imported. * Enhanced pkcs#12 support to allow import from simple keyBags. * Exporting to pkcs#12 now create bag attributes so that Mozilla is able to import the files. * Pkcs#12 files are now created with a MAC. This is for better interoperability. * Fixed uploading of certain keys to the smart card. * New command APDU for scdaemon to allow using it for general card access. Might be used through gpg-connect-agent by using the SCD prefix command. * Support for the CardMan 4040 PCMCIA reader (Linux 2.6.15 required). * Scdaemon does not anymore reset cards at the end of a connection. * Kludge to allow use of Bundesnetzagentur issued X.509 certificates. * Added --hash=xxx option to scdaemon's PKSIGN command.
2006-10-11Update to 1.0.0. After about 5 years of beta testing, I am pleased to ↵shannonjr2-9/+10
announce the availability of libksba 1.0.0. Libksba is an X.509 and CMS (pkcs#7) library. It is for example required to build the S/MIME part of GnuPG (gpgsm)
2006-10-11Update to 0.9.6. Changes:shannonjr3-16/+17
* A couple of bug fixes for OCSP. * OCSP does now make use of the responder ID and optionally included certificates in the response to locate certificates. * No more lost file descriptors when loading CRLs via HTTP. * HTTP redirection for CRL and OCSP has been implemented. * Man pages are now build and installed from the texinfo source. Note, that you need to update libksba to version 1.0.0 for this release.
2006-10-11Update to 1.3 to sastify dependancies in several other packages.shannonjr3-11/+10
2006-10-10Fix config file handling by honouring PKG_SYSCONFDIR, installing thejoerg4-4/+36
configuration file to share/examples and using CONF_FILES. It also stops the package from polluting /etc. Bump revision.
2006-10-10+pam-radiusadrianp1-1/+2
2006-10-10This is the PAM to RADIUS authentication module. It allows any PAM-capableadrianp4-0/+44
machine to become a RADIUS client for authentication and accounting requests. You will need a RADIUS server to perform the actual authentication.
2006-10-10pkgsrc added --without-libcrack to CONFIGURE_ARGS if libcrack is missingben4-19/+76
from PKG_OPTIONS, and also comments out the libcrack module in the PLIST. However this means nothing to the PAM configure script, which will find a system libcrack and install the libcrack module. When the pkgsrc bulk build deinstalls PAM, it detects the leftover libcrack module and marks PAM and its dependents failed. Fix this by adding a --disable-crack option to the configure script.
2006-10-09Flag a number of packages I use as supporting (user-)destdir.joerg2-7/+10
apg is a bit special as it has some hardcoded ownership, so mark that as "destdir".
2006-10-05When in verbose mode, print a note when no vulnerable packages arejoerg2-3/+9
found. Bump to 1.44. Addresses PR 24454. OK agc@
2006-10-05Fixed "test ==".rillig2-1/+15
2006-10-05Fixed path to the manual pages.rillig1-4/+4
2006-10-04Update MASTER_SITES and/or HOMEPAGE, from Sergey Svishchev.wiz23-53/+52
2006-10-04Update cyrus-sasl (and plugins, authd) to 2.1.22.obache21-118/+92
New in 2.1.22 ------------- * Added support for spliting big data blocks (bigger than maxbuf) into multiple SASL packets in sasl_encodev * Various sasl_decode64() fixes * Increase canonicalization buffer size to 1024 bytes * Call do_authorization() after successful APOP authentication * Allow for configuration file location to be configurable independently of plugin location (bug # 2795) * Added sasl_set_path function, which provides a more convenient way of setting plugin and config paths. Changed the default sasl_getpath_t/sasl_getconfpath_t callbacks to calculate the value only once and cache it for later use. * Fixed load_config to search for the config file in all directories (bug # 2796). Changed the default search path to be /usr/lib/sasl2:/etc/sasl2 * Don't ignore log_level configuration option in default UNIX syslog logging callback * (Windows) Minor IPv6 related changes in Makefiles for Visual Studio 6 * (Windows) Fixed bug of not setting the CODEGEN (code generation option) nmake option if STATIC nmake option is set. * Several fixed to DIGEST-MD5 plugin: - Enable RC4 cipher in Windows build of DIGEST-MD5 - Server side: handle missing realm option as if realm="" was sent - Fix DIGEST-MD5 to properly advertise maxssf when both DES and RC4 are disabled - Check that DIGEST-MD5 SASL packet are no shorter than 16 bytes * Several changes/fixed to SASLDB plugin: - Prevent spurious SASL_NOUSER errors - Added ability to keep BerkleyDB handle open between operations (for performance reason). New behavior can be enabled with --enable-keep-db-open. * Better error checking in SQL (MySQL) auxprop plugin code * Added support for HTTP POST password validation in saslauthd * Added new application ("pluginviewer") that helps report information about installed plugins * Allow for building with OpenSSL 0.9.8 * Allow for building with OpenLDAP 2.3+ * Several quoting fixes to configure script * A large number of other minor bugfixes and cleanups
2006-10-03Update to 0.0.6:gdt2-7/+7
** Parse "group" configuration parameters of GnuPG. ** epg-verify-file and epg-verify-string now return the plaintext after successful verification. ** Obey the decoding coding-system determined by decode-coding-inserted-region. ** Improved progress display. ** Allow file names starting with "-".
2006-10-03The self test sometimes ends in an endless loop.rillig1-1/+4
2006-10-03Update security/pgpdump to 0.25 applying patch by PR pkg/34701 fromtaca2-6/+6
jun@. From CHANGES: 0.25 2006/10/02 * Catching upto ID 18. Adding SHA224.
2006-10-02Imported p5-Crypt-PasswdMD5.rillig2-10/+10
This code provides various crypt()-compatible interfaces to the MD5-based crypt() function found in various *nixes.
2006-10-02Update amavisd-new to 2.4.3, based on PR 34041.obache4-26/+27
--------------------------------------------------------------------------- June 27, 2006 amavisd-new-2.4.2 release notes SUMMARY OF CHANGES: - new feature: "pen pals soft-whitelisting" lowers spam score of received replies to a message previously sent by a local user to this address; - new feature: added command line options to override certain configuration settings from a config file, see below; - documentation bug fixes, especially on the use of SQL data type TIMESTAMP; - zoo decoder interface routine can now use utility unzoo(1) or zoo(1); --------------------------------------------------------------------------- May 8, 2006 amavisd-new-2.4.1 release notes INCOMPATIBLE CHANGE WITH 2.4.0: - notification templates incompatibility with 2.4.0 (but not with versions 2.3.3 or older): major contents category numbers are renumbered due to a newly inserted category CC_SPAMMY; it affects the use of macro ccat_maj in templates (one field added), and only affect users which provide non-default templates based on 2.4.0 templates; older templates (2.3.3 or earlier) are unaffected as they do not use macro ccat_maj; --------------------------------------------------------------------------- April 3, 2006 amavisd-new-2.4.0 release notes The most important changes since 2.3.3 at a glance: Delivery status notifications (DSN) are now supported, both as a SMTP protocol extension and in notifications. Header fields like X-Amavis and X-Spam are now prepended to mail header for DomainKeys compatibility. Configuration variables can be chosen based on mail contents category, which is now represented explicitly. A built-in macro expander is enhanced, providing new macros and call types. Added support for passive operating system fingerprinting with the use of p0f, supplying collected information as a header field to SpamAssassin. Provide compatibility with Net::Server 0.91 and later.
2006-10-01Fixed some pkglint warnings.rillig1-4/+5
2006-10-01The "test" phase is interactive.rillig1-1/+4
2006-09-30Apply patches which fixes recent security problem of OpenSSL.taca14-3/+337
http://secunia.com/advisories/22130/ Bump PKGREVISION.
2006-09-28Always use "unsigned int" for a 32 bit unsigned integer which is correcttron4-7/+35
on all platforms supported by pkgsrc. This should fix LP64 problems reported in PR pkg/19765 by John Heasley.
2006-09-28Update to openssh-4.3.2 (OpenSSH 4.3p2). I missed existence of PR/32858taca2-8/+8
at previous commit. Note: OpenSSH 4.4p1 has already released, there is no hpn-patch patch yet, so I don't update to it while pkgsrc-freeze is in effect. 20060211 - (dtucker) [README] Bump release notes URL. - (djm) Release 4.3p2 20060208 - (tim) [session.c] Logout records were not updated on systems with post auth privsep disabled due to bug 1086 changes. Analysis and patch by vinschen at redhat.com. OK tim@, dtucker@. - (dtucker) [configure.ac] Typo in Ultrix and NewsOS sections (NEED_SETPRGP -> NEED_SETPGRP), reported by Berhard Simon. ok tim@ 20060206 - (tim) [configure.ac] Remove unnecessary tests for net/if.h and netinet/in_systm.h. OK dtucker@. 20060205 - (tim) [configure.ac] Add AC_REVISION. Add sys/time.h to lastlog.h test for Solaris. OK dtucker@. - (tim) [configure.ac] Bug #1149. Changes in QNX section only. Patch by kraai at ftbfs.org. 20060203 - (tim) [configure.ac] test for egrep (AC_PROG_EGREP) before first AC_CHECK_HEADERS test. Without it, if AC_CHECK_HEADERS is first run by a platform specific check, builtin standard includes tests will be skipped on the other platforms. Analysis and suggestion by vinschen at redhat.com, patch by dtucker@. OK tim@, djm@. 20060202 - (dtucker) [configure.ac] Bug #1148: Fix "crippled AES" test so that it works with picky compilers. Patch from alex.kiernan at thus.net.
2006-09-27Add patches to fix the problem reported by Secunia Advisory SA22091 (alsotaca5-5/+167
CVS-2006-4924); "OpenSSH Identical Blocks Denial of Service Vulnerability" referring to OpenBSD's CVS repository. Bump PKGREVISION.
2006-09-22 Fixed RSA e=3 bug (most likely nobody uses e=3 rsa keyskivinen20-5/+475
on ssh anyways, but better to make sure). Fixed some more ssh_*_{en,de}code calls missing necessary casts. Disabled x11-security extension on x86_64 as it does not work there (uses xauth instead). Updated pkgrevision.
2006-09-20Fixed the path to the manual pages.rillig1-8/+10
2006-09-17Fix build on DragonFly and other platforms without LOCAL_CREDS.joerg2-1/+34
No idea how this code was ever tested, it can't compile for obvious reaons.