summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Collapse)AuthorFilesLines
2005-03-24Remove FreeBSD RCS Ids. pkgsrc has diverged too much for syncing to bewiz6-14/+6
useful.
2005-03-24Depend on bash>=2 instead of bash>=2.05.2.7.reed1-2/+2
Okayed by maintainer. Sometime ago, I had noticed my bash was too old, but I found it was good enough for this.
2005-03-24Add and enable systrace-policiesagc1-1/+2
2005-03-24Initial import of the collection of systrace(1) policies from hairyeyeball.agc4-0/+242
The files in this archive are example systrace policy files, which can be used to raise the security levels of your computer by using the systrace(1) utility. These example policies can be used as a base for custom policies, or as learning material.
2005-03-24Strip off any leading "-Wl," in the compiler and linker flags beforejlam2-10/+82
the courier Makefile adds it to all of the flags again. This avoids situations where you end up with a flag that looks like "-Wl,-Wl,...". This should fix the problem noted in pkg/29777.
2005-03-23Missing installed files inPLISTmanu1-1/+18
2005-03-23Upgrade to ipsec-tools 0.6b1.manu2-9/+10
New features: - PAM support - privilege separation
2005-03-23Update security/openssl to openssl-0.9.7f.jlam8-117/+214
Pkgsrc changes from version 0.9.7e include: *) Install the man pages with names that are less likely to collide with other packages' man pages. *) Support PKG_OPTIONS of "idea", "mdc2" and "rc5" to allow building with patented algorithms. By default, this package still builds without patented algorithms. Major changes from version 0.9.7e include: *) Prompt for pass phrases when appropriate for PKCS12 input format. *) Back-port of selected performance improvements from development branch, as well as improved support for PowerPC platforms. *) Add lots of checks for memory allocation failure, error codes to indicate failure and freeing up memory if a failure occurs. *) Add new -passin argument to dgst. *) Make an explicit check during certificate validation to see that the CA setting in each certificate on the chain is correct.
2005-03-22Update to 1.4.1:wiz4-36/+26
Noteworthy changes in version 1.4.1 (2005-03-15) ------------------------------------------------ * New --rfc2440-text option which controls how text is handled in signatures. This is in response to some problems seen with certain PGP/MIME mail clients and GnuPG version 1.4.0. More details about this are available at <http://lists.gnupg.org/pipermail/gnupg-users/2005-January/024408.html>. * New "import-unusable-sigs" and "export-unusable-sigs" tags for --import-options and --export-options. These are off by default, and cause GnuPG to not import or export key signatures that are not usable (e.g. expired signatures). * New experimental HTTP, HTTPS, FTP, and FTPS keyserver helper that uses the cURL library <http://curl.haxx.se> to retrieve keys. This is disabled by default, but may be enabled with the configure option --with-libcurl. Without this option, the existing HTTP code is used for HTTP, and HTTPS, FTP, and FTPS are not supported. [enabled with the "curl" option for the package] * When running a --card-status or --card-edit and a public key is available, missing secret key stubs will be created on the fly. Details of the key are listed too. * The implicit packet dumping in double verbose mode is now sent to stderr and not to stdout. * Added countermeasures against the Mister/Zuccherato CFB attack <http://eprint.iacr.org/2005/033>. * Add new --edit-key command "bkuptocard" to allow restoring a card key from a backup. * The "fetch" command of --card-edit now retrieves the key using the default keyserver if no URL has been stored on the card. * New configure option --enable-noexecstack. Also, gpgkeys_mailto is not installed any longer, dropping the dependency on perl.
2005-03-22Bump revision due to update of eel2 to 2.10.0.jmmv1-1/+2
2005-03-22Update to 0.4.2:jmmv3-7/+8
* AIX portability fixes * Translation updates
2005-03-22Update security/courier-authlib to courier-authlib-0.55. Changes fromjlam2-7/+6
version 0.54 include: * authsystem.passwd.in: Explicitly set LC_ALL to en_US * SASL: Added CRAM-SHA256 authentication method (experimental). * courierauthdebug.h: Macro dprintf conflicts with new glibc.
2005-03-22Add and enable dsniff-nox11.wiz1-1/+2
2005-03-22Split parts of Makefile into Makefile.common for use by dsniff-nox11.wiz4-45/+36
Only build webspy in this package, and depend on dsniff to get the other tools. Bump PKGREVISION.
2005-03-22Initial import of dsniff-nox11, the tools from dsniff that don'twiz3-0/+45
need X11. Addresses PR 25703 by Jukka Salmi.
2005-03-21Do not open files opened for reading in RW mode. Helps in usingwiz3-3/+18
cfs over coda. From Greg Troxel in PR 28479. PKGREVISION++
2005-03-20Fix build by avoiding conflicts between the included tun files and the onesjmmv2-1/+23
provided by libdnet. This was broken during the last update of libdnet to 0.10, as the previous versions did not include the tun stuff.
2005-03-20Use BUILDLINK_PREFIX.libdnet rather than PREFIX to locate libdnet.jmmv1-2/+2
2005-03-20Update fprot-workstation-bin to version 4.5.4. This addresses PR#29747.ben4-19/+29
Version 4.5.4 is a bugfix release. Fixed a string error in the updater. Fixed a race condition in f-protd where f-protd would report 'Bad file number' on accept() under high loads. Fixed a crash issue with malformed word macros. Fixed a memory corruption in the x86 emulation code. Modified check-updates.pl to automatically detect f-prot version number.
2005-03-20Extend "fshcompat.py" to work with python24, using patch submitted byfredb3-2/+44
lukem in PR pkg/29704. Reviewed by recht.
2005-03-19Update to 5.2.1. Provided by Stefan Krüger in PR 28740.wiz6-35/+73
5.2 - merged in changes for 5.01 - 5.0.4 - added support for using encoding parameters and key derivation parameters with public key encryption (implemented by OAEP and DL/ECIES) - added Camellia, SHACAL-2, Two-Track-MAC, Whirlpool, RIPEMD-320, RIPEMD-128, RIPEMD-256, Base-32 coding - added ThreadUserTimer for timing thread CPU usage - added option for password-based key derivation functions to iterate until a mimimum elapsed thread CPU time is reached - added option (on by default) for DEFLATE compression to detect uncompressible files and process them more quickly - improved compatibility and performance on 64-bit platforms, including Alpha, IA-64, x86-64, PPC64, Sparc64, and MIPS64 - fixed ONE_AND_ZEROS_PADDING to use 0x80 instead 0x01 as padding. - fixed encoding/decoding of PKCS #8 privateKeyInfo to properly handle optional attributes 5.2.1 - fixed bug in the "dlltest" DLL testing program - fixed compiling with STLport using VC .NET - fixed compiling with -fPIC using GCC - fixed compiling with -msse2 on systems without memalign() - fixed inability to instantiate PanamaMAC - fixed problems with inline documentation
2005-03-18Avoid possibly linking everything against -lintl when PostgreSQLjlam4-8/+23
support is built into courier-authlib -- -lintl is only needed by the authpgsql authentication module. This avoids problems when linking clients with -lcourierauth and the linker thinks -lintl is needed when it really doesn't. Bump the PKGREVISION to 3.
2005-03-18Add and enable ruby16-digest package.taca1-1/+2
2005-03-18Importing security/ruby16-digest package which I forgot to import,taca5-0/+74
it is needed by ruby16 package. Now this package includes some fixes for IRIX, too.
2005-03-17Update HOMEPAGE and MASTER_SITES.wiz1-3/+3
2005-03-16Added patches for gcc-2.95.3 that properly order declarations and code.rillig3-1/+46
Approved by wiz.
2005-03-16Added proper CFLAGS quoting. Approved by wiz.rillig1-2/+2
2005-03-14There's no need to manually format and install a nroffed manpage.tv1-13/+1
Install the source and let man(1) do it. (Since this code is actually all commented out, no PKGREVISION bump.)
2005-03-10Make build on Interix, sharing some of the OS-specific oddities with _WIN32.tv4-7/+90
2005-03-10Sort.wiz1-2/+2
2005-03-08Make it explicit that the package doesn't install any authentication mechanismsbad1-2/+7
and what the likely, but opaque, error message is in that case.
2005-03-07nb5: Rework Interix support, based on work done by Interop Systemstv24-337/+613
*before* a BSD-with-advertising license was added to their diffs, and other work done personally by me. sshd now works. Most permissions checks work properly. Privsep is off by default, and the sshd user is not created, on Interix until some problems with privsep are fixed (perhaps by abstracting the auth functionality out to openpam).
2005-03-07Because LIBTOOLIZE_PLIST is "yes" by default we must list only the .la filebad1-10/+1
in the PLIST.
2005-03-07Fix quoting.uebayasi2-4/+4
2005-03-06Bump PKGREVISION with introduce of ruby16-base/ruby18-base pacakge.taca2-4/+4
2005-03-06Add and enable ruby-digest and ruby-openssl.taca1-1/+3
2005-03-06Revive separated ruby packages, ruby-dbm, ruby-zlib, ruby-digest andtaca9-0/+139
ruby-openssl with bump PKGREVISION.
2005-03-06Cosmetic change with pkglint(1).taca1-2/+2
2005-03-04Make p5-GnuPG-Interface and pgpenvelope work again by switching to thetv6-9/+49
Class::MethodMaker v1 compatibility interface in Class::MakeMethods. Bump PKGREVISION.
2005-03-03Update gpg2dot to version 1.4.agc2-14/+15
Fixes from Christoph Badura, who tested on gnupg-1.2. This new version works with gnupg-1.4.0 as well as older versions of gpg, and uses the --list-sigs argument as well as the --with-colons arguments to gpg.
2005-03-02- Change to my NetBSD.org addressadrianp1-2/+2
2005-03-02The path to the Courier authdaemond socket was improperly being set tojlam1-3/+3
the wrong value. Fix it so that the default is now correctly set to be /var/authdaemond/socket. Bump the PKGREVISION to 1.
2005-03-02Problem: Dirmngr depends on pth. With an explicit buildlink to pth, theshannonjr2-4/+14
package builds and works correctly. This approach was taken prior to this change. The is a problem because pth installs pthread.h in ${LOCALBASE}/include. This causes problems for things like Ada tasking that depend on native pthreads when also linking against libraries in pkgsrc (eg., gmp). This change solve the problem by building a static pth library locally and linking against it.
2005-02-28Add fwbuilder to the list of sub directories.bad1-1/+2
2005-02-28- Update to 0.6.8adrianp3-10/+7
> $Id: CHANGES,v 1.25 2005/02/20 16:02:21 sm Exp $ > version 0.6.8 (beta) - Sun Feb 20 2004 > * added detection for openssl 0.9.8 > * removed crlDistributionPoint for Root-CA > * added patch for multiple OUs > Thanks to Uwe Arndt <arndt@uni-koblenz.de> > * added patch for multiple subjectAltName extensions > Thanks to Peter Marschall <peter@adpm.de>
2005-02-28Changes 1.7.1:adam2-10/+8
* Fixed bug which caused hostnames containing hyphens to fail with an error. * Improved mapping of ID numbers to names in decode. This allows sparse IDs ranges (e.g. 1,2,3,65000) to be supported, which means that we can now decode XAUTH authentication method amongst other things. * Added SO_BROADCAST option to UDP socket to allow sending to broadcast addresses. Previously this gave a permission denied error.
2005-02-28Update to 0.2.5:wiz3-7/+10
* Version 0.2.5 (released 2005-02-08) ** Added self test of EXTERNAL mechanism. ** Vietnamese translation added, thanks to Clytie Siddall. * Version 0.2.4 (released 2005-01-01) ** The CRAM-MD5 mechanism is now preferred over DIGEST-MD5. This decision was based on recent public research that suggest MD5 is broken, while HMAC-MD5 not immediately compromised, and the lack of public analysis on what consequences the MD5 break have for DIGEST-MD5. Support for CRAM-SHA1 is under investigation, to enable users to avoid MD5 completely ** Fixed a bug that prevented SMTP client from working. ** New configure option --disable-obsolete to remove backwards compatibility. This is mostly intended to be used when compiling for platforms with constrained memory/space resources. ** DIGEST-MD5 rewritten and enabled by default (see lib/NEWS for details). ** Command line tool now query for realm, hostname and service name properly. ** Documentation updates and improvements. ** Self test improvements. ** Update of gnulib files.
2005-02-27Fix installation on NetBSD 1.6.peter3-7/+17
Reviewed by wiz@
2005-02-26Install some documentation files for courier-authlib, but only install thejlam3-5/+38
relevant ones depending on the options chosen. This fixes PR pkg/29465. Bump the PKGREVISION to 2.
2005-02-26Update to 0.4.1:jmmv3-8/+8
* Support for slaving lifecycle to a file descriptor * Translation updates