389-ds-base.git
5 years agoMerge version 1.4.4.3-1+rpi1 and 1.4.4.4-1 to produce 1.4.4.4-1+rpi1 archive/raspbian/1.4.4.4-1+rpi1 raspbian/1.4.4.4-1+rpi1
Raspbian automatic forward porter [Sat, 31 Oct 2020 14:12:44 +0000 (14:12 +0000)]
Merge version 1.4.4.3-1+rpi1 and 1.4.4.4-1 to produce 1.4.4.4-1+rpi1

5 years agoMerge 389-ds-base (1.4.4.4-1) import into refs/heads/workingbranch
Timo Aaltonen [Tue, 22 Sep 2020 06:23:30 +0000 (07:23 +0100)]
Merge 389-ds-base (1.4.4.4-1) import into refs/heads/workingbranch

5 years agodrop-old-man
Debian FreeIPA Team [Tue, 22 Sep 2020 06:23:30 +0000 (07:23 +0100)]
drop-old-man

Gbp-Pq: Name drop-old-man.diff

5 years ago[PATCH] Ticket bz1525628 - invalid password migration causes unauth bind
William Brown [Thu, 18 Jan 2018 01:27:58 +0000 (11:27 +1000)]
[PATCH] Ticket bz1525628 - invalid password migration causes unauth bind

Bug Description:  Slapi_ct_memcmp expects both inputs to be
at LEAST size n. If they are not, we only compared UP to n.

Invalid migrations of passwords (IE {CRYPT}XX) would create
a pw which is just salt and no hash. ct_memcmp would then
only verify the salt bits and would allow the authentication.

This relies on an administrative mistake both of allowing
password migration (nsslapd-allow-hashed-passwords) and then
subsequently migrating an INVALID password to the server.

Fix Description:  slapi_ct_memcmp now access n1, n2 size
and will FAIL if they are not the same, but will still compare
n bytes, where n is the "longest" memory, to the first byte
of the other to prevent length disclosure of the shorter
value (generally the mis-migrated password)

https://bugzilla.redhat.com/show_bug.cgi?id=1525628

Author: wibrown

Review by: ???

Gbp-Pq: Name CVE-2017-15135.patch

5 years agoFix the path to systemctl binary
Timo Aaltonen [Tue, 22 Sep 2020 06:23:30 +0000 (07:23 +0100)]
Fix the path to systemctl binary

Gbp-Pq: Name fix-systemctl-path.diff

5 years agofix-saslpath
Debian FreeIPA Team [Tue, 22 Sep 2020 06:23:30 +0000 (07:23 +0100)]
fix-saslpath

Gbp-Pq: Name fix-saslpath.diff

5 years ago389-ds-base (1.4.4.4-1) unstable; urgency=medium
Timo Aaltonen [Tue, 22 Sep 2020 06:23:30 +0000 (07:23 +0100)]
389-ds-base (1.4.4.4-1) unstable; urgency=medium

  * New upstream release.
  * watch: Update upstream git repo url.
  * control: Add python3-dateutil to build-depends.
  * copyright: Drop duplicate globbing patterns.
  * lintian: Drop obsolete overrides.
  * postinst: Drop obsolete rule to upgrade the instances.
  * prerm: Use dsctl instead of remove-ds.

[dgit import unpatched 389-ds-base 1.4.4.4-1]

5 years agoImport 389-ds-base_1.4.4.4.orig.tar.bz2
Timo Aaltonen [Tue, 22 Sep 2020 06:23:30 +0000 (07:23 +0100)]
Import 389-ds-base_1.4.4.4.orig.tar.bz2

[dgit import orig 389-ds-base_1.4.4.4.orig.tar.bz2]

5 years agoImport 389-ds-base_1.4.4.4-1.debian.tar.xz
Timo Aaltonen [Tue, 22 Sep 2020 06:23:30 +0000 (07:23 +0100)]
Import 389-ds-base_1.4.4.4-1.debian.tar.xz

[dgit import tarball 389-ds-base 1.4.4.4-1 389-ds-base_1.4.4.4-1.debian.tar.xz]

5 years agoMerge version 1.4.3.6-2+rpi1 and 1.4.4.3-1 to produce 1.4.4.3-1+rpi1 archive/raspbian/1.4.4.3-1+rpi1 raspbian/1.4.4.3-1+rpi1
Raspbian automatic forward porter [Sat, 6 Jun 2020 18:08:41 +0000 (19:08 +0100)]
Merge version 1.4.3.6-2+rpi1 and 1.4.4.3-1 to produce 1.4.4.3-1+rpi1

5 years agoMerge 389-ds-base (1.4.4.3-1) import into refs/heads/workingbranch
Timo Aaltonen [Tue, 2 Jun 2020 08:33:44 +0000 (09:33 +0100)]
Merge 389-ds-base (1.4.4.3-1) import into refs/heads/workingbranch

5 years agodrop-old-man
Debian FreeIPA Team [Tue, 2 Jun 2020 08:33:44 +0000 (09:33 +0100)]
drop-old-man

Gbp-Pq: Name drop-old-man.diff

5 years ago[PATCH] Ticket bz1525628 - invalid password migration causes unauth bind
William Brown [Thu, 18 Jan 2018 01:27:58 +0000 (11:27 +1000)]
[PATCH] Ticket bz1525628 - invalid password migration causes unauth bind

Bug Description:  Slapi_ct_memcmp expects both inputs to be
at LEAST size n. If they are not, we only compared UP to n.

Invalid migrations of passwords (IE {CRYPT}XX) would create
a pw which is just salt and no hash. ct_memcmp would then
only verify the salt bits and would allow the authentication.

This relies on an administrative mistake both of allowing
password migration (nsslapd-allow-hashed-passwords) and then
subsequently migrating an INVALID password to the server.

Fix Description:  slapi_ct_memcmp now access n1, n2 size
and will FAIL if they are not the same, but will still compare
n bytes, where n is the "longest" memory, to the first byte
of the other to prevent length disclosure of the shorter
value (generally the mis-migrated password)

https://bugzilla.redhat.com/show_bug.cgi?id=1525628

Author: wibrown

Review by: ???

Gbp-Pq: Name CVE-2017-15135.patch

5 years agoFix the path to systemctl binary
Timo Aaltonen [Tue, 2 Jun 2020 08:33:44 +0000 (09:33 +0100)]
Fix the path to systemctl binary

Gbp-Pq: Name fix-systemctl-path.diff

5 years agofix-saslpath
Debian FreeIPA Team [Tue, 2 Jun 2020 08:33:44 +0000 (09:33 +0100)]
fix-saslpath

Gbp-Pq: Name fix-saslpath.diff

5 years ago389-ds-base (1.4.4.3-1) unstable; urgency=medium
Timo Aaltonen [Tue, 2 Jun 2020 08:33:44 +0000 (09:33 +0100)]
389-ds-base (1.4.4.3-1) unstable; urgency=medium

  * New upstream release.
  * fix-db-home-dir.diff: Dropped, upstream.

[dgit import unpatched 389-ds-base 1.4.4.3-1]

5 years agoImport 389-ds-base_1.4.4.3.orig.tar.bz2
Timo Aaltonen [Tue, 2 Jun 2020 08:33:44 +0000 (09:33 +0100)]
Import 389-ds-base_1.4.4.3.orig.tar.bz2

[dgit import orig 389-ds-base_1.4.4.3.orig.tar.bz2]

5 years agoImport 389-ds-base_1.4.4.3-1.debian.tar.xz
Timo Aaltonen [Tue, 2 Jun 2020 08:33:44 +0000 (09:33 +0100)]
Import 389-ds-base_1.4.4.3-1.debian.tar.xz

[dgit import tarball 389-ds-base 1.4.4.3-1 389-ds-base_1.4.4.3-1.debian.tar.xz]

5 years agoMerge version 1.4.3.4-1+rpi1 and 1.4.3.6-2 to produce 1.4.3.6-2+rpi1 archive/raspbian/1.4.3.6-2+rpi1 raspbian/1.4.3.6-2+rpi1
Raspbian automatic forward porter [Fri, 24 Apr 2020 21:25:12 +0000 (22:25 +0100)]
Merge version 1.4.3.4-1+rpi1 and 1.4.3.6-2 to produce 1.4.3.6-2+rpi1

5 years agoMerge 389-ds-base (1.4.3.6-2) import into refs/heads/workingbranch
Timo Aaltonen [Tue, 21 Apr 2020 17:19:06 +0000 (18:19 +0100)]
Merge 389-ds-base (1.4.3.6-2) import into refs/heads/workingbranch

5 years agofix-db-home-dir
Debian FreeIPA Team [Tue, 21 Apr 2020 17:19:06 +0000 (18:19 +0100)]
fix-db-home-dir

Gbp-Pq: Name fix-db-home-dir.diff

5 years agodrop-old-man
Debian FreeIPA Team [Tue, 21 Apr 2020 17:19:06 +0000 (18:19 +0100)]
drop-old-man

Gbp-Pq: Name drop-old-man.diff

5 years ago[PATCH] Ticket bz1525628 - invalid password migration causes unauth bind
William Brown [Thu, 18 Jan 2018 01:27:58 +0000 (11:27 +1000)]
[PATCH] Ticket bz1525628 - invalid password migration causes unauth bind

Bug Description:  Slapi_ct_memcmp expects both inputs to be
at LEAST size n. If they are not, we only compared UP to n.

Invalid migrations of passwords (IE {CRYPT}XX) would create
a pw which is just salt and no hash. ct_memcmp would then
only verify the salt bits and would allow the authentication.

This relies on an administrative mistake both of allowing
password migration (nsslapd-allow-hashed-passwords) and then
subsequently migrating an INVALID password to the server.

Fix Description:  slapi_ct_memcmp now access n1, n2 size
and will FAIL if they are not the same, but will still compare
n bytes, where n is the "longest" memory, to the first byte
of the other to prevent length disclosure of the shorter
value (generally the mis-migrated password)

https://bugzilla.redhat.com/show_bug.cgi?id=1525628

Author: wibrown

Review by: ???

Gbp-Pq: Name CVE-2017-15135.patch

5 years agoFix the path to systemctl binary
Timo Aaltonen [Tue, 21 Apr 2020 17:19:06 +0000 (18:19 +0100)]
Fix the path to systemctl binary

Gbp-Pq: Name fix-systemctl-path.diff

5 years agofix-saslpath
Debian FreeIPA Team [Tue, 21 Apr 2020 17:19:06 +0000 (18:19 +0100)]
fix-saslpath

Gbp-Pq: Name fix-saslpath.diff

5 years ago389-ds-base (1.4.3.6-2) unstable; urgency=medium
Timo Aaltonen [Tue, 21 Apr 2020 17:19:06 +0000 (18:19 +0100)]
389-ds-base (1.4.3.6-2) unstable; urgency=medium

  * fix-db-home-dir.diff: Set db_home_dir same as db_dir to fix an issue
    starting a newly created instance.

[dgit import unpatched 389-ds-base 1.4.3.6-2]

5 years agoImport 389-ds-base_1.4.3.6-2.debian.tar.xz
Timo Aaltonen [Tue, 21 Apr 2020 17:19:06 +0000 (18:19 +0100)]
Import 389-ds-base_1.4.3.6-2.debian.tar.xz

[dgit import tarball 389-ds-base 1.4.3.6-2 389-ds-base_1.4.3.6-2.debian.tar.xz]

5 years agoImport 389-ds-base_1.4.3.6.orig.tar.bz2
Timo Aaltonen [Mon, 20 Apr 2020 12:01:35 +0000 (13:01 +0100)]
Import 389-ds-base_1.4.3.6.orig.tar.bz2

[dgit import orig 389-ds-base_1.4.3.6.orig.tar.bz2]

5 years agoMerge version 1.4.3.2-1+rpi1 and 1.4.3.4-1 to produce 1.4.3.4-1+rpi1 archive/raspbian/1.4.3.4-1+rpi1 raspbian/1.4.3.4-1+rpi1
Raspbian automatic forward porter [Fri, 20 Mar 2020 21:07:47 +0000 (21:07 +0000)]
Merge version 1.4.3.2-1+rpi1 and 1.4.3.4-1 to produce 1.4.3.4-1+rpi1

5 years agoMerge 389-ds-base (1.4.3.4-1) import into refs/heads/workingbranch
Timo Aaltonen [Wed, 18 Mar 2020 06:47:32 +0000 (06:47 +0000)]
Merge 389-ds-base (1.4.3.4-1) import into refs/heads/workingbranch

5 years agodrop-old-man
Debian FreeIPA Team [Wed, 18 Mar 2020 06:47:32 +0000 (06:47 +0000)]
drop-old-man

Gbp-Pq: Name drop-old-man.diff

5 years ago[PATCH] Ticket bz1525628 - invalid password migration causes unauth bind
William Brown [Thu, 18 Jan 2018 01:27:58 +0000 (11:27 +1000)]
[PATCH] Ticket bz1525628 - invalid password migration causes unauth bind

Bug Description:  Slapi_ct_memcmp expects both inputs to be
at LEAST size n. If they are not, we only compared UP to n.

Invalid migrations of passwords (IE {CRYPT}XX) would create
a pw which is just salt and no hash. ct_memcmp would then
only verify the salt bits and would allow the authentication.

This relies on an administrative mistake both of allowing
password migration (nsslapd-allow-hashed-passwords) and then
subsequently migrating an INVALID password to the server.

Fix Description:  slapi_ct_memcmp now access n1, n2 size
and will FAIL if they are not the same, but will still compare
n bytes, where n is the "longest" memory, to the first byte
of the other to prevent length disclosure of the shorter
value (generally the mis-migrated password)

https://bugzilla.redhat.com/show_bug.cgi?id=1525628

Author: wibrown

Review by: ???

Gbp-Pq: Name CVE-2017-15135.patch

5 years agoFix the path to systemctl binary
Timo Aaltonen [Wed, 18 Mar 2020 06:47:32 +0000 (06:47 +0000)]
Fix the path to systemctl binary

Gbp-Pq: Name fix-systemctl-path.diff

5 years agofix-saslpath
Debian FreeIPA Team [Wed, 18 Mar 2020 06:47:32 +0000 (06:47 +0000)]
fix-saslpath

Gbp-Pq: Name fix-saslpath.diff

5 years ago389-ds-base (1.4.3.4-1) unstable; urgency=medium
Timo Aaltonen [Wed, 18 Mar 2020 06:47:32 +0000 (06:47 +0000)]
389-ds-base (1.4.3.4-1) unstable; urgency=medium

  * New upstream release.
  * Add debian/gitlab-ci.yml.
    - allow blhc to fail
  * control: Bump policy to 4.5.0.
  * control: Use https url for upstream.
  * control: Use canonical URL in Vcs-Browser.
  * copyright: Use spaces rather than tabs to start continuation lines.
  * Add lintian-overrides for the source, cockpit index.js has long lines.

[dgit import unpatched 389-ds-base 1.4.3.4-1]

5 years agoImport 389-ds-base_1.4.3.4.orig.tar.bz2
Timo Aaltonen [Wed, 18 Mar 2020 06:47:32 +0000 (06:47 +0000)]
Import 389-ds-base_1.4.3.4.orig.tar.bz2

[dgit import orig 389-ds-base_1.4.3.4.orig.tar.bz2]

5 years agoImport 389-ds-base_1.4.3.4-1.debian.tar.xz
Timo Aaltonen [Wed, 18 Mar 2020 06:47:32 +0000 (06:47 +0000)]
Import 389-ds-base_1.4.3.4-1.debian.tar.xz

[dgit import tarball 389-ds-base 1.4.3.4-1 389-ds-base_1.4.3.4-1.debian.tar.xz]

5 years agoMerge version 1.4.2.4-1+rpi1 and 1.4.3.2-1 to produce 1.4.3.2-1+rpi1 archive/raspbian/1.4.3.2-1+rpi1 raspbian/1.4.3.2-1+rpi1
Raspbian automatic forward porter [Tue, 18 Feb 2020 10:54:09 +0000 (10:54 +0000)]
Merge version 1.4.2.4-1+rpi1 and 1.4.3.2-1 to produce 1.4.3.2-1+rpi1

5 years agoMerge 389-ds-base (1.4.3.2-1) import into refs/heads/workingbranch
Timo Aaltonen [Wed, 12 Feb 2020 17:39:22 +0000 (17:39 +0000)]
Merge 389-ds-base (1.4.3.2-1) import into refs/heads/workingbranch

5 years agodrop-old-man
Debian FreeIPA Team [Wed, 12 Feb 2020 17:39:22 +0000 (17:39 +0000)]
drop-old-man

Gbp-Pq: Name drop-old-man.diff

5 years ago[PATCH] Ticket bz1525628 - invalid password migration causes unauth bind
William Brown [Thu, 18 Jan 2018 01:27:58 +0000 (11:27 +1000)]
[PATCH] Ticket bz1525628 - invalid password migration causes unauth bind

Bug Description:  Slapi_ct_memcmp expects both inputs to be
at LEAST size n. If they are not, we only compared UP to n.

Invalid migrations of passwords (IE {CRYPT}XX) would create
a pw which is just salt and no hash. ct_memcmp would then
only verify the salt bits and would allow the authentication.

This relies on an administrative mistake both of allowing
password migration (nsslapd-allow-hashed-passwords) and then
subsequently migrating an INVALID password to the server.

Fix Description:  slapi_ct_memcmp now access n1, n2 size
and will FAIL if they are not the same, but will still compare
n bytes, where n is the "longest" memory, to the first byte
of the other to prevent length disclosure of the shorter
value (generally the mis-migrated password)

https://bugzilla.redhat.com/show_bug.cgi?id=1525628

Author: wibrown

Review by: ???

Gbp-Pq: Name CVE-2017-15135.patch

5 years agoFix the path to systemctl binary
Timo Aaltonen [Wed, 12 Feb 2020 17:39:22 +0000 (17:39 +0000)]
Fix the path to systemctl binary

Gbp-Pq: Name fix-systemctl-path.diff

5 years agofix-saslpath
Debian FreeIPA Team [Wed, 12 Feb 2020 17:39:22 +0000 (17:39 +0000)]
fix-saslpath

Gbp-Pq: Name fix-saslpath.diff

5 years ago389-ds-base (1.4.3.2-1) unstable; urgency=medium
Timo Aaltonen [Wed, 12 Feb 2020 17:39:22 +0000 (17:39 +0000)]
389-ds-base (1.4.3.2-1) unstable; urgency=medium

  * New upstream release.
  * prerm: Fix slapd install path. (Closes: #945583)
  * install: Updated.
  * control: Use debhelper-compat.

[dgit import unpatched 389-ds-base 1.4.3.2-1]

5 years agoImport 389-ds-base_1.4.3.2.orig.tar.bz2
Timo Aaltonen [Wed, 12 Feb 2020 17:39:22 +0000 (17:39 +0000)]
Import 389-ds-base_1.4.3.2.orig.tar.bz2

[dgit import orig 389-ds-base_1.4.3.2.orig.tar.bz2]

5 years agoImport 389-ds-base_1.4.3.2-1.debian.tar.xz
Timo Aaltonen [Wed, 12 Feb 2020 17:39:22 +0000 (17:39 +0000)]
Import 389-ds-base_1.4.3.2-1.debian.tar.xz

[dgit import tarball 389-ds-base 1.4.3.2-1 389-ds-base_1.4.3.2-1.debian.tar.xz]

6 years agoMerge version 1.4.1.6-4+rpi1 and 1.4.2.4-1 to produce 1.4.2.4-1+rpi1 archive/raspbian/1.4.2.4-1+rpi1 raspbian/1.4.2.4-1+rpi1
Raspbian automatic forward porter [Sat, 30 Nov 2019 14:27:57 +0000 (14:27 +0000)]
Merge version 1.4.1.6-4+rpi1 and 1.4.2.4-1 to produce 1.4.2.4-1+rpi1

6 years agoMerge 389-ds-base (1.4.2.4-1) import into refs/heads/workingbranch
Timo Aaltonen [Tue, 26 Nov 2019 22:00:59 +0000 (22:00 +0000)]
Merge 389-ds-base (1.4.2.4-1) import into refs/heads/workingbranch

6 years agodrop-old-man
Debian FreeIPA Team [Tue, 26 Nov 2019 22:00:59 +0000 (22:00 +0000)]
drop-old-man

Gbp-Pq: Name drop-old-man.diff

6 years agoTicket bz1525628 - invalid password migration causes unauth bind
William Brown [Thu, 18 Jan 2018 01:27:58 +0000 (11:27 +1000)]
Ticket bz1525628 - invalid password migration causes unauth bind

Bug Description:  Slapi_ct_memcmp expects both inputs to be
at LEAST size n. If they are not, we only compared UP to n.

Invalid migrations of passwords (IE {CRYPT}XX) would create
a pw which is just salt and no hash. ct_memcmp would then
only verify the salt bits and would allow the authentication.

This relies on an administrative mistake both of allowing
password migration (nsslapd-allow-hashed-passwords) and then
subsequently migrating an INVALID password to the server.

Fix Description:  slapi_ct_memcmp now access n1, n2 size
and will FAIL if they are not the same, but will still compare
n bytes, where n is the "longest" memory, to the first byte
of the other to prevent length disclosure of the shorter
value (generally the mis-migrated password)

https://bugzilla.redhat.com/show_bug.cgi?id=1525628

Author: wibrown

Review by: ???

Gbp-Pq: Name CVE-2017-15135.patch

6 years agofix-systemctl-path
Debian FreeIPA Team [Tue, 26 Nov 2019 22:00:59 +0000 (22:00 +0000)]
fix-systemctl-path

Gbp-Pq: Name fix-systemctl-path.diff

6 years agofix-saslpath
Debian FreeIPA Team [Tue, 26 Nov 2019 22:00:59 +0000 (22:00 +0000)]
fix-saslpath

Gbp-Pq: Name fix-saslpath.diff

6 years ago389-ds-base (1.4.2.4-1) unstable; urgency=medium
Timo Aaltonen [Tue, 26 Nov 2019 22:00:59 +0000 (22:00 +0000)]
389-ds-base (1.4.2.4-1) unstable; urgency=medium

  * New upstream release.
    - CVE-2019-14824 deref plugin displays restricted attributes
      (Closes: #944150)
  * fix-obsolete-target.diff: Dropped, obsolete
    drop-old-man.diff: Refreshed
  * control: Add python3-packaging to build-depends and python3-lib389 depends.
  * dev,libs.install: Nunc-stans got dropped.
  * source/local-options: Add some files to diff-ignore.
  * rules: Refresh list of files to purge.
  * rules: Update dh_auto_clean override.

[dgit import unpatched 389-ds-base 1.4.2.4-1]

6 years agoImport 389-ds-base_1.4.2.4.orig.tar.bz2
Timo Aaltonen [Tue, 26 Nov 2019 22:00:59 +0000 (22:00 +0000)]
Import 389-ds-base_1.4.2.4.orig.tar.bz2

[dgit import orig 389-ds-base_1.4.2.4.orig.tar.bz2]

6 years agoImport 389-ds-base_1.4.2.4-1.debian.tar.xz
Timo Aaltonen [Tue, 26 Nov 2019 22:00:59 +0000 (22:00 +0000)]
Import 389-ds-base_1.4.2.4-1.debian.tar.xz

[dgit import tarball 389-ds-base 1.4.2.4-1 389-ds-base_1.4.2.4-1.debian.tar.xz]

6 years agoMerge version 1.4.1.5-1+rpi1 and 1.4.1.6-4 to produce 1.4.1.6-4+rpi1 archive/raspbian/1.4.1.6-4+rpi1 raspbian/1.4.1.6-4+rpi1
Raspbian automatic forward porter [Fri, 27 Sep 2019 22:11:58 +0000 (23:11 +0100)]
Merge version 1.4.1.5-1+rpi1 and 1.4.1.6-4 to produce 1.4.1.6-4+rpi1

6 years agoMerge 389-ds-base (1.4.1.6-4) import into refs/heads/workingbranch
Timo Aaltonen [Mon, 16 Sep 2019 22:37:39 +0000 (23:37 +0100)]
Merge 389-ds-base (1.4.1.6-4) import into refs/heads/workingbranch

6 years agodrop-old-man
Debian FreeIPA Team [Mon, 16 Sep 2019 22:37:39 +0000 (23:37 +0100)]
drop-old-man

Gbp-Pq: Name drop-old-man.diff

6 years agoTicket bz1525628 - invalid password migration causes unauth bind
William Brown [Thu, 18 Jan 2018 01:27:58 +0000 (11:27 +1000)]
Ticket bz1525628 - invalid password migration causes unauth bind

Bug Description:  Slapi_ct_memcmp expects both inputs to be
at LEAST size n. If they are not, we only compared UP to n.

Invalid migrations of passwords (IE {CRYPT}XX) would create
a pw which is just salt and no hash. ct_memcmp would then
only verify the salt bits and would allow the authentication.

This relies on an administrative mistake both of allowing
password migration (nsslapd-allow-hashed-passwords) and then
subsequently migrating an INVALID password to the server.

Fix Description:  slapi_ct_memcmp now access n1, n2 size
and will FAIL if they are not the same, but will still compare
n bytes, where n is the "longest" memory, to the first byte
of the other to prevent length disclosure of the shorter
value (generally the mis-migrated password)

https://bugzilla.redhat.com/show_bug.cgi?id=1525628

Author: wibrown

Review by: ???

Gbp-Pq: Name CVE-2017-15135.patch

6 years agofix-systemctl-path
Debian FreeIPA Team [Mon, 16 Sep 2019 22:37:39 +0000 (23:37 +0100)]
fix-systemctl-path

Gbp-Pq: Name fix-systemctl-path.diff

6 years agofix-saslpath
Debian FreeIPA Team [Mon, 16 Sep 2019 22:37:39 +0000 (23:37 +0100)]
fix-saslpath

Gbp-Pq: Name fix-saslpath.diff

6 years agofix-obsolete-target
Debian FreeIPA Team [Mon, 16 Sep 2019 22:37:39 +0000 (23:37 +0100)]
fix-obsolete-target

Gbp-Pq: Name fix-obsolete-target.diff

6 years ago389-ds-base (1.4.1.6-4) unstable; urgency=medium
Timo Aaltonen [Mon, 16 Sep 2019 22:37:39 +0000 (23:37 +0100)]
389-ds-base (1.4.1.6-4) unstable; urgency=medium

  * tests: Redirect stderr to stdout.

[dgit import unpatched 389-ds-base 1.4.1.6-4]

6 years agoImport 389-ds-base_1.4.1.6-4.debian.tar.xz
Timo Aaltonen [Mon, 16 Sep 2019 22:37:39 +0000 (23:37 +0100)]
Import 389-ds-base_1.4.1.6-4.debian.tar.xz

[dgit import tarball 389-ds-base 1.4.1.6-4 389-ds-base_1.4.1.6-4.debian.tar.xz]

6 years agoImport 389-ds-base_1.4.1.6.orig.tar.bz2
Timo Aaltonen [Wed, 11 Sep 2019 14:01:03 +0000 (15:01 +0100)]
Import 389-ds-base_1.4.1.6.orig.tar.bz2

[dgit import orig 389-ds-base_1.4.1.6.orig.tar.bz2]

6 years agoMerge version 1.4.0.22-1+rpi1 and 1.4.1.5-1 to produce 1.4.1.5-1+rpi1 archive/raspbian/1.4.1.5-1+rpi1 raspbian/1.4.1.5-1+rpi1
Raspbian automatic forward porter [Sat, 7 Sep 2019 02:11:31 +0000 (03:11 +0100)]
Merge version 1.4.0.22-1+rpi1 and 1.4.1.5-1 to produce 1.4.1.5-1+rpi1

6 years agoMerge 389-ds-base (1.4.0.22-1+rpi1) import into refs/heads/workingbranch
Raspbian forward porter [Thu, 11 Jul 2019 17:33:27 +0000 (18:33 +0100)]
Merge 389-ds-base (1.4.0.22-1+rpi1) import into refs/heads/workingbranch

6 years agofix-dsctl-remove
Debian FreeIPA Team [Thu, 11 Jul 2019 17:33:27 +0000 (18:33 +0100)]
fix-dsctl-remove

Gbp-Pq: Name fix-dsctl-remove.diff

6 years agofix-nss-path
Debian FreeIPA Team [Thu, 11 Jul 2019 17:33:27 +0000 (18:33 +0100)]
fix-nss-path

Gbp-Pq: Name fix-nss-path.diff

6 years agoicu_pkg-config
Debian FreeIPA Team [Thu, 11 Jul 2019 17:33:27 +0000 (18:33 +0100)]
icu_pkg-config

Gbp-Pq: Name icu_pkg-config.patch

6 years agoperl-use-move-instead-of-rename
Debian FreeIPA Team [Thu, 11 Jul 2019 17:33:27 +0000 (18:33 +0100)]
perl-use-move-instead-of-rename

Gbp-Pq: Name perl-use-move-instead-of-rename.diff

6 years agoTicket bz1525628 - invalid password migration causes unauth bind
William Brown [Thu, 18 Jan 2018 01:27:58 +0000 (11:27 +1000)]
Ticket bz1525628 - invalid password migration causes unauth bind

Bug Description:  Slapi_ct_memcmp expects both inputs to be
at LEAST size n. If they are not, we only compared UP to n.

Invalid migrations of passwords (IE {CRYPT}XX) would create
a pw which is just salt and no hash. ct_memcmp would then
only verify the salt bits and would allow the authentication.

This relies on an administrative mistake both of allowing
password migration (nsslapd-allow-hashed-passwords) and then
subsequently migrating an INVALID password to the server.

Fix Description:  slapi_ct_memcmp now access n1, n2 size
and will FAIL if they are not the same, but will still compare
n bytes, where n is the "longest" memory, to the first byte
of the other to prevent length disclosure of the shorter
value (generally the mis-migrated password)

https://bugzilla.redhat.com/show_bug.cgi?id=1525628

Author: wibrown

Review by: ???

Gbp-Pq: Name CVE-2017-15135.patch

6 years agofix-systemctl-path
Debian FreeIPA Team [Thu, 11 Jul 2019 17:33:27 +0000 (18:33 +0100)]
fix-systemctl-path

Gbp-Pq: Name fix-systemctl-path.diff

6 years agofix-saslpath
Debian FreeIPA Team [Thu, 11 Jul 2019 17:33:27 +0000 (18:33 +0100)]
fix-saslpath

Gbp-Pq: Name fix-saslpath.diff

6 years agofix-obsolete-target
Debian FreeIPA Team [Thu, 11 Jul 2019 17:33:27 +0000 (18:33 +0100)]
fix-obsolete-target

Gbp-Pq: Name fix-obsolete-target.diff

6 years agorename-online-scripts
Debian FreeIPA Team [Thu, 11 Jul 2019 17:33:27 +0000 (18:33 +0100)]
rename-online-scripts

Gbp-Pq: Name rename-online-scripts.diff

6 years agouse-bash-instead-of-sh
Debian FreeIPA Team [Thu, 11 Jul 2019 17:33:27 +0000 (18:33 +0100)]
use-bash-instead-of-sh

Gbp-Pq: Name use-bash-instead-of-sh.diff

6 years ago389-ds-base (1.4.0.22-1+rpi1) bullseye-staging; urgency=medium
Raspbian forward porter [Thu, 11 Jul 2019 17:33:27 +0000 (18:33 +0100)]
389-ds-base (1.4.0.22-1+rpi1) bullseye-staging; urgency=medium

  [changes brought forward from 1.4.0.19-2+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Thu, 27 Dec 2018 01:27:25 +0000]
  * Add -latomic to LDFLAGS on armhf too.

[dgit import unpatched 389-ds-base 1.4.0.22-1+rpi1]

6 years agoImport 389-ds-base_1.4.0.22-1+rpi1.debian.tar.xz
Raspbian forward porter [Thu, 11 Jul 2019 17:33:27 +0000 (18:33 +0100)]
Import 389-ds-base_1.4.0.22-1+rpi1.debian.tar.xz

[dgit import tarball 389-ds-base 1.4.0.22-1+rpi1 389-ds-base_1.4.0.22-1+rpi1.debian.tar.xz]

6 years agoMerge 389-ds-base (1.4.1.5-1) import into refs/heads/workingbranch
Timo Aaltonen [Wed, 10 Jul 2019 07:05:31 +0000 (08:05 +0100)]
Merge 389-ds-base (1.4.1.5-1) import into refs/heads/workingbranch

6 years agoperl-use-move-instead-of-rename
Debian FreeIPA Team [Wed, 10 Jul 2019 07:05:31 +0000 (08:05 +0100)]
perl-use-move-instead-of-rename

Gbp-Pq: Name perl-use-move-instead-of-rename.diff

6 years agoTicket bz1525628 - invalid password migration causes unauth bind
William Brown [Thu, 18 Jan 2018 01:27:58 +0000 (11:27 +1000)]
Ticket bz1525628 - invalid password migration causes unauth bind

Bug Description:  Slapi_ct_memcmp expects both inputs to be
at LEAST size n. If they are not, we only compared UP to n.

Invalid migrations of passwords (IE {CRYPT}XX) would create
a pw which is just salt and no hash. ct_memcmp would then
only verify the salt bits and would allow the authentication.

This relies on an administrative mistake both of allowing
password migration (nsslapd-allow-hashed-passwords) and then
subsequently migrating an INVALID password to the server.

Fix Description:  slapi_ct_memcmp now access n1, n2 size
and will FAIL if they are not the same, but will still compare
n bytes, where n is the "longest" memory, to the first byte
of the other to prevent length disclosure of the shorter
value (generally the mis-migrated password)

https://bugzilla.redhat.com/show_bug.cgi?id=1525628

Author: wibrown

Review by: ???

Gbp-Pq: Name CVE-2017-15135.patch

6 years agofix-systemctl-path
Debian FreeIPA Team [Wed, 10 Jul 2019 07:05:31 +0000 (08:05 +0100)]
fix-systemctl-path

Gbp-Pq: Name fix-systemctl-path.diff

6 years agofix-saslpath
Debian FreeIPA Team [Wed, 10 Jul 2019 07:05:31 +0000 (08:05 +0100)]
fix-saslpath

Gbp-Pq: Name fix-saslpath.diff

6 years agofix-obsolete-target
Debian FreeIPA Team [Wed, 10 Jul 2019 07:05:31 +0000 (08:05 +0100)]
fix-obsolete-target

Gbp-Pq: Name fix-obsolete-target.diff

6 years agorename-online-scripts
Debian FreeIPA Team [Wed, 10 Jul 2019 07:05:31 +0000 (08:05 +0100)]
rename-online-scripts

Gbp-Pq: Name rename-online-scripts.diff

6 years agouse-bash-instead-of-sh
Debian FreeIPA Team [Wed, 10 Jul 2019 07:05:31 +0000 (08:05 +0100)]
use-bash-instead-of-sh

Gbp-Pq: Name use-bash-instead-of-sh.diff

6 years ago389-ds-base (1.4.1.5-1) unstable; urgency=medium
Timo Aaltonen [Wed, 10 Jul 2019 07:05:31 +0000 (08:05 +0100)]
389-ds-base (1.4.1.5-1) unstable; urgency=medium

  * New upstream release.
  * watch: Use https.
  * control: Bump policy to 4.4.0.
  * Bump debhelper to 12.
  * patches: fix-dsctl-remove.diff, fix-nss-path.diff, icu_pkg-config.patch
    removed, upstream. Others refreshed.
  * rules: Pass --enable-perl, we still need the perl tools.
  * *.install: Updated.

[dgit import unpatched 389-ds-base 1.4.1.5-1]

6 years agoImport 389-ds-base_1.4.1.5.orig.tar.bz2
Timo Aaltonen [Wed, 10 Jul 2019 07:05:31 +0000 (08:05 +0100)]
Import 389-ds-base_1.4.1.5.orig.tar.bz2

[dgit import orig 389-ds-base_1.4.1.5.orig.tar.bz2]

6 years agoImport 389-ds-base_1.4.1.5-1.debian.tar.xz
Timo Aaltonen [Wed, 10 Jul 2019 07:05:31 +0000 (08:05 +0100)]
Import 389-ds-base_1.4.1.5-1.debian.tar.xz

[dgit import tarball 389-ds-base 1.4.1.5-1 389-ds-base_1.4.1.5-1.debian.tar.xz]

6 years agoMerge 389-ds-base (1.4.0.22-1) import into refs/heads/workingbranch
Timo Aaltonen [Fri, 5 Apr 2019 21:32:06 +0000 (22:32 +0100)]
Merge 389-ds-base (1.4.0.22-1) import into refs/heads/workingbranch

6 years agoImport 389-ds-base_1.4.0.22.orig.tar.bz2
Timo Aaltonen [Fri, 5 Apr 2019 21:32:06 +0000 (22:32 +0100)]
Import 389-ds-base_1.4.0.22.orig.tar.bz2

[dgit import orig 389-ds-base_1.4.0.22.orig.tar.bz2]

6 years agofix-dsctl-remove
Debian FreeIPA Team [Fri, 5 Apr 2019 21:32:06 +0000 (22:32 +0100)]
fix-dsctl-remove

Gbp-Pq: Name fix-dsctl-remove.diff

6 years agofix-nss-path
Debian FreeIPA Team [Fri, 5 Apr 2019 21:32:06 +0000 (22:32 +0100)]
fix-nss-path

Gbp-Pq: Name fix-nss-path.diff

6 years agoicu_pkg-config
Debian FreeIPA Team [Fri, 5 Apr 2019 21:32:06 +0000 (22:32 +0100)]
icu_pkg-config

Gbp-Pq: Name icu_pkg-config.patch

6 years agoperl-use-move-instead-of-rename
Debian FreeIPA Team [Fri, 5 Apr 2019 21:32:06 +0000 (22:32 +0100)]
perl-use-move-instead-of-rename

Gbp-Pq: Name perl-use-move-instead-of-rename.diff

6 years agoTicket bz1525628 - invalid password migration causes unauth bind
William Brown [Thu, 18 Jan 2018 01:27:58 +0000 (11:27 +1000)]
Ticket bz1525628 - invalid password migration causes unauth bind

Bug Description:  Slapi_ct_memcmp expects both inputs to be
at LEAST size n. If they are not, we only compared UP to n.

Invalid migrations of passwords (IE {CRYPT}XX) would create
a pw which is just salt and no hash. ct_memcmp would then
only verify the salt bits and would allow the authentication.

This relies on an administrative mistake both of allowing
password migration (nsslapd-allow-hashed-passwords) and then
subsequently migrating an INVALID password to the server.

Fix Description:  slapi_ct_memcmp now access n1, n2 size
and will FAIL if they are not the same, but will still compare
n bytes, where n is the "longest" memory, to the first byte
of the other to prevent length disclosure of the shorter
value (generally the mis-migrated password)

https://bugzilla.redhat.com/show_bug.cgi?id=1525628

Author: wibrown

Review by: ???

Gbp-Pq: Name CVE-2017-15135.patch

6 years agofix-systemctl-path
Debian FreeIPA Team [Fri, 5 Apr 2019 21:32:06 +0000 (22:32 +0100)]
fix-systemctl-path

Gbp-Pq: Name fix-systemctl-path.diff

6 years agofix-saslpath
Debian FreeIPA Team [Fri, 5 Apr 2019 21:32:06 +0000 (22:32 +0100)]
fix-saslpath

Gbp-Pq: Name fix-saslpath.diff

6 years agofix-obsolete-target
Debian FreeIPA Team [Fri, 5 Apr 2019 21:32:06 +0000 (22:32 +0100)]
fix-obsolete-target

Gbp-Pq: Name fix-obsolete-target.diff