keystone 2012.2.4-0ubuntu3 source package in Ubuntu

Changelog

keystone (2012.2.4-0ubuntu3) quantal-proposed; urgency=low

  * debian/patches/update_certs.patch: Fix FTBFS.  Original SSL certs
    for test suite expired May 18 2013. Cherry-picked regenerated certs
    from stable/folsom commit c14f2789.

keystone (2012.2.4-0ubuntu2) quantal-proposed; urgency=low

  * Rebase on latest security fixes.
  * SECURITY UPDATE: delete user token immediately upon delete when using v2
    API
    - CVE-2013-2059.patch: adjust keystone/identity/core.py to call
      token_api.delete_token() during delete. Also update test suite.
    - CVE-2013-2059
    - LP: #1166670

keystone (2012.2.4-0ubuntu1) quantal-proposed; urgency=low

  * Dropped patches, applied upstream:
    - debian/patches/CVE-2013-1865.patch: [255b1d4]
    - debian/patches/CVE-2013-0282.patch: [f0b4d30]
    - debian/patches/CVE-2013-1664+1665.patch: [8a22745]
  * Resynchronize with stable/folsom (09f28020) (LP: #1179707):
    - [5ea4fcf] V2 API reported at Beta LP: 1135230
    - [1889299] PKI-signed token hash saved as token ID for SQL backend only
      LP: 1073272
    - [40660f0] Key PKI tokens on hash in memcached for auth_token middleware
      LP: 1073343
    - [b3ce6a7] Use the right subprocess based on os monkeypatch
    - [bb1ded0] keystone-all --config-dir is being ignored LP: 1101129
    - [9e0a97d] Temporary network outage results in connection refused and
      invalid token LP: 1150299
    - [255b1d4] Validation of PKI tokens bypasses revocation check LP: 1129713
    - [8690166] PKI tokens are broken after 24 hours LP: 1074172
    - [790c87e] PKI tokens are broken after 24 hours LP: 1074172
    - [f0b4d30] EC2 authentication does not ensure user or tenant is enabled
      LP: 1121494
    - [8a22745] DoS through XML entity expansion (CVE-2013-1664) LP: 1100282
 -- James Page <email address hidden>   Wed, 29 May 2013 20:59:34 +0100

Upload details

Uploaded by:
James Page
Uploaded to:
Quantal
Original maintainer:
Ubuntu Developers
Architectures:
all
Section:
net
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Quantal: [FULLYBUILT] i386

Downloads

File Size SHA-256 Checksum
keystone_2012.2.4.orig.tar.gz 542.4 KiB ab3a9a6c1f8ef9b95a73920883294f888f298db6330b8d4ed43e28354e8ca7af
keystone_2012.2.4-0ubuntu3.debian.tar.gz 25.7 KiB 14773716404f5485521564573bb2013bb42bf9d9b8a118d90ee956c6614194cd
keystone_2012.2.4-0ubuntu3.dsc 2.4 KiB 3affbaa30085b0c354e4ccaae161321f1df09476c26c2c230d0c0e3c07a17f00

View changes file

Binary packages built by this source

keystone: No summary available for keystone in ubuntu quantal.

No description available for keystone in ubuntu quantal.

keystone-doc: No summary available for keystone-doc in ubuntu quantal.

No description available for keystone-doc in ubuntu quantal.

python-keystone: No summary available for python-keystone in ubuntu quantal.

No description available for python-keystone in ubuntu quantal.