Change logs for openldap source package in Oneiric

  • openldap (2.4.25-1.1ubuntu4.1) oneiric-security; urgency=low
    
      * SECURITY UPDATE: potential denial of service (LP: #884163)
        - debian/patches/CVE-2011-4079: fix off by one error in
          postalAddressNormalize()
        - CVE-2011-4079
     -- Jamie Strandboge <email address hidden>   Mon, 14 Nov 2011 13:22:54 -0600
  • openldap (2.4.25-1.1ubuntu4) oneiric; urgency=low
    
      * Brown paper bag: really fix the .links.in handling, so we don't generate
        broken /usr/lib/${DEB_HOST_MULTIARCH} dirs.
     -- Steve Langasek <email address hidden>   Mon, 15 Aug 2011 09:43:29 +0000
  • openldap (2.4.25-1.1ubuntu3) oneiric; urgency=low
    
      * Cherry-pick multiarch support from Debian (LP: #826601):
        - Bump to compat level 7, so we don't have to spell out debian/tmp in
          every single .install file
        - Build for multiarch.
     -- Steve Langasek <email address hidden>   Mon, 15 Aug 2011 02:23:43 -0700
  • openldap (2.4.25-1.1ubuntu2) oneiric; urgency=low
    
      * debian/apparmor-profile: Allow /var/run and /run. (LP: #810270)
     -- Martin Pitt <email address hidden>   Thu, 14 Jul 2011 15:18:02 +0200
  • openldap (2.4.25-1.1ubuntu1) oneiric; urgency=low
    
      * Merge from debian unstable.  Remaining changes:
        - Install a default DIT (LP: #442498).
        - Document cn=config in README file (LP: #370784).
        - remaining changes:
          + AppArmor support:
            - debian/apparmor-profile: add AppArmor profile
            - use dh_apparmor:
              - debian/rules: use dh_apparmor
              - debian/control: Build-Depends on debhelper 7.4.20ubuntu5
            - updated debian/slapd.README.Debian for note on AppArmor
            - debian/slapd.dirs: add etc/apparmor.d/force-complain
          + Enable GSSAPI support (LP: #495418):
            - debian/patches/gssapi.diff, thanks to Jerry Carter (Likewise):
              - Add --with-gssapi support
              - Make guess_service_principal() more robust when determining
                principal
            - debian/patches/series: apply gssapi.diff patch.
            - debian/configure.options: Configure with --with-gssapi
            - debian/control: Added libkrb5-dev as a build depend
          + debian/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support
            in the openldap library, as required by Likewise-Open (LP: #390579)
          + Don't build smbk5pwd overlay since it uses heimdal instead of krb5:
            - debian/control:
              - remove build-dependency on heimdal-dev.
              - remove slapd-smbk5pwd binary package.
            - debian/rules: don't build smbk5pwd slapd module.
          + debian/{control,rules}: enable PIE hardening
          + ufw support (LP: #423246):
            - debian/control: suggest ufw.
            - debian/rules: install ufw profile.
            - debian/slapd.ufw.profile: add ufw profile.
          + Enable nssoverlay:
            - debian/patches/nssov-build, debian/series, debian/rules:
              Apply, build and package the nss overlay.
            - debian/schema/extra/misc.ldif: add ldif file for the misc schema
              which defines rfc822MailMember (required by the nss overlay).
          + debian/rules, debian/schema/extra/:
            Fix configure rule to supports extra schemas shipped as part
            of the debian/schema/ directory.
          + debian/rules, debian/slapd.py: Add apport hook. (LP: #610544)
          + debian/slapd.init.ldif: don't set olcRootDN since it's not defined in
            neither the default DIT nor via an Authn mapping.
          + debian/slapd.scripts-common: adjust minimum version that triggers a
            database upgrade. Upgrade from maverick shouldn't trigger database
            upgrade (which would happen with the version used in Debian).
          + debian/slapd.scripts-common: add slapcat_opts to local variables.
            Remove unused variable new_conf.
          + debian/slapd.script-common: Fix package reconfiguration.
            - Fix backup directory naming for multiple reconfiguration.
          + debian/slapd.default, debian/slapd.README.Debian:
            use the new configuration style.
          + Install nss overlay (LP: #675391):
            - debian/rules: run install target for nssov module.
            - debian/patches/nssov-build: fix patch to install schema in /etc/ldap/schema
          + debian/patches/gssapi.diff:
            - Update patch so that likewise-open is usuable again. (LP: #661547)
          + debian/patches/service-operational-before-detach: New patch replacing old one
            of the same name as previous could cause database corruption based on upstream commits.
            (LP: #727973)
    
    openldap (2.4.25-1.1) unstable; urgency=low
    
      * Non-maintainer upload to fix RC bug.
      * Fix "dpkg-reconfigure slapd". Closes: #596343
     -- Chuck Short <email address hidden>   Sun, 05 Jun 2011 17:38:40 +0100
  • openldap (2.4.25-1ubuntu1) oneiric; urgency=low
    
      * Merge from debian unstable.  Remaining changes:
        - Install a default DIT (LP: #442498).
        - Document cn=config in README file (LP: #370784).
        - remaining changes:
          + AppArmor support:
            - debian/apparmor-profile: add AppArmor profile
            - use dh_apparmor:
              - debian/rules: use dh_apparmor
              - debian/control: Build-Depends on debhelper 7.4.20ubuntu5
            - updated debian/slapd.README.Debian for note on AppArmor
            - debian/slapd.dirs: add etc/apparmor.d/force-complain
          + Enable GSSAPI support (LP: #495418):
            - debian/patches/gssapi.diff, thanks to Jerry Carter (Likewise):
              - Add --with-gssapi support
              - Make guess_service_principal() more robust when determining
                principal
            - debian/patches/series: apply gssapi.diff patch.
            - debian/configure.options: Configure with --with-gssapi
            - debian/control: Added libkrb5-dev as a build depend
          + debian/rules: Enable -DLDAP_CONNECTIONLESS to build CLDAP (UDP) support
            in the openldap library, as required by Likewise-Open (LP: #390579)
          + Don't build smbk5pwd overlay since it uses heimdal instead of krb5:
            - debian/control:
              - remove build-dependency on heimdal-dev.
              - remove slapd-smbk5pwd binary package.
            - debian/rules: don't build smbk5pwd slapd module.
          + debian/{control,rules}: enable PIE hardening
          + ufw support (LP: #423246):
            - debian/control: suggest ufw.
            - debian/rules: install ufw profile.
            - debian/slapd.ufw.profile: add ufw profile.
          + Enable nssoverlay:
            - debian/patches/nssov-build, debian/series, debian/rules:
              Apply, build and package the nss overlay.
            - debian/schema/extra/misc.ldif: add ldif file for the misc schema
              which defines rfc822MailMember (required by the nss overlay).
          + debian/rules, debian/schema/extra/:
            Fix configure rule to supports extra schemas shipped as part
            of the debian/schema/ directory.
          + debian/rules, debian/slapd.py: Add apport hook. (LP: #610544)
          + debian/slapd.init.ldif: don't set olcRootDN since it's not defined in
            neither the default DIT nor via an Authn mapping.
          + debian/slapd.scripts-common: adjust minimum version that triggers a
            database upgrade. Upgrade from maverick shouldn't trigger database
            upgrade (which would happen with the version used in Debian).
          + debian/slapd.scripts-common: add slapcat_opts to local variables.
            Remove unused variable new_conf.
          + debian/slapd.script-common: Fix package reconfiguration.
            - Fix backup directory naming for multiple reconfiguration.
          + debian/slapd.default, debian/slapd.README.Debian:
            use the new configuration style.
          + Install nss overlay (LP: #675391):
            - debian/rules: run install target for nssov module.
            - debian/patches/nssov-build: fix patch to install schema in /etc/ldap/schema
          + debian/patches/gssapi.diff:
            - Update patch so that likewise-open is usuable again. (LP: #661547)
          + debian/patches/service-operational-before-detach: New patch replacing old one
            of the same name as previous could cause database corruption based on upstream commits.
            (LP: #727973)
           + Dropped:
             - debian/patches/gold: Use the debian version instead
             - debian/patches/CVE-2011-1024: Fixed upstream
             - debian/patches/CVE-2011-1025: Fixed upstream
             - debian/patches/CVE-2011-1081: Fixed upstream
    
    openldap (2.4.25-1) unstable; urgency=low
    
      * New upstream version (Closes: #617606, #618904, #606815, #608813)
        - Fixes CVE-2011-1024, CVE-2011-1025, CVE-2011-1081
        - slapd server process frequently hangs during everyday usage is fixed in
          newer versions of openldap according to the bug submitter
      * Refresh all patches
      * Remove manpage-tlscyphersuite-additions, applied upstream
      * Remove issue-6534-patch, applied upstream
      * Add Slovak translation, thanks Slavko <email address hidden> (Closes: #608699)
      * Add debian specific patch for ldap.conf. Add TLS_CACERT option and set it
        by default to /etc/ssl/certs/ca-certificates.crt (Closes: #555409, #616703)
      * Add patch to fix a FTBFS with binutils-gold (Closes: #555867)
      * Add slapschema, just hardlink it (Closes: #601569)
      * Update patch service-operational-before-detach (Closes: #616164, #598361)
      * Add ldif_* symbols to libldap-2.4-2
      * Add upstream patch for a locking issue in libldap_r
      * Fix build failure, use @SHELL@ instead of hardcoded /bin/sh (build/top.mk)
        (Closes: #621925)
    
    openldap (2.4.23-7) unstable; urgency=low
    
      * Updated vietnamese translation, thanks Clytie Siddall
        (Closes: #601537, #598575)
      * Updated portuguese translation, thanks Traduz (Closes: #599760)
      * Updated danish translation, thanks Joe Dalton (Closes: #599835)
     -- Chuck Short <email address hidden>   Sun, 08 May 2011 16:34:09 +0100
  • openldap (2.4.23-6ubuntu7) oneiric; urgency=low
    
      * Rebuild for Perl 5.12.
     -- Colin Watson <email address hidden>   Sun, 08 May 2011 13:40:28 +0100
  • openldap (2.4.23-6ubuntu6) natty; urgency=low
    
      * SECURITY UPDATE: fix successful anonymous bind via chain overlay when
        using forwarded authentication failures
        - debian/patches/CVE-2011-1024
        - CVE-2011-1024
      * SECURITY UPDATE: verify password when authenticating to rootdn and using ndb
        backend. Note: Ubuntu is not compiled with --enable-ndb by default
        - debian/patches/CVE-2011-1025
        - CVE-2011-1025
      * SECURITY UPDATE: fix DoS when processing unauthenticated modrdn requests
        and requestDN is empty
        - debian/patches/CVE-2011-1081
        - CVE-2011-1081
        - LP: #742104
     -- Jamie Strandboge <email address hidden>   Thu, 07 Apr 2011 11:36:53 -0500