Age | Commit message (Collapse) | Author | Files | Lines | |
---|---|---|---|---|---|
2012-09-04 | SSH: Simplify public key formatting function | Jan Cholasta | 4 | -46/+12 | |
2012-09-04 | SSH: Return error code in SSH utility functions | Jan Cholasta | 4 | -29/+54 | |
2012-09-04 | Adding -std=gnu99 flag. | Michal Zidek | 1 | -1/+2 | |
2012-09-04 | Check if the SELinux login directory exists | Jakub Hrozek | 3 | -3/+13 | |
https://fedorahosted.org/sssd/ticket/1492 | |||||
2012-08-29 | RPM: Always include the patch file | Jakub Hrozek | 1 | -2/+0 | |
2012-08-28 | RPM: Switch the default ccache location | Jakub Hrozek | 3 | -1/+29 | |
https://fedorahosted.org/sssd/ticket/1500 | |||||
2012-08-27 | Use PTHREAD_MUTEX_ROBUST to avoid deadlock in the client | Jakub Hrozek | 3 | -8/+115 | |
https://fedorahosted.org/sssd/ticket/1460 | |||||
2012-08-24 | Use new debug levels in validate_tgt() | Sumit Bose | 1 | -13/+16 | |
2012-08-24 | Fix fallback in validate_tgt() | Sumit Bose | 1 | -8/+20 | |
To validate a TGT a keytab entry from the client realm is preferred but if none ca be found the last entry should be used. But the entry was freed and zeroed before it could be used. This should also fix the trusted domain use case mentioned in https://fedorahosted.org/sssd/ticket/1396 although a different approach then suggested in the ticket is used. | |||||
2012-08-23 | Fix: IPv6 address with square brackets doesn't work. | Michal Zidek | 6 | -1/+67 | |
https://fedorahosted.org/sssd/ticket/1365 | |||||
2012-08-23 | Unify usage of sysdb transactions | Michal Zidek | 20 | -67/+270 | |
Removing bad examples of usage of sysdb_transaction_start/commit/end functions and making it more consistent (all files except of src/db/sysdb_*.c). | |||||
2012-08-23 | Typo in debug message (SSSd -> SSSD). | Michal Zidek | 1 | -1/+1 | |
https://fedorahosted.org/sssd/ticket/1434 | |||||
2012-08-23 | Clean up cache on server reinitialization | Pavel Březina | 6 | -4/+404 | |
https://fedorahosted.org/sssd/ticket/734 We successfully detect when the server is reinitialized by testing the new lastUSN value. The maximum USN values are set to zero, but the current cache content remains. This patch removes records that were deleted from the server. It uses the following approach: 1. remove entryUSN attribute from all entries 2. run enumeration 3. remove records that doesn't have entryUSN attribute updated We don't need to do this for sudo rules, they will be refreshed automatically during next smart/full refresh, or when an expired rule is deleted. | |||||
2012-08-23 | Consolidation of functions that make realm upper-case | Ondrej Kos | 5 | -31/+28 | |
2012-08-23 | AD context was set to null due to type mismatch | Ondrej Kos | 3 | -1/+14 | |
2012-08-21 | Remove compilation warning: ret may be uninitialized | Pavel Březina | 1 | -0/+2 | |
2012-08-21 | Unbreak build on RHEL5: replace ldap_destroy() with ldap_unbind_ext() | Pavel Březina | 1 | -1/+1 | |
ldap_destroy() is not present in RHEL5 | |||||
2012-08-21 | Close LDAP connection when unable to install TLS | Pavel Březina | 1 | -13/+13 | |
We were not closing LDAP connection when using SSL with invalid certificate. https://fedorahosted.org/sssd/ticket/1490 | |||||
2012-08-21 | accept_fd_handler: add missing return | Sumit Bose | 1 | -0/+1 | |
2012-08-21 | SYSDB: Make sysdb_attrs_get_el_int() public | Stephen Gallagher | 2 | -8/+10 | |
Also rename it to sysdb_attrs_get_el_ext() | |||||
2012-08-21 | Process all groups from a single nesting level | Jakub Hrozek | 1 | -4/+14 | |
https://bugzilla.redhat.com/show_bug.cgi?id=846664 If the first group was cached when processing the nested group membership, we would call tevent_req_done, effectivelly marking the whole nesting level as done. | |||||
2012-08-16 | Fix compilation error in Python murmurhash bindings | Jakub Hrozek | 2 | -4/+10 | |
The compilation produced an error due to missing declaration of uint32_t and a couple of warnings caused by different prototypes of argument parsing functions in older Python releases. | |||||
2012-08-16 | Only create the SELinux login file if there are mappings on the server | Jakub Hrozek | 2 | -51/+78 | |
https://fedorahosted.org/sssd/ticket/1455 In case there are no rules on the IPA server, we must simply avoid generating the login file. That would make us fall back to the system-wide default defined in /etc/selinux/targeted/seusers. The IPA default must be only used if there *are* rules on the server, but none matches. | |||||
2012-08-16 | Do not try to remove the temp login file if already renamed | Jakub Hrozek | 1 | -2/+3 | |
write_selinux_string() would try to unlink the temporary file even after it was renamed. Failure to unlink the file would not be fatal, but would produce a confusing error message. Also don't use "0" for the default fd number, that's reserved for stdin. Using -1 is safer. | |||||
2012-08-16 | Build SELinux code in responder conditionally | Jakub Hrozek | 1 | -0/+7 | |
https://fedorahosted.org/sssd/ticket/1480 | |||||
2012-08-15 | Fix LOCAL domain lookups | Pavel Březina | 1 | -19/+22 | |
https://fedorahosted.org/sssd/ticket/1436 Now subdomains are not evaluated for local domains. | |||||
2012-08-15 | Add python bindings for murmurhash3 | Sumit Bose | 4 | -3/+184 | |
2012-08-15 | KRB5: Only return PAM error for unreachable kpasswd when performing chpass | Jakub Hrozek | 1 | -2/+4 | |
https://fedorahosted.org/sssd/ticket/1452 | |||||
2012-08-15 | FO: Return EAGAIN if there are more servers to try | Jakub Hrozek | 1 | -0/+9 | |
The caller should issue a next request, which would just shortcut with ENOENT. | |||||
2012-08-15 | FO: Don't retry the same server if it's not working | Jakub Hrozek | 1 | -2/+3 | |
2012-08-15 | Duplicate detection in fail over did not work. | Michal Zidek | 9 | -15/+69 | |
https://fedorahosted.org/sssd/ticket/1472 | |||||
2012-08-13 | sss_client: Group lookups should work even when fastcache cannot be initialized | Jakub Hrozek | 1 | -8/+2 | |
https://fedorahosted.org/sssd/ticket/1415 | |||||
2012-08-13 | Add autofs-related options to configAPI | Jakub Hrozek | 2 | -1/+12 | |
https://fedorahosted.org/sssd/ticket/1478 | |||||
2012-08-10 | MAN: Improve description of ldap_*_search_base options | Stephen Gallagher | 4 | -96/+63 | |
It was ambiguous that these options supported the new multiple search base format, as well as the search filters. | |||||
2012-08-10 | When ldap_group_nesting_level was reached, the LDAP provider tried to link ↵ | Michal Zidek | 1 | -1/+45 | |
group members with groups outside nesting limit. https://fedorahosted.org/sssd/ticket/1194 | |||||
2012-08-10 | Document entry_cache_autofs_timeout | Jakub Hrozek | 1 | -0/+14 | |
2012-08-10 | remove duplicate sss_obfuscate reference in seealso manpage section | Nick Guay | 1 | -3/+0 | |
2012-08-10 | MAN: Fix minor typo in ldap_search_base section | Stephen Gallagher | 1 | -1/+1 | |
2012-08-09 | Don't use server after SRV data collapsed | Jakub Hrozek | 1 | -5/+8 | |
2012-08-09 | SRV resolution for backup servers should not be permitted. | Michal Zidek | 5 | -6/+37 | |
https://fedorahosted.org/sssd/ticket/1463 | |||||
2012-08-09 | Change default for ldap_idmap_range_min to 200000 | Jakub Hrozek | 4 | -4/+4 | |
https://fedorahosted.org/sssd/ticket/1462 | |||||
2012-08-09 | Abort PAM access phase if HBAC does not return PAM_SUCCESS | Jakub Hrozek | 1 | -0/+1 | |
2012-08-09 | Backward GOTOs rewritten into do-while loops. | Ondrej Kos | 2 | -245/+271 | |
2012-08-09 | Change default value of ldap_sasl_string to host/hostname@REALM in man page. | Michal Zidek | 1 | -1/+1 | |
https://fedorahosted.org/sssd/ticket/1464 | |||||
2012-08-08 | Replaced "id_max" & "id_min" | Ondrej Kos | 1 | -4/+4 | |
2012-08-08 | Allocate on top of a talloc context, not NULL | Jakub Hrozek | 1 | -0/+3 | |
2012-08-07 | Always mark SRV servers as primary | Jakub Hrozek | 1 | -0/+1 | |
https://fedorahosted.org/sssd/ticket/1459 | |||||
2012-08-07 | Remove SYSDB_SUDO_CACHE_OC from attribute lists | Pavel Březina | 2 | -2/+0 | |
It is not an attribute. | |||||
2012-08-07 | Rename SYSDB_SUDO_CACHE_AT_OC to SYSDB_SUDO_CACHE_OC | Pavel Březina | 5 | -8/+8 | |
It does not contain name of the object class attribute but the value itself. I renamed it to avoid confusion. | |||||
2012-08-07 | Remove redefinition of some SYSDB_* macros | Pavel Březina | 1 | -10/+0 | |