Age | Commit message (Collapse) | Author | Files | Lines | |
---|---|---|---|---|---|
2011-08-11 | Use sysdb attribute name for GID, not LDAP attribute | Stephen Gallagher | 1 | -3/+3 | |
2011-08-11 | Allow the O_NONBLOCK flag to be reset correctly | Ralf Haferkamp | 1 | -14/+0 | |
sssd set the O_NONBLOCK flag on the LDAP socket twice. First in set_fd_flags_and_opts(). And the second time in sdap_async_sys_connect_send() after storing a backup in the local state structure. The backup is later used to restore the original flags (after connect() succeeded). As NONBLOCK was already set before it didn't correctly reset that flag. https://fedorahosted.org/sssd/ticket/952 | |||||
2011-08-10 | Fix potential double-free issue | Stephen Gallagher | 1 | -1/+1 | |
tmp_ctx is a child of ctx. | |||||
2011-08-10 | Cancel sysdb upgrade transaction if commit fails | Stephen Gallagher | 1 | -60/+30 | |
2011-08-08 | Remove unused temporary context | Jakub Hrozek | 1 | -5/+0 | |
2011-08-08 | Prevent segfault if vetoed_shells are specified without allowed_shells | Jakub Hrozek | 1 | -16/+19 | |
https://fedorahosted.org/sssd/ticket/954 | |||||
2011-08-08 | Fixed implicit declaration of function 'time' in src/sss_client/common.c. | Pavel Březina | 1 | -0/+1 | |
2011-08-08 | debug_timestamps fixes | Pavel Březina | 4 | -14/+24 | |
Fixed: could not overwrite debug_timestamps when set in sssd.conf Fixed: invalid description of debug_timestamps in sssd man page | |||||
2011-08-08 | Rename sssd.conf to sssd-example.conf | Stephen Gallagher | 1 | -1/+1 | |
This file should not be installed by default. It leads to user confusion. We will instead install it as documentation. Fix incorrect example of entry_cache_nowait_percentage | |||||
2011-08-04 | Revert "Allow LDAP to decide when an expiration warning is warranted" | Stephen Gallagher | 1 | -4/+3 | |
This reverts commit b0b9c38dfce3e3ccbfaa4d00fdf2ea08a70d41a6. | |||||
2011-08-04 | Fix returning groups when gidNumber attribute is not ordered | Jakub Hrozek | 3 | -4/+10 | |
https://fedorahosted.org/sssd/ticket/951 | |||||
2011-08-04 | pyhbac: Do not convert int to bool | Jakub Hrozek | 1 | -2/+11 | |
2011-08-03 | Fix two man page typos | Yuri Chornoivan | 2 | -2/+2 | |
2011-08-02 | Updating translations for 1.6.0 release | Stephen Gallagher | 6 | -2596/+4336 | |
2011-08-01 | Allow LDAP to decide when an expiration warning is warranted | Stephen Gallagher | 1 | -3/+4 | |
Previously, we were only displaying expiration warnings if the password was going to expire within a day. We'll allow LDAP to make this decision (by whether it passes us the expiration time). In the future, we can add an option to clamp this down to a shorter period if the local admin prefers it. | |||||
2011-08-01 | Request password control unconditionally during bind | Jakub Hrozek | 1 | -6/+6 | |
https://fedorahosted.org/sssd/ticket/940 | |||||
2011-08-01 | HBAC rule validation Python bindings | Jakub Hrozek | 2 | -0/+129 | |
https://fedorahosted.org/sssd/ticket/943 | |||||
2011-08-01 | Change the default value of ldap_tls_cacert in IPA provider | Jakub Hrozek | 1 | -1/+1 | |
https://fedorahosted.org/sssd/ticket/944 | |||||
2011-08-01 | Add rule validator to libipa_hbac | Stephen Gallagher | 3 | -0/+189 | |
https://fedorahosted.org/sssd/ticket/943 | |||||
2011-08-01 | Remove incorrect private variable | Stephen Gallagher | 1 | -1/+1 | |
This caused no ill effects, since it wasn't used in the callback. However, it is a layering violation (especially since req is freed in the callback) | |||||
2011-08-01 | Wrong paramater to sysdb_attrs_add_uint32 | Jakub Hrozek | 1 | -1/+1 | |
2011-07-29 | Converge accept_fd_handler and accept_priv_fd_handler | Stephen Gallagher | 1 | -85/+50 | |
These two functions were almost identical. Better to maintain them as a single function. | |||||
2011-07-29 | Fix incorrect NULL check in ipa_hbac_common.c | Stephen Gallagher | 1 | -1/+1 | |
https://fedorahosted.org/sssd/ticket/936 | |||||
2011-07-29 | Fix memory leak in ipa_hbac_evaluate_rules | Stephen Gallagher | 1 | -0/+1 | |
https://fedorahosted.org/sssd/ticket/933 | |||||
2011-07-29 | Add vetoed_shells option | John Hodrien | 6 | -1/+27 | |
There may be users in LDAP that have a valid but unwelcome shell set in their account. This adds a blacklist of shells that should always be replaced by the fallback_shell. Signed-off-by: Stephen Gallagher <sgallagh@redhat.com> | |||||
2011-07-29 | sss_client: avoid leaking file descriptors | Simo Sorce | 1 | -0/+3 | |
If a pam or nss module is dlcolse()d and unloaded we were leaking the file descriptor used to communicate to sssd in the process. Make sure the fucntion used to close the socket file descriptor is called on dlclose() Silence autoconf 2.28 warnings (Patch by Jakub Hrozek) | |||||
2011-07-29 | UTF8 HBAC test | Jakub Hrozek | 1 | -0/+117 | |
2011-07-29 | libipa_hbac: Support case-insensitive comparisons with UTF8 | Stephen Gallagher | 2 | -16/+107 | |
2011-07-27 | Handle allocation error in python HBAC bindings | Jakub Hrozek | 1 | -0/+3 | |
https://fedorahosted.org/sssd/ticket/934 | |||||
2011-07-27 | Remove dead code from python HBAC bindings | Jakub Hrozek | 1 | -4/+0 | |
https://fedorahosted.org/sssd/ticket/935 | |||||
2011-07-27 | Explicitly ignore groups with gidNumber=0 | Jakub Hrozek | 2 | -11/+18 | |
https://fedorahosted.org/sssd/ticket/916 | |||||
2011-07-27 | Set gidNumber of non-posix groups to 0 even on updates | Jakub Hrozek | 1 | -8/+44 | |
2011-07-27 | silence compilation warnings on RHEL5 | pbrezina | 1 | -12/+13 | |
https://fedorahosted.org/sssd/ticket/930 | |||||
2011-07-21 | Fix indexing of skipped groups | Jakub Hrozek | 1 | -2/+4 | |
https://fedorahosted.org/sssd/ticket/928 | |||||
2011-07-21 | fo_get_server_name() getter for a server name | Jakub Hrozek | 6 | -4/+32 | |
Allows to be more concise in tests and more defensive in resolve callbacks | |||||
2011-07-21 | Rename fo_get_server_name to fo_get_server_str_name | Jakub Hrozek | 7 | -11/+11 | |
2011-07-21 | Only print server address if one is available | Jakub Hrozek | 1 | -0/+7 | |
2011-07-21 | Do not add a NULL host parsed from LDAP URI | Jakub Hrozek | 1 | -1/+8 | |
https://fedorahosted.org/sssd/ticket/911 | |||||
2011-07-13 | Fix python HBAC bindings for python <= 2.4 | Jakub Hrozek | 5 | -84/+311 | |
Several parts of the HBAC python bindings did not work with old Python versions, such as the one shipped in RHEL5. The changes include: * a compatibility wrapper around python set object * PyModule_AddIntMacro compat macro * Py_ssize_t compat definition * Do not use PyUnicode_FromFormat * several function prototypes and structures used to have "char arguments where they have "const char *" in recent versions. This caused compilation warnings this patch mitigates by using the discard_const hack on python 2.4 | |||||
2011-07-13 | Fixes for python HBAC bindings | Jakub Hrozek | 2 | -12/+105 | |
These changes were proposed during a review: * Change the signature of str_concat_sequence() to const char * * use a getsetter for HbacRule.enabled to allow string true/false and integer 1/0 in addition to bool * fix a minor memory leak (HbacRequest.rule_name) * remove overzealous discard consts | |||||
2011-07-13 | Use ares_search instead of ares_query for hostname resolution | Jakub Hrozek | 1 | -1/+1 | |
ares_query does not take search or domain directives from /etc/resolv.conf into account https://fedorahosted.org/sssd/ticket/922 | |||||
2011-07-13 | Remove unused krb5_service structure member | Jakub Hrozek | 3 | -7/+1 | |
2011-07-11 | Check DNS records before updating | Jakub Hrozek | 4 | -25/+470 | |
https://fedorahosted.org/sssd/ticket/802 | |||||
2011-07-11 | Allow returning arbitrary address from resolv_hostent as string | Jakub Hrozek | 2 | -3/+10 | |
2011-07-11 | Split reading resolver family order into a separate function | Jakub Hrozek | 3 | -23/+52 | |
2011-07-11 | Do not hardcode default resolver timeout | Jakub Hrozek | 2 | -1/+3 | |
2011-07-11 | Escape IP address in kdcinfo | Jakub Hrozek | 2 | -14/+36 | |
https://fedorahosted.org/sssd/ticket/909 | |||||
2011-07-11 | Move IP adress escaping from the LDAP namespace | Jakub Hrozek | 5 | -14/+14 | |
2011-07-08 | Allow NULL memctx in sysdb_custom_subtree_dn | Stephen Gallagher | 1 | -3/+11 | |
ldb_dn_new_fmt() has a bug and cannot take a NULL memory context | |||||
2011-07-08 | Add LDAP access control based on NDS attributes | Sumit Bose | 9 | -3/+253 | |