History log of /opensolaris-onvv-gate/usr/src/lib/pam_modules/krb5/krb5_setcred.c
Revision Date Author Comments
# 11780:26d2e4a6a702 26-Feb-2010 Will Fiveash <Will.Fiveash@Sun.COM>

6894506 pam_krb5 is not lint clean


# 11411:c2fe1bf96826 30-Dec-2009 Surya Prakki <Surya.Prakki@Sun.COM>

6894056 libc is not clean
6894060 libnsl is not lint clean
6894068 libpool is not lint clean
6894073 some zone libs are not lint clean
6913623 some user land components of ON are not ss12u1 lint clean


# 8991:5ab80299f68b 06-Mar-2009 Peter Shoults <Peter.Shoults@Sun.COM>

6799884 pam_krb5 could allow authentication to an attacker's KDC


# 8303:02efd6ae718f 08-Dec-2008 Peter Shoults <Peter.Shoults@Sun.COM>

6724959 pam_modules/krb5/utils.h`set_active_user() declaration is adrift
6724557 Potential for a memory leak in krb5_setcred's krb5_renew_tgt routine
6691206 pam_krb5's store_cred should always store new credentials if a previous auth pass was successful
6752096 krb5_renew_tgt incorrectly tests for the value of char *filepath


# 6924:ffea62602690 20-Jun-2008 ps57422

6607813 pam_krb5 setcred coredumps on successful refresh if auth was not previously called


# 6488:b47361eaf8f2 25-Apr-2008 semery

6455225 pam_krb5 should overwrite ccache with new credentials when handling pam_setcred(PAM_REFRESH_CRED)
6642279 kdcmgr has to run twice if the pw file option is used and an existing db is present


# 5890:9e8e51bc1851 23-Jan-2008 jjj

6483447 pam_sm_chauthtok NOT mt-safe: authtok_check/dict.c:lock_db uses alarm(2)
6548129 some pam modules can use some malloc/strdup error checking


# 4621:77407f8b6bb2 09-Jul-2007 semery

6550530 pam_krb5_migrate's expire_pw expires the Kerberos password too late
6557188 included pam_krb5 doesn't function correctly as 'auth required' in pam.conf
6559678 kpasswd returns "KDC reply did not match expectations" when using Heimdal server
6564714 Option "-m" doesn't work for kadmind.
6564718 kdb5_util dump doesn't create a "dump ok" file if the master key is not available
6570434 libkadm5srv should be smarter in figuring out the enc type of the master key in the stash file
6575452 kdb5_util should be more robust after CF providers have failed


# 3924:4a2c8e3e6786 29-Mar-2007 gtb

6531864 ktkt_warnd not warning after login


# 3391:2e4fef544e31 08-Jan-2007 semery

6266812 pam_krb5 and pam_krb5_migrate localize their syslog messages
6430941 pam_krb5 pam_sm_setcred can cause /tmp/krb5cc_<PAM_USER> to be owned by euid rather than PAM_USER
6484675 pam_krb5(5) needs some cleanup
6499804 pam_krb5 account management should not return success if user is not defined in kerberos realm
6507080 autofs no longer passing credential information in upcalls


# 781:57319a72b15f 28-Oct-2005 gtb

6224704 core kerberos mechanism resync with MIT 1.4


# 0:68f95e015346 14-Jun-2005 stevel@tonic-gate

OpenSolaris Launch


# 11780:26d2e4a6a702 26-Feb-2010 Will Fiveash <Will.Fiveash@Sun.COM>

6894506 pam_krb5 is not lint clean


# 11411:c2fe1bf96826 30-Dec-2009 Surya Prakki <Surya.Prakki@Sun.COM>

6894056 libc is not clean
6894060 libnsl is not lint clean
6894068 libpool is not lint clean
6894073 some zone libs are not lint clean
6913623 some user land components of ON are not ss12u1 lint clean


# 8991:5ab80299f68b 06-Mar-2009 Peter Shoults <Peter.Shoults@Sun.COM>

6799884 pam_krb5 could allow authentication to an attacker's KDC


# 8303:02efd6ae718f 08-Dec-2008 Peter Shoults <Peter.Shoults@Sun.COM>

6724959 pam_modules/krb5/utils.h`set_active_user() declaration is adrift
6724557 Potential for a memory leak in krb5_setcred's krb5_renew_tgt routine
6691206 pam_krb5's store_cred should always store new credentials if a previous auth pass was successful
6752096 krb5_renew_tgt incorrectly tests for the value of char *filepath


# 6924:ffea62602690 20-Jun-2008 ps57422

6607813 pam_krb5 setcred coredumps on successful refresh if auth was not previously called


# 6488:b47361eaf8f2 25-Apr-2008 semery

6455225 pam_krb5 should overwrite ccache with new credentials when handling pam_setcred(PAM_REFRESH_CRED)
6642279 kdcmgr has to run twice if the pw file option is used and an existing db is present


# 5890:9e8e51bc1851 23-Jan-2008 jjj

6483447 pam_sm_chauthtok NOT mt-safe: authtok_check/dict.c:lock_db uses alarm(2)
6548129 some pam modules can use some malloc/strdup error checking


# 4621:77407f8b6bb2 09-Jul-2007 semery

6550530 pam_krb5_migrate's expire_pw expires the Kerberos password too late
6557188 included pam_krb5 doesn't function correctly as 'auth required' in pam.conf
6559678 kpasswd returns "KDC reply did not match expectations" when using Heimdal server
6564714 Option "-m" doesn't work for kadmind.
6564718 kdb5_util dump doesn't create a "dump ok" file if the master key is not available
6570434 libkadm5srv should be smarter in figuring out the enc type of the master key in the stash file
6575452 kdb5_util should be more robust after CF providers have failed


# 3924:4a2c8e3e6786 29-Mar-2007 gtb

6531864 ktkt_warnd not warning after login


# 3391:2e4fef544e31 08-Jan-2007 semery

6266812 pam_krb5 and pam_krb5_migrate localize their syslog messages
6430941 pam_krb5 pam_sm_setcred can cause /tmp/krb5cc_<PAM_USER> to be owned by euid rather than PAM_USER
6484675 pam_krb5(5) needs some cleanup
6499804 pam_krb5 account management should not return success if user is not defined in kerberos realm
6507080 autofs no longer passing credential information in upcalls


# 781:57319a72b15f 28-Oct-2005 gtb

6224704 core kerberos mechanism resync with MIT 1.4


# 0:68f95e015346 14-Jun-2005 stevel@tonic-gate

OpenSolaris Launch