Fedora 23 Update: pam_krb5-2.4.12-1.fc23

updates at fedoraproject.org updates at fedoraproject.org
Fri Jan 8 20:56:04 UTC 2016


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2016-da1145ad41
2016-01-08 18:07:50.291246
--------------------------------------------------------------------------------

Name        : pam_krb5
Product     : Fedora 23
Version     : 2.4.12
Release     : 1.fc23
URL         : https://fedorahosted.org/pam_krb5/
Summary     : A Pluggable Authentication Module for Kerberos 5
Description :
This is pam_krb5, a pluggable authentication module that can be used by
PAM-aware applications to check passwords and obtain ticket granting tickets
using Kerberos 5, and to change user passwords.

--------------------------------------------------------------------------------
Update Information:

This update makes two changes:  * Fixes a likely bug when checking authorization
using APIs that usually check the user's .k5login file (should fix #1263745). *
Adds support for deriving DES keys for use in AFS tokens from session keys of
non-DES types (#1076197).  More about that second item: when obtaining
credentials for use when setting AFS tokens, earlier versions of this package
would request credentials which used only DES key types.  Starting with version
2.4.12, this is no longer be the case, as the module can now derive a suitable
key from credentials which use keys of other types.  Tokens generated using
credentials which use non-DES keys can only be accepted by servers running
OpenAFS 1.4.15 or 1.6.5 or newer.  If your cell has any keys of non-DES types
set in the KDC, but is running server software which can not accept tokens
generated from credentials which use those keys, and this can not be remedied,
please make a note of that here.
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #1076197 - please add support for rxkad-kdf for AFS tokens
        https://bugzilla.redhat.com/show_bug.cgi?id=1076197
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program. Use
su -c 'yum update pam_krb5' at the command line.
For more information, refer to "Managing Software with yum",
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the package-announce mailing list