pagure Logo
  • Log In

SSSD / sssd

Clone
Source Code
GIT
Documentation
GIT

Learn more about these different git repos.

Other Git URLs

  • Source
  • Docs
  • Issues  0
  • Pull Requests  0
  • Roadmap 
  • Stats
 Overview  Files  Commits  Branches  Forks  Releases

Commits 3696

Branch: sssd-1-9
1-0-0 1-1-0 maint-0.6 maint-0.7 master sssd-1-10 sssd-1-11 sssd-1-12 sssd-1-13 sssd-1-14 sssd-1-16 sssd-1-2 sssd-1-3 sssd-1-4 sssd-1-5 sssd-1-6 sssd-1-7 sssd-1-8 sssd-1-9
This branch contains 369 commits not in the main branch master
Updating version for 1.9.8
Jakub Hrozek • 10 years ago  
41ad910
Updating translations for the 1.9.7 release
Jakub Hrozek • 10 years ago  
a1215fb
Do not switch to credentials everytime.
Lukas Slebodnik • 10 years ago  
ce21876
Every time return directory for krb5 cache collection.
Lukas Slebodnik • 10 years ago  
da1ee87
Fix wrong detection of krb5 ccname
Lukas Slebodnik • 10 years ago  
cd1e5f2
LDAP: Setup periodic task only once.
Lukas Slebodnik • 11 years ago  
f52d80d
AUTOTOOLS: krb5 1.12 is also supported krb5 libs
Lukas Slebodnik • 11 years ago  
1ee7e7c
NSS: Fix memory leak in sss_setnetgrent
Lukas Slebodnik • 11 years ago  
3472831
do not use default_domain_suffix with autofs
Aron Parsons • 11 years ago  
1b092d8
LDAP: Initialize user count for AD matching rule
Jakub Hrozek • 11 years ago  
9fcfa6c
LDAP: Search for original DN during auth if it's missing
Jakub Hrozek • 11 years ago  
ce2c2b2
LDAP: Split out a request to search for a user w/o saving
Jakub Hrozek • 11 years ago  
ed98d79
PROXY: Handle empty GECOS
Jakub Hrozek • 11 years ago  
e913f43
proxy: Allow initgroup to return NOTFOUND
Simo Sorce • 11 years ago  
dd2936e
Inherit ID limits of parent domains if set
Jakub Hrozek • 11 years ago  
30016dd
Bumping the version for 1.9.7
Jakub Hrozek • 11 years ago  
ddc11f4
Updating translations for the 1.9.6 release
Jakub Hrozek • 11 years ago  
cd1a0c9
Updating Transifex URL
Jakub Hrozek • 11 years ago  
addb3e1
be_spy_create: free be_req and not the long living data
Sumit Bose • 11 years ago  
2a97e22
sdap_get_generic_ext_send: check if we a re still connected
Sumit Bose • 11 years ago  
1c5f201
Check slot validity before MC_SLOT_TO_PTR.
Michal Zidek • 11 years ago  
94162ba
AUTOTOOLS: Fix warnings: macro xyz not found in library
Lukas Slebodnik • 11 years ago  
1f62bcc
man sssd: Add note about SSS_NSS_USE_MEMCACHE
Michal Zidek • 11 years ago  
2e2fb25
Rename _SSS_MC_SPECIAL
Michal Zidek • 11 years ago  
f48be9b
is_dn(): free dn
Pavel Březina • 11 years ago  
f8817e0
AUTOTOOLS: More robust detection of inotify.
Lukas Slebodnik • 11 years ago  
9c393e2
AUTOTOOLS: Use pkg-config to detect libraries.
Lukas Slebodnik • 11 years ago  
e64a66e
AUTOTOOLS: add check for type intptr_t
Lukas Slebodnik • 11 years ago  
2ff2cc0
AUTOTOOLS: Refactor unicode library detection
Lukas Slebodnik • 11 years ago  
a20685b
AUTOTOOLS: Add directories for searching ldap headers and libs
Lukas Slebodnik • 11 years ago  
24a4c00
AUTOMAKE: Use portable way to link with gettext
Lukas Slebodnik • 11 years ago  
9c649c8
AUTOMAKE: Use portable way to link with dlopen
Lukas Slebodnik • 11 years ago  
ed19d07
AUTOTOOLS: Add missing AC_MSG_RESULT
Lukas Slebodnik • 11 years ago  
a53c3db
AUTOTOOLS: Add -LLIBDIR to PYTHON_LIBS
Lukas Slebodnik • 11 years ago  
09d330c
mmap_cache: Do not remove record from chain twice
Lukas Slebodnik • 11 years ago  
e5697f3
Make IPA SELinux provider aware of subdomain users
Jakub Hrozek • 11 years ago  
563cb29
UTIL: Use standard maximum value of type size_t
Lukas Slebodnik • 11 years ago  
2db20f9
Include sys/types.h for types id_t and uid_t
Lukas Slebodnik • 11 years ago  
07f8737
SIGCHLD handler: do not call callback when pvt data was freed
Pavel Březina • 11 years ago  
0e9563e
CONFIGURE: Get rid of bashism
Lukas Slebodnik • 11 years ago  
3dc0400
IPA_HBAC: Explicitelly include header file time.h
Lukas Slebodnik • 11 years ago  
b7fd1a3
MEMBEROF: Remove temporary workaround
Lukas Slebodnik • 11 years ago  
9260f20
UTIL: Explicitly include header file sys/socket.h
Lukas Slebodnik • 11 years ago  
e526b83
MONITOR: Move function declaration out of conditional build
Lukas Slebodnik • 11 years ago  
8f209f0
CLIENT: Fix non gnu sss_strnlen implementation
Lukas Slebodnik • 11 years ago  
8abef63
UTIL: Create new wraper header file sss_endian.h
Lukas Slebodnik • 11 years ago  
fc97ab8
DP: Use the correct type for DBus boolean
Jakub Hrozek • 11 years ago  
298b57a
mmap_cache: Use stricter check for hash keys.
Lukas Slebodnik • 11 years ago  
98ce2a1
mmap_cache: Skip records which doesn't have same hash
Lukas Slebodnik • 11 years ago  
b493966
sss_packet_grow: correctly pad packet length to 512B
Pavel Březina • 11 years ago  
8b9b986
Removing unused parameter type from sudosrv_get_sudorules_query_cache()
Lukas Slebodnik • 11 years ago  
1c27f00
mmap_cache: Store corrupted mmap cache before reset
Michal Zidek • 11 years ago  
6a06ea8
mmap_cache: Use better checks for corrupted mc in responder
Michal Zidek • 11 years ago  
c49ddf7
mmap_cache: Off by one error.
Michal Zidek • 11 years ago  
c58c458
mmap_cache: Remove triple checks in client code.
Michal Zidek • 11 years ago  
87fb9c0
mmap_cache: Check data->name value in client code
Michal Zidek • 11 years ago  
f01f4cc
print hint about password complexity when new password is rejected
Pavel Březina • 11 years ago  
658e275
ldap, krb5: More descriptive msg on chpass failure.
Michal Zidek • 11 years ago  
f4f0a4c
providers: refresh expired netgroups
Pavel Březina • 11 years ago  
261bc18
back end: add refresh expired records periodic task
Pavel Březina • 11 years ago  
edbafc2
back end: periodical refresh of expired records API
Pavel Březina • 11 years ago  
f47934c
back end: periodic task API
Pavel Březina • 11 years ago  
651ab87
mmap_cache: Check if slot and name_ptr are not invalid.
Michal Zidek • 11 years ago  
4fda997
resolv-tests failing with memory leak
Michal Zidek • 11 years ago  
560e2b4
Set default DNS resolution timeout to 6 seconds.
Jakub Hrozek • 11 years ago  
8d4485d
Lower timeout to contact DNS server
Michal Zidek • 11 years ago  
1e50573
Add a commit template
Simo Sorce • 11 years ago  
7a45875
init script: source /etc/sysconfig/sssd
Pavel Březina • 11 years ago  
230e4e4
Configure SYSV init scripts properly
Stephen Gallagher • 11 years ago  
60d3b25
Handle too many results from getnetgr.
Lukas Slebodnik • 11 years ago  
4a3ad2f
Do not call sss_cmd_done in function check_cache.
Lukas Slebodnik • 11 years ago  
67771f6
MAN: Clarify the min_id/max_id limits further
Jakub Hrozek • 11 years ago  
5d762a9
NSS: Clear cached netgroups if a request comes in from the sss_cache
Lukas Slebodnik • 11 years ago  
3678074
NSS: allow removing entries from netgroup hash table
Lukas Slebodnik • 11 years ago  
845deed
LDAP: Fix crash when processing nested groups
Jakub Hrozek • 11 years ago  
f081ea9
sudo: print better debug message when a rule has multiple cn values
Pavel Březina • 11 years ago  
c487f42
sudo: skip rule on error instead of failing completely
Pavel Březina • 11 years ago  
a810814
Every time use permissive control in function memberof_mod.
Lukas Slebodnik • 12 years ago  
e4c8fd0
Always set port status to neutral when resetting service.
Michal Zidek • 12 years ago  
26df163
sudo responder: use different callback for oob refresh
Pavel Březina • 12 years ago  
ec7fbcd
IPA: Do not download or store the member attribute of host groups
Jakub Hrozek • 12 years ago  
e7769aa
failover: if expanded server is marked as neutral, invoke srv collapse
Pavel Březina • 12 years ago  
ab4c050
collapse_srv_lookup may free the server, make it clear from the API
Pavel Březina • 12 years ago  
5ecdadb
failover: set state->out when meta server remains in SRV_RESOLVE_ERROR
Pavel Březina • 12 years ago  
5e0f0c4
Add ignore_group_members option.
Paul B. Henson • 12 years ago  
868bf88
Adding option to disable retrieving large AD groups.
Lukas Slebodnik • 12 years ago  
c13eb93
Removing unused functions.
Lukas Slebodnik • 12 years ago  
200d054
sudo responder: use fully qualified name for subdomain users
Pavel Březina • 12 years ago  
2aaa41c
SUDO: IPA provider
Lukas Slebodnik • 12 years ago  
96db69c
Display the last grace warning, too
Jakub Hrozek • 12 years ago  
ac77faa
Only try to relink ghost users if we're not enumerating
Jakub Hrozek • 12 years ago  
3896c82
Bump the version for the 1.9.6 release
Jakub Hrozek • 12 years ago  
916ed98
Updating the translations for the 1.9.5 release
Jakub Hrozek • 12 years ago  
6d94922
tests: Link the simple access tests with -ldl
Jakub Hrozek • 12 years ago  
661a983
LDAP: do not invalidate pointer with realloc while processing ghost users
Jakub Hrozek • 12 years ago  
f4fddaf
Fix simple access group control in case-insensitive domains
Jakub Hrozek • 12 years ago  
4f57212
Fix krbcc dir creation issue with MIT krb5 1.11
Lukas Slebodnik • 12 years ago  
e495127
krb5: include backwards compatible declaration of krb5_trace_info
Jakub Hrozek • 12 years ago  
c215e00
sssd fails with readonly SELinux login files
Michal Zidek • 12 years ago  
ecc95c0
Allocate PAM DP request data on responder context
Jakub Hrozek • 12 years ago  
9ef2f2a
sssd-1.8.0: work around a bug in cov-build from Coverity
Kamil Dudka • 12 years ago  
81cd0de
Document what does access_provider=ad do
Jakub Hrozek • 12 years ago  
6bd336b
ldap: Fallback option for rfc2307 schema
Simo Sorce • 12 years ago  
8acdbd4
Resolve GIDs in the simple access provider
Jakub Hrozek • 12 years ago  
8b8019f
Do not compile main() in DP if UNIT_TESTING is defined
Jakub Hrozek • 12 years ago  
26590d3
Add unit tests for simple access test by groups
Jakub Hrozek • 12 years ago  
754b09b
Provide a be_get_account_info_send function
Jakub Hrozek • 12 years ago  
b63830b
krb5-utils-tests: remove invalid condition
Pavel Březina • 12 years ago  
b49ca26
Debug message in sss_mc_create_file.
Michal Zidek • 12 years ago  
2404777
File descriptor leak in nss responder.
Michal Zidek • 12 years ago  
0410011
Don't treat 0 as default for pam_pwd_expiration warning
Jakub Hrozek • 12 years ago  
cb4a317
if selinux is disabled, ignore that selogin dir is missing
Pavel Březina • 12 years ago  
82ce93d
autofs: fix invalid header 'number of entries' in packet
Pavel Březina • 12 years ago  
f5fb945
sdap_fill_memberships: continue if a member is not foud in sysdb
Pavel Březina • 12 years ago  
0aaf4a3
Remove enumerate=true from man sssd-ldap
Jakub Hrozek • 12 years ago  
f6d33cb
sysdb: try dealing with binary-content attributes
Jan Engelhardt • 12 years ago  
6072f51
Fix the krb5 password expiration warning
Jakub Hrozek • 12 years ago  
8bbdf17
subdomains: replace invalid characters with underscore in krb5 mapping file name
Pavel Březina • 12 years ago  
270d714
NSS: Add original homedir to home directory template options
Stephen Gallagher • 12 years ago  
fb91c1c
Unchecked return value in files.c
Michal Zidek • 12 years ago  
1117cf6
Don't use srcdir with tests
Jakub Hrozek • 12 years ago  
2425216
Fix minor grammar error in log
Stephen Gallagher • 12 years ago  
a6ad1de
krb: recreate ccache if it was deleted
Pavel Březina • 12 years ago  
ac85128
Bump the version to 1.9.5, reset release in RPMs to 0
Jakub Hrozek • 12 years ago  
2148369
Updating the translations for the 1.9.4 release
Jakub Hrozek • 12 years ago  
1525d43
nested groups: fix group lookup hangs if member dn is incorrect
Pavel Březina • 12 years ago  
8ded6ba
TOOLS: Compile on old platforms such as RHEL5
Jakub Hrozek • 12 years ago  
5c17895
MAN: Clarify that saving users after enumerating large domain might be CPU intensive
Jakub Hrozek • 12 years ago  
31778d7
SYSDB: Expire group if adding ghost users fails with EEXIST
Jakub Hrozek • 12 years ago  
cb1ab8f
SYSDB: make the sss_ldb_modify_permissive function public
Jakub Hrozek • 12 years ago  
9e48d08
TOOLS: Use file descriptor to avoid races when creating a home directory
Jakub Hrozek • 12 years ago  
3843b28
TOOLS: Use openat/unlinkat when removing the homedir
Jakub Hrozek • 12 years ago  
e864d91
Check that strings do not go beyond the end of the packet body in autofs and SSH requests.
Jan Cholasta • 12 years ago  
30e2585
sudo responder: change num_rules type from size_t to uint32_t
Pavel Březina • 12 years ago  
dac148d
Convert the value of pwd_exp_warning to seconds
Jakub Hrozek • 12 years ago  
42e4c17
fix backend callbacks: remove callback properly from dlist
Pavel Březina • 12 years ago  
a873473
TOOLS: invalidate parent groups in memory cache, too
Jakub Hrozek • 12 years ago  
a53bebc
LDAP: Compare lists of DNs when saving autofs entries
Jakub Hrozek • 12 years ago  
eafa1e3
Invalidate user entry even if there are no groups
Jakub Hrozek • 12 years ago  
a40f572
NSS: invalidate memcache user entry on initgr, too
Jakub Hrozek • 12 years ago  
11d0cb5
autofs: Use SAFEALIGN_SET_UINT32 instead of SAFEALIGN_COPY_UINT32
Jakub Hrozek • 12 years ago  
b12d149
LDAP: avoid complex realloc logic in save_rfc2307bis_group_memberships
Jakub Hrozek • 12 years ago  
131213e
TOOLS: Refresh memcache after changes to local users and groups
Jakub Hrozek • 12 years ago  
6dd6222
TOOLS: Provide a convenience function to refresh a list of groups
Jakub Hrozek • 12 years ago  
8935744
TOOLS: Split querying nss responder into a separate function
Jakub Hrozek • 12 years ago  
ee385ca
TOOLS: move memcache related functions to tools_mc_utils.c
Jakub Hrozek • 12 years ago  
97091d2
Fix invalidating autofs maps
Simo Sorce • 12 years ago  
e6ad861
let ldap_backup_chpass_uri work
Pavel Březina • 12 years ago  
3dc287c
AD: Add user as a direct member of his primary group
Jakub Hrozek • 12 years ago  
dff7192
AD: replace GID/UID, do not add another one
Jakub Hrozek • 12 years ago  
3a7ad75
IPA: Rename IPA_CONFIG_SELINUX_DEFAULT_MAP
Jakub Hrozek • 12 years ago  
77064ac
SELINUX: Process maps even when offline
Jakub Hrozek • 12 years ago  
7018d58
SYSDB: Split a function to read all SELinux maps
Jakub Hrozek • 12 years ago  
2a0019b
SYSDB: Remove duplicate selinux defines
Jakub Hrozek • 12 years ago  
9670c7d
Refactor gid handling in the PAC responder
Sumit Bose • 12 years ago  
8fe509c
PAC responder: check if existing user differs
Sumit Bose • 12 years ago  
a603316
Add tests for get_gids_from_pac()
Sumit Bose • 12 years ago  
4044e7d
Use hash table to collect GIDs from PAC to avoid dups
Sumit Bose • 12 years ago  
12d37e4
Translate LDB_ERR_ATTRIBUTE_OR_VALUE_EXISTS to EEXIST
Sumit Bose • 12 years ago  
5965c32
Read remote groups from PAC
Sumit Bose • 12 years ago  
2c18f0b
Remote groups do not have an original DN attribute
Sumit Bose • 12 years ago  
5295690
Save domain and GID for groups from the configured domain
Sumit Bose • 12 years ago  
b99b8e4
Always get user data from PAC
Sumit Bose • 12 years ago  
1e21d10
Update domain ID for local domain as well
Sumit Bose • 12 years ago  
32cc86b
IDMAP: add sss_idmap_smb_sid_to_unix()
Sumit Bose • 12 years ago  
cbae075
Add find_domain_by_id()
Sumit Bose • 12 years ago  
2d9aa35
Use struct pac_grp instead of gid_t for groups from PAC
Sumit Bose • 12 years ago  
7856e34
Potential resource leak in sss_nss_mc_get_record
Jakub Hrozek • 12 years ago  
df53c59
sudo smart refresh: fix debug message
Pavel Březina • 12 years ago  
1d8a60c
sudo smart refresh: do not include usn in filter if no valid usn is known
Pavel Březina • 12 years ago  
d1a7774
memcache: make MC_PTR_TO_SLOT() more readable
Pavel Březina • 12 years ago  
7e3b02d
explicit null dereferenced in sss_nss_mc_get_record()
Pavel Březina • 12 years ago  
f73e8aa
memcache: add macro that validates record length
Pavel Březina • 12 years ago  
09d04ff
sss_userdel and sss_groupdel with use_fully_qualified_names
Michal Zidek • 12 years ago  
c924a99
SYSDB: Modify ghosts in permissive mode
Ondrej Kos • 12 years ago  
a05c352
Search for SHORTNAME$@REALM instead of fqdn$@REALM by default
Jakub Hrozek • 12 years ago  
07a833f
Remove unused header
Simo Sorce • 12 years ago  
7a7b289
sss_cache: fqdn not accepted
Michal Zidek • 12 years ago  
d435608
LDAP: initialize refresh function handler
Ondrej Kos • 12 years ago  
380c911
let krb5_backup_kpasswd failover work
Pavel Březina • 12 years ago  
254bd9a
mmap cache: invalidate cache on fatal error
Simo Sorce • 12 years ago  
26288fe
Carefully check records when forcibly invalidating
Simo Sorce • 12 years ago  
70d5663
Update free table when records are invalidated.
Simo Sorce • 12 years ago  
884c92c
nss_mc: Add extra checks when dereferencing records
Simo Sorce • 12 years ago  
26ae48f
krb5 tgt renewal: fix usage of ldb_dn_get_component_val()
Sumit Bose • 12 years ago  
8144958
Free resources if fileno failed
Jakub Hrozek • 12 years ago  
a8c4867
Add default section to switch statement
Sumit Bose • 12 years ago  
d1993f1
Fix a 'shadows a global declaration' warning
Sumit Bose • 12 years ago  
514c691
sssd_nss: Plug memory leaks
Simo Sorce • 12 years ago  
529beaa
memberof: Prevent unneded failure case
Simo Sorce • 12 years ago  
85da72d
Add responder_sbus.h to noinst_HEADERS
Jakub Hrozek • 12 years ago  
eaeb4c5
select_principal_from_keytab() do wildcard lookups after specific ones
Sumit Bose • 12 years ago  
cbc1548
select_principal_from_keytab() look for plain input as well
Sumit Bose • 12 years ago  
163d021
responder_dp: Add timeout to side requets
Simo Sorce • 12 years ago  
dd85581
AUTOFS: Clear enum cache if a request comes in from the sss_cache
Jakub Hrozek • 12 years ago  
10bfd01
RESPONDERS: Create a common file with service names and versions
Jakub Hrozek • 12 years ago  
c65afc2
AUTOFS: remove all maps from hash if request for auto.master comes in
Jakub Hrozek • 12 years ago  
286b115
AUTOFS: allow removing entries from hash table
Jakub Hrozek • 12 years ago  
a0d1219
DP: invalidate all cached maps if a request for auto.master comes in
Jakub Hrozek • 12 years ago  
05bc499
SYSDB: Add API to invalidate all map objects
Jakub Hrozek • 12 years ago  
fb4cb94
SYSDB: fix copy-n-paste error
Jakub Hrozek • 12 years ago  
20798b1
sudo: do full refresh when data provider is back online
Pavel Březina • 12 years ago  
7024f71
sudo: schedule another full refresh in short interval if the first fails
Pavel Březina • 12 years ago  
9043ef6
check dp error in sdap_sudo_full_refresh_done()
Pavel Březina • 12 years ago  
b2b0f4e
add sdap_sudo_schedule_refresh()
Pavel Březina • 12 years ago  
6a86d67
try primary server after retry_timeout + 1 seconds when switching to backup
Pavel Březina • 12 years ago  
cdfc4ba
RESOLV: Do not steal the resulting hostent on error
Jakub Hrozek • 12 years ago  
3766058
Set cloexec flag for log files
Jakub Hrozek • 12 years ago  
ba4f38e
MEMBEROF: silence compilation warnings
Jakub Hrozek • 12 years ago  
e57a115
PROXY: fix groups caching
Ondrej Kos • 12 years ago  
e9e4cc8
let ldap_chpass_uri failover work when using same hostname
Pavel Březina • 12 years ago  
91705fd
sssd_pam: Cleanup requests cache on sbus reconect
Simo Sorce • 12 years ago  
23669fd
Allow mmap calls to gracefully return absent ctx
Simo Sorce • 12 years ago  
eeeae56
MAN: Fix the title of sssd-sudo
Jakub Hrozek • 12 years ago  
9403457
sudo: support generalized time format
Pavel Březina • 12 years ago  
073c745
tools: sss_userdel and groupdel remove entries from memory cache
Michal Zidek • 12 years ago  
882e558
sssd_nss: Remove entries from memory cache if not found in sysdb
Michal Zidek • 12 years ago  
ab1c798
sudo: include primary group in user group list
Pavel Březina • 12 years ago  
50cf9f4
sysdb_get_sudo_user_info() initialize attrs on declaration
Pavel Březina • 12 years ago  
f7dd07f
Add a macro to copy with barriers
Simo Sorce • 12 years ago  
4d0f4f8
SYSDB: More debugging during the conversion to ghost users
Jakub Hrozek • 12 years ago  
e69dbbd
sudo: don't get stuck in rules and smart refresh when offline
Pavel Březina • 12 years ago  
a5e8583
NSS: Fix the error handler in sss_mc_create_file
Jakub Hrozek • 12 years ago  
1f2964b
let krb5_kpasswd failover work
Pavel Březina • 12 years ago  
a18e2af
sudo manpage: clarify that sudoHost may contain wildcards and not regular expression
Pavel Březina • 12 years ago  
cf455f4
MEMBEROF: Fix copy-n-paste error
Jakub Hrozek • 12 years ago  
5392a6b
LDAP: remove dead assignment
Jakub Hrozek • 12 years ago  
41b0b7d
SYSDB: Move misplaced assignment
Jakub Hrozek • 12 years ago  
9460448
PAC: check the return value of diff_git_lists
Jakub Hrozek • 12 years ago  
3693be5
SSH: Reject requests for authorized keys of root
Jan Cholasta • 12 years ago  
8178921
PROXY: fix negative cache
Ondrej Kos • 12 years ago  
2f4ff13
SUDO: strdup the input variable
Jakub Hrozek • 12 years ago  
bb9e2ad
Updating the version for the 1.9.4 release
Jakub Hrozek • 12 years ago  
678ac52
Updating the translations for the 1.9.3 release
Jakub Hrozek • 12 years ago  
f96147e
sudo: print rule name if notBefore or notAfter attribute is missing
Pavel Březina • 12 years ago  
a3cbc57
MAN: Move ssh_known_hosts_timeout documentation to the correct section
Jan Cholasta • 12 years ago  
fd1d89e
RESOLV: return ENOENT if the address list is empty
Jakub Hrozek • 12 years ago  
1d883fb
MEMBEROF: Keep inherited ghost users around on modify operation
Jakub Hrozek • 12 years ago  
0c0066f
MEMBEROF: Implement the modify operation for ghost users
Jakub Hrozek • 12 years ago  
5bbea52
MEMBEROF: Split the add ghost operation into a separate function
Jakub Hrozek • 12 years ago  
e266638
MEMBEROF: Split the del ghost attribute op into a reusable function
Jakub Hrozek • 12 years ago  
2577575
MEMBEROF: split processing the member modify into a separate function
Jakub Hrozek • 12 years ago  
7f530eb
MEMBEROF: Implement delete operation for ghost users
Jakub Hrozek • 12 years ago  
55d04dd
LDAP: Continue adjusting group membership even if there is nothing to add
Jakub Hrozek • 12 years ago  
b7ca502
Add memory barrier to mmap cache client code loop
Simo Sorce • 12 years ago  
ddd46c1
Always append rctx as private data
Simo Sorce • 12 years ago  
b9d9832
Add backchannel NSS provider query on initgr calls
Simo Sorce • 12 years ago  
593ed71
Hook for mmap cache update on initgroup calls
Simo Sorce • 12 years ago  
d2282b4
Hook to perform a mmap cache update from sssd_nss
Simo Sorce • 12 years ago  
535e5ce
mmap cache: public functions to invalidate records
Simo Sorce • 12 years ago  
f1d38d5
link sss_ssh_authorizedkeys and sss_ssh_knownhostsproxy with -lpthread
Timo Aaltonen • 12 years ago  
50dba57
do not crash when id_provider is not set
Pavel Březina • 12 years ago  
39927aa
Missing parameter in DEBUG message.
Michal Zidek • 12 years ago  
6187037
Dereference after null check in sss_idmap_sid_to_unix
Michal Zidek • 12 years ago  
af6614c
NSS: Fix netgroup midpoint cache refresh
Jakub Hrozek • 12 years ago  
83c5a01
warn user if password is about to expire
Pavel Březina • 12 years ago  
b0662f6
IPA: Handle bad results from c-ares lookup
Stephen Gallagher • 12 years ago  
a729f07
avoid versioning libsss_sudo
Pavel Březina • 12 years ago  
0f1736c
Monitor quit when not exists no process no stops
Ariel O. Barria • 12 years ago  
7ad76d1
Null pointer dereferenced.
Michal Zidek • 12 years ago  
78bbe54
idmap: Silence DEBUG messages when dealing with built-in SIDs.
Michal Zidek • 12 years ago  
33e0886
Uninitialized pointer read
Michal Zidek • 12 years ago  
f024eec
sss_cache: Small refactor.
Michal Zidek • 12 years ago  
2636bda
TESTS: Test ghosts users in the RFC2307 schema
Jakub Hrozek • 12 years ago  
4a0b98d
MEMBEROF: Do not add the ghost attribute to self
Jakub Hrozek • 12 years ago  
4cbb5c7
debug: print fatal and critical errors if debug level is unresolved
Michal Zidek • 12 years ago  
2cb77cf
SYSDB: Don't operate with aliases same as name
Ondrej Kos • 12 years ago  
81b05ad
LDAP: fix uninitialized variable
Ondrej Kos • 12 years ago  
8f70dee
Handle compiling FQDN regular expression with old pcre gracefully
Jakub Hrozek • 12 years ago  
727fc5f
Fix errors reported by rpmlint
Jan Cholasta • 12 years ago  
144031b
Use systemd by default on Fedora 16+
Jan Cholasta • 12 years ago  
0d1c4aa
MONITOR: Fix off-by-one error in add_string_to_list
Jakub Hrozek • 12 years ago  
011e322
fix SIGSEGV in IPA provider when ldap_sasl_authid is not set
Pavel Březina • 12 years ago  
94aeeb0
LDAP: Only convert direct parents' ghost attribute to member
Jakub Hrozek • 12 years ago  
b22f24e
SYSDB: Use the add_string convenience functions for managing ghost user attribute
Jakub Hrozek • 12 years ago  
9dd91ef
BUILD: Temporary workaround for Kerberos build
Stephen Gallagher • 12 years ago  
1523b8a
KRB5: Work around const warning for krb5 releases older than 1.11
Sumit Bose • 12 years ago  
0d20b3f
Disable canonicalization during password changes
Sumit Bose • 12 years ago  
8fd7d4b
Fix compare_principal_realm() check
Sumit Bose • 12 years ago  
cfed272
Just use the service name with krb5_get_init_creds_password()
Sumit Bose • 12 years ago  
d2386d8
LDAP: Make it possible to use full principal in ldap_sasl_authid again
Jakub Hrozek • 12 years ago  
b0e32fb
LDAP: Checking the principal should not be considered fatal
Jakub Hrozek • 12 years ago  
83e75fc
LDAP: Provide a common sdap_set_sasl_options init function
Jakub Hrozek • 12 years ago  
9f4df8c
MAN: document the ldap_sasl_realm option
Jakub Hrozek • 12 years ago  
2387cce
Restart services with a delay in case they are restarted too often
Jakub Hrozek • 12 years ago  
3c92241
Handle conversion to fully qualified usernames
Simo Sorce • 12 years ago  
9a0e490
Do not save HBAC rules in subdomain subtree
Sumit Bose • 12 years ago  
d5809af
Refactor the way subdomain accounts are saved
Simo Sorce • 12 years ago  
2f5fbac
Simplify writing db update functions
Simo Sorce • 12 years ago  
c16a30f
LDAP: Refactor saving ghost users
Jakub Hrozek • 12 years ago  
ebdc4a6
LDAP: use the correct memory context
Jakub Hrozek • 12 years ago  
a2fba7e
LDAP: Fix saving empty groups
Jakub Hrozek • 12 years ago  
a00c1d4
LDAP: Allocate the temporary context on NULL, not memctx
Jakub Hrozek • 12 years ago  
2e20322
SERVER: Check the return value of waitpid
Jakub Hrozek • 12 years ago  
9ffff74
Display more information on DB version crash
Ondrej Kos • 12 years ago  
3e454b5
SUDO: Fix wrong variable check
Jakub Hrozek • 12 years ago  
28556a5
LDAP: Expire even non authenticated connections
Jakub Hrozek • 12 years ago  
28edb30
Provide AM_COND_IF-combatible implementation for old automake systems
Jakub Hrozek • 12 years ago  
f9e4b82
sudo: store rules with no sudoHost attribute
Pavel Březina • 12 years ago  
ea903f7
SUDO: Remove unused variable
Stephen Gallagher • 12 years ago  
0411c03
sudo: print how many rules we are refreshing or returning
Pavel Březina • 12 years ago  
894d2d5
sudo: do not send domain name with username
Pavel Březina • 12 years ago  
d3f7600
sudo: support users from subdomains
Pavel Březina • 12 years ago  
cc255b7
use tmp_ctx in sudosrv_get_sudorules_from_cache()
Pavel Březina • 12 years ago  
3cc3ecc
sudo: fix missing parameter in two debug messages
Pavel Březina • 12 years ago  
4d2c8ac
Run IPA subdomain provider if IPA ID provider is configured
Sumit Bose • 12 years ago  
6830f45
Always start PAC responder if IPA ID provider is configured
Sumit Bose • 12 years ago  
03b555b
Add string_in_list() and add_string_to_list() with tests
Sumit Bose • 12 years ago  
a3241ce
SYSDB: Do not touch the member attribute during conversion to ghost users
Jakub Hrozek • 12 years ago  
0169011
Include the auth_utils.h header in the distribution
Jakub Hrozek • 12 years ago  
137d132
Only build extract_and_send_pac on platforms that support it
Jakub Hrozek • 12 years ago  
98124bf
KRB5: Rename variable to avoid shadowing a global declaration
Jakub Hrozek • 12 years ago  
0451273
backend: add PAC to the list of known clients
Pavel Březina • 12 years ago  
56728c1
subdomains: check request type on one place only
Pavel Březina • 12 years ago  
e02ac98
Do not always return PAM_SYSTEM_ERR when offline krb5 authentication fails
Jakub Hrozek • 12 years ago  
16e0b00
Store the original group DN in the subdomain user object
Sumit Bose • 12 years ago  
375d570
Get lists of GIDs to be added and deleted and use them
Sumit Bose • 12 years ago  
666a418
Add pac_user_get_grp_info() to read current group memberships
Sumit Bose • 12 years ago  
1b9ac1b
Add diff_gid_lists() with test
Sumit Bose • 12 years ago  
01fb2a7
Do not remove a group if it has members from subdomains
Sumit Bose • 12 years ago  
bd97189
MAN: Fix validation error caused by bad 'ca' translation
Stephen Gallagher • 12 years ago  
c441e83
Clarify debug message about initgroups and subdomains
Sumit Bose • 12 years ago  
ab1b2ad
MAN: sssd-simple - suggest awarness of empty rules
Ondrej Kos • 12 years ago  
e2971bf
sss_dp_get_domains_send(): handle subreq error correctly
Pavel Březina • 12 years ago  
2d86062
util_lock.c: sss_br_lock_file accepted invalid parameter value
Michal Zidek • 12 years ago  
7a65039
SSSDConfig: Locate the force_timeout option in the correct sections
Stephen Gallagher • 12 years ago  
c469044
MAN: Specify the correct location for the force_timeout option
Stephen Gallagher • 12 years ago  
ccec8b0
Monitor: Better debugging for ping timeouts
Stephen Gallagher • 12 years ago  
8287077
do not default fullname to gecos when schema = ad
Pavel Březina • 12 years ago  
45e2a56
sss_cache: Remove fastcache even if sssd is not running.
Michal Zidek • 12 years ago  
304ce93
util: Added new file util_lock.c
Michal Zidek • 12 years ago  
b17eae0
RPMS: Move sss_cache tool to main package
Stephen Gallagher • 12 years ago  
9e74782
sss_cache: Multiple domains not handled properly
Michal Zidek • 12 years ago  
42b70fb
create pid file immediately after fork again
Pavel Březina • 12 years ago  
3a3e1a3
exit original process after sssd is initialized
Pavel Březina • 12 years ago  
d80485d
make monitor_quit() usable outside signal handler
Pavel Březina • 12 years ago  
6ec69c2
fix indendation, coding style and debug levels in server.c
Pavel Březina • 12 years ago  
8b130e4
add SSSDBG_IMPORTANT_INFO macro
Pavel Březina • 12 years ago  
3d73923
PAM: Do not leak fd after SELinux context file is written
Jakub Hrozek • 12 years ago  
56d894d
Monitor: read the correct SIGKILL timeout for providers, too
Jakub Hrozek • 12 years ago  
851d015
LDAP: Better debug logging when saving groups
Stephen Gallagher • 12 years ago  
df7d40c
LDAP: Fix off-by-one error when saving ghost users
Jakub Hrozek • 12 years ago  
d5f0868
authconfig: allow chpass_provider = proxy
Pavel Březina • 12 years ago  
ccc46e7
Free the internal DP request
Jakub Hrozek • 12 years ago  
ff73778
Make sub-domains case-insensitive
Sumit Bose • 12 years ago  
004968e
sss_parse_name_for_domains: always return the canonical domain name
Sumit Bose • 12 years ago  
fe41254
krb5_auth: update with correct UPN if needed
Sumit Bose • 12 years ago  
541ba2d
Use find_or_guess_upn() where needed
Sumit Bose • 12 years ago  
5fcdbf6
Add new call find_or_guess_upn()
Sumit Bose • 12 years ago  
53e2d78
krb5_child: send back the client principal
Sumit Bose • 12 years ago  
f67ee4a
krb5_mod_ccname: replace wrong memory context
Sumit Bose • 12 years ago  
6caff4c
krb5_child: send PAC to PAC responder
Sumit Bose • 12 years ago  
b3435ea
krb5_auth: send different_realm flag to krb5_child
Sumit Bose • 12 years ago  
2b61532
krb5_auth: check if principal belongs to a different realm
Sumit Bose • 12 years ago  
ba772c9
Add replacement for krb5_find_authdata()
Sumit Bose • 12 years ago  
95a386c
check_ccache_files: search sub-domains as well
Sumit Bose • 12 years ago  
8af633c
sysdb: add sysdb_base_dn()
Sumit Bose • 12 years ago  
aab727b
krb5_auth_send: check for sub-domains
Sumit Bose • 12 years ago  
203663b
pac responder: add user principal and name alias to cached user object
Sumit Bose • 12 years ago  
538db73
pac responder: use only lower case user name
Sumit Bose • 12 years ago  
8847542
sysdb: look for ranges in the parent tree
Sumit Bose • 12 years ago  
1a21292
pac responder: fix copy-and-paste error
Sumit Bose • 12 years ago  
00e7269
subdomain-id: Generate homedir only for users not groups
Sumit Bose • 12 years ago  
4ecd8c5
KRB5: Return error when principal selection fails
Jakub Hrozek • 12 years ago  
606865b
sudo refresh: handle errors properly
Pavel Březina • 12 years ago  
18208ef
sudo: do not fail if usn value is zero but full refresh is completed
Pavel Březina • 12 years ago  
547d616
Fix two errors in the nss responder
Sumit Bose • 12 years ago  
10e08f0
Allow setting the default_shell option per-domain as well
Jakub Hrozek • 12 years ago  
b8c3368
LDAP: Check validity of naming_context
Jakub Hrozek • 12 years ago  
78fb6ec
Updating version for 1.9.8
Jakub Hrozek • 10 years ago  
41ad910
Updating translations for the 1.9.7 release
Jakub Hrozek • 10 years ago  
a1215fb
Do not switch to credentials everytime.
Lukas Slebodnik • 10 years ago  
ce21876
Every time return directory for krb5 cache collection.
Lukas Slebodnik • 10 years ago  
da1ee87
Fix wrong detection of krb5 ccname
Lukas Slebodnik • 10 years ago  
cd1e5f2
LDAP: Setup periodic task only once.
Lukas Slebodnik • 11 years ago  
f52d80d
AUTOTOOLS: krb5 1.12 is also supported krb5 libs
Lukas Slebodnik • 11 years ago  
1ee7e7c
NSS: Fix memory leak in sss_setnetgrent
Lukas Slebodnik • 11 years ago  
3472831
do not use default_domain_suffix with autofs
Aron Parsons • 11 years ago  
1b092d8
LDAP: Initialize user count for AD matching rule
Jakub Hrozek • 11 years ago  
9fcfa6c
LDAP: Search for original DN during auth if it's missing
Jakub Hrozek • 11 years ago  
ce2c2b2
LDAP: Split out a request to search for a user w/o saving
Jakub Hrozek • 11 years ago  
ed98d79
PROXY: Handle empty GECOS
Jakub Hrozek • 11 years ago  
e913f43
proxy: Allow initgroup to return NOTFOUND
Simo Sorce • 11 years ago  
dd2936e
Inherit ID limits of parent domains if set
Jakub Hrozek • 11 years ago  
30016dd
Bumping the version for 1.9.7
Jakub Hrozek • 11 years ago  
ddc11f4
Updating translations for the 1.9.6 release
Jakub Hrozek • 11 years ago  
cd1a0c9
Updating Transifex URL
Jakub Hrozek • 11 years ago  
addb3e1
be_spy_create: free be_req and not the long living data
Sumit Bose • 11 years ago  
2a97e22
sdap_get_generic_ext_send: check if we a re still connected
Sumit Bose • 11 years ago  
1c5f201
Check slot validity before MC_SLOT_TO_PTR.
Michal Zidek • 11 years ago  
94162ba
AUTOTOOLS: Fix warnings: macro xyz not found in library
Lukas Slebodnik • 11 years ago  
1f62bcc
man sssd: Add note about SSS_NSS_USE_MEMCACHE
Michal Zidek • 11 years ago  
2e2fb25
Rename _SSS_MC_SPECIAL
Michal Zidek • 11 years ago  
f48be9b
is_dn(): free dn
Pavel Březina • 11 years ago  
f8817e0
AUTOTOOLS: More robust detection of inotify.
Lukas Slebodnik • 11 years ago  
9c393e2
AUTOTOOLS: Use pkg-config to detect libraries.
Lukas Slebodnik • 11 years ago  
e64a66e
AUTOTOOLS: add check for type intptr_t
Lukas Slebodnik • 11 years ago  
2ff2cc0
AUTOTOOLS: Refactor unicode library detection
Lukas Slebodnik • 11 years ago  
a20685b
AUTOTOOLS: Add directories for searching ldap headers and libs
Lukas Slebodnik • 11 years ago  
24a4c00
AUTOMAKE: Use portable way to link with gettext
Lukas Slebodnik • 11 years ago  
9c649c8
AUTOMAKE: Use portable way to link with dlopen
Lukas Slebodnik • 11 years ago  
ed19d07
AUTOTOOLS: Add missing AC_MSG_RESULT
Lukas Slebodnik • 11 years ago  
a53c3db
AUTOTOOLS: Add -LLIBDIR to PYTHON_LIBS
Lukas Slebodnik • 11 years ago  
09d330c
mmap_cache: Do not remove record from chain twice
Lukas Slebodnik • 11 years ago  
e5697f3
Make IPA SELinux provider aware of subdomain users
Jakub Hrozek • 11 years ago  
563cb29
UTIL: Use standard maximum value of type size_t
Lukas Slebodnik • 11 years ago  
2db20f9
Include sys/types.h for types id_t and uid_t
Lukas Slebodnik • 11 years ago  
07f8737
SIGCHLD handler: do not call callback when pvt data was freed
Pavel Březina • 11 years ago  
0e9563e
CONFIGURE: Get rid of bashism
Lukas Slebodnik • 11 years ago  
3dc0400
IPA_HBAC: Explicitelly include header file time.h
Lukas Slebodnik • 11 years ago  
b7fd1a3
MEMBEROF: Remove temporary workaround
Lukas Slebodnik • 11 years ago  
9260f20
UTIL: Explicitly include header file sys/socket.h
Lukas Slebodnik • 11 years ago  
e526b83
MONITOR: Move function declaration out of conditional build
Lukas Slebodnik • 11 years ago  
8f209f0
CLIENT: Fix non gnu sss_strnlen implementation
Lukas Slebodnik • 11 years ago  
8abef63
UTIL: Create new wraper header file sss_endian.h
Lukas Slebodnik • 11 years ago  
fc97ab8
DP: Use the correct type for DBus boolean
Jakub Hrozek • 11 years ago  
298b57a
mmap_cache: Use stricter check for hash keys.
Lukas Slebodnik • 11 years ago  
98ce2a1
mmap_cache: Skip records which doesn't have same hash
Lukas Slebodnik • 11 years ago  
b493966
sss_packet_grow: correctly pad packet length to 512B
Pavel Březina • 11 years ago  
8b9b986
Removing unused parameter type from sudosrv_get_sudorules_query_cache()
Lukas Slebodnik • 11 years ago  
1c27f00
  • « Newer
  • page 1 of 74
  • » Older
Powered by Pagure 5.14.1
Documentation • File an Issue • About • SSH Hostkey/Fingerprint
© Red Hat, Inc. and others.