[Pkg-sssd-devel] sssd: Changes to 'refs/tags/debian/1.15.3-1'
Timo Aaltonen
tjaalton at moszumanska.debian.org
Sat Jul 29 09:15:27 UTC 2017
Tag 'debian/1.15.3-1' created by Timo Aaltonen <tjaalton at debian.org> at 2017-07-29 08:50 +0000
tagging package sssd version debian/1.15.3-1
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAABCAAGBQJZfExnAAoJEMtwMWWoiYTcQE0P/i1eNEJjZIn4ZzDVgZ5AXUCn
LUGCSZJNFqRodHufZr48O0uGsKuw+LZJPdZv7QsnTsJuyrVlVRYgqO3WRS2LAZ1m
SZgRIsK0WREnjhqKTezRvGaxV7xLnA0oXCCSL71pK768d+x/B0/8rxaMCklgvgQp
xjOMmrYEGY8pL8TkFWRIgzHu/tASlHkwq6PgCp5bOF/UDNWNqZMf3b12ZXUDcDbP
82nfty0TZUkMSrr5uhwIk5vZJipYtus9tQyMhtciyN6ewYbECW5+xLeBnUiJC3pe
0KiGg2PhdOEW6QZ4GIBzBUy/oC77YiuXkd+pHEr+rP+Zf2bRNoC5dF/fuMqSAFR3
egaA5kDWoPElsn9EwythKSw0+UhqPYqVZvjDJP0glCCQvcRRqB4Tc9jUWqPW+Hed
OR0thBBF4jQhDgLj+/7APwew7Tll0CM/zVx2b6c9XouSWwp5vCkArcqHNjyA0Fry
kgx9Fxc+NuZmTZ+iTaDLl4GonklezRG6QRYTe7K6KRSBeH4RFazbokqqb2GNmHKz
T/QCT3/0DA/5fhFIqO0IejGV/tBkyaM6EiH1xTNLydyVhhEpykqrpUqSRlWft8uA
mKNeybWwNhj8ePVlMhcmT6BMYdhmWqiA7FXbURfR3SSjqq0szMYajsKLOs7H3noi
btfa7KFU0zNUM61UGH9X
=Grgw
-----END PGP SIGNATURE-----
Changes since debian/1.15.2-1:
AmitKumar (2):
MAN: The timeout option doesn't say after how many heartbeats will the process be killed
MAN: Updating option ipa_server_mode in man sssd-ipa
David Kupka (1):
libsss_certmap: Accept certificate with data before header
Fabiano Fidêncio (40):
CACHE_REQ: Descend into subdomains on lookups
NSS/TESTS: Improve setup/teardown for subdomains tests
NSS/TESTS: Include searches for non-fqnames members of a subdomain
SYSDB: Add methods to deal with the domain's resolution order
SYSDB/TESTS: Add tests for the domain's resolution order methods
IPA: Get ipaDomainsResolutionOrder from ipaConfig
IPA_SUBDOMAINS: Rename _refresh_view() to _refresh_view_name()
IPA: Get ipaDomainsResolutionOrder from IPA ID View
DLINKLIST: Add DLIST_FOR_EACH_SAFE macro
CACHE_REQ: Make use of domainResolutionOrder
UTIL: Expose replace_char() as sss_replace_char()
Add domain_resolution_order config option
RESPONDER: Fallback to global domain resolution order in case the view doesn't have this option set
NSS/TESTS: Improve non-fqnames tests
CACHE_REQ: Allow configurationless shortname lookups
CACHE_REQ_DOMAIN: Add some comments to cache_req_domain_new_list_from_string_list()
RESPONDER_COMMON: Improve domaiN_resolution_order debug messages
CACHE_REQ_DOMAIN: debug the set domain resolution order
NSS: Fix typo inigroups -> initgroups
LDAP: Remove duplicated debug message
CONTRIB: Force single-thread install to workaround concurrency issues
LDAP/AD: Do not fail in case rfc2307bis_nested_groups_recv() returns ENOENT
CACHE_REQ: Add a new cache_req_ncache_filter_fn() plugin function
CACHE_REQ_RESULT: Introduce cache_req_create_ldb_result_from_msg_list()
CACHE_REQ: Make use of cache_req_ncache_filter_fn()
CACHE_REQ: Avoid using of uninitialized value
CACHE_REQ: Ensure the domains are updated for "filter" related calls
CACHE_REQ: Simplify _search_ncache_filter()
CACHE_REQ_SEARCH: Check for filtered users/groups also on cache_req_send()
INTG_TESTS: Add one more test for filtered out users/groups
SYSDB: Return ERR_NO_TS when there's no timestamp cache present
SYSDB: Internally expose sysdb_search_ts_matches()
SYSDB: Make the usage of the filter more generic for search_ts_matches()
SYSDB_OPS: Mark an entry as expired also in the timestamp cache
SYSDB_OPS: Invalidate a cache entry also in the ts_cache
SYSDB: Introduce _search_{users,groups}_by_timestamp()
LDAP_ID_CLEANUP: Use sysdb_search_*_by_timestamp()
RESPONDER: Use fqnames as output when needed
DOMAIN: Add sss_domain_info_{get,set}_output_fqnames()
INTG/FILES_PROVIDER: Test user and group override
Jakub Hrozek (70):
Updating the version for the 1.15.3 release
UTIL: iobuf: Make input parameter for the readonly operation const
UTIL: Fix a typo in the tcurl test tool
UTIL: Add SAFEALIGN_COPY_UINT8_CHECK
UTIL: Add utility macro cli_creds_get_gid()
UTIL: Add type-specific getsetters to sss_iobuf
UTIL: krb5 principal (un)marshalling
KCM: Initial responder build and packaging
KCM: request parsing and sending a reply
KCM: Implement an internal ccache storage and retrieval API
KCM: Add a in-memory credential storage
KCM: Implement KCM server operations
MAN: Add a manual page for sssd-kcm
TESTS: Add integration tests for the KCM responder
SECRETS: Create DB path before the operation itself
SECRETS: Return a nicer error message on request with no PUT data
SECRETS: Store ccaches in secrets for the KCM responder
TCURL: Support HTTP POST for creating containers
KCM: Store ccaches in secrets
KCM: Make the secrets ccache back end configurable, make secrets the default
KCM: Queue requests by the same UID
KCM: Idle-terminate the responder if the secrets back end is used
CONFDB: Introduce SSSD domain type to distinguish POSIX and application domains
CONFDB: Allow configuring [application] sections as non-POSIX domains
CACHE_REQ: Domain type selection in cache_req
IFP: Search both POSIX and non-POSIX domains
IFP: ListByName: Don't crash when no results are found
PAM: Remove unneeded memory context
PAM: Add application services
SYSDB: Allow storing non-POSIX users
SYSDB: Only generate new UID in local domain
LDAP: save non-POSIX users in application domains
LDAP: Relax search filters in application domains
KRB5: Authenticate users in a non-POSIX domain using a MEMORY ccache
KCM: Fix off-by-one error in secrets key parsing
Move sized_output_name() and sized_domain_name() into responder common code
IFP: Use sized_domain_name to format the groups the user is a member of
IPA: Improve DEBUG message if a group has no ipaNTSecurityIdentifier
LDAP: Allow passing a NULL map to sdap_search_bases_ex_send
IPA: Use search bases instead of domain_to_basedn when fetching external groups
CONFDB: Fix standalone application domains
AD: Make ad_account_can_shortcut() reusable by SSSD on an IPA server
KRB5: Advise the user to inspect the krb5_child.log if the child doesn't return a valid response
KCM: Fix the per-client serialization queue
TESTS: Add a test for parallel execution of klist
IPA: Avoid using uninitialized ret value when skipping entries from the joined domain
IPA: Return from function after marking a request as finished
HBAC: Do not rely on originalMemberOf, use the sysdb memberof links instead
test_kcm: Remove commented code
TESTS: Fix pep8 errors in test_kcm.py
TESTS: Fix pep8 errors in test_secrets.py
TESTS: Fix pep8 errors in test_ts_cache.py
RESP: Provide a reusable request to fully resolve incomplete groups
IFP: Only format the output name to the short version before output
IFP: Resolve group names from GIDs if required
KRB5: Fix access_provider=krb5
IFP: Fix error handling in ifp_user_get_attr_handle_reply()
IPA: Enable enterprise principals even if there are no changes to subdomains
README: Add a hint on how to submit bugs
README: Add social network links
Fix fedorahosted links in BUILD.txt
README.md: Point to our releases on pagure
RESPONDERS: Fix terminating idle connections
TESTS: Integration test for idle timeout
MAN: Document that client_idle_timeout can't be shorter than 10 seconds
CRYPTO: Do not call NSS_Shutdown after every operation
KRB5: Return invalid credentials internally when attempting to renew an expired TGT
KCM: Fix Description of sssd-kcm.socket
Remove the locale tag from zanata.xml
Updating translations for the 1.15.3 release
Justin Stephenson (9):
IPA: Add s2n request to string function
IPA: Enhance debug logging for ipa s2n operations
IPA: Improve s2n debug message for missing ipaNTSecurityIdentifier
MAN: AD Provider GSSAPI clarification
DP: Reduce Data Provider log level noise
CONFIG: Add subdomain_homedir to config locations
SSSCTL: Add parent or trusted domain type
LDAP: Fix nesting level comparison
TESTS: Update zero nesting level test
Lukas Slebodnik (57):
MAN: Mention sssd-secrets in "SEE ALSO" section
CONFIGURE: Fix fallback if pkg-config for uuid is missing
intg: fix configure failure with strict cflags
intg: Remove bashism from intgcheck-prepare
BUILD: Fix compilation of libsss_certmap with libcrypto
CONFDB: Fix handling of enable_files_domain
UTIL: Use max 15 characters for AD host UPN
SPEC: Drop conditional build for krb5_local_auth_plugin
README: Update links to mailing lists
SECRETS: remove unused variable
cache_req: Avoid bool in switch/case
SPEC: Update processing of translation in %install
SPEC: Move systemd service sssd-ifp.service to right package
SPEC: Add missing scriptlets for package sssd-dbus
SPEC: Use correct package for translated sssd-ifp man page
SPEC: Move man page for sss_rpcidmapd to the right package
SPEC: Use correct package for translated sss_ssh* man pages
SPEC: Use correct package for translated sssctl man pages
SPEC: Use correct package for translated idmap_sss man pages
SPEC: Use correct package for translated sss_certmap man pages
SPEC: Use correct package for translated sssd-kcm man pages
SPEC: Move files provider files within package
SPEC: Move kcm scriptlets to systemd section
SPEC: Call ldconfig in libsss_certmap scriptlets
SPEC: Use macro python_provide conditionally
SPEC: Use %license macro
KCM: include missing header file
test_ldap.py: Add test for filter_{users,groups}
CONFDB: Use default configuration with missing sssd.conf
UTIL: Drop unused error code ERR_MISSING_CONF
INTG: Do not use configure time option enable-files-domain
BUILD: Link libwbclient with libdl
BUILD: Fix build without ssh
SSSDConfig: Handle integer parsing more leniently
SSSDConfig: Fix saving of debug_level
SECRETS: Fix warning Wpointer-bool-conversion
BUILD: Improve error messages for optional dependencies
VALIDATOR: prevent duplicite report from subdomain sections
test_config_check: Fix few issues
pam_sss: Fix checking of empty string cert_user
codegen: Remove util.h from generated files
UTIL: Remove few unused headed files
UTIL: Remove signal.h from util/util.h
UTIL: Remove signal.h from util/util.h
UTIL: Remove fcntl.h from util/util.h
Remove string{,s}.h
UTIL: Remove ctype.h from util/util.h
UTIL: Remove limits.h from util/util.h
Remove unnecessary sys/param.h
certmap: Remove unnecessary included files
cache_req: Do not use default_domain_suffix with netgroups
pam_sss: Fix leaking of memory in case of failures
CI: Do not use valgrind for dummy-child
Revert "CI: Use /bin/sh as a CONFIG SHELL"
Revert "LDAP: Fix nesting level comparison"
KCM: temporary increase hardcoded buffers
KCM: Modify krb5 snippet file kcm_default_ccache
Michal Židek (20):
UTIL: Typo in comment
UTIL: Introduce subdomain_create_conf_path()
SUBDOMAINS: Allow use_fully_qualified_names for subdomains
selinux: Do not fail if SELinux is not managed
config-check: Message when sssd.conf is missing
SDAP: Fix handling of search bases
SERVER_MODE: Update sdap lists for each ad_ctx
AD: Add debug messages
AD SUBDOMAINS: Fix search bases for child domains
VALIDATORS: Add subdomain section
VALIDATORS: Remove application section domain
VALIDATORS: Escape special regex chars
TESTS: Add unit tests for cfg validation
MAN: Fix typo in trusted domain section
VALIDATORS: Change regex for app domains
VALIDATORS: Detect inherit_from in normal domain
TESTS: Add one config-check test case
GPO: Fix typo in DEBUG message
SDAP: Update parent sdap_list
SDAP: Add sdap_domain_copy_search_bases
Nikolai Kondrashov (1):
NSS: Move output name formatting to utils
Pavel Březina (22):
NSS/TESTS: Fix subdomains attribution
tcurl: add support for ssl and raw output
tcurl test: refactor so new options can be added more easily
tcurl test: add support for raw output
tcurl test: add support for tls settings
tcurl: add support for http basic auth
tcurl test: allow to set custom headers
tcurl test: add support for client certificate
ci: do not build secrets on rhel6
build: make curl required by secrets
secrets: use tcurl in proxy provider
secrets: remove http-parser code in proxy provider
secrets: allow to configure certificate check
secrets: support HTTP basic authentication with proxy provider
secrets: fix debug message
secrets: always add Content-Length header
sss_iobuf: fix 'read' shadows a global declaration
configure: fix typo
responders: do not leak selinux context on clients destruction
ipa_s2n_get_acct_info_send: provide correct req_input name
DP: Fix typo
IFP: Add domain and domainname attributes to the user
René Genz (2):
minor typo fixes
Use correct spelling of override
Simo Sorce (3):
ssh tools: The ai structure is not an array,
ssh tools: Fix issues with multiple IP addresses
ssh tools: Split connect and communication phases
Sumit Bose (53):
split_on_separator: move to a separate file
util: move string_in_list to util_ext
certmap: add new library libsss_certmap
certmap: add placeholder for OpenSSL implementation
sysdb: add sysdb_attrs_copy()
sdap_get_users_send(): new argument mapped_attrs
LDAP: always store the certificate from the request
sss_cert_derb64_to_ldap_filter: add sss_certmap support
sysdb: add certmap related calls
IPA: add certmap support
nss-idmap: add sss_nss_getlistbycert()
nss: allow larger buffer for certificate based requests
ssh: handle binary keys correctly
ssh: add support for certificates from non-default views
krb5: return to responder that pkinit is not available
IPA: add mapped attributes to user from trusted domains
IPA: lookup AD users by certificates on IPA clients
IPA: enable AD user lookup by certificate
pam_test_client: add service and environment to PAM test client
pam_test_client: add SSSD getpwnam lookup
sss_sifp: update method names
pam_test_client: add InfoPipe user lookup
sssctl: integrate pam_test_client into sssctl
i18n: adding sssctl files
KRB5_LOCATOR: add env variable to disable plugin
sbus: check connection for NULL before unregister it
utils: add sss_domain_is_forest_root()
ad: handle forest root not listed in ad_enabled_domains
overrides: add certificates to mapped attribute
PAM: check matching certificates from all domains
sss_nss_getlistbycert: return results from multiple domains
cache_req: use the right negative cache for initgroups by upn
test: make sure p11_child is build for pam-srv-tests
pam: properly support UPN logon names
ipa: filter IPA users from extdom lookups by certificate
krb5: accept changed principal if krb5_canonicalize=True
ldap: handle certmap errors gracefully
RESPONDER_COMMON: update certmaps in responders
tests: fix test_pam_preauth_cert_no_logon_name()
pam_sss: add support for SSS_PAM_CERT_INFO_WITH_HINT
add_pam_cert_response: add support for SSS_PAM_CERT_INFO_WITH_HINT
PAM: send user name hint response when needed
sysdb: sysdb_get_certmap() allow empty certmap
sssctl: show user name used for authentication in user-checks
IPA: Fix the PAM error code that auth code expects to start migration
krb5: disable enterprise principals during password changes
krb5: use plain principal if password is expired
tests: update expired certificate
files: refresh override attributes after re-read
responders: update domain even for local and files provider
PAM: make sure the files provider uses the right auth provider
idmap_error_string: add missing descriptions
ad_account_can_shortcut: shortcut if ID is unknown
Timo Aaltonen (11):
apparmor-profile: Add chown capability, allow to notify systemd.
Merge branch 'upstream'
bump version
control: Add libcurl4-gnutls-dev and uuid-dev to build depends.
Add libsss-certmap{0,-dev} packages.
Add sssd-kcm.
rules: Migrate to dh_missing.
fix changelog spelling
control: Bump policy to 4.0.0, no changes.
compat, control, rules: Bump debhelper compat to 10, drop --parallel as it's the default now.
releasing package sssd version 1.15.3-1
Ville Skyttä (1):
SSSDConfig: Python 3.6 invalid escape sequence deprecation fix
---
BUILD.txt | 4
Makefile.am | 307
README.md | 32
configure.ac | 16
contrib/ci/configure.sh | 8
contrib/ci/deps.sh | 6
contrib/ci/run | 5
contrib/fedora/bashrc_sssd | 3
contrib/kcm_default_ccache | 12
contrib/sssd.spec.in | 242
debian/apparmor-profile | 2
debian/changelog | 14
debian/compat | 2
debian/control | 33
debian/libsss-certmap-dev.install | 3
debian/libsss-certmap0.install | 2
debian/rules | 6
debian/sssd-kcm.install | 5
po/POTFILES.in | 9
po/bg.po | 1300
po/ca.po | 1303
po/de.po | 1302
po/es.po | 1301
po/eu.po | 1298
po/fr.po | 1302
po/hu.po | 1301
po/id.po | 1298
po/it.po | 1301
po/ja.po | 1302
po/nb.po | 1297
po/nl.po | 1302
po/pl.po | 1302
po/pt.po | 1301
po/pt_BR.po | 1296
po/ru.po | 1301
po/sssd.pot | 1296
po/sv.po | 1302
po/tg.po | 1296
po/tr.po | 1296
po/uk.po | 1302
po/zh_CN.po | 1298
po/zh_TW.po | 1299
src/conf_macros.m4 | 16
src/confdb/confdb.c | 340
src/confdb/confdb.h | 32
src/confdb/confdb_setup.c | 5
src/config/SSSDConfig/__init__.py.in | 24
src/config/SSSDConfig/ipachangeconf.py | 7
src/config/SSSDConfigTest.py | 63
src/config/cfg_rules.ini | 60
src/config/etc/sssd.api.conf | 10
src/config/etc/sssd.api.d/sssd-ipa.conf | 2
src/config/testconfigs/sssd-valid.conf | 6
src/db/sysdb.c | 24
src/db/sysdb.h | 71
src/db/sysdb_certmap.c | 428
src/db/sysdb_domain_resolution_order.c | 169
src/db/sysdb_domain_resolution_order.h | 37
src/db/sysdb_ops.c | 307
src/db/sysdb_private.h | 10
src/db/sysdb_search.c | 91
src/db/sysdb_subdomains.c | 137
src/db/sysdb_views.c | 117
src/external/libcurl.m4 | 22
src/external/libhttp_parser.m4 | 2
src/external/libjansson.m4 | 5
src/external/libuuid.m4 | 17
src/krb5_plugin/sssd_krb5_locator_plugin.c | 15
src/lib/certmap/sss_cert_content_crypto.c | 32
src/lib/certmap/sss_cert_content_nss.c | 1014
src/lib/certmap/sss_certmap.c | 997
src/lib/certmap/sss_certmap.doxy.in | 3
src/lib/certmap/sss_certmap.exports | 13
src/lib/certmap/sss_certmap.h | 152
src/lib/certmap/sss_certmap.pc.in | 11
src/lib/certmap/sss_certmap_attr_names.c | 107
src/lib/certmap/sss_certmap_int.h | 189
src/lib/certmap/sss_certmap_krb5_match.c | 559
src/lib/certmap/sss_certmap_ldap_mapping.c | 371
src/lib/idmap/sss_idmap.c | 16
src/lib/idmap/sss_idmap.h | 6
src/lib/sifp/sss_sifp_common.c | 4
src/man/Makefile.am | 11
src/man/idmap_sss.8.xml | 2
src/man/include/seealso.xml | 6
src/man/po/br.po | 2958 +-
src/man/po/ca.po | 3075 +-
src/man/po/cs.po | 2952 +-
src/man/po/de.po | 3082 +-
src/man/po/es.po | 3038 +-
src/man/po/eu.po | 2952 +-
src/man/po/fi.po |14191 ++++++++++
src/man/po/fr.po | 3113 +-
src/man/po/ja.po | 3038 +-
src/man/po/lv.po | 2954 +-
src/man/po/nl.po | 2960 +-
src/man/po/po4a.cfg | 4
src/man/po/pt.po | 2966 +-
src/man/po/pt_BR.po | 2952 +-
src/man/po/ru.po | 2952 +-
src/man/po/sssd-docs.pot | 2884 +-
src/man/po/tg.po | 2952 +-
src/man/po/uk.po | 3131 +-
src/man/po/zh_CN.po | 2952 +-
src/man/sss-certmap.5.xml | 600
src/man/sssd-ad.5.xml | 5
src/man/sssd-ipa.5.xml | 17
src/man/sssd-kcm.8.xml | 193
src/man/sssd-ldap.5.xml | 8
src/man/sssd-secrets.5.xml | 76
src/man/sssd.conf.5.xml | 173
src/man/sssd_krb5_locator_plugin.8.xml | 5
src/monitor/monitor.c | 15
src/monitor/monitor_iface_generated.c | 5
src/monitor/monitor_iface_generated.h | 1
src/providers/ad/ad_common.c | 52
src/providers/ad/ad_common.h | 7
src/providers/ad/ad_gpo.c | 2
src/providers/ad/ad_id.c | 164
src/providers/ad/ad_subdomains.c | 89
src/providers/data_provider/dp_iface_generated.c | 5
src/providers/data_provider/dp_iface_generated.h | 1
src/providers/data_provider/dp_methods.c | 2
src/providers/data_provider/dp_target_id.c | 4
src/providers/data_provider/dp_targets.c | 2
src/providers/data_provider_be.c | 1
src/providers/files/files_ops.c | 115
src/providers/ipa/ipa_access.c | 1
src/providers/ipa/ipa_auth.c | 1
src/providers/ipa/ipa_config.h | 2
src/providers/ipa/ipa_hbac_common.c | 97
src/providers/ipa/ipa_opts.c | 2
src/providers/ipa/ipa_s2n_exop.c | 260
src/providers/ipa/ipa_subdomains.c | 735
src/providers/ipa/ipa_subdomains_ext_groups.c | 30
src/providers/ipa/ipa_subdomains_id.c | 1
src/providers/ipa/ipa_subdomains_server.c | 40
src/providers/ipa/ipa_views.c | 2
src/providers/ipa/selinux_child.c | 9
src/providers/krb5/krb5_auth.c | 68
src/providers/krb5/krb5_auth.h | 2
src/providers/krb5/krb5_child.c | 81
src/providers/krb5/krb5_child_handler.c | 20
src/providers/krb5/krb5_common.c | 1
src/providers/krb5/krb5_delayed_online_authentication.c | 7
src/providers/krb5/krb5_init.c | 3
src/providers/ldap/ldap_child.c | 1
src/providers/ldap/ldap_common.c | 2
src/providers/ldap/ldap_id.c | 79
src/providers/ldap/ldap_id_cleanup.c | 6
src/providers/ldap/ldap_options.c | 2
src/providers/ldap/sdap.c | 12
src/providers/ldap/sdap.h | 7
src/providers/ldap/sdap_access.c | 1
src/providers/ldap/sdap_async.h | 3
src/providers/ldap/sdap_async_enum.c | 9
src/providers/ldap/sdap_async_initgroups.c | 40
src/providers/ldap/sdap_async_initgroups_ad.c | 8
src/providers/ldap/sdap_async_private.h | 1
src/providers/ldap/sdap_async_users.c | 115
src/providers/ldap/sdap_child_helpers.c | 1
src/providers/ldap/sdap_domain.c | 5
src/providers/ldap/sdap_ops.c | 2
src/providers/ldap/sdap_users.h | 1
src/providers/proxy/proxy_auth.c | 2
src/providers/proxy/proxy_iface_generated.c | 5
src/providers/proxy/proxy_iface_generated.h | 1
src/python/pysss_nss_idmap.c | 103
src/resolv/async_resolv.c | 1
src/resolv/async_resolv_utils.c | 1
src/responder/common/cache_req/cache_req.c | 255
src/responder/common/cache_req/cache_req.h | 19
src/responder/common/cache_req/cache_req_domain.c | 243
src/responder/common/cache_req/cache_req_domain.h | 56
src/responder/common/cache_req/cache_req_plugin.h | 13
src/responder/common/cache_req/cache_req_private.h | 8
src/responder/common/cache_req/cache_req_result.c | 35
src/responder/common/cache_req/cache_req_search.c | 113
src/responder/common/cache_req/plugins/cache_req_enum_groups.c | 13
src/responder/common/cache_req/plugins/cache_req_enum_svc.c | 6
src/responder/common/cache_req/plugins/cache_req_enum_users.c | 13
src/responder/common/cache_req/plugins/cache_req_group_by_filter.c | 8
src/responder/common/cache_req/plugins/cache_req_group_by_id.c | 13
src/responder/common/cache_req/plugins/cache_req_group_by_name.c | 8
src/responder/common/cache_req/plugins/cache_req_host_by_name.c | 9
src/responder/common/cache_req/plugins/cache_req_initgroups_by_name.c | 8
src/responder/common/cache_req/plugins/cache_req_initgroups_by_upn.c | 5
src/responder/common/cache_req/plugins/cache_req_netgroup_by_name.c | 9
src/responder/common/cache_req/plugins/cache_req_object_by_id.c | 20
src/responder/common/cache_req/plugins/cache_req_object_by_name.c | 7
src/responder/common/cache_req/plugins/cache_req_object_by_sid.c | 5
src/responder/common/cache_req/plugins/cache_req_svc_by_name.c | 7
src/responder/common/cache_req/plugins/cache_req_svc_by_port.c | 7
src/responder/common/cache_req/plugins/cache_req_user_by_cert.c | 5
src/responder/common/cache_req/plugins/cache_req_user_by_filter.c | 8
src/responder/common/cache_req/plugins/cache_req_user_by_id.c | 13
src/responder/common/cache_req/plugins/cache_req_user_by_name.c | 12
src/responder/common/cache_req/plugins/cache_req_user_by_upn.c | 1
src/responder/common/iface/responder_iface_generated.c | 5
src/responder/common/iface/responder_iface_generated.h | 1
src/responder/common/responder.h | 45
src/responder/common/responder_common.c | 318
src/responder/common/responder_dp.c | 13
src/responder/common/responder_get_domains.c | 54
src/responder/common/responder_packet.c | 21
src/responder/common/responder_packet.h | 1
src/responder/common/responder_utils.c | 206
src/responder/ifp/ifp_groups.c | 139
src/responder/ifp/ifp_iface.c | 2
src/responder/ifp/ifp_iface.xml | 2
src/responder/ifp/ifp_iface_generated.c | 23
src/responder/ifp/ifp_iface_generated.h | 5
src/responder/ifp/ifp_private.h | 4
src/responder/ifp/ifp_users.c | 223
src/responder/ifp/ifp_users.h | 8
src/responder/ifp/ifpsrv_cmd.c | 225
src/responder/ifp/ifpsrv_util.c | 74
src/responder/kcm/kcm.c | 316
src/responder/kcm/kcm.h | 97
src/responder/kcm/kcmsrv_ccache.c | 1423 +
src/responder/kcm/kcmsrv_ccache.h | 351
src/responder/kcm/kcmsrv_ccache_be.h | 205
src/responder/kcm/kcmsrv_ccache_json.c | 930
src/responder/kcm/kcmsrv_ccache_mem.c | 805
src/responder/kcm/kcmsrv_ccache_pvt.h | 62
src/responder/kcm/kcmsrv_ccache_secrets.c | 2169 +
src/responder/kcm/kcmsrv_cmd.c | 648
src/responder/kcm/kcmsrv_op_queue.c | 326
src/responder/kcm/kcmsrv_ops.c | 1984 +
src/responder/kcm/kcmsrv_ops.h | 46
src/responder/kcm/kcmsrv_pvt.h | 101
src/responder/nss/nss_cmd.c | 90
src/responder/nss/nss_enum.c | 2
src/responder/nss/nss_get_object.c | 3
src/responder/nss/nss_iface.c | 2
src/responder/nss/nss_iface_generated.c | 5
src/responder/nss/nss_iface_generated.h | 1
src/responder/nss/nss_private.h | 11
src/responder/nss/nss_protocol.h | 12
src/responder/nss/nss_protocol_grent.c | 16
src/responder/nss/nss_protocol_pwent.c | 13
src/responder/nss/nss_protocol_sid.c | 141
src/responder/nss/nss_utils.c | 114
src/responder/nss/nsssrv.c | 2
src/responder/pam/pamsrv.c | 41
src/responder/pam/pamsrv.h | 7
src/responder/pam/pamsrv_cmd.c | 175
src/responder/pam/pamsrv_p11.c | 21
src/responder/secrets/local.c | 192
src/responder/secrets/providers.c | 155
src/responder/secrets/proxy.c | 836
src/responder/secrets/secsrv_cmd.c | 3
src/responder/secrets/secsrv_private.h | 15
src/responder/ssh/ssh_reply.c | 28
src/responder/sudo/sudosrv_get_sudorules.c | 3
src/sbus/sbus_codegen | 6
src/sbus/sssd_dbus_interface.c | 8
src/sbus/sssd_dbus_server.c | 1
src/sss_client/idmap/sss_nss_idmap.c | 110
src/sss_client/idmap/sss_nss_idmap.exports | 6
src/sss_client/idmap/sss_nss_idmap.h | 17
src/sss_client/pam_message.h | 1
src/sss_client/pam_sss.c | 132
src/sss_client/pam_test_client.c | 115
src/sss_client/ssh/sss_ssh_knownhostsproxy.c | 40
src/sss_client/sss_cli.h | 16
src/sysv/systemd/sssd-kcm.service.in | 9
src/sysv/systemd/sssd-kcm.socket.in | 10
src/tests/cmocka/common_mock_resp.c | 6
src/tests/cmocka/common_mock_resp_dp.c | 7
src/tests/cmocka/p11_nssdb/cert9.db |binary
src/tests/cmocka/p11_nssdb/key4.db |binary
src/tests/cmocka/test_cert_utils.c | 57
src/tests/cmocka/test_certmap.c | 1443 +
src/tests/cmocka/test_config_check.c | 308
src/tests/cmocka/test_fqnames.c | 2
src/tests/cmocka/test_ifp.c | 12
src/tests/cmocka/test_ipa_subdomains_server.c | 5
src/tests/cmocka/test_kcm_json_marshalling.c | 309
src/tests/cmocka/test_kcm_queue.c | 365
src/tests/cmocka/test_nss_srv.c | 580
src/tests/cmocka/test_pam_srv.c | 409
src/tests/cmocka/test_responder_cache_req.c | 62
src/tests/cmocka/test_sss_idmap.c | 11
src/tests/cmocka/test_sysdb_certmap.c | 261
src/tests/cmocka/test_sysdb_domain_resolution_order.c | 190
src/tests/cmocka/test_sysdb_subdomains.c | 25
src/tests/cmocka/test_utils.c | 2
src/tests/cwrap/Makefile.am | 1
src/tests/dlopen-tests.c | 1
src/tests/intg/Makefile.am | 4
src/tests/intg/kdc.py | 175
src/tests/intg/krb5utils.py | 160
src/tests/intg/test_files_provider.py | 90
src/tests/intg/test_kcm.py | 466
src/tests/intg/test_ldap.py | 172
src/tests/intg/test_secrets.py | 106
src/tests/intg/test_ts_cache.py | 6
src/tests/sbus_codegen_tests_generated.c | 5
src/tests/sbus_codegen_tests_generated.h | 1
src/tests/sysdb-tests.c | 162
src/tests/tcurl_test_tool.c | 400
src/tests/util-tests.c | 1
src/tools/common/sss_process.c | 1
src/tools/common/sss_tools.c | 2
src/tools/sss_cache.c | 2
src/tools/sss_signal.c | 1
src/tools/sssctl/sssctl.c | 1
src/tools/sssctl/sssctl.h | 4
src/tools/sssctl/sssctl_config.c | 6
src/tools/sssctl/sssctl_domains.c | 50
src/tools/sssctl/sssctl_logs.c | 1
src/tools/sssctl/sssctl_user_checks.c | 299
src/tools/tools_mc_util.c | 1
src/util/cert.h | 3
src/util/cert/cert_common.c | 76
src/util/cert/nss/cert.c | 9
src/util/child_common.c | 1
src/util/crypto/nss/nss_nite.c | 2
src/util/crypto/nss/nss_obfuscate.c | 2
src/util/crypto/sss_crypto.c | 4
src/util/dlinklist.h | 5
src/util/domain_info_utils.c | 46
src/util/inotify.c | 1
src/util/nscd.c | 1
src/util/safe-format-string.h | 2
src/util/server.c | 1
src/util/signal.c | 2
src/util/sss_ini.c | 53
src/util/sss_iobuf.c | 110
src/util/sss_iobuf.h | 35
src/util/sss_krb5.c | 204
src/util/sss_krb5.h | 9
src/util/sss_ldap.c | 3
src/util/sss_semanage.c | 61
src/util/string_utils.c | 12
src/util/tev_curl.c | 841
src/util/tev_curl.h | 186
src/util/usertools.c | 67
src/util/util.c | 114
src/util/util.h | 33
src/util/util_creds.h | 1
src/util/util_errors.c | 13
src/util/util_errors.h | 13
src/util/util_ext.c | 143
src/util/util_safealign.h | 6
src/util/util_watchdog.c | 2
version.m4 | 2
zanata.xml | 95
349 files changed, 101920 insertions(+), 25055 deletions(-)
---
More information about the Pkg-sssd-devel
mailing list