6352 Updated DC locator for SMB and idmapPortions contributed by: Matt Barden <Matt.Barden@nexenta.com>Portions contributed by: Kevin Crowe <kevin.crowe@nexenta.com>Portions contributed by: Alek P
6352 Updated DC locator for SMB and idmapPortions contributed by: Matt Barden <Matt.Barden@nexenta.com>Portions contributed by: Kevin Crowe <kevin.crowe@nexenta.com>Portions contributed by: Alek Pinchuk <alek@nexenta.com>Reviewed by: Bayard Bell <bayard.bell@nexenta.com>Reviewed by: Alek Pinchuk <alek.pinchuk@nexenta.com>Reviewed by: Rick McNeal <rick.mcneal@nexenta.com>Reviewed by: Kevin Crowe <kevin.crowe@nexenta.com>Reviewed by: Tony Nguyen <tony.nguyen@nexenta.com>Approved by: Robert Mustacchi <rm@joyent.com>
show more ...
1122 smbsrv should use SPNEGO (inbound authentication)Portions contributed by: Matt Barden <Matt.Barden@nexenta.com>Portions contributed by: Kevin Crowe <kevin.crowe@nexenta.com>Portions contribut
1122 smbsrv should use SPNEGO (inbound authentication)Portions contributed by: Matt Barden <Matt.Barden@nexenta.com>Portions contributed by: Kevin Crowe <kevin.crowe@nexenta.com>Portions contributed by: Alek Pinchuk <alek@nexenta.com>Reviewed by: Bayard Bell <bayard.bell@nexenta.com>Reviewed by: Dan Fields <dan.fields@nexenta.com>Reviewed by: Kevin Crowe <kevin.crowe@nexenta.com>Reviewed by: Matt Barden <Matt.Barden@nexenta.com>Approved by: Robert Mustacchi <rm@joyent.com>
872 remove duplicate daemon() definitionsReviewed by: Garrett D'Amore <garrett@damore.org>Reviewed by: Marcel Telka <marcel@telka.sk>Approved by: Richard Lowe <richlowe@richlowe.net>
PSARC 2010/135 Kerberos Diagnostic Enhancements (umbrella case)6835328 Error messages generated by applications using RPCSEC_GSS are too vague
6909129 krb5 keytab management API should be simplified to easily merge keys from different realms
6613083 The host specified as the admin_server is not used when sending Kerberos KPASSWD request.
6941204 krb5_fcc_read_addrs() returns garbage on failure
6941201 double-frees on error path in krb5_os_hostaddr()
6941191 krb5_send_tgs doesn't do all the error checking it could
6941173 logic error in krb5_build_principal_ext
6941162 krb5_encrypt_helper returns success and an apparently valid buffer on malloc failure
6794523 rcache could skip fsync(2)s in common cases with a dynamic skew concept
6938652 krb5_sendto_kdc should initialize the addrlist structures
6889700 __krb5_get_init_creds_password leaks krb5_gic_opt_ext *opte
6806014 unable to join domain using kerberos via tcp when no SRV _kerberos-master._tcp is in DNS
6899293 Use of uninitialized variable in krb5_sname_to_principal on error path
6565115 Bug in krb5_get_credentials_core() function
6885980 Need case-insensitive keytab lookups for MS interop6885387 gsskrb5_extract_authz_data_from_sec_context() fails with service ticket sent by Windows 7 client6858400 kclient cant join Windows
6885980 Need case-insensitive keytab lookups for MS interop6885387 gsskrb5_extract_authz_data_from_sec_context() fails with service ticket sent by Windows 7 client6858400 kclient cant join Windows AD domain if hostname is 20 characters or longer6867203 Solaris acceptors fail in Windows 2000 environment6868908 Solaris acceptors should have returned KRB5KRB_AP_ERR_MODIFIED for Microsoft interoperability6867208 Windows client cannot recover from KRB5KRB_AP_ERR_SKEW error
PSARC 2009/418 Kerberos V5 PAC API6283931 SPNEGO needs to follow latest RFC6808598 krb5 APIs needed to create and parse PAC data6817447 libgss and various mechs are hiding both the real minor_stat
PSARC 2009/418 Kerberos V5 PAC API6283931 SPNEGO needs to follow latest RFC6808598 krb5 APIs needed to create and parse PAC data6817447 libgss and various mechs are hiding both the real minor_status and the error token
6802931 krb5 nfs allows access to shares without credentials by symlinking to someone else's cred cache6840235 Some slight changes need to be made to gssd_getuid.c to be more readable
6822062 multiple vulnerabilities in SPNEGO, ASN.1 decoder (CVE-2009-0847, CVE-2009-0845, CVE-2009-0844)6822066 ASN.1 decoder frees uninitialized pointer (CVE-2009-0846)
6777148 idmap fails to auto-discover AD due to ldap_sasl_bind failure
6782682 krb5_recvauth() should return NULL for auth_context on failure
PSARC/2008/631 Kerberos PKINITPSARC/2008/358 removal of kadm5.keytab6698059 Resync with mit 1.6.3 (pkinit)6749302 pam_krb5 auth fails with key table entry not found
6736781 Memory leak in mech_krb5.so.1 when obtaining FQHN for comparison to host principal
123