Files
freeipa/debian/changelog

693 lines
28 KiB
Plaintext
Raw Normal View History

freeipa (4.8.6-1) UNRELEASED; urgency=medium
* New upstream release.
* pki-proxy-Don-t-rely-on-running-apache-until-it-s-co.patch: Dropped,
upstream.
* migrate-to-gpg.diff: Use gpg instead of gpg2, update dependencies.
(Closes: #919062)
2020-03-30 21:48:43 +03:00
* control: Bump gssproxy depends.
* control: Relax apache2 dependency so it works on ubuntu.
2020-03-31 06:33:20 +03:00
* control: Bump policy to 4.5.0.
2020-03-31 06:39:37 +03:00
* control: Fix some M-A issues.
* control: Drop the dummy freeipa-admintools package.
-- Timo Aaltonen <tjaalton@debian.org> Mon, 30 Mar 2020 16:38:52 +0300
freeipa (4.8.5-1) unstable; urgency=medium
2020-02-06 10:44:59 +02:00
* New upstream release.
* control: Drop client from freeipa-tests depends.
* Fix-font-awesome-path.patch: Dropped, upstream.
* fix-ods-conf-template.diff: Dropped, upstream.
2020-02-06 21:29:14 +02:00
* Use debhelper-compat.
* Add debian/gitlab-ci.yml.
2020-02-27 15:41:20 +02:00
- allow blhc and piuparts to fail
* write-out-only-one-cert-per-file.diff: Fix writing CA cert to file.
* tests: Make failure an actual failure again, and dump only last 2000
lines on failure, also from ipaclient log.
2020-02-28 14:35:11 +02:00
* rules: Import architecture.mk.
2020-03-18 00:16:27 +02:00
* source: Update extend-diff-ignore.
2020-03-18 00:16:43 +02:00
* server.install: Updated.
* pki-proxy-Don-t-rely-on-running-apache-until-it-s-co.patch: Fix
httpd_proxy install.
* control: Bump dependency on apache2 to where mod_proxy_ajp got fixed.
* tests: Add sudo to dependencies for dogtag.
-- Timo Aaltonen <tjaalton@debian.org> Wed, 25 Mar 2020 19:42:37 +0200
freeipa (4.8.3-1) unstable; urgency=medium
2019-11-26 20:05:05 +02:00
* New upstream release.
- CVE-2019-10195: Don't log passwords embedded in commands in calls
using batch
- CVE-2019-14867: Make sure to have storage space for tag
* Fix-font-awesome-path.patch: Fix the path to font-awesome dir. (LP:
#1853863)
-- Timo Aaltonen <tjaalton@debian.org> Tue, 26 Nov 2019 20:14:47 +0200
freeipa (4.8.2-1) unstable; urgency=medium
2019-11-20 18:27:35 +02:00
* New upstream release.
* control: Server needs to depend on the py3 version of mod-wsgi.
2019-11-20 18:52:30 +02:00
* server.install: Updated.
-- Timo Aaltonen <tjaalton@debian.org> Wed, 20 Nov 2019 19:58:42 +0200
freeipa (4.8.1-2) unstable; urgency=medium
* client.postinst: Migrate checks to python3. (Closes: #936555)
* server.postinst: Let ipactl run the upgrader when needed, drop it from here.
* control: Add python3-pki-base to python3-ipaserver depends.
* control: Add ssl-cert to freeipa-server depends.
-- Timo Aaltonen <tjaalton@debian.org> Thu, 12 Sep 2019 00:30:23 +0300
freeipa (4.8.1-1) experimental; urgency=medium
2019-09-07 23:25:39 +03:00
* New upstream release.
2019-04-26 00:23:31 +03:00
* Drop upstreamed patches.
2019-04-26 01:02:51 +03:00
* install: Updated.
* fix-ods-conf-template.diff: Drop an obsolete conf option.
2019-05-05 14:06:26 +03:00
* rules: Rework gentarball target.
2019-08-08 20:50:28 +03:00
* control: Bump policy to 4.4.0.
2019-08-08 20:50:55 +03:00
* Bump debhelper compat to 12.
2019-08-08 23:37:45 +03:00
* Migrate to python3.
2019-08-08 23:38:07 +03:00
* d/s/local-options: Updated.
2019-08-08 23:59:27 +03:00
* install: Updated.
* control, install: Add freeipa-client-samba.
2019-08-09 00:28:22 +03:00
* d/pydist-overrides: Updated.
2019-04-26 00:13:20 +03:00
-- Timo Aaltonen <tjaalton@debian.org> Sun, 08 Sep 2019 00:18:39 +0300
2019-04-26 00:13:20 +03:00
freeipa (4.7.2-3) unstable; urgency=medium
* control: Move python-jwcrypto to python-ipaserver depends.
-- Timo Aaltonen <tjaalton@debian.org> Mon, 06 May 2019 08:43:34 +0300
2019-02-12 16:04:49 +02:00
freeipa (4.7.2-2+exp1) experimental; urgency=medium
* rules: Build the server for experimental.
-- Timo Aaltonen <tjaalton@debian.org> Tue, 12 Feb 2019 16:05:05 +0200
freeipa (4.7.2-2) unstable; urgency=medium
* tests: Disabled, they are for the server.
2019-02-12 14:48:32 +02:00
* Split server build-deps from the stub.
-- Timo Aaltonen <tjaalton@debian.org> Tue, 12 Feb 2019 16:02:08 +0200
freeipa (4.7.2-1) unstable; urgency=medium
2019-02-05 09:37:51 +02:00
* New upstream release.
* client.tmpfile: Use /run instead of /var/run.
* control.common: Use same arch set on node-uglify build-dep as for
nodejs. (Closes: #918579)
2019-02-05 09:45:01 +02:00
* fix-fontawesome-path.diff: Refreshed.
* rules: Build only the client until Dogtag works again.
-- Timo Aaltonen <tjaalton@debian.org> Tue, 05 Feb 2019 12:39:34 +0200
freeipa (4.7.1-3) unstable; urgency=medium
* control: Replace libsvrcore-dev build-dep with 389-ds-base-dev.
* tests: Install only the packages which are used for testing.
* rules: Don't run git on clean. (Closes: #912202)
* control: Nodejs is not available on all archs, build server packages
only where it is.
* control: Add systemd to python-ipalib depends. (Closes: #851158)
-- Timo Aaltonen <tjaalton@debian.org> Thu, 06 Dec 2018 02:22:35 +0200
freeipa (4.7.1-2) unstable; urgency=medium
* control: Change python-nose to -mock on python-ipatests Depends.
* fix-oddjobd-conf.diff: Fix path to org.freeipa.server.conncheck.
2018-10-18 14:06:09 +03:00
* server.postinst: Fix a typo.
* fix-fontawesome-path.diff: Fix upgrade.
-- Timo Aaltonen <tjaalton@debian.org> Thu, 18 Oct 2018 14:30:44 +0300
freeipa (4.7.1-1) unstable; urgency=medium
2018-10-08 10:49:59 +03:00
* New upstream release.
- fix-replicainstall.diff dropped, not applicable anymore
- ipa-httpd-pwdreader-force-fqdn.diff dropped, obsolete
- refresh patches
2018-10-09 10:29:50 +03:00
- server: drop ipa-replica-prepare
* dont-migrate-to-authselect.diff We don't have authselect, so just
return true when trying to migrate to it. (LP: #1793994)
* control: Move client dependency on chrony to recommends. (Closes:
#909803)
* control: Build server on any arch again.
* tests: Don't fail the tests, just dump the log if something goes
wrong.
-- Timo Aaltonen <tjaalton@debian.org> Tue, 09 Oct 2018 10:30:09 +0300
freeipa (4.7.0-1) unstable; urgency=medium
* New upstream release. (LP: #1772447, #1772450)
2018-05-21 10:00:55 +03:00
- fix-version.diff: Dropped, not needed
- hack-duplicate-cert-directive.diff: Dropped, fixed upstream
- ldap-multiarch.diff: Dropped, fixed upstream
- support-pam-mkhomedir.diff: Dropped, fixed upstream
- fix-apache-ssl-setup.diff: Dropped, fixed upstream
- fix-httpd-group.diff: Dropped, fixed upstream
- fix-named-conf-template.diff: Dropped, fixed upstream
- fix-paths.diff: Dropped, fixed upstream
2018-05-23 20:02:01 +03:00
- refresh patches
* tests/server-install: Fix the fake domain, single label domains are not
supported anymore.
* server.postinst: Fix upgrade from earlier version.
* fix-fontawesome-path.diff: Fix the path to font-awesome. (LP:
#1772921)
* fix-krb5kdc-cert-path.diff: Apache can't access KDC certs, move them
to /var/lib/ipa/certs. (LP: #1772447)
* ipa-httpd-pwdreader-force-fqdn.diff: Make sure HOSTNAME is a FQDN. (LP:
#1769485)
* control: Add libjs-scriptaculous to server depends.
* fix-gzip-path.diff: Fix path to gzip. (LP: #1778236)
* control, rules: Switch rhino to nodejs for ui build.
* d/s/local-options: Add some files to ignore.
* control, copyright: Add node-uglify to build-depends, the embedded
copy was removed.
* control, fix-py3-lesscpy-name.diff: Add python3-lesscpy to build-
depends, call the binary with the correct name.
* control: Add python3-pkg-resources to build-depends.
2018-08-04 10:38:19 +03:00
* client.install: Add new template.
2018-08-04 10:44:18 +03:00
* control: Update vcs urls.
2018-08-04 10:45:01 +03:00
* control: Mark priority as optional.
2018-08-04 10:57:40 +03:00
* control, rules: Bump dh to 11.
* control: Add adduser to server depends.
2018-08-04 11:04:02 +03:00
* source/lintian-overrides: Updated.
2018-08-04 11:04:55 +03:00
* control: Bump policy to 4.1.5.
* control: Update maintainer list address.
* control: Build the server only on archs where 389-ds-base is
available.
* control: Bump python-ldap build-dep to 3.1.
-- Timo Aaltonen <tjaalton@debian.org> Fri, 28 Sep 2018 14:10:34 +0300
freeipa (4.7.0~pre1+git20180411-2) experimental; urgency=medium
* fix-bind-ldap-so-path.diff: Dropped, the plugin uses non-MA path
now, fix depends to match.
* control: Add python-augeas to python-ipaclient depends. (LP: #1764615)
* ldap-multiarch.diff: Replace hack-libarch.diff with a new patch to
support more than x86. (LP: #1600634)
-- Timo Aaltonen <tjaalton@debian.org> Tue, 17 Apr 2018 23:47:32 +0300
freeipa (4.7.0~pre1+git20180411-1) experimental; urgency=medium
2018-04-06 16:23:32 +03:00
2018-04-11 20:38:09 +03:00
* New upstream prerelease + git snapshot.
* tests: Fix whitespace.
* client.dirs: Add /var/lib/ipa-client/pki.
* server.post*: Enable session, session_cookie apache modules.
* control: Add sssd-dbus to server Depends.
* fix-httpd-group.diff: Fix apache group for Debian.
* control: Bump dependency on certmonger.
* support-pam-mkhomedir.diff: Add support for enabling pam_mkhomedir.
(LP: #1336869)
2018-04-11 20:38:09 +03:00
* control: Add libsss-certmap-dev to build-depends.
* control: Drop hardcoded libcurl3 dependency from client.
* control*, rules: Add support for client-only build.
* Fold admintools into the client package.
* fix-bind-ldap-so-path.diff: Use multiarch path to bind/ldap.so.
2018-04-06 16:28:57 +03:00
* fix-ipa-conf.diff: Dropped, upstream.
2018-04-06 17:00:23 +03:00
* rules: Force building with python2.
2018-04-06 17:00:51 +03:00
* server.install: Updated.
2018-04-06 17:01:53 +03:00
* debian/.gitignore: Ignore d/control.
* rules: If git is installed, revert po/ on clean.
* server.dirs: Add missing directories, fix some permissions in
postinst.
* control.server: Bump dogtag dependencies to 10.6.0~.
* control.server: Drop mod-nss from Depends, mod_ssl is used instead.
* enable-mod-nss-during-setup.diff: Dropped, not needed anymore.
* server.postinst/postrm: Enable/disable mod_ssl.
2018-04-06 17:34:37 +03:00
* control: Bump 389-ds-base dependency.
* rules: Modify python scripts to use python2.
* fix-paths.diff: Add some paths to platform data.
* hack-tomcat-race.diff: Restarting pki-tomcatd takes time, and renew_ca_cert
2018-04-11 00:23:08 +03:00
does that several times in a row, so wait for 80s before starting migrating
profiles to ldap to make sure the instance is up.
* fix-apache-ssl-setup.diff: Fix mod_ssl setup.
* hack-duplicate-cert-directive.diff: Delete a duplicate
SSLCertificateFile directive until upstream is fixed.
* server.postinst: Enable default-ssl site.
* control: Depend on chrony instead of ntp.
2018-04-11 20:46:42 +03:00
* fix-paths.diff: Add CHRONY_CONF.
* python-ipaserver.install: Updated after dropping NTP.
* fix-version.diff: Append +git to prerelease tag, don't require git.
2018-04-11 23:31:41 +03:00
* pydist_overrides: Added.
2018-04-12 00:39:56 +03:00
* rules: Update clean target.
2018-04-12 14:01:47 +03:00
* control: Bump depends on bind9.
2018-04-06 16:23:32 +03:00
-- Timo Aaltonen <tjaalton@debian.org> Thu, 12 Apr 2018 14:01:56 +0300
2018-04-06 16:23:32 +03:00
freeipa (4.6.3-1) unstable; urgency=medium
2018-02-01 14:14:23 +02:00
* New upstream release.
* support-kdb-dal-7.0.diff: Dropped, upstream.
* tests: Force hostname as 'autopkgtest' if the system didn't have
one.
2018-02-01 14:14:23 +02:00
-- Timo Aaltonen <tjaalton@debian.org> Fri, 02 Feb 2018 17:27:41 +0200
2018-02-01 14:14:23 +02:00
freeipa (4.6.2-4) unstable; urgency=medium
* client.postinst: Migrate from old nssdb only if it exists.
-- Timo Aaltonen <tjaalton@debian.org> Tue, 30 Jan 2018 17:42:08 +0200
freeipa (4.6.2-3) unstable; urgency=medium
* tests: Add some debug info, and fail properly.
-- Timo Aaltonen <tjaalton@debian.org> Mon, 29 Jan 2018 13:17:25 +0200
freeipa (4.6.2-2) unstable; urgency=medium
* server.postinst: Fix output redirection.
-- Timo Aaltonen <tjaalton@debian.org> Sat, 20 Jan 2018 21:33:26 +0200
freeipa (4.6.2-1) unstable; urgency=medium
* New upstream release.
- Remove upstreamed patches:
add-debian-platform.diff,
ipa-kdb-support-dal-version-5-and-6.diff,
purge-firefox-extension.diff,
fix-ipa-otpd-install.diff,
fix-ipa-otpd-service.diff,
purge-firefox-extension.diff,
prefix.patch,
fix-kdcproxy-path.diff,
fix-is-running.diff,
fix-pkcs11-helper.diff,
fix-dnssec-services.diff
- Remove obsolete patches: fix-memcached.diff,
fix-oddjobs.diff,
fix-kdcproxy-paths.diff
- Refresh rest of the patches
* control et al: Memcached is not used anymore.
* control, server.install: Depend on gssproxy.
* control: Build-depend on python-jinja2, add CSR files to python-
ipaclient.
2017-03-15 09:57:56 +02:00
* *.install: Updated.
* client.postinst: Fix update_ipa_nssdb import.
* rules, autoreconf: Refactor the build to match current upstream,
drop d/autoreconf.
* local-options: Ignore some files not on tarballs.
2017-12-21 18:15:13 +02:00
* rules: Migrate to dh_missing.
* Drop server tmpfile, ship upstream one, and create ipaapi/kdcproxy
users/groups on install and add www-data to ipaapi group.
* control: Add python-sss to python-ipaserver depends.
* rules: Disable building on a builddirectory, it's broken upstream
for now.
* control: Drop libcurl4-nss-dev from build-depends, bump libkrb5-dev
build-dependency.
* control: Bump dependency on bind9 and bind9-dyndb-ldap.
* control: add libapache2-mod-lookup-identity to server dependencies,
enable/disable it in postinst/postrm.
* control: Depend on newer custodia, move dep on python-custodia to
python-ipaserver.
* control: Add python-sss to client depends.
* Add support for krb 1.16. (Closes: #887814)
-- Timo Aaltonen <tjaalton@debian.org> Sat, 20 Jan 2018 12:41:28 +0200
freeipa (4.4.4-4) unstable; urgency=medium
[ Timo Aaltonen ]
* fix-opendnssec-setup.diff: Use /usr/sbin prefix for ods binaries.
* samba-4.7-fix-*: Add backported commits to allow building against
samba 4.7. (Closes: #880841)
[ Steve Langasek ]
* Fix autopkgtest to be robust in the face of changed iproute2 output.
-- Timo Aaltonen <tjaalton@debian.org> Sat, 16 Dec 2017 09:15:37 +0200
freeipa (4.4.4-3) unstable; urgency=medium
* fix-opendnssec-setup.diff: Fix a typo. (Closes: #878095)
-- Timo Aaltonen <tjaalton@debian.org> Mon, 09 Oct 2017 23:51:56 +0300
freeipa (4.4.4-2) unstable; urgency=medium
* control: Add a dependency on fonts-open-sans. (LP: #1656236)
* fix-opendnssec-install.diff: Updated for opendnssec 2.1.x. (LP:
#1703836)
-- Timo Aaltonen <tjaalton@debian.org> Mon, 09 Oct 2017 10:41:55 +0300
freeipa (4.4.4-1) unstable; urgency=medium
2017-05-17 21:19:20 +03:00
* Upload to unstable. (Closes: #862846)
2017-03-30 11:41:40 +03:00
* New upstream release.
- CVE-2017-2590
- ipa-kdb-support-dal-version-5-and-6.diff: Dropped, upstream.
- purge-firefox-extension.diff: Refreshed.
* fix-is-running.diff: Add a third argument to is_running() in
2017-03-02 09:38:58 +02:00
ipaplatform/debian/services.py. (Closes: #856533)
* fix-kdcproxy-path.diff: Update debian/paths.py to use correct path
for ipa-httpd-kdcproxy.
* client.dirs: Ship /etc/krb5.conf.d, because not having that breaks
the installer when krb5.conf tries to include that.
* copyright, watch: Update source/release location.
* control, ipaserver: Move adtrustinstance python files to python-
ipaserver, and add samba-common to python-ipaserver depends so that
uninstall works.
* fix-pkcs11-helper.diff: Fix ipa-dnskeysyncd setup which was broken
by softhsm 2.2.
* fix-opendnssec-setup.diff: Opendnssec 2.0.x broke DNSSEC setup, fix
it.
-- Timo Aaltonen <tjaalton@debian.org> Wed, 17 May 2017 21:19:22 +0300
freeipa (4.4.3-3) experimental; urgency=medium
2017-01-28 15:29:02 +02:00
* client.postinst: Fix logfile location.
-- Timo Aaltonen <tjaalton@debian.org> Thu, 16 Feb 2017 11:26:08 +0200
2017-01-28 15:29:02 +02:00
freeipa (4.4.3-2) experimental; urgency=medium
* control: Fix python-ipatests to depend on python-sss instead of
python-sssdconfig.
-- Timo Aaltonen <tjaalton@debian.org> Sat, 28 Jan 2017 00:15:53 +0200
freeipa (4.4.3-1) experimental; urgency=medium
2016-12-01 08:25:50 +02:00
2016-12-23 08:20:42 +02:00
* New upstream release. (Closes: #848762)
2016-12-01 08:25:50 +02:00
* configure-apache-from-installer.diff: Dropped, upstream.
* fix-cve-2016-5404.diff: Dropped, upstream.
2016-12-01 08:30:36 +02:00
* patches: Refreshed.
* work-around-apache-fail.diff: Dropped, apache supports systemd now
so this should not be needed.
2016-12-01 08:40:41 +02:00
* watch: Use https url.
* client.postinst: Use update_ipa_nssdb(), which also removes remnants
from /etc/pki/nssdb.
* control: Bump depends on slapi-nis to 0.56.1.
* control: Add python-custodia and python-requests to ipalib depends.
* control: Use python-netifaces instead of iproute.
* control: Add python-sssdconfig to python-ipatests depends.
* control: Bump depends on 389-ds-base to 1.3.5.6, upstream #5396
#2008.
* control: Bump bind9-dyndb-ldap depends to 10, upstream #2008.
* control: Add python-libsss-nss-idmap to build-depends.
* control: Bump depends on sssd to 1.14.0.
2016-12-01 11:14:28 +02:00
* install: Updated.
2016-12-01 13:20:26 +02:00
* platform:
- drop variables that were commented out
- add some comments to tasks.py
- migrate some services to use systemd
- add & update some paths
2017-01-14 11:21:06 +02:00
- add some stub services (LP: #1653245)
* control: Add krb5-otp to server depends. (LP: #1640732)
* control: Demote ntp to Recommends so that lxc containers can be
enrolled without it. (LP: #1630911)
2016-12-01 08:25:50 +02:00
-- Timo Aaltonen <tjaalton@debian.org> Sat, 14 Jan 2017 15:29:25 +0200
2016-12-01 08:25:50 +02:00
freeipa (4.3.2-5) unstable; urgency=medium
* fix-cve-2016-5404.diff: Fix permission check bypass (Closes: #835131)
- CVE-2016-5404
* ipa-kdb-support-dal-version-5-and-6.diff: Support mit-krb5 1.15.
(Closes: #844114)
-- Timo Aaltonen <tjaalton@debian.org> Sat, 03 Dec 2016 01:02:40 +0200
freeipa (4.3.2-4) unstable; urgency=medium
* freeipa-client.post*: Use /var/log/ipaclient-upgrade.log instead of
ipaupgrade.log, and remove it on purge. (Closes: #842071)
* control: Bump dependency on libapache2-mod-auth-gssapi to verify
upstream bug #5653 is resolved.
* platform: Add Debian mapping for rpcgssd and rpcidmapd service
files. (LP: #1645201)
-- Timo Aaltonen <tjaalton@debian.org> Thu, 01 Dec 2016 08:12:27 +0200
freeipa (4.3.2-3) unstable; urgency=medium
* rules: Add a check to override_dh_fixperms so that chmod is not run
on arch-indep build where the targets don't exist. (Closes: #839844)
-- Timo Aaltonen <tjaalton@debian.org> Thu, 06 Oct 2016 01:22:13 +0300
freeipa (4.3.2-2) unstable; urgency=medium
* copyright: Since ffb9a09a0d all original code should be GPL-3+, so
drop some exceptions.
* control: Add libnss-sss, libpam-sss and libsss-sudo to client depends
to ensure they get installed. (LP: #1600513)
* fix-ipa-otpd-service.diff: Use correct path for ipa-otpd. (LP:
#1628884)
* add-debian-platform.diff: Fix libsofthsm2.so install path.
* control: Bump dep on softhsm2 due to changed lib install path.
* tests: Add simple autopkgtest to check that ipa-server-install
works.
-- Timo Aaltonen <tjaalton@debian.org> Wed, 05 Oct 2016 00:35:51 +0300
freeipa (4.3.2-1) experimental; urgency=medium
2016-08-30 01:28:31 +03:00
* New upstream release.
* copyright, missing-sources, README.source: Exclude minified javascript
that the runtime does not need. Add unminified versions of others,
update copyright to match. (Closes: #787593)
* source/lintian-overrides: Document minified javascript issues.
-- Timo Aaltonen <tjaalton@debian.org> Wed, 14 Sep 2016 13:03:54 +0300
freeipa (4.3.1-2) experimental; urgency=medium
* control: python-ipalib can be arch:all now.
-- Timo Aaltonen <tjaalton@debian.org> Mon, 25 Jul 2016 22:22:52 +0300
freeipa (4.3.1-1) unstable; urgency=medium
2015-10-03 08:57:09 +03:00
* New upstream release. (Closes: #781607, #786411) (LP: #1449304)
- drop no-test-lang.diff, obsolete
* fix-match-hostname.diff, control: Drop the patch and python-openssl
deps, not needed anymore
2016-04-07 18:29:31 +03:00
* rules, platform, server.dirs, server.install:
Add support for DNSSEC.
* control, rules: Add support for kdcproxy.
* control, server: Migrate to mod-auth-gssapi.
2016-03-27 16:37:27 +03:00
* control, rules, fix-ipa-conf.diff: Add support for custodia.
2016-04-07 18:29:31 +03:00
* control:
- Add python-cryptography to build-deps and python-freeipa deps.
- Add libp11-kit-dev to build-deps, p11-kit to server deps.
- Depend on python-gssapi instead of python-kerberos/-krbV.
- Add libini-config-dev and python-dbus to build-deps, replace wget
with curl.
- Bump libkrb5-dev build-dep.
- Add pki-base to build-deps and pki-kra to server deps, bump pki-ca
version.
- Drop python-m2crypto from deps, obsolete.
- Bump sssd deps to 1.13.1.
- Add python-six to build-deps and python-freeipa deps.
- Split python stuff from server, client, tests to python-
ipa{server,client,tests}, rename python-freeipa to match and move
translations to freeipa-common. Mark them Arch:all where possible,
and add Breaks/Replaces.
- Add oddjob to server and oddjob-mkhomedir to client deps.
- Add python-setuptools to python-ipalib deps.
- Bump 389-ds-base* deps.
- Bump server and python-ipaserver dependency on python-ldap to 2.4.22
to fix a bug on ipa-server-upgrade.
- Add pki-tools to python-ipaserver deps.
- Add zip to python-ipaserver depends.
- Add python-systemd to server depends.
- Add opendnssec to freeipa-server-dns depends.
- Add python-cffi to python-ipalib depends.
- Bump dep on bind9-dyndb-ldap.
- Bump certmonger dependency to version that has helpers in the correct
place.
* patches:
- prefix.patch: Fix ipalib install too.
- Drop bits of platform.diff and other patches that are now upstream.
- fix-kdcproxy-paths.diff: Fix paths in kdcproxy configs.
- fix-oddjobs.diff: Fix paths and uids in oddjob configs.
- fix-replicainstall.diff: Use ldap instead of ldaps for conncheck.
- fix-dnssec-services.diff: Debianize ipa-dnskeysyncd & ipa-ods-
exporter units.
- create-sysconfig-ods.diff: Create an empty file for opendnssec
daemons, until opendnssec itself is fixed.
- purge-firefox-extension.diff: Clean obsolete kerberosauth.xpi.
- enable-mod-nss-during-setup.diff: Split from platform.diff, call
a2enmod/a2dismod from httpinstance.py.
- fix-memcached.diff: Split from platform.diff, debianize memcached
conf & unit.
- hack-libarch.diff: Don't use fedora libpaths.
* add-debian-platform.diff:
- Update paths.py to include all variables, comment out ones we don't
modify.
- Use systemwide certificate store; put ipa-ca.crt in
/usr/local/share/ca-certificates, and run update-ca-certificates
2016-03-02 14:05:49 +02:00
- Map smb service to smbd (LP: #1543230)
2016-04-07 18:29:31 +03:00
- Don't ship /var/cache/bind/data, fix named.conf a bit.
- Use DebianNoService() for dbus. (LP: #1564981)
2016-04-07 18:29:31 +03:00
- Add more constants
* Split freeipa-server-dns from freeipa-server, add -dns to -server
Recommends.
2016-04-07 18:29:31 +03:00
* server.postinst: Use ipa-server-upgrade.
* admintools: Use the new location for bash completions.
* rules: Remove obsolete configure.jar, preferences.html.
* platform: Fix ipautil.run stdout handling, add support for systemd.
* server.postinst, tmpfile: Create state directories for
mod_auth_gssapi.
* rules, server.install: Install scripts under /usr/lib instead of
multiarch path to avoid hacking the code too much.
* fix-ipa-otpd-install.diff, rules, server.install: Put ipa-otpd in
/usr/lib/ipa instead of directly under multiarch lib path.
* control, server*.install: Move dirsrv plugins from server-trust-ad
to server, needed on upgrades even if trust-ad isn't set up.
2016-03-02 11:42:19 +02:00
* server: Enable mod_proxy_ajp and mod_proxy_http on postinst, disable
on postrm.
* rules: Add SKIP_API_VERSION_CHECK, and adjust directories to clean.
2016-04-07 18:29:31 +03:00
* rules: Don't enable systemd units on install.
* client: Don't create /etc/pki/nssdb on postinst, it's not used
anymore.
2016-04-07 18:29:31 +03:00
* platform.diff, rules, server.install: Drop generate-rndc-key.sh, bind
already generates the keyfile.
2015-10-03 08:57:09 +03:00
-- Timo Aaltonen <tjaalton@debian.org> Mon, 18 Apr 2016 17:40:32 +0300
2015-10-03 08:57:09 +03:00
freeipa (4.1.4-1) experimental; urgency=medium
2015-04-02 14:09:14 +03:00
2015-09-24 16:38:33 +03:00
* New upstream release. (LP: #1492226)
2015-04-02 14:09:14 +03:00
- Refresh patches
- platform-support.diff: Added NAMED_VAR_DIR.
- fix-bind-conf.diff: Dropped, obsolete with above.
- disable-dnssec-support.patch: Disable DNSSEC-support as we're
missing the dependencies for now.
* control: Add python-usb to build-depends and to python-freeipa
depends.
2015-09-24 05:45:01 +03:00
* control: Bump SSSD dependencies.
* control: Add libsofthsm2-dev to build-depends and softhsm2 to server
depends.
* freeipa-{server,client}.install: Add new files.
* control: Bump Depends on slapi-nis for CVE fixes.
* control: Bump 389-ds-base, pki-ca depends.
* control: Drop dogtag-pki-server-theme from server depends, it's not
needed.
* control: Server needs newer python-ldap, bump build-dep too.
2015-09-24 05:51:36 +03:00
* control: Bump certmonger depends.
2015-09-24 05:57:51 +03:00
* control: Bump python-nss depends.
* freeipa-client: Add /etc/ipa/nssdb, rework /etc/pki/nssdb handling.
2015-09-24 13:22:19 +03:00
* platform: Add DebianNamedService.
* platform, disable-dnssec-support.patch: Fix named.conf template.
* server.postinst: Run ipa-ldap-updater and ipa-upgradeconfig on
postinst.
* Revert DNSSEC changes to schema and ACI, makes upgrade tools fail.
* server.postrm: Clean logs on purge and disable apache modules on
remove/purge.
2015-04-02 14:09:14 +03:00
-- Timo Aaltonen <tjaalton@debian.org> Fri, 25 Sep 2015 14:07:40 +0300
2015-04-02 14:09:14 +03:00
freeipa (4.0.5-6) unstable; urgency=medium
* control Add gnupg-agent to python-freeipa depends, and change gnupg
to gnupg2. (LP: #1492184)
* Rebuild against current krb5, there was an abi break which broke at
least the setup phase.
-- Timo Aaltonen <tjaalton@debian.org> Thu, 24 Sep 2015 23:22:24 +0300
freeipa (4.0.5-5) unstable; urgency=medium
* control: Drop selinux-policy-dev from build-depends, not needed
anymore.
* client.dirs,postrm: Drop removing /etc/pki/nssdb from postrm and let
dpkg handle it. (Closes: #781114)
-- Timo Aaltonen <tjaalton@debian.org> Thu, 09 Apr 2015 17:16:37 +0300
freeipa (4.0.5-4) unstable; urgency=medium
2015-03-05 15:49:14 +02:00
* control: Fix freeipa-tests depends.
* control: Add systemd-sysv to server depends. (Closes: #780386)
* freeipa-client.postrm: Purge /etc/pki if empty. (Closes: #781114)
* add-a-clear-openssl-exception.diff: Add a clear OpenSSL exception.
(Closes: #772136)
2015-04-02 10:07:42 +03:00
* control: Add systemd to build-depends.
* dont-check-for-systemd-pc.diff: Dropped, not needed anymore.
2015-03-05 15:49:14 +02:00
-- Timo Aaltonen <tjaalton@debian.org> Thu, 02 Apr 2015 10:53:55 +0300
2015-03-05 15:49:14 +02:00
freeipa (4.0.5-3) unstable; urgency=medium
* rules: Set JAVA_STACK_SIZE to hopefully avoid FTBFS on exotic archs.
* freeipa-client.postrm: Remove nssdb files on purge. (Closes:
#775387)
* freeipa-client.postinst: Fix bashism with echo. (Closes: #772242)
-- Timo Aaltonen <tjaalton@debian.org> Wed, 04 Mar 2015 14:51:35 +0200
freeipa (4.0.5-2) unstable; urgency=medium
* Team upload.
* Let python-freeipa depend on python-pyasn1, because pyasn1 is imported
by ipalib/pkcs10.py and ipalib/plugins/cert.py.
* debian/copyright: Drop unused PD license section
* debian/copyright: Fix paths of Javascript files
-- Benjamin Drung <benjamin.drung@profitbricks.com> Mon, 24 Nov 2014 12:32:36 +0100
freeipa (4.0.5-1) unstable; urgency=medium
2014-11-04 12:17:00 +02:00
2014-11-07 11:42:40 +02:00
* New upstream release
- Fix CVE-2014-7828. (Closes: #768294)
2014-11-04 12:17:00 +02:00
* control: Update my email address.
2014-11-05 17:14:07 +02:00
* fix-bind-conf.diff, add-debian-platform.diff: Fix bind config
template to use Debian specific paths, and replace named.conf not
named.conf.local. (Closes: #768122)
* rules, -server.postinst: Create /var/cache/bind/data owned by bind
user.
2014-11-07 11:42:40 +02:00
* rules: Fix /var/lib/ipa/backup permissions.
* Add non-standard-dir-perm to server lintian overrides.
2014-11-05 14:43:30 +02:00
* copyright: Fix a typo.
2014-11-07 11:43:26 +02:00
* control: Bump dependency on bind9-dyndb-ldap to 6.0-4~.
* control: Move dependency on python-qrcode and python-yubico from
server to python-freeipa and drop python-selinux which belongs to
pki-server.
* control: Relax libxmlrpc-core-c3-dev buil-dep and 389-ds-base dep
for easier backporting.
* control: Add python-dateutils to server, and python-dbus and python-
memcache to python-freeipa dependencies. (Closes: #768187)
* platform: Handle /etc/default/nfs-common and /etc/default/autofs,
drop NSS_DB_DIR since it's inherited already. (Closes: #769037)
* control: Bump policy to 3.9.6, no changes.
2014-11-04 12:17:00 +02:00
-- Timo Aaltonen <tjaalton@debian.org> Tue, 11 Nov 2014 10:38:52 +0200
2014-11-04 12:17:00 +02:00
freeipa (4.0.4-2) unstable; urgency=medium
* control: Add python-qrcode, python-selinux, python-yubico
to freeipa-server dependencies. (Closes: #767427)
* freeipa-server.postinst: Enable mod_authz_user and mod_deflate too,
but since they should be part of the default apache2 install, don't
disable them on uninstall like the other modules. (Closes: #767425)
* control: Bump server dependency on -mod-nss to 1.0.10-2 which
doesn't enable the module by default.
-- Timo Aaltonen <tjaalton@debian.org> Fri, 31 Oct 2014 11:36:51 +0200
freeipa (4.0.4-1) unstable; urgency=medium
2014-06-17 16:12:05 +03:00
2014-01-14 23:39:35 +02:00
* Initial release (Closes: #734703)
-- Timo Aaltonen <tjaalton@debian.org> Sat, 25 Oct 2014 02:43:59 +0300