1. 19 Aug, 2015 1 commit
    • Russ Allbery's avatar
      Update to rra-c-util 5.8 and C TAP Harness 3.3 · 531cdbab
      Russ Allbery authored
      Update to rra-c-util 5.8:
      
      * Support the Solaris 10 embedded Kerberos implementation.
      * Use calloc or reallocarray instead of malloc.
      * Fix compilation with a C++ compiler.
      
      Update to C TAP Harness 3.3:
      
      * Display verbose test results with -v or C_TAP_VERBOSE.
      * Reopen standard input to /dev/null when running a test list.
      * Don't leak extraneous file descriptors to tests.
      531cdbab
  2. 13 Apr, 2014 1 commit
  3. 10 Dec, 2013 2 commits
  4. 07 Dec, 2013 1 commit
  5. 06 Dec, 2013 3 commits
  6. 05 Dec, 2013 15 commits
  7. 04 Dec, 2013 1 commit
  8. 21 Nov, 2013 10 commits
  9. 20 Nov, 2013 2 commits
  10. 19 Nov, 2013 1 commit
    • Russ Allbery's avatar
      Add support for ad_base_instance · 50c9870a
      Russ Allbery authored
      Add a new string krb5.conf option, ad_base_instance, which, if set,
      changes the way that password synchronization is handled.  When this
      option is set, the password for the principal formed by appending that
      instance to a base principal is propagated to Active Directory as the
      password for the base principal.  So, for instance, if this is set to
      the string "windows", the password of the principal "user/windows" is
      propagated to Active Directory as the password for the principal
      "user" and password changes for the principal "user" are ignored.
      This special behavior only happens if "user/windows" exists in the
      local Kerberos KDC database; if not, password propagation for the
      principal "user" happens normally, just as if this option weren't set.
      This allows the Active Directory principal to be treated as an
      instance rather than a main account for specific users without
      affecting behavior for other users.
      
      No regressions, but currently untested otherwise.
      50c9870a
  11. 16 Nov, 2013 1 commit
    • Russ Allbery's avatar
      Add ad_queue_only to force queuing of all changes · 4563cb8b
      Russ Allbery authored
      Add a new boolean krb5.conf option, ad_queue_only, which, if set to
      true, forces all changes to be queued even if there are no conflicting
      changes already queued.  The changes can then be processed later with
      krb5-sync-backend.  This can be useful if real-time updates to Active
      Directory cause performance issues in kadmind or kpasswdd.  kpasswd
      clients in particular are often intolerant of delays.
      4563cb8b
  12. 18 Sep, 2012 2 commits