Debian release 4.1.0-1 Format: 1.8 Date: Thu, 15 Mar 2012 16:18:41 -0700 Source: webauth Binary: libapache2-webauth libapache2-webkdc libwebauth-perl libwebauth6 libwebauth-dev libwebkdc-perl webauth-tests webauth-utils webauth-weblogin Architecture: source i386 all Version: 4.1.0-1 Distribution: unstable Urgency: low Maintainer: Russ Allbery <rra@debian.org> Changed-By: Russ Allbery <rra@debian.org> Description: libapache2-webauth - Apache 2 modules for WebAuth authentication libapache2-webkdc - Apache 2 modules for a WebAuth authentication KDC libwebauth-dev - Development files for WebAuth authentication libwebauth-perl - Perl library for WebAuth authentication libwebauth6 - Shared libraries for WebAuth authentication libwebkdc-perl - Perl libraries for WebAuth central login server webauth-tests - Tests for the WebAuth authentication modules webauth-utils - Command-line utilities for WebAuth authentication webauth-weblogin - Central login server for WebAuth authentication Changes: webauth (4.1.0-1) unstable; urgency=low . * New upstream release. - New mod_webkdc WebKdcUserInfoTimeout option to set a network timeout for user information service queries. The new default is 30 seconds. - New mod_webkdc WebKdcUserInfoIgnoreFail error to allow users to authenticate with password and use pre-existing single sign-on cookies even if the user information service is down. Be aware that this can allow bypassing a centrally-mandated multifactor requirement. - Use remctl_set_ccache instead of setting KRB5CCNAME when available to avoid memory leaks on calling the user information service and to not leak settings across threads. - Fix WebLogin error handling when the password field is left blank. - Fix WebLogin error handling of empty usernames. - Drop library support for base64-encoded token attributes (which was never used by WebAuth). - Drop webauth_info_{build,version} library APIs. - Document Apache/Tomcat security interaction around URL parsing in the mod_webauth manual. This affects any Apache security mechanism used in conjunction with Tomcat. * Bump libremctl-dev build dependency to >= 3.1 for consistent builds. * Add Build-Depends-Package to the symbols file for better dependency handling. * Update standards version to 3.9.3 (no changes required). Checksums-Sha1: b86f14995bdfb72037e3249ed536e239d3b42d79 1973 webauth_4.1.0-1.dsc 0faeeb24178e4e0946d2cf91ee4a34688ead2b8d 1053315 webauth_4.1.0.orig.tar.gz ee7da5a4f39f624ed3e9dfa7305f7d8608653361 25016 webauth_4.1.0-1.debian.tar.gz 53541147c60569fe1b3f214bc51caaafe78ea73d 223030 libapache2-webauth_4.1.0-1_i386.deb 64241e8a6776f18ad245cc4ba96d1dbc427151ce 93024 libapache2-webkdc_4.1.0-1_i386.deb bc65b6a316c24ea5b8f71a14a6246f4bf8b54485 69250 libwebauth-perl_4.1.0-1_i386.deb d12255d75c5c22faf5f7eeb167d46026c6884e73 72688 libwebauth6_4.1.0-1_i386.deb 8cfe6af41a7ea50984dbeb9a5fa9b5d50e5a479a 93244 libwebauth-dev_4.1.0-1_i386.deb ea72e1d1c285639b5818d260859b1623be21e94d 78880 libwebkdc-perl_4.1.0-1_all.deb 5c9da11bbe8ae92c00cfd9dc2efc0874057f4e97 46216 webauth-tests_4.1.0-1_all.deb b3060c10483844d80410798fe1ef3ee78b2ffb96 43282 webauth-utils_4.1.0-1_i386.deb 2971871b4980abfedf46aa5583298f1ddb27c5d3 95426 webauth-weblogin_4.1.0-1_all.deb Checksums-Sha256: e509853a3e31ea24a9c8c8f6debc180aac05884bb40cad9c7e1f02f5abd52964 1973 webauth_4.1.0-1.dsc 0700aef26b7f57bade32490a79eb218df6b190c4badd96253cbab930599a7be5 1053315 webauth_4.1.0.orig.tar.gz bad254b7f0eb39a05ab413ba80db3a882955b86887e97ebc0bc7d70f47251336 25016 webauth_4.1.0-1.debian.tar.gz a3e7e32485b38ea57ae9da5ecd3d186ff94a0103092238268dbfa591f3a23352 223030 libapache2-webauth_4.1.0-1_i386.deb 6e5654ad0289ac97b722e7217938fd2a8ba5d364d4dba3a8d5412acf8104ebc6 93024 libapache2-webkdc_4.1.0-1_i386.deb 44eeaf98e4572261cad46c90bb5ca28b47c9b79c070ea0f3215960c0e87cd2db 69250 libwebauth-perl_4.1.0-1_i386.deb 44146b4dbfecad5151d911aee03911316c0dd739049ca1f4fbfc77f5666a6b39 72688 libwebauth6_4.1.0-1_i386.deb f7851798837ffee2381c0e1056c790f0a0d8abd9c12338342173bc3b9dadb85a 93244 libwebauth-dev_4.1.0-1_i386.deb 99ffd7a13ebb1f37ff2a2a36d7529b4b641e9067ce9682a6f850308b01c848f1 78880 libwebkdc-perl_4.1.0-1_all.deb 95ebbdb4dfb29d1b98ee20b5f1f16fb2d3b294bd2e0c543c5247e7e708320c17 46216 webauth-tests_4.1.0-1_all.deb 72eb3792ffaf14f316ac9a7e91aef7a7a448f5d142f8173cc28986d8dc74b664 43282 webauth-utils_4.1.0-1_i386.deb c2f782de132558c2145dfcc31772267a54aa985860f4c38323c81bd9a35d127a 95426 webauth-weblogin_4.1.0-1_all.deb Files: 1456de247d15deba1465b02bc8d3d9f5 1973 web optional webauth_4.1.0-1.dsc b00e4c299e1a1d02f506cd43d0e00ca9 1053315 web optional webauth_4.1.0.orig.tar.gz e9d34c19ac27872c18e61157ef87c611 25016 web optional webauth_4.1.0-1.debian.tar.gz d3743d18e7d35348bfd3112b74762ba7 223030 httpd optional libapache2-webauth_4.1.0-1_i386.deb 17064f2ee657ffbdb72b81874ac840ff 93024 httpd optional libapache2-webkdc_4.1.0-1_i386.deb 068fdddd9d47fc41519c14b1fa46cdee 69250 perl optional libwebauth-perl_4.1.0-1_i386.deb d7a5bbc50dea53d848939a2579026f81 72688 libs optional libwebauth6_4.1.0-1_i386.deb 31cc3f6c745fcc00974419e7886c08a1 93244 libdevel extra libwebauth-dev_4.1.0-1_i386.deb 2beb6d593b571445ab769b00d4beb166 78880 perl optional libwebkdc-perl_4.1.0-1_all.deb 8e675dc42f9a73ac9602e3b48e3e0b4a 46216 web optional webauth-tests_4.1.0-1_all.deb 2c4c631288710b06bb231cd84b6fb7bd 43282 web optional webauth-utils_4.1.0-1_i386.deb 86c3e267f270966888ee5ba9d89bd0f4 95426 web optional webauth-weblogin_4.1.0-1_all.deb