Debian release 4.5.4-1 Format: 1.8 Date: Fri, 16 Aug 2013 15:15:12 -0700 Source: webauth Binary: libapache2-mod-webauth libapache2-mod-webauthldap libapache2-mod-webkdc libapache2-webauth libapache2-webkdc libwebauth-perl libwebauth10 libwebauth-dev libwebkdc-perl webauth-tests webauth-utils webauth-weblogin Architecture: source i386 all Version: 4.5.4-1 Distribution: unstable Urgency: low Maintainer: Russ Allbery <rra@debian.org> Changed-By: Russ Allbery <rra@debian.org> Description: libapache2-mod-webauth - Apache module for WebAuth authentication libapache2-mod-webauthldap - Apache module for WebAuth LDAP lookup and authorization libapache2-mod-webkdc - Apache modules for a WebAuth authentication KDC libapache2-webauth - Transitional package for WebAuth Apache modules libapache2-webkdc - Transitional package for WebAuth authentication KDC libwebauth-dev - Development files for WebAuth authentication libwebauth-perl - Perl library for WebAuth authentication libwebauth10 - Shared libraries for WebAuth authentication libwebkdc-perl - Perl libraries for WebAuth central login server webauth-tests - Tests for the WebAuth authentication modules webauth-utils - Command-line utilities for WebAuth authentication webauth-weblogin - Central login server for WebAuth authentication Changes: webauth (4.5.4-1) unstable; urgency=low . * New upstream release. - Warn about mismatched webkdc-proxy tokens but no longer treat them as a fatal error. - Fix handling of non-password session factor requirements. - Improve handling of initial factor requirements when users have a way to establish initial credentials that don't include a password factor. - Improve handling of a Kerberos webkdc-proxy token requirement during a multifactor authentication. - Retry WebLogin posts to the WebKDC once to be more robust against interruptions by signals (such as from the FastCGI process manager). - Produce more succinct and hopefully better error messages when WebLogin cannot post to the WebKDC. - Ignore SIGPIPE signals in WebLogin scripts. - Require the return URL be absolute and not contain non-ASCII characters in mod_webkdc processing. - Fix WebLogin replay detection logic to not trigger on password changes. - Work around problems in WebLogin caused by the WebKDC returning error messages that contain undeclared non-UTF-8 characters in violation of the XML standard. - Improve error reporting of unparsable XML received by the WebLogin server from the WebKDC. - Fix logging of mod_webkdc <requestTokenRequest> failures. - Fix the prototype attributes for webauth_user_validate. - Log when mod_webkdc ignores expired tokens. - Display more correct errors after some failures during the second step of a multifactor authentication. - Correctly diagnose a missing service token in a WebLogin request and report the correct error instead of an internal error. - Make the version of all Perl modules match the WebAuth release. Checksums-Sha1: e603dd926b0d8e9492b3b2d0c9b16a0031782bfe 2082 webauth_4.5.4-1.dsc 5009b31157600883662d8e0d989157ec9438aa28 868296 webauth_4.5.4.orig.tar.xz 9036538109c1a8c6599418a2c5b2296fda965bd0 27632 webauth_4.5.4-1.debian.tar.xz 288ae517eb2f71ce955dcab6dd8b57e7d9941046 224234 libapache2-mod-webauth_4.5.4-1_i386.deb 3c995d69492cab7e6166cba82bd58c39d1c63543 90072 libapache2-mod-webauthldap_4.5.4-1_i386.deb 4b175b3e7cae7486db7b7b03f760e29c075f08be 109686 libapache2-mod-webkdc_4.5.4-1_i386.deb 73aca366e1549154311e6dced83d0382272b96dc 51842 libapache2-webauth_4.5.4-1_all.deb 927db7eeba6e9da18293656d1a4d56052dd30553 51088 libapache2-webkdc_4.5.4-1_all.deb 27188c18e602e3b5380d9a1cbe35f07c1ea9ddec 145068 libwebauth-perl_4.5.4-1_i386.deb 05b9e998623afdf066cb2e4bde7628ca4910f339 84334 libwebauth10_4.5.4-1_i386.deb ce021bb55c3f3f537e97cad27dd253643287e869 100074 libwebauth-dev_4.5.4-1_i386.deb 33ef1c799acc43e307b3f4a1b215c77ffcbd2eb8 119526 libwebkdc-perl_4.5.4-1_all.deb 7202f06833f2d09bba374580389f288e75602120 61936 webauth-tests_4.5.4-1_all.deb a98ef481e12eb211c495e9f328e3a0f895db718a 60092 webauth-utils_4.5.4-1_i386.deb 5fee2f4cb9e1fcf6274bf84158b7349ddef06bd9 120306 webauth-weblogin_4.5.4-1_all.deb Checksums-Sha256: 4ae08a5dad7d212aca0eb58d2e36fb174f13e4789998585b57b19d35145ac602 2082 webauth_4.5.4-1.dsc 9c393ffb63d86166cd80948ef4da250d0ce82174cafb460c0d5fa60d5e4391df 868296 webauth_4.5.4.orig.tar.xz ecbf211d569c196e9cda3fa442dde702b190837861ca8ae142973eb99ff3f964 27632 webauth_4.5.4-1.debian.tar.xz cfb684df13b22cef0687f19b62023411224a0212c45194ae4a59b8c19370b186 224234 libapache2-mod-webauth_4.5.4-1_i386.deb 91d55b522e035b0a1a56510b2bd255b1ffee23f65c17d0bbec5240929b858a17 90072 libapache2-mod-webauthldap_4.5.4-1_i386.deb 509447a8fe270ba7c99d80327598a1671382ebdb3668f2917287ee29efd8d0f8 109686 libapache2-mod-webkdc_4.5.4-1_i386.deb 66703e6be11d5aa7680184f84d9e40de66c0383518c0abbe6f06cd139147cdfb 51842 libapache2-webauth_4.5.4-1_all.deb c44793d8577d13491a75af56b56d7c164f8b73316a09a59e89f255d0fbd1028d 51088 libapache2-webkdc_4.5.4-1_all.deb ccf84e02d0794230237166a8422bd5321a096ced24dbec30255e0ba66799b706 145068 libwebauth-perl_4.5.4-1_i386.deb 7745f28a3c13873a2296c62ee106b20f6587ad77771167dc7e9ad4e77002eb83 84334 libwebauth10_4.5.4-1_i386.deb 0ced746e03d0e8d7579922af17f097f0c0d1adbb2b8d46daff648f4704a03a24 100074 libwebauth-dev_4.5.4-1_i386.deb 86d544fb4ed0f4c7eaf43e52f98d441ce4f91b4dfccf5bd88351c1be59b98932 119526 libwebkdc-perl_4.5.4-1_all.deb 038322b801c035c8050dd6aa0488ad3a7c83dbbc5c51c9cd91c84fb3daae3df2 61936 webauth-tests_4.5.4-1_all.deb 0c12ee11ca83c8dc5b0aef144f92f59311905dcc4ec85a87f07388c7ce286d5c 60092 webauth-utils_4.5.4-1_i386.deb 76cc7916cd276ee81b535809ee6c6f34931e69e2f74b82944d1d2259160741cc 120306 webauth-weblogin_4.5.4-1_all.deb Files: 7d4924018ba35d9520852259aa6885b2 2082 web optional webauth_4.5.4-1.dsc 4053be33fcaed57108893ed5c8ea0b1d 868296 web optional webauth_4.5.4.orig.tar.xz dff303bb0d3649cae97403478f185ba3 27632 web optional webauth_4.5.4-1.debian.tar.xz a36d55d84884e5dad5cc122c893af141 224234 httpd optional libapache2-mod-webauth_4.5.4-1_i386.deb 039c3fc4d7b91ecf5e77bf2d698e879d 90072 httpd optional libapache2-mod-webauthldap_4.5.4-1_i386.deb 3c2fab27c04d2678af3bf6c02f25f4c5 109686 httpd optional libapache2-mod-webkdc_4.5.4-1_i386.deb aec1d3c1007816142c06cb90321de64f 51842 oldlibs extra libapache2-webauth_4.5.4-1_all.deb 77aafd3f3ef9f712ba32fee6f4b5780c 51088 oldlibs extra libapache2-webkdc_4.5.4-1_all.deb a49ed7f61948a02df6bc11b1f4e4b193 145068 perl optional libwebauth-perl_4.5.4-1_i386.deb d44c5acf27937ee286fc434dba1818ea 84334 libs optional libwebauth10_4.5.4-1_i386.deb c33196c17d0e6b1effa463469c2a6710 100074 libdevel extra libwebauth-dev_4.5.4-1_i386.deb b47232a27b5b6b3c9de47847fd8f8618 119526 perl optional libwebkdc-perl_4.5.4-1_all.deb 632046aef5dcfefdec2093b26f0be42e 61936 web optional webauth-tests_4.5.4-1_all.deb a32dd3dfb860c3f7d985e0d913835ef5 60092 web optional webauth-utils_4.5.4-1_i386.deb 1fd4117036dd1ed2efffdbf7b20dc886 120306 web optional webauth-weblogin_4.5.4-1_all.deb