<feed xmlns='http://www.w3.org/2005/Atom'>
<title>src/lib/libpam, branch releng/9.0</title>
<subtitle>FreeBSD source tree</subtitle>
<id>https://cgit-dev.freebsd.org/src/atom?h=releng%2F9.0</id>
<link rel='self' href='https://cgit-dev.freebsd.org/src/atom?h=releng%2F9.0'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/'/>
<updated>2011-12-11T17:32:37Z</updated>
<entry>
<title>MFH r228410: check for null passphrases, since openssl doesn't</title>
<updated>2011-12-11T17:32:37Z</updated>
<author>
<name>Dag-Erling Smørgrav</name>
<email>des@FreeBSD.org</email>
</author>
<published>2011-12-11T17:32:37Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=691c2aa20a3d9cf525de73f0b1d86417a56d6373'/>
<id>urn:sha1:691c2aa20a3d9cf525de73f0b1d86417a56d6373</id>
<content type='text'>
Approved by:	re (kib)
Security:	prevents users with unencrypted ssh keys (prohibited
		unless the nullok option is specified) from logging in
		by providing a bogus non-null passphrase.
</content>
</entry>
<entry>
<title>Mention the name of the module in warning messages.</title>
<updated>2011-03-12T11:26:37Z</updated>
<author>
<name>Dag-Erling Smørgrav</name>
<email>des@FreeBSD.org</email>
</author>
<published>2011-03-12T11:26:37Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=864cac079fb8dac8934b6000d95a855f5cc72cf3'/>
<id>urn:sha1:864cac079fb8dac8934b6000d95a855f5cc72cf3</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Add "ruser" and "luser" options.  The former corresponds to the current</title>
<updated>2011-03-12T11:12:30Z</updated>
<author>
<name>Dag-Erling Smørgrav</name>
<email>des@FreeBSD.org</email>
</author>
<published>2011-03-12T11:12:30Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=e84da6fb397bfc780582271e3722d7073f9ba4a5'/>
<id>urn:sha1:e84da6fb397bfc780582271e3722d7073f9ba4a5</id>
<content type='text'>
behavior, where the module checks that the supplicant is a member of the
required group.  The latter checks the target user instead.  If neither
option was specified, pam_group(8) assumes "ruser" and issues a warning.
I intend to eventually change the default to "luser" to match the
behavior of similarly-named service modules in other operating systems.

MFC after:	1 month
</content>
</entry>
<entry>
<title>No newline required.</title>
<updated>2011-03-09T14:38:00Z</updated>
<author>
<name>Dag-Erling Smørgrav</name>
<email>des@FreeBSD.org</email>
</author>
<published>2011-03-09T14:38:00Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=8e391be103de3d175a40b384b4c48327d20b4bfa'/>
<id>urn:sha1:8e391be103de3d175a40b384b4c48327d20b4bfa</id>
<content type='text'>
MFC after:	2 weeks
</content>
</entry>
<entry>
<title>Add &lt;time.h&gt; for ctime(), which we accidentally picked up through</title>
<updated>2010-11-22T14:45:16Z</updated>
<author>
<name>Dag-Erling Smørgrav</name>
<email>des@FreeBSD.org</email>
</author>
<published>2010-11-22T14:45:16Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=beb8ef4a7d3c7a4a8fc0a4278c35990e804da78b'/>
<id>urn:sha1:beb8ef4a7d3c7a4a8fc0a4278c35990e804da78b</id>
<content type='text'>
&lt;sys/time.h&gt;.

Submitted by:	Garrett Cooper &lt;yanegomi@gmail.com&gt;
MFC after:	3 days
</content>
</entry>
<entry>
<title>Bump .Dd date.</title>
<updated>2010-05-03T09:49:42Z</updated>
<author>
<name>Xin LI</name>
<email>delphij@FreeBSD.org</email>
</author>
<published>2010-05-03T09:49:42Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=f93beda98af381f5ce34d8bf3322669895857d9f'/>
<id>urn:sha1:f93beda98af381f5ce34d8bf3322669895857d9f</id>
<content type='text'>
Forgotten by:	delphij
</content>
</entry>
<entry>
<title>Code indent according to style(9).</title>
<updated>2010-05-03T07:39:51Z</updated>
<author>
<name>Martin Matuska</name>
<email>mm@FreeBSD.org</email>
</author>
<published>2010-05-03T07:39:51Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=54c7282725e84db4062a1aa3756a47b5574e1968'/>
<id>urn:sha1:54c7282725e84db4062a1aa3756a47b5574e1968</id>
<content type='text'>
PR:		bin/146186
Submitted by:	myself
Approved by:	delphij (mentor)
MFC after:	2 weeks
</content>
</entry>
<entry>
<title>Implement the no_user_check option to pam_krb5.</title>
<updated>2010-05-03T07:32:24Z</updated>
<author>
<name>Martin Matuska</name>
<email>mm@FreeBSD.org</email>
</author>
<published>2010-05-03T07:32:24Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=551e75c7af421b58b9ba54d639af1e5f7a79ca23'/>
<id>urn:sha1:551e75c7af421b58b9ba54d639af1e5f7a79ca23</id>
<content type='text'>
This option is available in the Linux implementation of pam_krb5
and allows to authorize a user not known to the local system.

Ccache is not used as we don't have a secure uid/gid for the cache file.

Usable for authentication of external kerberos users (e.g Active Directory)
via PAM from applications like Cyrus saslauthd, PHP or perl.

PR:		bin/146186
Submitted by:	myself
Approved by:	deplhij (mentor)
MFC after:	2 weeks
</content>
</entry>
<entry>
<title>Upgrade to OpenSSH 5.4p1.</title>
<updated>2010-03-09T19:16:43Z</updated>
<author>
<name>Dag-Erling Smørgrav</name>
<email>des@FreeBSD.org</email>
</author>
<published>2010-03-09T19:16:43Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=b15c83408cb1e9b86c1895af0f097de05fc92ccf'/>
<id>urn:sha1:b15c83408cb1e9b86c1895af0f097de05fc92ccf</id>
<content type='text'>
MFC after:	1 month
</content>
</entry>
<entry>
<title>Remove redundant WARNS?=6 overrides and inherit the WARNS setting from</title>
<updated>2010-03-02T18:44:08Z</updated>
<author>
<name>Ulrich Spörlein</name>
<email>uqs@FreeBSD.org</email>
</author>
<published>2010-03-02T18:44:08Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=7729e3ba4017a3af96cff64b68751cb9d72c79b8'/>
<id>urn:sha1:7729e3ba4017a3af96cff64b68751cb9d72c79b8</id>
<content type='text'>
the toplevel directory.

This does not change any WARNS level and survives a make universe.

Approved by:        ed (co-mentor)
</content>
</entry>
</feed>
