mirror of
https://git.FreeBSD.org/ports.git
synced 2025-01-30 10:38:37 +00:00
191d528d94
In addition, deprecate krb5-116 to retire one year after the release of krb5-118: Feb 12, 2021. Major changes in 1.18 (2020-02-12) ================================== Administrator experience: * Remove support for single-DES encryption types. * Change the replay cache format to be more efficient and robust. Replay cache filenames using the new format end with ".rcache2" by default. * setuid programs will automatically ignore environment variables that normally affect krb5 API functions, even if the caller does not use krb5_init_secure_context(). * Add an "enforce_ok_as_delegate" krb5.conf relation to disable credential forwarding during GSSAPI authentication unless the KDC sets the ok-as-delegate bit in the service ticket. * Use the permitted_enctypes krb5.conf setting as the default value for default_tkt_enctypes and default_tgs_enctypes. Developer experience: * Implement krb5_cc_remove_cred() for all credential cache types. * Add the krb5_pac_get_client_info() API to get the client account name from a PAC. Protocol evolution: * Add KDC support for S4U2Self requests where the user is identified by X.509 certificate. (Requires support for certificate lookup from a third-party KDB module.) * Remove support for an old ("draft 9") variant of PKINIT. * Add support for Microsoft NegoEx. (Requires one or more third-party GSS modules implementing NegoEx mechanisms.) * Honor the transited-policy-checked ticket flag on application servers, eliminating the requirement to configure capaths on servers in some scenarios. User experience: * Add support for "dns_canonicalize_hostname=fallback""`, causing host-based principal names to be tried first without DNS canonicalization, and again with DNS canonicalization if the un-canonicalized server is not found. * Expand single-component hostnames in host-based principal names when DNS canonicalization is not used, adding the system's first DNS search path as a suffix. Add a "qualify_shortname" krb5.conf relation to override this suffix or disable expansion. Code quality: * The libkrb5 serialization code (used to export and import krb5 GSS security contexts) has been simplified and made type-safe. * The libkrb5 code for creating KRB-PRIV, KRB-SAFE, and KRB-CRED messages has been revised to conform to current coding practices. * The test suite has been modified to work with macOS System Integrity Protection enabled. * The test suite incorporates soft-pkcs11 so that PKINIT PKCS11 support can always be tested.
179 lines
3.9 KiB
Plaintext
179 lines
3.9 KiB
Plaintext
bin/compile_et
|
|
bin/gss-client
|
|
bin/k5srvutil
|
|
bin/kadmin
|
|
bin/kdestroy
|
|
bin/kinit
|
|
bin/klist
|
|
bin/kpasswd
|
|
bin/krb5-config
|
|
@mode 04755
|
|
@owner root
|
|
@group wheel
|
|
bin/ksu
|
|
@mode
|
|
@owner root
|
|
@group wheel
|
|
bin/kswitch
|
|
bin/ktutil
|
|
bin/kvno
|
|
bin/sclient
|
|
bin/sim_client
|
|
bin/uuclient
|
|
include/com_err.h
|
|
include/gssapi.h
|
|
include/gssapi/gssapi.h
|
|
include/gssapi/gssapi_alloc.h
|
|
include/gssapi/gssapi_ext.h
|
|
include/gssapi/gssapi_generic.h
|
|
include/gssapi/gssapi_krb5.h
|
|
include/gssapi/mechglue.h
|
|
include/gssrpc/auth.h
|
|
include/gssrpc/auth_gss.h
|
|
include/gssrpc/auth_gssapi.h
|
|
include/gssrpc/auth_unix.h
|
|
include/gssrpc/clnt.h
|
|
include/gssrpc/netdb.h
|
|
include/gssrpc/pmap_clnt.h
|
|
include/gssrpc/pmap_prot.h
|
|
include/gssrpc/pmap_rmt.h
|
|
include/gssrpc/rename.h
|
|
include/gssrpc/rpc.h
|
|
include/gssrpc/rpc_msg.h
|
|
include/gssrpc/svc.h
|
|
include/gssrpc/svc_auth.h
|
|
include/gssrpc/types.h
|
|
include/gssrpc/xdr.h
|
|
include/krad.h
|
|
include/krb5.h
|
|
include/krb5/ccselect_plugin.h
|
|
include/krb5/clpreauth_plugin.h
|
|
include/krb5/hostrealm_plugin.h
|
|
include/krb5/kadm5_hook_plugin.h
|
|
include/krb5/kdcpolicy_plugin.h
|
|
include/krb5/kdcpreauth_plugin.h
|
|
include/krb5/localauth_plugin.h
|
|
include/krb5/krb5.h
|
|
include/krb5/locate_plugin.h
|
|
include/krb5/plugin.h
|
|
include/krb5/pwqual_plugin.h
|
|
include/kadm5/admin.h
|
|
include/kadm5/chpass_util_strings.h
|
|
include/krb5/kadm5_auth_plugin.h
|
|
include/kadm5/kadm_err.h
|
|
include/kdb.h
|
|
include/krb5/certauth_plugin.h
|
|
include/krb5/preauth_plugin.h
|
|
include/profile.h
|
|
include/verto-module.h
|
|
include/verto.h
|
|
lib/libcom_err.so
|
|
lib/libcom_err.so.3
|
|
lib/libcom_err.so.3.0
|
|
lib/libgssapi_krb5.so
|
|
lib/libgssapi_krb5.so.2
|
|
lib/libgssapi_krb5.so.2.2
|
|
lib/libgssrpc.so
|
|
lib/libgssrpc.so.4
|
|
lib/libgssrpc.so.4.2
|
|
lib/libk5crypto.so
|
|
lib/libk5crypto.so.3
|
|
lib/libk5crypto.so.3.1
|
|
lib/libkadm5clnt.so
|
|
lib/libkadm5clnt_mit.so
|
|
lib/libkadm5clnt_mit.so.12
|
|
lib/libkadm5clnt_mit.so.12.0
|
|
lib/libkadm5srv.so
|
|
lib/libkadm5srv_mit.so
|
|
lib/libkadm5srv_mit.so.12
|
|
lib/libkadm5srv_mit.so.12.0
|
|
lib/libkdb5.so
|
|
lib/libkdb5.so.10
|
|
lib/libkdb5.so.10.0
|
|
lib/libkrb5.so
|
|
lib/libkrb5.so.3
|
|
lib/libkrb5.so.3.3
|
|
lib/libkrb5support.so
|
|
lib/libkrb5support.so.0
|
|
lib/libkrb5support.so.0.1
|
|
lib/krb5/plugins/kdb/db2.so
|
|
%%LMDB%%lib/krb5/plugins/kdb/klmdb.so
|
|
lib/krb5/plugins/tls/k5tls.so
|
|
%%LDAP%%lib/krb5/plugins/kdb/kldap.so
|
|
lib/krb5/plugins/preauth/otp.so
|
|
lib/krb5/plugins/preauth/pkinit.so
|
|
lib/krb5/plugins/preauth/spake.so
|
|
lib/krb5/plugins/preauth/test.so
|
|
%%LDAP%%lib/libkdb_ldap.so
|
|
%%LDAP%%lib/libkdb_ldap.so.1
|
|
%%LDAP%%lib/libkdb_ldap.so.1.0
|
|
lib/libkrad.so
|
|
lib/libkrad.so.0
|
|
lib/libkrad.so.0.0
|
|
lib/libverto.so
|
|
lib/libverto.so.0
|
|
lib/libverto.so.0.0
|
|
libdata/pkgconfig/gssrpc.pc
|
|
libdata/pkgconfig/kadm-client.pc
|
|
libdata/pkgconfig/kadm-server.pc
|
|
libdata/pkgconfig/kdb.pc
|
|
libdata/pkgconfig/krb5-gssapi.pc
|
|
libdata/pkgconfig/krb5.pc
|
|
libdata/pkgconfig/mit-krb5-gssapi.pc
|
|
libdata/pkgconfig/mit-krb5.pc
|
|
man/man1/compile_et.1.gz
|
|
man/man1/k5srvutil.1.gz
|
|
man/man1/kadmin.1.gz
|
|
man/man1/kdestroy.1.gz
|
|
man/man1/kinit.1.gz
|
|
man/man1/klist.1.gz
|
|
man/man1/kpasswd.1.gz
|
|
man/man1/krb5-config.1.gz
|
|
man/man1/ksu.1.gz
|
|
man/man1/kswitch.1.gz
|
|
man/man1/ktutil.1.gz
|
|
man/man1/kvno.1.gz
|
|
man/man1/sclient.1.gz
|
|
man/man3/com_err.3.gz
|
|
man/man5/.k5identity.5.gz
|
|
man/man5/.k5login.5.gz
|
|
man/man5/k5identity.5.gz
|
|
man/man5/k5login.5.gz
|
|
man/man5/kadm5.acl.5.gz
|
|
man/man5/kdc.conf.5.gz
|
|
man/man5/krb5.conf.5.gz
|
|
man/man7/kerberos.7.gz
|
|
man/man8/kadmin.local.8.gz
|
|
man/man8/kadmind.8.gz
|
|
man/man8/kdb5_ldap_util.8.gz
|
|
man/man8/kdb5_util.8.gz
|
|
man/man8/kprop.8.gz
|
|
man/man8/kpropd.8.gz
|
|
man/man8/kproplog.8.gz
|
|
man/man8/krb5kdc.8.gz
|
|
man/man8/sserver.8.gz
|
|
sbin/gss-server
|
|
sbin/kadmin.local
|
|
sbin/kadmind
|
|
%%LDAP%%sbin/kdb5_ldap_util
|
|
sbin/kdc
|
|
sbin/kdb5_util
|
|
sbin/kprop
|
|
sbin/kpropd
|
|
sbin/kproplog
|
|
sbin/krb5-send-pr
|
|
sbin/krb5kdc
|
|
sbin/sim_server
|
|
sbin/sserver
|
|
sbin/uuserver
|
|
share/et/et_c.awk
|
|
share/et/et_h.awk
|
|
%%NLS%%share/locale/de/LC_MESSAGES/mit-krb5.mo
|
|
%%NLS%%share/locale/en_US/LC_MESSAGES/mit-krb5.mo
|
|
%%LDAP%%%%DATADIR%%/kerberos.schema
|
|
%%LDAP%%%%DATADIR%%/kerberos.ldif
|
|
@dir lib/krb5/plugins/authdata
|
|
@dir lib/krb5/plugins/libkrb5
|
|
@dir var/run/krb5kdc
|
|
@dir var/krb5kdc
|