[Bug 1400095] Re: Homepage is a dead link

2020-12-25 Thread Russ Allbery
This was fixed in 3.0-22 ** Changed in: xfonts-jmk (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1400095 Title: Homepage is a dead link To manage

[Bug 670207] Re: SASL mechanism ignored in bind_s?

2020-12-24 Thread Russ Allbery
Very belatedly, this was fixed in 3.0.4-1. ** Changed in: libnet-ldapapi-perl (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/670207 Title: SASL mechanism

Re: [Bug 1852997] [NEW] /etc/krb5.conf options seem to be ignored by pam_krb5.so

2019-11-18 Thread Russ Allbery
nd of the pam_krb5.so options will produce more verbose logging. If you don't see any additional logging at DEBUG level in syslog, that means that the module isn't running at all. -- Russ Allbery (r...@debian.org) <https://www.eyrie.org/~eagle/> -- You received this bug notif

Re: [Bug 1852998] [NEW] pam_krb5.so is supposed to set KRB5CCNAME, but does not

2019-11-18 Thread Russ Allbery
Thomas Schweikle <1852...@bugs.launchpad.net> writes: > pam_krb5.so is supposed to set and export KRB5CCNAME as stated in the > man pages, but does not. This seems like the same problem as your other bug: pam_krb5.so doesn't seem to actually be running. -- Russ Allbery (r..

Re: [Bug 1852470] Re: default krb5 configuration does not request tgt for local users

2019-11-14 Thread Russ Allbery
e the keyring store as root, then change > the UID of the owner, which handles the keyring store over to the user > in question. That would be great -- I have no idea how to do that, though. Do you have any pointers? -- Russ Allbery (r...@debian.org) <https://www.eyrie.org

[Bug 1852470] Re: default krb5 configuration does not request tgt for local users

2019-11-13 Thread Russ Allbery
yrings. It should be possible to use session keyrings instead, although you'll need a pam_keyinit with https://github.com/linux-pam/linux-pam/issues/149 fixed first. -- Russ Allbery (r...@debian.org) <https://www.eyrie.org/~eagle/> ** Bug watch added: github.com/linux-pam/linux-pa

[Bug 1815935] Re: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing

2019-02-26 Thread Russ Allbery
Debian has released the fix for both stable and oldstable. As I said above, I personally don't use Ubuntu, don't maintain the Ubuntu package, and don't have upload rights to Ubuntu, so I'm afraid I can't help with fixing the bug in Ubuntu. Presumably you need to find someone who works on Ubuntu

[Bug 1815935] Re: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing

2019-02-18 Thread Russ Allbery
sftp is natively supported by sshd (with ForceCommand internal-sftp and ChrootDirectory), so that avoids the problem that rssh has where ssh keeps adding new features that add new security vulnerabilities in the rssh model. That's probably the best solution if you're currently using scp. -- You

[Bug 1815935] Re: Regression in 2.3.4-4+deb8u1build0.16.04.1 on scp command parsing

2019-02-18 Thread Russ Allbery
Thanks for the report! While I don't use or maintain the Ubuntu version of rssh, it looks like Ubuntu is importing the Debian security fixes, and this is indeed a regression in Debian as well. I'm working on a fix now, and checking with the Debian security team to confirm that it's worth a

Re: [Bug 1791325] Re: freeipa server needs read access /var/lib/krb5kdc

2018-09-07 Thread Russ Allbery
blic KDC certificate is, well, public, so maybe don't put it in /var/lib/krb5kdc, which is not? (I always put mine in /etc/krb5kdc.) -- Russ Allbery (r...@debian.org) <http://www.eyrie.org/~eagle/> -- You received this bug notification because you are a member of Ub

Re: [Bug 1776489] [NEW] libxmltooling7 depends on libcurl3, which has been replaced by libcurl4 in Bionic

2018-06-12 Thread Russ Allbery
ve beem removed from Debian testing for the same reason. -- Russ Allbery (r...@debian.org) <http://www.eyrie.org/~eagle/> -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1776489 Ti

[Bug 1336663] Re: lightdm uses wrong ccache name on pam_krb5 credentials refresh

2018-02-12 Thread Russ Allbery
Yes, if KRB5CCNAME were set in the environment of the screen saver, it would fix this problem. To be clear, this isn't a bug in libpam-krb5, but in the means by which the screen saver is launched without the user's environment set properly (which should be created via the pam_setcred and

Re: [Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2017-12-21 Thread Russ Allbery
nfig-y to me, and that would be another relatively clean solution. -- Russ Allbery (r...@debian.org) <http://www.eyrie.org/~eagle/> -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/36

Re: [Bug 1680223] [NEW] Crash when exporting to html

2017-04-05 Thread Russ Allbery
sure how that will affect propagation into Ubuntu, but I think Ubuntu might pull from Debian unstable during our release freezes. -- Russ Allbery (r...@debian.org) <http://www.eyrie.org/~eagle/> -- You received this bug notification because you are a member of Ubuntu Bugs, whic

Re: [Bug 1680223] [NEW] Crash when exporting to html

2017-04-05 Thread Russ Allbery
pstream release rather than trying to cherry-pick specific patches. -- Russ Allbery (r...@debian.org) <http://www.eyrie.org/~eagle/> -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/16

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2016-04-26 Thread Russ Allbery
In order to take the path of moving this setting to a krb5.conf snippet that's included by the default krb5.conf, at the very least it needs to work with both Heimdal and MIT. I don't think Heimdal supports including krb5.conf snippets, which means we can't use the include functionality in

Re: [Bug 1400095] [NEW] Homepage is a dead link

2014-12-07 Thread Russ Allbery
has lost interest, gone off-line, or otherwise isn't planning on doing further development. (The Debian and Ubuntu versions are already pretty forked from the original.) I suppose I'll just drop the homepage link from the next version of the package. -- Russ Allbery (r...@debian.org

[Bug 1336663] Re: lightdm uses wrong ccache name on pam_krb5 credentials refresh

2014-07-08 Thread Russ Allbery
Note that all that pam-krb5 specifically cares about is KRB5CCNAME, so an alternative approach that may require less refactoring and would work for that PAM module would be to preserve the PAM environment from pam_getenvlist and set those variables in the environment before invoking PAM for

Re: [Bug 1332985] [NEW] Add the krb5-send-pr command to the ubuntu package

2014-06-22 Thread Russ Allbery
and operating system information with your bug report. Please note that bug reports are public; if you are reporting a security vulnerability, send mail to krbcore-secur...@mit.edu instead, ideally using PGP encryption. EOF -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You

Re: [Bug 1332985] [NEW] Add the krb5-send-pr command to the ubuntu package

2014-06-22 Thread Russ Allbery
and operating system information with your bug report. Please note that bug reports are public; if you are reporting a security vulnerability, send mail to krbcore-secur...@mit.edu instead, ideally using PGP encryption. EOF -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You

[Bug 1323671] Re: /usr/share/shibboleth/logo.jpg missing

2014-05-27 Thread Russ Allbery
While I probably could have handled the transition and notification better, this was an intentional upstream change. See the Debian changelog entry for 2.5.1+dfsg-1: - The example style sheet for error templates has been moved to a version-independent location in /usr/share/shibboleth.

Re: [Bug 1319336] Re: Cannot compile external software against OpenAFS headers any more

2014-05-14 Thread Russ Allbery
wrote it from the start to have a very stable API and ABI. But that's not the functionality you're looking for, I suspect.) -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed

Re: [Bug 1296276] Re: Unlocking with greeter fails to properly renew kerberos tickets with pam-krb5

2014-05-12 Thread Russ Allbery
this but there's a setuid program in the loop, in which case the environment variables are ignored. That would require a more complex fix. Let me know if that's the case.) -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you

Re: [Bug 1296276] [NEW] light-locker fails to properly renew kerberos tickets with pam-krb5

2014-03-23 Thread Russ Allbery
with this program rather than with your system configuration by running xscreensaver, locking the screen, unlocking with your Kerberos password, and seeing if that properly refreshes your credentials. I know that xscreensaver does PAM properly. -- Russ Allbery (r...@debian.org) http

Re: [Bug 1296276] Re: light-locker fails to properly renew kerberos tickets with pam-krb5

2014-03-23 Thread Russ Allbery
Robert Ancell robert.anc...@canonical.com writes: Could you please try lp:~robert-ancell/lightdm/setcred-on-unlock and see if this fixes it? It will surprise me if this change fixes the issue. pam-krb5 treats PAM_REFRESH_CRED and PAM_REINITIALIZE_CRED identically. -- Russ Allbery (r

Re: [Bug 1296276] [NEW] light-locker fails to properly renew kerberos tickets with pam-krb5

2014-03-23 Thread Russ Allbery
much more detail about exactly what the Kerberos PAM module is trying to do. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs

Re: [Bug 1296276] Re: Unlocking with greeter fails to properly renew kerberos tickets with pam-krb5

2014-03-23 Thread Russ Allbery
on the file after calling pam_setcred). Oh! I'm sorry. I looked at the head commit to the branch, and didn't realize that it diverged more than that. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member

Re: [Bug 1296276] Re: Unlocking with greeter fails to properly renew kerberos tickets with pam-krb5

2014-03-23 Thread Russ Allbery
environment will be set for it to find the user's ticket cache, but hopefully it will just work. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https

Re: [Bug 1269434] [NEW] Enable XPath support

2014-01-15 Thread Russ Allbery
. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1269434 Title: Enable XPath support To manage notifications about

Re: [Bug 1264742] [NEW] Sync openafs 1.6.5.2-1 (universe) from Debian unstable (main)

2013-12-28 Thread Russ Allbery
issue fixed upstream You probably want 1.6.6~pre2-1 (just uploaded) instead. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs

[Bug 1035000] Re: libapache2-mod-shib2 will not install

2013-12-18 Thread Russ Allbery
*** This bug is a duplicate of bug 884402 *** https://bugs.launchpad.net/bugs/884402 ** This bug has been marked a duplicate of bug 884402 package libapache2-mod-shib2 2.4.3+dfsg-1ubuntu1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error

[Bug 1007354] Re: package libapache2-mod-shib2 2.4.3+dfsg-1ubuntu1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2013-12-18 Thread Russ Allbery
*** This bug is a duplicate of bug 884402 *** https://bugs.launchpad.net/bugs/884402 ** This bug has been marked a duplicate of bug 884402 package libapache2-mod-shib2 2.4.3+dfsg-1ubuntu1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error

[Bug 807416] Re: Security bug in xml-security-c may require rebuilding of this package

2013-12-18 Thread Russ Allbery
Marking invalid since, as noted, no recompilation should be required after the affected library package was upgraded. ** Changed in: shibboleth-sp2 (Ubuntu) Status: Confirmed = Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

Re: [Bug 1206387] Re: openafs-modules-dkms 1.6.1-1+ubuntu0.2: module FTBFS on 3.8.0

2013-12-02 Thread Russ Allbery
, at which point you're doing all the work that you had to do in order to cherry-pick the required changes anyway, but doing it in a fairly unstable way. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu

Re: [Bug 1206387] Re: openafs-modules-dkms 1.6.1-1+ubuntu0.2: module FTBFS on 3.8.0

2013-12-02 Thread Russ Allbery
Ubuntu, and y'all should certainly feel free to decide on the strategy that works for your community, but it might be an interesting data point that this was one of my arguments against supporting Ubuntu internally in my group when we had that discussion internally a couple of weeks ago. -- Russ

[Bug 1145560] Re: OpenAFS Security Advisories 2013-001 and 2013-002

2013-03-04 Thread Russ Allbery
For the current development release of Ubuntu, you want to sync 1.6.2-1 from Debian experimental. For quantal, precise, and oneiric, you want 1.6.1-3 as uploaded to Debian unstable. I'm not sure if there are any Ubuntu-specific changes that need to be preserved in the patch you're carrying. For

[Bug 1119465] Re: credential verification failed: KDC has no support for encryption type

2013-02-08 Thread Russ Allbery
Reassigning to krb5, as: Feb 8 15:38:09 vpn-gw-ausfall openvpn[9031]: pam_krb5(openvpn- krb5:auth): (user hildeb) credential verification failed: KDC has no support for encryption type is an error message from the underlying Kerberos library that libpam- krb5 can't do anything about.

[Bug 1119465] Re: credential verification failed: KDC has no support for encryption type

2013-02-08 Thread Russ Allbery
Reassigning to krb5, as: Feb 8 15:38:09 vpn-gw-ausfall openvpn[9031]: pam_krb5(openvpn- krb5:auth): (user hildeb) credential verification failed: KDC has no support for encryption type is an error message from the underlying Kerberos library that libpam- krb5 can't do anything about.

[Bug 1098294] Re: Use of uninitialized value $admin in string eq at ...

2013-01-10 Thread Russ Allbery
This should be harmless, just noisy, but will be fixed in the next release. Thanks! -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to kerberos-configs in Ubuntu. https://bugs.launchpad.net/bugs/1098294 Title: Use of uninitialized

[Bug 1098294] Re: Use of uninitialized value $admin in string eq at ...

2013-01-10 Thread Russ Allbery
This should be harmless, just noisy, but will be fixed in the next release. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1098294 Title: Use of uninitialized value $admin in string eq at

[Bug 998525] Re: libpam-krb5 segfaults consistently after upgrade to 12.04

2012-05-24 Thread Russ Allbery
As mentioned in the reply to the original report, while I'll fix the segfault in the next release, all that's going to do is cause pam-krb5 to always fail instead of segfault. If you're having the same problem, it's because your local Kerberos configuration is invalid. You need to figure out

[Bug 988520] Re: After failed auth, subsequent auths in same context fail

2012-05-14 Thread Russ Allbery
Oh, wow, great job with the test case. It wouldn't have occurred to me to just do that. (And yes, you have to use the Git version because I've been adding a ton of new tests compared to the latest full release.) -- You received this bug notification because you are a member of Ubuntu Server

[Bug 988520] Re: After failed auth, subsequent auths in same context fail

2012-05-14 Thread Russ Allbery
Oh, wow, great job with the test case. It wouldn't have occurred to me to just do that. (And yes, you have to use the Git version because I've been adding a ton of new tests compared to the latest full release.) -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 998525] Re: libpam-krb5 segfaults consistently after upgrade to 12.04

2012-05-12 Thread Russ Allbery
krb5_init_context is failing. Does running kinit from the command-line work, or does it fail as well? (pam-krb5 should not segfault when krb5_init_context fails, but it's just a NULL pointer dereference on a local configuration or library error, so it's not a particularly major bug. However, I

[Bug 988520] Re: After failed auth, subsequent auths in same context fail

2012-04-27 Thread Russ Allbery
I have a test case, but I'm not sure you'll particularly enjoy it, since it isn't in a neatly isolated form. But if you: git clone git://git.eyrie.org/kerberos/pam-krb5.git cd pam-krb5 ./autogen ./configure and then add the username and password of an account in a test Kerberos

[Bug 988520] Re: After failed auth, subsequent auths in same context fail

2012-04-27 Thread Russ Allbery
I have a test case, but I'm not sure you'll particularly enjoy it, since it isn't in a neatly isolated form. But if you: git clone git://git.eyrie.org/kerberos/pam-krb5.git cd pam-krb5 ./autogen ./configure and then add the username and password of an account in a test Kerberos

[Bug 715765] Re: Can't change kerberos password, pam-krb5 try_first_pass also fails

2012-04-25 Thread Russ Allbery
This bug was introduced in MIT Kerberos 1.10. After a failing authentication with preauth required in a particular Kerberos context, all subsequent authentications in that context that require preauth will fail. Upstream has fixed this with commit 25822. This is a fairly serious issue, blocking

[Bug 715765] Re: Can't change kerberos password, pam-krb5 try_first_pass also fails

2012-04-25 Thread Russ Allbery
Actually, now that I look more at this, this may be an unrelated problem. The problem I encountered was reported upstream as a password change problem, but this may be a slightly different issue. I'll open another bug about the failed second authentication problem. -- You received this bug

[Bug 988520] [NEW] After failed auth, subsequent auths in same context fail

2012-04-25 Thread Russ Allbery
Public bug reported: MIT Kerberos 1.10 (including pre-releases and betas) exposed a bug in the tracking of preauth mechanisms such that, if an authentication fails after preauth was requested, all subsequent preauth-required authentications in the same Kerberos context will also fail. This

[Bug 988520] Re: After failed auth, subsequent auths in same context fail

2012-04-25 Thread Russ Allbery
** Bug watch added: Debian Bug tracker #670457 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670457 ** Also affects: krb5 (Debian) via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670457 Importance: Unknown Status: Unknown -- You received this bug notification because you

[Bug 715765] Re: Can't change kerberos password

2012-04-25 Thread Russ Allbery
** Summary changed: - Can't change kerberos password, pam-krb5 try_first_pass also fails + Can't change kerberos password -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in Ubuntu. https://bugs.launchpad.net/bugs/715765 Title:

Re: [Bug 715765] Re: Can't change kerberos password

2012-04-25 Thread Russ Allbery
Steve Langasek steve.langa...@canonical.com writes: Setting this back to 'triaged', which is the more-better bug state in LP. Thanks. I tried to do that but it didn't let me (probably not enough access bits). -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle

[Bug 715765] Re: Can't change kerberos password, pam-krb5 try_first_pass also fails

2012-04-25 Thread Russ Allbery
This bug was introduced in MIT Kerberos 1.10. After a failing authentication with preauth required in a particular Kerberos context, all subsequent authentications in that context that require preauth will fail. Upstream has fixed this with commit 25822. This is a fairly serious issue, blocking

[Bug 715765] Re: Can't change kerberos password, pam-krb5 try_first_pass also fails

2012-04-25 Thread Russ Allbery
Actually, now that I look more at this, this may be an unrelated problem. The problem I encountered was reported upstream as a password change problem, but this may be a slightly different issue. I'll open another bug about the failed second authentication problem. -- You received this bug

[Bug 988520] [NEW] After failed auth, subsequent auths in same context fail

2012-04-25 Thread Russ Allbery
Public bug reported: MIT Kerberos 1.10 (including pre-releases and betas) exposed a bug in the tracking of preauth mechanisms such that, if an authentication fails after preauth was requested, all subsequent preauth-required authentications in the same Kerberos context will also fail. This

[Bug 988520] Re: After failed auth, subsequent auths in same context fail

2012-04-25 Thread Russ Allbery
** Bug watch added: Debian Bug tracker #670457 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670457 ** Also affects: krb5 (Debian) via http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670457 Importance: Unknown Status: Unknown -- You received this bug notification because you

[Bug 715765] Re: Can't change kerberos password

2012-04-25 Thread Russ Allbery
** Summary changed: - Can't change kerberos password, pam-krb5 try_first_pass also fails + Can't change kerberos password -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/715765 Title: Can't change

Re: [Bug 715765] Re: Can't change kerberos password

2012-04-25 Thread Russ Allbery
Steve Langasek steve.langa...@canonical.com writes: Setting this back to 'triaged', which is the more-better bug state in LP. Thanks. I tried to do that but it didn't let me (probably not enough access bits). -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle

[Bug 891839] Re: xscreensaver will not unlock when using Kerberos authentication

2012-04-20 Thread Russ Allbery
At the least, not a bug in libpam-krb5, since it can't help the permissions. There's still a mystery about what set the permissions to 0600, but I'm not sure where else to reassign the bug, so closing here. ** Changed in: libpam-krb5 (Ubuntu) Status: Incomplete = Invalid -- You received

[Bug 962560] Re: pam-auth-update Account-Type should be Additional

2012-03-26 Thread Russ Allbery
This analysis looks right to me, and I think may run deeper than just this one module. If every account module should be additional and not primary, I think that points to an error in the data model or interpretation of the data model, rather than in individual PAM configurations. And viewing

[Bug 962560] Re: pam-auth-update Account-Type should be Additional

2012-03-26 Thread Russ Allbery
Ah, in fact, I see comment #20 mentioned above is from Steve. Steve, when would you ever want to have an account type of Primary given those semantics? Shouldn't Primary just be treated the same as Additional for the account stack? -- You received this bug notification because you are a member

[Bug 962560] Re: pam-auth-update Account-Type should be Additional

2012-03-26 Thread Russ Allbery
This analysis looks right to me, and I think may run deeper than just this one module. If every account module should be additional and not primary, I think that points to an error in the data model or interpretation of the data model, rather than in individual PAM configurations. And viewing

[Bug 962560] Re: pam-auth-update Account-Type should be Additional

2012-03-26 Thread Russ Allbery
Ah, in fact, I see comment #20 mentioned above is from Steve. Steve, when would you ever want to have an account type of Primary given those semantics? Shouldn't Primary just be treated the same as Additional for the account stack? -- You received this bug notification because you are a member

Re: [Bug 179142] Re: /etc/krb5.conf is malformed

2012-03-19 Thread Russ Allbery
initializing Kerberos code [realms] MYGROUP.COM = { kdc = kerberos.mygroup.com.:88 I'm not sure if this is your problem, but the trailing period here looks suspicious. Try removing the period just before the colon. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle

Re: [Bug 179142] Re: /etc/krb5.conf is malformed

2012-03-19 Thread Russ Allbery
initializing Kerberos code [realms] MYGROUP.COM = { kdc = kerberos.mygroup.com.:88 I'm not sure if this is your problem, but the trailing period here looks suspicious. Try removing the period just before the colon. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle

[Bug 884402] Re: package libapache2-mod-shib2 2.4.3+dfsg-1ubuntu1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2012-02-16 Thread Russ Allbery
Oh! It never even occurred to me that update-rc.d would change its *option parser* based on whether you have dependency-based boot enabled. Aie. I can confirm this behavior in Debian if I disable dependency- based boot. Okay, this is a bug in sysv-rc, then, which I suspect no one has noticed on

[Bug 884402] Re: package libapache2-mod-shib2 2.4.3+dfsg-1ubuntu1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2012-02-16 Thread Russ Allbery
Steve is completely right. I just misunderstood how to do this. Will fix in shibboleth-sp2; sorry about my failure to understand what was going on previously. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 884402] Re: package libapache2-mod-shib2 2.4.3+dfsg-1ubuntu1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2012-02-06 Thread Russ Allbery
This patch is actually wrong in Debian, so I'm not willing to take it upstream in the Debian package. The shibd init script should have no stop links, since it can just be killed. This is really a bug in the upstart update-rc.d; it needs to be able to support the new syntax for compatibility

[Bug 891839] Re: xscreensaver will not unlock when using Kerberos authentication

2012-02-05 Thread Russ Allbery
Permission denied from krb5_init_context probably means that /etc/krb5.conf is not readable by the process. Could you check that? Could you also check whether running kinit as the same user that gnome- screensaver is running as works properly? ** Changed in: libpam-krb5 (Ubuntu) Status:

[Bug 732990] Re: libpam-krb5 writes to /tmp, does not work when disk is full.

2012-02-05 Thread Russ Allbery
As of libpam-krb5 4.5, the temporary ticket cache will be written to ccache_dir rather than /tmp if ccache_dir is set. This version is in Debian (and has been for a little bit), but it looks like it's not yet been imported into Ubuntu. ** Changed in: libpam-krb5 (Ubuntu) Status: New = Fix

[Bug 734530] Re: [wishlist] rssh git support (with patch)

2012-02-05 Thread Russ Allbery
The version of rssh in Ubuntu is from Debian and is already patched for Subversion support, which means that this patch doesn't apply directly to the current package. (Subversion has already stolen the next number.) The patch would need to update conf_convert.sh as well and modify the postinst

[Bug 249473] Re: can't use race databases (only default works)

2012-02-04 Thread Russ Allbery
Closing this as not reproducible. ** Changed in: gnubg (Ubuntu) Status: New = Incomplete ** Changed in: gnubg (Ubuntu) Status: Incomplete = Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 418683] Re: gnubg depends on old python2.5 instead of default python2.6

2012-02-04 Thread Russ Allbery
All recent versions of gnubg are built with current Python. It seems unlikely at this point that anyone will go back and rebuild the packages in old versions of the distribution. ** Changed in: gnubg (Ubuntu) Status: Confirmed = Fix Released -- You received this bug notification because

[Bug 545982] Re: waiting for other software to quit

2012-02-04 Thread Russ Allbery
This was a problem with the Java package you were installing, not gnubg. It was prompting you to accept the license, possibly somewhere where you didn't see it. ** Changed in: gnubg (Ubuntu) Status: New = Invalid -- You received this bug notification because you are a member of Ubuntu

Re: [Bug 913166] Re: kprop will not find slave-kdc

2012-01-11 Thread Russ Allbery
? -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in Ubuntu. https://bugs.launchpad.net/bugs/913166 Title: kprop will not find slave-kdc To manage

Re: [Bug 913166] Re: kprop will not find slave-kdc

2012-01-11 Thread Russ Allbery
? -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/913166 Title: kprop will not find slave-kdc To manage notifications about

Re: [Bug 913166] [NEW] kprop will not find slave-kdc

2012-01-07 Thread Russ Allbery
/kerbe...@example.net, which fails. Changing the system hostname of the master to kerberos.example.net will probably fix this problem. kprop should really gain an additional command-line option to specify the client principal to authenticate as. -- Russ Allbery (r...@debian.org) http

Re: [Bug 913166] [NEW] kprop will not find slave-kdc

2012-01-07 Thread Russ Allbery
/kerbe...@example.net, which fails. Changing the system hostname of the master to kerberos.example.net will probably fix this problem. kprop should really gain an additional command-line option to specify the client principal to authenticate as. -- Russ Allbery (r...@debian.org) http

Re: [Bug 900447] [NEW] Man 5 page for kdc.conf does not mention acceptable encryption types

2011-12-05 Thread Russ Allbery
They're listed in the krb5-admin info pages included in krb5-doc under Configuration Files. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in Ubuntu

Re: [Bug 900447] Re: Man 5 page for kdc.conf does not mention acceptable encryption types

2011-12-05 Thread Russ Allbery
reference manual; they don't have very much useful structure.) -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to krb5 in Ubuntu. https://bugs.launchpad.net/bugs

Re: [Bug 900447] [NEW] Man 5 page for kdc.conf does not mention acceptable encryption types

2011-12-05 Thread Russ Allbery
They're listed in the krb5-admin info pages included in krb5-doc under Configuration Files. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https

Re: [Bug 900447] Re: Man 5 page for kdc.conf does not mention acceptable encryption types

2011-12-05 Thread Russ Allbery
reference manual; they don't have very much useful structure.) -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/900447 Title: Man

[Bug 884402] Re: package libapache2-mod-shib2 2.4.3+dfsg-1ubuntu1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2011-10-31 Thread Russ Allbery
Ubuntu-specific error caused by Ubuntu's update-rc.d not supporting the same syntax as Debian. Setting up libapache2-mod-shib2 (2.4.3+dfsg-1ubuntu1) ... Installing new version of config file /etc/shibboleth/native.logger ... Installing new version of config file /etc/shibboleth/shibd.logger ...

[Bug 836223] Re: package libapache2-mod-shib2 2.4.3+dfsg-1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error exit status 1

2011-10-31 Thread Russ Allbery
*** This bug is a duplicate of bug 884402 *** https://bugs.launchpad.net/bugs/884402 ** This bug has been marked a duplicate of bug 884402 package libapache2-mod-shib2 2.4.3+dfsg-1ubuntu1 failed to install/upgrade: ErrorMessage: subprocess installed post-installation script returned error

Re: [Bug 854221] [NEW] package openafs-modules-dkms 1.4.12 dfsg-3 ubuntu0.1 failed to install/upgrade: openafs kernel module failed to build after I upgraded my lucid kernel to 2.6.38-11

2011-09-19 Thread Russ Allbery
+dfsg-1 or later for Linux 2.6.38. 1.4.12 (or even an unpatched 1.4.14) won't build with that kernel. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https

Re: [Bug 854221] [NEW] package openafs-modules-dkms 1.4.12 dfsg-3 ubuntu0.1 failed to install/upgrade: openafs kernel module failed to build after I upgraded my lucid kernel to 2.6.38-11

2011-09-19 Thread Russ Allbery
could try the PPA at: https://launchpad.net/~openafs/+archive/master which has builds of the openafs 1.6.0 packages for various older versions of Ubuntu including lucid. That may avoid the need to update your libc6. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle

Re: [Bug 826989] [NEW] Cannot change Kerberos password with passwd(1)

2011-08-15 Thread Russ Allbery
with pam-krb5 that's rejecting password changes for that user. Probably pam_unix without /etc/shadow data. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https

Re: [Bug 826989] Re: Cannot change Kerberos password with passwd(1)

2011-08-15 Thread Russ Allbery
, though, is that this is not a libpam-krb5 problem. Everything about libpam-krb5 in your trace succeeded; some other module is failing. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs

[Bug 721290] Re: Natty PAM update causes slow logins

2011-08-15 Thread Russ Allbery
I think we need more information, such as a debug trace of what libpam- krb5 is doing when the slowness is observed, to figure out what could be causing this. Another useful data point would be whether kinit is slow when libpam-krb5 is slow. ** Changed in: libpam-krb5 (Ubuntu) Status: New

Re: [Bug 826989] Re: Cannot change Kerberos password with passwd(1)

2011-08-15 Thread Russ Allbery
rationale for it, but I don't remember what it is. :/ I'll ask him separately. It may be that they should change. Thanks, that gets me pointed in the right direction. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you

[Bug 807416] Re: Security bug in xml-security-c may require rebuilding of this package

2011-08-03 Thread Russ Allbery
No update or recompile of the shibboleth-sp2 package is required for either the xml-security-c or the opensaml2 security advisories so far as I know. Only upgrading the libraries to patched versions and then restarting shibd and Apache is required, I think. The changes didn't affect the external

Re: [Bug 810786] [NEW] package openafs-modules-dkms 1.4.14 dfsg-1 ubuntu1 failed to install/upgrade: openafs kernel module failed to build

2011-07-14 Thread Russ Allbery
sure DKMS does something similar. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/810786 Title: package openafs-modules

[Bug 800329] Re: rssh: /usr/libexec assumed in ./configure no longer exists

2011-06-21 Thread Russ Allbery
Closing as requested -- oh, good, I didn't miss something when I couldn't figure out what was going on. ** Changed in: rssh (Ubuntu) Status: New = Invalid -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

Re: [Bug 800329] Re: rssh: /usr/libexec assumed in ./configure no longer exists

2011-06-21 Thread Russ Allbery
, and the rssh binary has never been built to use libexec. However, I don't personally use Ubuntu; maybe something went way wrong with the build system when importing the package from Debian into Ubuntu? The package relies on dh_auto_configure to pass the appropriate flags into configure. -- Russ

Re: [Bug 786088] Re: package openafs-modules-dkms 1.4.14+dfsg-1+ubuntu1 failed to install/upgrade: openafs kernel module failed to build

2011-05-25 Thread Russ Allbery
-2 should be fairly solid (I'm using it myself), but there are some additional fixes in the 1.6.0pre6 release that upstream is currently working on. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member

Re: [Bug 786088] Re: package openafs-modules-dkms 1.4.14+dfsg-1+ubuntu1 failed to install/upgrade: openafs kernel module failed to build

2011-05-24 Thread Russ Allbery
upstream release from upstream that was never in Debian, I believe. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/786088

Re: [Bug 786088] Re: package openafs-modules-dkms 1.4.14+dfsg-1+ubuntu1 failed to install/upgrade: openafs kernel module failed to build

2011-05-24 Thread Russ Allbery
be backporting OpenAFS 1.6 once there's a final release, though. -- Russ Allbery (r...@debian.org) http://www.eyrie.org/~eagle/ -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/786088 Title

[Bug 740477] Re: kinit should print an error if credentials cache has invalid permissions

2011-03-24 Thread Russ Allbery
The bug is trivially reproducible given the instructions given by the reporter. I don't see any need for them to run apport-collect to gather more data. ** Changed in: krb5 (Ubuntu) Status: Incomplete = Confirmed -- You received this bug notification because you are a member of Ubuntu

[Bug 740477] Re: kinit should print an error if credentials cache has invalid permissions

2011-03-24 Thread Russ Allbery
The bug is trivially reproducible given the instructions given by the reporter. I don't see any need for them to run apport-collect to gather more data. ** Changed in: krb5 (Ubuntu) Status: Incomplete = Confirmed -- You received this bug notification because you are a member of Ubuntu

Re: [Bug 732990] [NEW] libpam-krb5 writes to /tmp, does not work when disk is full.

2011-03-22 Thread Russ Allbery
built the filesystem. But sure, I see what you're saying. It would be nice if we could control where the tempfile was written in /etc/krb5.conf like many of the other pam options. Yeah, I can do that. I'll try to get that into the next upstream release. -- Russ Allbery (r...@debian.org

  1   2   3   4   >