lorikeet-heimdal.git
2023-10-11 Kacper Boströmkdc: support pkinit_kdc_revoke for pkinit anchors lorikeet-heimdal-202310092148
2023-10-11 Joseph Suttonpkinit: Correctly pad Diffie-Hellman key
2023-10-11 Joseph Suttonkrb5: Clarify documentation for ‘pkinit_revoke’ parameter
2023-10-11 Joseph Suttonkrb5: Fix typos in documentation
2023-10-11 Joseph Suttonkdc: Add KDC support for PKINIT Freshness extension...
2023-07-04 Joseph Suttonkdc: Move TGS lookup to before preauth data validation
2023-07-04 Joseph Suttonkdc: Fix spelling
2023-07-04 Joseph Suttonkdc: Fix leak with PK-INIT-Win2k
2023-07-04 Joseph Suttonkdc: Prefer nonce in PKAuthenticator over that in reque...
2023-06-26 Joseph Suttonkdc: Add support for resource-based constrained delegation
2023-06-26 Joseph Suttonhdb: Add hook for resource-based constrained delegation
2023-06-26 Stefan Metzmacherkdc: add kdc_request_get_[explicit_]armor_server
2023-06-26 Joseph Suttonkdc: Add KDC_AUTH_EVENT_CLIENT_FOUND authentication...
2023-06-26 Joseph SuttonRevert "Verify flags after the user been required to...
2023-06-26 Joseph Suttonkdc-plugin: Provide plugin with delegated proxy HDB...
2023-06-26 Joseph Suttonkdc: Check server of constrained delegation evidence...
2023-06-26 Joseph Suttonkdc-plugin: Make ‘client_principal’ const
2023-06-26 Joseph Suttonkdc: Validate armor TGT for AS-REQs
2023-06-26 Joseph Suttonkdc: Don’t update the PAC if we perform Services for...
2023-06-26 Joseph Suttonkdc: Have caller perform checking for _kdc_validate_con...
2023-06-26 Joseph Suttonkdc: Have _kdc_validate_protocol_transition() take...
2023-06-26 Joseph Suttonkdc: Inline calls to Services for User functions
2023-06-26 Joseph Suttonkdc: Provide kdc_request_get_armor_{clientdb,client...
2023-06-26 Joseph Suttonkdc: Add enable_fast_cookie option (enabled by default)
2023-06-26 Joseph Suttonkdc: Check lifetime of correct ticket
2023-06-26 Joseph Suttonkdc: Allow e_data field of KDC request structure to...
2023-06-26 Joseph Suttonkdc: Split out function to create error data
2023-06-26 Joseph Suttonkdc: Add ‘e-data’ field to KDC request structure
2023-06-26 Joseph Suttonasn1: Add KERB-ERROR-DATA type
2023-06-26 Joseph Suttonkdc: Do not return ETYPE-INFO if the client is locked out
2023-06-26 Joseph Suttonkdc: Ensure return value is initialized
2023-06-26 Joseph Suttonkdc: Return NEVER_VALID error code if ticket will never...
2023-06-26 Joseph Suttonkdc: Always apply maximum ticket lifetime and renew...
2023-06-26 Joseph Suttonhdb: Make maximum ticket lifetime and renew time signed...
2023-06-26 Joseph Suttonkdc: Set PAC as trusted if indicated by the plugin
2023-06-26 Joseph Suttonkrb5: Add functions to determine whether PAC is trusted
2023-06-26 Joseph Suttonkdc: Move _krb5_pac_get_attributes_info() call to right...
2023-06-26 Joseph Suttonkdc-plugin: Split updating a PAC out of PAC verification
2023-06-26 Joseph Suttonkdc: Call _kdc_fast_check_armor_pac() prior to calling...
2023-06-26 Joseph Suttonlib/hdb: Make hdb_enctype2key() parameter const
2023-06-26 Andrew BartlettCVE-2022-37966 kdc: Implement new Kerberos session...
2023-06-26 Joseph SuttonCVE-2022-37966 third_party/heimdal: Fix error message...
2023-06-26 Joseph SuttonCVE-2022-37967 Add new PAC checksum
2023-06-26 Andrew BartlettCVE-2022-37966 HEIMDAL: Look up the server keys to...
2023-06-26 Joseph SuttonSAMBA ONLY krb5: Don't generate PAC_ATTRIBUTES_INFO...
2023-06-26 Joseph SuttonSAMBA ONLY kdc: Always include PAC if it is non-NULL
2023-06-26 Joseph Suttonkdc: Allow requesting no PAC for AS-REQ to non-TGS...
2023-06-26 Joseph Suttonkrb5: Remove UPN_DNS_INFO_EX realm check
2023-06-26 Stefan Metzmacherkdc: don't fail salt_fastuser_crypto with r->req.req_bo...
2023-06-26 Joseph Suttonkdc: Add function to get current KDC time
2023-06-26 Stefan Metzmacherkdc: add kdc_log() before _kdc_fast_mk_error() also...
2023-06-26 Joseph Suttonkrb5: Check for signed overflow
2023-06-26 Joseph Suttonkdc: Reinstate publicly accessible configuration struct...
2023-06-26 Joseph Suttonkuser: Avoid conflicting macro definitions
2023-06-26 Stefan Metzmacherkrb5: Set canonicalize flag for enterprise principals
2023-06-26 Stefan Metzmacherlib/krb5: allow access to anonymous mcache entries...
2023-06-26 Andrew Bartlettlib/krb5: Fix loss of information in _gsskrb5_canon_nam...
2023-06-26 Andrew Bartlettlib/krb5: Honour KRB5_CTX_F_DNS_CANONICALIZE_HOSTNAME...
2023-06-26 Andrew Bartlettkdc: Change KDC to respect HDB server name type if...
2023-06-26 Joseph Suttonkdc: Don't conceal error code when using FAST
2023-06-26 Joseph Suttonkdc: Send ETYPE-INFO2 instead of PW-SALT for validated...
2023-06-26 Andrew BartlettAdapt apply_heimdal.sh to new Heimdal location in Samba
2023-06-26 Stefan Metzmacherkdc: use the correct authtime from addtitional ticket...
2023-06-26 Stefan Metzmacherkdc: if we don't have an authenticator subkey for S4U2P...
2023-06-26 Stefan Metzmacherkdc: decrypt b->enc_authorization_data in tgs_build_reply()
2023-06-26 Stefan Metzmacherkdc: fix memory leak when decryption AuthorizationData
2023-06-26 Stefan Metzmacherkdc: remember kvno numbers for longterm key pre-auth
2023-06-26 Stefan Metzmacherkdc: add KDC_AUTH_EVENT_HISTORIC_LONG_TERM_KEY support...
2023-06-26 Stefan Metzmacherkdc: add KDC_AUTH_EVENT_HISTORIC_LONG_TERM_KEY support...
2023-06-26 Stefan Metzmacherkdc: add KDC_AUTH_EVENT_HISTORIC_LONG_TERM_KEY value
2023-06-26 Stefan Metzmacherkdc: add success logging to pa_enc_chal_validate()
2023-06-26 Stefan Metzmacherkdc: split out pa_enc_chal_decrypt_kvno() from pa_enc_c...
2023-06-26 Stefan Metzmacherkdc: split out pa_enc_ts_decrypt_kvno() from pa_enc_ts_...
2023-06-26 Joseph Suttonlorikeet-heimdal: Move Heimdal into third_party directory
2023-06-26 Andrew Bartlettlorikeet-heimdal: modernize URLs in helper scripts
2023-06-26 Andrew Bartlettlorikeet-heimdal: import-lorikeet: Use --no-verify...
2023-06-26 Andrew Bartlettlorikeet-heimdal: apply_heimdal: Try harder to apply...
2023-06-26 Andrew Bartlettlorikeet-heimdal: apply_heimdal: Only show the Heimdal...
2023-06-26 Andrew Bartlettlorikeet-heimdal: Include Samba commit in cherry-picked...
2023-06-26 Andrew Bartlettlorikeet-heimdal: improve apply_heimdal.sh
2023-06-26 Andrew Bartlettlorikeet-heimdal: specify hash to heimdal import, rathe...
2023-06-26 Jelmer Vernooijlorikeet-heimdal: rebase-lorikeet: Explicitly use bash.
2023-06-26 Andrew Tridgelllorikeet-heimdal: Add a new script to help merging...
2023-06-26 Stefan Metzmacherlorikeet-heimdal: improve import-lorikeet.sh for the...
2023-06-26 Andrew Bartlettlorikeet-heimdal: Improve the heimdal import scripts
2023-06-26 Stefan Metzmacherlorikeet-heimdal: add scipts to rebase and import the...
2023-06-26 Stefan Metzmacherlorikeet-heimdal: add HEIMDAL-LICENCE.txt
2023-06-26 Stefan Metzmacherlorikeet-heimdal: camellia-ntt GPLv2+ license
2023-06-26 Stefan Metzmacherlorikeet-heimdal: autogen.sh modifications
2023-06-24 Andrew SimUse perl module JSON:PP, part of core, instead of JSON...
2023-06-23 Nicolas Williamskdc: Add global disable_pac config param
2023-06-23 Nicolas Williamshttpkadmind: Add auth-data-reqd attribute
2023-06-23 Nicolas Williamskadmin: Add auth-data-reqd attribute
2023-06-23 Nicolas Williamskadm5: Add KRB5_KDB_AUTH_DATA_REQUIRED attribute
2023-06-23 Nicolas Williamshdb: Add auth-data-reqd flag
2023-06-23 Nicolas Williamskdc: Honor no-auth-data-reqd on cross-real TGTs
2023-06-22 Taylor R CampbellMakefile.am: Set AM_YFLAGS and AM_LFLAGS, not YFLAGS...
2023-06-21 Taylor R CampbellPass -d to yacc(1) so it generates the header file.
2023-06-21 Taylor R Campbellkinit: Update SecKeychainFindGenericPassword to SecItem...
2023-06-21 Taylor R Campbellhdb/hdb-mitdb: Nix unused variable key_data in mdb_seq.
next