diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..99877f4 --- /dev/null +++ b/.gitignore @@ -0,0 +1,11 @@ +/heimdal-7.1.0-7195232.tar.gz +/heimdal-7195232-autoconf.tar.gz +/heimdal-7.3.0-40d4229.tar.gz +/heimdal-40d4229-autoconf.tar.gz +/heimdal-7.4.0-a3d72c6.tar.gz +/heimdal-a3d72c6-autoconf.tar.gz +/heimdal-3e58559-autoconf.tar.gz +/heimdal-7.5.0-3e58559.tar.gz +/heimdal-7.7.0.tar.gz +/heimdal-7.7.1.tar.gz +/heimdal-7.8.0.tar.gz diff --git a/changelog b/changelog new file mode 100644 index 0000000..37d9cd9 --- /dev/null +++ b/changelog @@ -0,0 +1,453 @@ +* Wed Mar 08 2023 Alexander Boström - 7.8.0-14 +- Add upstream patch for autoconf 2.72 + +* Sat Feb 01 2025 Björn Esser - 7.8.0-13 +- Add explicit BR: libxcrypt-devel + +* Mon Jan 20 2025 Fedora Release Engineering - 7.8.0-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild + +* Mon Sep 02 2024 Miroslav Suchý - 7.8.0-11 +- convert license to SPDX + +* Thu Jul 18 2024 Fedora Release Engineering - 7.8.0-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild + +* Wed Jan 24 2024 Fedora Release Engineering - 7.8.0-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Sat Jan 20 2024 Fedora Release Engineering - 7.8.0-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild + +* Thu Jul 20 2023 Fedora Release Engineering - 7.8.0-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild + +* Thu Apr 13 2023 Florian Weimer - 7.8.0-6 +- Port configure script to C99 + +* Wed Mar 08 2023 Alexander Boström - 7.8.0-5 +- Remove conditionals prior to RHEL7 + +* Wed Mar 08 2023 Alexander Boström - 7.8.0-4 +- remove _with_systemd conditional +- remove unused source files + +* Wed Mar 08 2023 Alexander Boström - 7.8.0-3 +- Move libraries to a lib subdirectory +- Include pkgconfig files (#1525462) (#1565954) (#1931072) + +* Thu Jan 19 2023 Fedora Release Engineering - 7.8.0-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild + +* Mon Nov 21 2022 Alexander Boström - 7.8.0-1 +- Update to 7.8.0 (#2143478) + +* Mon Nov 21 2022 Alexander Boström - 7.7.1-3 +- Restart services on upgrade + +* Mon Nov 21 2022 Alexander Boström - 7.7.1-2 +- Delay service starts until after network is online (rhbz#2005501) + +* Wed Nov 16 2022 Alexander Boström - 7.7.1-1 +- Update to 7.7.1 +- Remove upstreamed patch +- Replace patch with sed command + +* Thu Jul 21 2022 Fedora Release Engineering - 7.7.0-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild + +* Thu Jan 20 2022 Fedora Release Engineering - 7.7.0-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild + +* Thu Jul 22 2021 Fedora Release Engineering - 7.7.0-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild + +* Tue Apr 13 2021 Alexander Boström - 7.7.0-9 +- Backport autoconf-2.70 fix + +* Tue Jan 26 2021 Fedora Release Engineering - 7.7.0-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild + +* Tue Jul 28 2020 Fedora Release Engineering - 7.7.0-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Tue Mar 31 2020 Alexander Boström - 7.7.0-6 +- Do not buildrequire openldap-servers on RHEL8+ + +* Sat Mar 21 2020 Alexander Boström - 7.7.0-5 +- Add Python 3 code patch +- Use Python 3 binary path +- BuildRequire Python 3 + +* Wed Jan 29 2020 Fedora Release Engineering - 7.7.0-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + +* Fri Jan 17 2020 Jeff Law - 7.7.0-3 +- Fix configure tests compromised by LTO + +* Sat Dec 21 2019 Alexander Boström - 7.7.0-2 +- Set timeout on make check + +* Fri Dec 20 2019 Alexander Boström - 7.7.0-1 +- Update to 7.7.0 +- Remove upstreamed patch +- New project URL +- Update buildreqs +- Add locale build fix + +* Thu Jul 25 2019 Fedora Release Engineering - 7.5.0-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + +* Fri Feb 01 2019 Fedora Release Engineering - 7.5.0-8 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + +* Mon Jan 14 2019 Björn Esser - 7.5.0-7 +- Rebuilt for libcrypt.so.2 (#1666033) + +* Sun Jan 06 2019 Björn Esser - 7.5.0-6 +- Add patch to explicitly use python2 binary, fixes FTBFS (#1604316) +- Do not run 'make dist', fixes FTBFS (#1604316) +- Make sure 'krb5-types.h' is build, fixes FTBFS (#1604316) +- Remove el5 bits +- Drop unneeded scriptlets for newer distros +- Use %%make_build and %%make_install macros +- Install license file using %%license in libs package + +* Fri Jul 13 2018 Fedora Release Engineering - 7.5.0-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild + +* Thu Mar 15 2018 Iryna Shcherbina - 7.5.0-4 +- Update Python 2 dependency declarations to new packaging standards + (See https://fedoraproject.org/wiki/FinalizingFedoraSwitchtoPython3) + +* Wed Feb 07 2018 Fedora Release Engineering - 7.5.0-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + +* Sat Jan 20 2018 Björn Esser - 7.5.0-2 +- Rebuilt for switch to libxcrypt + +* Thu Dec 14 2017 Ken Dreyer - 7.5.0-1 +- Update to 7.5.0 GA release (CVE-2017-17439) + +* Mon Oct 23 2017 Alexander Boström - 7.4.0-5 +- Backport fix to prevent wait() loop on non-existant child process + +* Wed Aug 02 2017 Fedora Release Engineering - 7.4.0-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild + +* Wed Jul 26 2017 Fedora Release Engineering - 7.4.0-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + +* Wed Jul 12 2017 Ken Dreyer - 7.4.0-2 +- Make test failures non-fatal + +* Tue Jul 11 2017 Ken Dreyer - 7.4.0-1 +- Update to 7.4.0 GA release (CVE-2017-11103) + +* Mon Apr 17 2017 Ken Dreyer - 7.3.0-1 +- Update to 7.3.0 GA release (CVE-2017-6594) + +* Fri Feb 10 2017 Fedora Release Engineering - 7.1.0-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Thu Dec 29 2016 Ken Dreyer - 7.1.0-1 +- Update to 7.1.0 GA release +- Drop all remaining xinetd bits + +* Wed Feb 03 2016 Fedora Release Engineering - 1.6.0-0.13.20150115gitc25f45a +- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild + +* Mon Aug 10 2015 Ken Dreyer - 1.6.0-0.12.20150115gitc25f45a +- Fix ld.so.conf.d file conflict between 32-bit and 64-bit packages + (rhbz#1244316) +- Mark ld.so.conf.d as %%config(noreplace) + +* Wed Jun 17 2015 Fedora Release Engineering - 1.6.0-0.11.20150115gitc25f45a +- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild + +* Thu Jan 15 2015 Ken Dreyer - 1.6.0-0.10.20150115gitc25f45a +- Update git snapshot to latest tip of heimdal-1-6-branch +- Remove upstreamed patches +- Add virtual provides for bundled(libtommath) (RHBZ #1118462) + +* Sat Aug 16 2014 Fedora Release Engineering - 1.6.0-0.10.20140621gita5adc06 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild + +* Mon Jul 07 2014 Ken Dreyer - 1.6.0-0.9.20140621gita5adc06 +- Remove OpenSSL BR and go back to using hcrypto with bundled libtommath. + OpenSSL is not thread safe without callbacks (RHBZ #1118462) + +* Tue Jul 01 2014 Ken Dreyer - 1.6.0-0.8.20140621gita5adc06 +- Patch for parallel build failure in kadm5. Thanks Jakub Čajka. +- Remove comments about X11 binaries (we will never ship those). + +* Sun Jun 22 2014 Ken Dreyer - 1.6.0-0.7.20140621gita5adc06 +- Update git snapshot to latest tip of heimdal-1-6-branch + +* Sat Jun 07 2014 Ken Dreyer - 1.6.0-0.6.20140606git966108b +- Update git snapshot to latest tip of heimdal-1-6-branch +- Don't ship xinetd support if the distro has systemd (RHBZ #613001) + +* Fri May 30 2014 Ken Dreyer - 1.6.0-0.5.20140529gitddde77b +- Update git snapshot to latest tip of heimdal-1-6-branch +- Use /sbin path in %%pre/%%post scripts for EL6 and EL5 +- Install login.users(5) normally, since it doesn't conflict with anything + (RHBZ #613001) +- Don't ship ftpusers(5) (RHBZ #613001) +- Patch heimtools to deal with the commands' "heimdal-" prefixes (RHBZ #613001) +- Use "simple" systemd service type for kdc, kadmind, kpasswdd +- Add "--detach" flag in heimdal-ipropd-slave-wrapper to match the systemd + forking service type +- Patch kadmind to handle systemd's restrictions on setpgid() (RHBZ #613001) + +* Thu May 22 2014 Ken Dreyer - 1.6.0-0.4.20140522git229d8c7 +- Update git snapshot to latest tip of heimdal-1-6-branch +- Drop upstreamed text-fx patch +- Install Texinfo files (RHBZ #613001) +- Add Provides: heimdal-static to -devel subpackage (RHBZ #613001) +- Drop %%defattr (RHBZ #613001) +- Add text content to kadmind.acl to help users (and remove a zero-length file) +- Install profile.d scripts with non-executable permissions +- Remove .la files +- Patch to remove AC_PROG_LIBTOOL macro +- Reload xinetd when using systemd +- Require logrotate and setup, since we drop config files into directories that + these packages own. +- Add unowned Heimdal directories in %%files +- Replace "heimdal" with %%{name} in %%files +- Do not BR libcap-ng-devel on EL5 + +* Tue Apr 29 2014 Ken Dreyer - 1.6.0-0.3.20140429gitd60ba47 +- Add BR libdb-devel on Fedora (RHBZ #613001) +- Add BR openssl-devel and libcap-ng-devel (RHBZ #613001) +- Only set BuildRoot on el5 +- Alphabetize non-conditional BuildRequires +- Remove duplicate BR openldap-devel + +* Tue Apr 29 2014 Ken Dreyer - 1.6.0-0.2.20140326git7e6b55 +- Update git snapshot to latest tip of heimdal-1-6-branch +- Rename Source11 with "heimdal-" prefix +- Use newer macro for UnversionedDocdirs change + +* Mon Jan 06 2014 Ken Dreyer - 1.6.0-0.1.20140106git46a508 +- Package git snapshot from master branch + +* Wed Oct 16 2013 Ken Dreyer - 1.5.3-24.20130903gitb074e0b +- Disable autogen and parallel make on EL5 +- Add pregenerated autoconf tarball as Source1 +- Add script to pregenerate autoconf files as Source2 + +* Tue Sep 10 2013 Alexander Boström - 1.5.3-23.20130903gitb074e0b +- Fix build. (Problem with symlinks to kcc.) + +* Thu Sep 05 2013 Alexander Boström - 1.5.3-22.20130903gitb074e0b +- Rename rename kcc to heimdal-kcc (conflicts in el5 and fedora) +- Rename kswitch to heimdal-kswitch in el6 too + +* Tue Sep 03 2013 Alexander Boström - 1.5.3-21.20130903gitb074e0b +- Update to latest git snapshot of heimdal-1-5-branch +- remove upstreamed patch + +* Tue Sep 03 2013 Alexander Boström - 1.5.3-20.20130813gitdcc7c13 +- Split ipv6_loopbacks_fix.patch into one backport and one smaller change + +* Tue Aug 20 2013 Ken Dreyer - 1.5.3-19.20130813gitdcc7c13 +- Build against libedit instead of readline (avoid GPL entanglements) + +* Tue Aug 13 2013 Ken Dreyer - 1.5.3-18.20130813gitdcc7c13 +- Update to latest git snapshot of heimdal-1-5-branch +- remove upstreamed texinfo patches + +* Tue Aug 13 2013 Alexander Boström - 1.5.3-17.20130730gitd9b3691 +- remove workaround for bogus check-iprop check failure + +* Mon Aug 12 2013 Alexander Boström - 1.5.3-16.20130730gitd9b3691 +- buildreq groff on el6 and older +- remove most comments from sysconfig file +- systemd: only use /etc/sysconfig/heimdal to specify the iprop master + host, via a wrapper script +- systemd: use Type=forking +- make systemd the default, check for known sysv systems + +* Mon Aug 12 2013 Ken Dreyer - 1.5.3-15.20130812git29f0a90 +- Update to latest git snapshot of heimdal-1-5-branch + +* Mon Aug 12 2013 Alexander Boström - 1.5.3-14.20130730gitd9b3691 +- do not ghost files in owned directory + +* Mon Aug 12 2013 Alexander Boström - 1.5.3-13.20130730gitd9b3691 +- use global instead of define + +* Mon Aug 12 2013 Alexander Boström - 1.5.3-12.20130730gitd9b3691 +- add doc references to unit files + +* Mon Aug 12 2013 Alexander Boström - 1.5.3-11.20130730gitd9b3691 +- add missing req on xinetd +- remove slash after buildroot macro usage +- preserve timestamps of installed files +- move slaves config file to /etc +- no attributes on symlinks +- only ghost own the slave-stats file + +* Fri Aug 09 2013 Ken Dreyer - 1.5.3-10.20130730gitd9b3691 +- add systemd files and _with_systemd conditional +- remove "--detach" from sysconfig comments +- tweak kadmind service description +- add comments about texinfo patches + +* Fri Aug 09 2013 Alexander Boström - 1.5.3-9.20130730gitd9b3691 +- SysV scriptlets and initscript cleanups +- xinetd services ipv6 enabled + +* Thu Aug 08 2013 Ken Dreyer - 1.5.3-8.20130730gitd9b3691 +- Add Debian's texinfo patch to hx509, plus my own hacks for 5.1 + +* Thu Aug 08 2013 Ken Dreyer - 1.5.3-7.20130730gitd9b3691 +- Add missing groff buildreq on F19 and above +- Tweak Summary + +* Thu Aug 08 2013 Alexander Boström - 1.5.3-6 +- Add missing buildreqs + +* Thu Aug 08 2013 Alexander Boström - 1.5.3-5 +- Update to post 1.5.3 snapshot, deprecating a couple of patches +- Add autogen.sh and extra BRs, build fixes. + +* Thu Aug 08 2013 Alexander Boström - 1.5.3-4 +- No autoreconf +- More robust ?rhel macro usage +- BR libcom_err-devel instead of e2fsprogs-devel (but not on el5) +- el5 build fixes + +* Tue Aug 06 2013 Alexander Boström - 1.5.3-3 +- Add heimdal-des-key-selection.patch + +* Tue Aug 06 2013 Alexander Boström - 1.5.3-2 +- Use upstream tarball. +- Remove unused patches. +- Fix heimdal-kdc.conf +- Handle the case of no .mo files + +* Tue Aug 06 2013 Ken Dreyer - 1.5.3-1 +- Update to 1.5.3 (tag from Git) +- Use the find_lang macro to include the translation files +- Add Getopt patch in order to build with Fedora's newer Perl +- Adjust Group to satisfy rpmlint +- Remove macros from comments to satisfy rpmlint + +* Mon Jul 29 2013 Alexander Boström - 1.5.2-3.kth.19 +- really fix prefix munge patch +- fix texi build + +* Wed Jul 3 2013 Alexander Boström - 1.5.2-3.kth.18 +- fix prefix munge patch + +* Tue Jul 2 2013 Alexander Boström - 1.5.2-3.kth.17 +- rename kswitch to heimdal-kswitch (except on el6) + +* Tue Jul 2 2013 Alexander Boström - 1.5.2-3.kth.16 +- ignore missing otp binaries + +* Fri Jun 28 2013 Alexander Boström - 1.5.2-3.kth.15 +- fix license, fix macro-in-changelog + +* Fri Jun 28 2013 Alexander Boström - 1.5.2-3.kth.14 +- enable dns_lookup_realm and dns_lookup_kdc in the sample config file +- changed logrotate conf, postrotate should not be required +- add kdc.conf +- move kadmind.acl to sysconfdir + +* Thu Jun 27 2013 Alexander Boström - 1.5.2-3.kth.13 +- fix qop man symlink + +* Thu Jun 27 2013 Alexander Boström - 1.5.2-3.kth.12 +- workstation does not require xinetd +- fix paths in xinetd confs + +* Wed Jun 26 2013 Alexander Boström - 1.5.2-3.kth.11 +- fix symlinks + +* Wed Jun 26 2013 Alexander Boström - 1.5.2-3.kth.10 +- provide/obsolete heimdal-kdc + +* Wed Apr 10 2013 Alexander Boström - 1.5.2-3.kth.9 +- make PATH manipulation an optional subpackage + +* Wed Apr 10 2013 Alexander Boström - 1.5.2-3.kth.8 +- rename to heimdal-* instead of *.heimdal + +* Tue Apr 9 2013 Alexander Boström - 1.5.2-3.kth.7 +- split init script into multiple services + +* Tue Apr 9 2013 Alexander Boström - 1.5.2-3.kth.6 +- move su to the workstation subpkg + +* Tue Apr 9 2013 Alexander Boström - 1.5.2-3.kth.5 +- Add symlinks in the bin dir. + +* Tue Apr 9 2013 Alexander Boström - 1.5.2-3.kth.4 +- Reuse /etc/security/access.conf from PAM. + +* Tue Apr 9 2013 Alexander Boström - 1.5.2-3.kth.3 +- move daemon binaries to regular libexec dir, with executable name suffix + +* Mon Apr 8 2013 Alexander Boström - 1.5.2-3.kth.2 +- move binaries from /usr/lib64/heimdal/bin to /usr/lib/heimdal/bin + +* Mon Apr 8 2013 Alexander Boström - 1.5.2-3.kth.1 +- disable tests + +* Wed Jul 4 2012 Rok Papež, ARNES - 1.5.2-3 + - updated to upstream 1.5.2 + - added support for Fedora 17 + - fixed wrong PATH on x86_64 + - fixed IPv6 and multiple interfaces bug in krb5_parse_address: + https://bugzilla.redhat.com/show_bug.cgi?id=808147 + - added support for .heimdal prefix to kcc + +* Tue Oct 4 2011 Rok Papež, ARNES - 1.5.1-1 + - updated to upstream 1.5.1 + +* Tue Sep 27 2011 Rok Papež, ARNES - 1.5.1.pre20110912git-2 + - FESCo updates: https://fedorahosted.org/fesco/ticket/577 + - Implicit requires removed, rpmbuild can figure them out itself + - Implicit provides removed, we are NOT compatible with krb5 + - Enable hardened build: + https://fedoraproject.org/wiki/Packaging:Guidelines#PIE + https://fedoraproject.org/wiki/User:Kevin/DRAFT_When_to_use_PIE_compiler_flags + - Merged updates from Orion Poplawski + +* Mon Sep 12 2011 Rok Papež, ARNES - 1.5.1.pre20110912git-1.arnes + - Updated to Heimdal 1.5.1.pre20110912git + +* Tue Nov 30 2010 Rok Papež, ARNES - 1.4.1rc1-1.arnes + - Updated to Heimdal 1.4.1rc1 + +* Fri Jul 09 2010 Rok Papež, ARNES - 1.3.3-1.arnes + - Updated to Heimdal 1.3.3 + +* Wed Apr 21 2010 Rok Papež, ARNES - 1.3.2-2.arnes + - Updated to Heimdal 1.3.2 + +* Thu Sep 17 2009 Rok Papež, ARNES - 1.3.0pre9-1 + - Updated to Heimdal 1.3.0pre9 + - Building on CentOS 5.3 i386 and Fedora 11 x86_64. + +* Wed Jun 10 2009 Rok Papež, ARNES - 1.2.1-9 + - Fixed build for CentOS 4.7 (thanks to Nitzan Zaifman for bugreport) + +* Mon Jun 8 2009 Rok Papež, ARNES - 1.2.1-8 + - Fixed paths for building on CentOS 5.3 + - Rebuilt for CentOS 5.3 + - removed obsolete X11 dependency + +* Thu Feb 19 2009 Mitja Mihelic, ARNES - 1.2.1-7 + - added dependency on xinetd for heimdal-workstation + +* Tue Jan 20 2009 Rok Papež, ARNES + - Fixed permissions + +* Wed Oct 8 2008 Rok Papež, ARNES + - New specs for Heimdel 1.2.1, suggestions taken from both PDC and Mandrake specs file. + - Need to be compatible with MIT Kerberos 5 installation. + - Let MIT have priority diff --git a/dead.package b/dead.package deleted file mode 100644 index a72aec0..0000000 --- a/dead.package +++ /dev/null @@ -1 +0,0 @@ -epel8-playground decommissioned : https://pagure.io/epel/issue/136 diff --git a/heimdal-1.6.0-c25f45a-rename-commands.patch b/heimdal-1.6.0-c25f45a-rename-commands.patch new file mode 100644 index 0000000..bc0f92b --- /dev/null +++ b/heimdal-1.6.0-c25f45a-rename-commands.patch @@ -0,0 +1,55 @@ +From 15d0c5593079f0c75b0e3ed9209e549e5d2e7822 Mon Sep 17 00:00:00 2001 +From: Ken Dreyer +Date: Wed, 28 May 2014 15:00:44 -0600 +Subject: [PATCH 1/2] Fedora: add heimdal- prefixes to heimtools cmds + +The Fedora Heimdal package renames the klist and kswitch commands in +/usr/bin to use "heimdal-" prefixes in order to avoid conflicting with +MIT's utilities. + +Add these "heimdal-" names to the heimtools command configuration so +that heimtools will recognize the commands under the new names as well +as the old names. +--- + kuser/heimtools-commands.in | 2 ++ + kuser/heimtools.c | 4 ++-- + 2 files changed, 4 insertions(+), 2 deletions(-) + +diff --git a/kuser/heimtools-commands.in b/kuser/heimtools-commands.in +index b22a8c5..62388ce 100644 +--- a/kuser/heimtools-commands.in ++++ b/kuser/heimtools-commands.in +@@ -34,6 +34,7 @@ + command = { + name = "klist" + name = "list" ++ name = "heimdal-klist" + help = "List kerberos tickets" + option = { + long = "cache" +@@ -136,6 +137,7 @@ command = { + command = { + name = "kswitch" + name = "switch" ++ name = "heimdal-kswitch" + help = "Switch default kerberos cache" + option = { + long = "type" +diff --git a/kuser/heimtools.c b/kuser/heimtools.c +index 70b23d6..c1ef60e 100644 +--- a/kuser/heimtools.c ++++ b/kuser/heimtools.c +@@ -89,8 +89,8 @@ static int + command_alias(const char *name) + { + const char *aliases[] = { +- "kinit", "klist", "kswitch", "kgetcred", "kvno", "kdeltkt", +- "kdestroy", "kcpytkt", NULL ++ "kinit", "klist", "heimdal-klist", "kswitch", "heimdal-kswitch", ++ "kgetcred", "kvno", "kdeltkt", "kdestroy", "kcpytkt", NULL + }, **p = aliases; + + while (*p && strcmp(name, *p) != 0) +-- +1.9.3 + diff --git a/heimdal-7.7.0-58c8ad96-py3.patch b/heimdal-7.7.0-58c8ad96-py3.patch new file mode 100644 index 0000000..61882ed --- /dev/null +++ b/heimdal-7.7.0-58c8ad96-py3.patch @@ -0,0 +1,296 @@ +commit 58c8ad967e765f703273c95140f7f7a7f1694ae0 +Author: Alexander Boström +Date: Sat Mar 21 13:56:33 2020 +0100 + + Changes generated by 2to3 for all Python sources. + +diff --git a/cf/symbol-version.py b/cf/symbol-version.py +index 414f06f8f..23666ecf8 100644 +--- a/cf/symbol-version.py ++++ b/cf/symbol-version.py +@@ -40,7 +40,7 @@ t_SYMBOL = r'[a-zA-Z_][a-zA-Z0-9_\.]*' + t_ignore = " \t\n" + + def t_error(t): +- print "Illegal character '%s'" % t.value[0] ++ print("Illegal character '%s'" % t.value[0]) + t.lexer.skip(1) + + import ply.lex as lex +@@ -51,7 +51,7 @@ symbols = [] + + def p_syms(p): + 'syms : SYMBOL "{" elements "}"' +- print "# %s" % p[1] ++ print("# %s" % p[1]) + + def p_elements(p): + '''elements : element +@@ -68,9 +68,9 @@ def p_element(p): + + def p_error(p): + if p: +- print "Syntax error at '%s'" % p.value ++ print("Syntax error at '%s'" % p.value) + else: +- print "Syntax error at EOF" ++ print("Syntax error at EOF") + + import ply.yacc as yacc + yacc.yacc() +@@ -82,4 +82,4 @@ for line in lines: + + for symbol in symbols: + if symbol[0] == "global": +- print "%s" % symbol[1] ++ print("%s" % symbol[1]) +diff --git a/lib/hx509/quote.py b/lib/hx509/quote.py +index 41887e5d4..95898d4c5 100644 +--- a/lib/hx509/quote.py ++++ b/lib/hx509/quote.py +@@ -76,26 +76,26 @@ chars[ord('>')] |= RFC2253_QUOTE + chars[ord('#')] |= RFC2253_QUOTE + chars[ord(';')] |= RFC2253_QUOTE + +-print "#define Q_CONTROL_CHAR 1" +-print "#define Q_PRINTABLE 2" +-print "#define Q_RFC2253_QUOTE_FIRST 4" +-print "#define Q_RFC2253_QUOTE_LAST 8" +-print "#define Q_RFC2253_QUOTE 16" +-print "#define Q_RFC2253_HEX 32" +-print "" +-print "#define Q_RFC2253 (Q_RFC2253_QUOTE_FIRST|Q_RFC2253_QUOTE_LAST|Q_RFC2253_QUOTE|Q_RFC2253_HEX)" +-print "\n" * 2 ++print("#define Q_CONTROL_CHAR 1") ++print("#define Q_PRINTABLE 2") ++print("#define Q_RFC2253_QUOTE_FIRST 4") ++print("#define Q_RFC2253_QUOTE_LAST 8") ++print("#define Q_RFC2253_QUOTE 16") ++print("#define Q_RFC2253_HEX 32") ++print("") ++print("#define Q_RFC2253 (Q_RFC2253_QUOTE_FIRST|Q_RFC2253_QUOTE_LAST|Q_RFC2253_QUOTE|Q_RFC2253_HEX)") ++print("\n" * 2) + + + + +-print "unsigned char char_map[] = {\n\t", ++print("unsigned char char_map[] = {\n\t", end=' ') + for x in range(0, 256): + if (x % 8) == 0 and x != 0: +- print "\n\t", +- print "0x%(char)02x" % { 'char' : chars[x] }, ++ print("\n\t", end=' ') ++ print("0x%(char)02x" % { 'char' : chars[x] }, end=' ') + if x < 255: +- print ", ", ++ print(", ", end=' ') + else: +- print "" +-print "};" ++ print("") ++print("};") +diff --git a/lib/wind/gen-bidi.py b/lib/wind/gen-bidi.py +index e2efcbb55..fdadcbec7 100644 +--- a/lib/wind/gen-bidi.py ++++ b/lib/wind/gen-bidi.py +@@ -42,7 +42,7 @@ import generate + import rfc3454 + + if len(sys.argv) != 3: +- print("usage: %s rfc3454.txt outdir" % sys.argv[0]) ++ print(("usage: %s rfc3454.txt outdir" % sys.argv[0])) + sys.exit(1) + + tables = rfc3454.read(sys.argv[1]) +diff --git a/lib/wind/gen-combining.py b/lib/wind/gen-combining.py +index 43e0d52eb..4e73840b5 100644 +--- a/lib/wind/gen-combining.py ++++ b/lib/wind/gen-combining.py +@@ -42,13 +42,13 @@ import generate + import UnicodeData + + if len(sys.argv) != 3: +- print("usage: %s UnicodeData.txt out-dir" % sys.argv[0]) ++ print(("usage: %s UnicodeData.txt out-dir" % sys.argv[0])) + sys.exit(1) + + ud = UnicodeData.read(sys.argv[1]) + + trans = {} +-for k,v in ud.items(): ++for k,v in list(ud.items()): + if int(v[2]) != 0 : + trans[k] = [int(v[2]), v[1]] + +diff --git a/lib/wind/gen-errorlist.py b/lib/wind/gen-errorlist.py +index 97646cf5a..345be300b 100644 +--- a/lib/wind/gen-errorlist.py ++++ b/lib/wind/gen-errorlist.py +@@ -44,13 +44,13 @@ import rfc4518 + import stringprep + + if len(sys.argv) != 3: +- print("usage: %s rfc3454.txt out-dir" % sys.argv[0]) ++ print(("usage: %s rfc3454.txt out-dir" % sys.argv[0])) + sys.exit(1) + + tables = rfc3454.read(sys.argv[1]) + t2 = rfc4518.read() + +-for x in t2.keys(): ++for x in list(t2.keys()): + tables[x] = t2[x] + + error_list = stringprep.get_errorlist() +@@ -85,7 +85,7 @@ const struct error_entry _wind_errorlist_table[] = { + + trans=[] + +-for t in error_list.keys(): ++for t in list(error_list.keys()): + for l in tables[t]: + m = re.search('^ *([0-9A-F]+)-([0-9A-F]+); *(.*) *$', l) + if m: +@@ -104,7 +104,7 @@ for x in trans: + (start, length, description, tables) = x + symbols = stringprep.symbols(error_list, tables) + if len(symbols) == 0: +- print("no symbol for %s" % description) ++ print(("no symbol for %s" % description)) + sys.exit(1) + errorlist_c.file.write(" {0x%x, 0x%x, %s}, /* %s: %s */\n" + % (start, length, symbols, ",".join(tables), description)) +diff --git a/lib/wind/gen-map.py b/lib/wind/gen-map.py +index dc10d6fae..c84d71cd2 100644 +--- a/lib/wind/gen-map.py ++++ b/lib/wind/gen-map.py +@@ -45,7 +45,7 @@ import stringprep + import util + + if len(sys.argv) != 3: +- print("usage: %s rfc3454.txt out-dir" % sys.argv[0]) ++ print(("usage: %s rfc3454.txt out-dir" % sys.argv[0])) + sys.exit(1) + + tables = rfc3454.read(sys.argv[1]) +@@ -114,7 +114,7 @@ trans = stringprep.sort_merge_trans(trans) + + for x in trans: + if x[0] == 0xad: +- print("fooresult %s" % ",".join(x[3])) ++ print(("fooresult %s" % ",".join(x[3]))) + + for x in trans: + (key, value, description, table) = x +@@ -130,7 +130,7 @@ for x in trans: + (key, value, description, tables) = x + symbols = stringprep.symbols(map_list, tables) + if len(symbols) == 0: +- print("no symbol for %s %s (%s)" % (key, description, tables)) ++ print(("no symbol for %s %s (%s)" % (key, description, tables))) + sys.exit(1) + v = value.split() + map_c.file.write(" {0x%x, %u, %u, %s}, /* %s: %s */\n" +diff --git a/lib/wind/gen-normalize.py b/lib/wind/gen-normalize.py +index daf3c3dc4..901a07fee 100644 +--- a/lib/wind/gen-normalize.py ++++ b/lib/wind/gen-normalize.py +@@ -43,8 +43,8 @@ import UnicodeData + import util + + if len(sys.argv) != 4: +- print("usage: %s UnicodeData.txt" +- " CompositionExclusions-3.2.0.txt out-dir" % sys.argv[0]) ++ print(("usage: %s UnicodeData.txt" ++ " CompositionExclusions-3.2.0.txt out-dir" % sys.argv[0])) + sys.exit(1) + + ud = UnicodeData.read(sys.argv[1]) +@@ -56,10 +56,10 @@ def sortedKeys(d): + return keys + + trans = dict([(k, [re.sub('<[a-zA-Z]+>', '', v[4]), v[0]]) +- for k,v in ud.items() if v[4]]) ++ for k,v in list(ud.items()) if v[4]]) + + maxLength = 0 +-for v in trans.values(): ++for v in list(trans.values()): + maxLength = max(maxLength, len(v[0].split())) + + normalize_h = generate.Header('%s/normalize_table.h' % sys.argv[3]) +@@ -135,7 +135,7 @@ exclusions = UnicodeData.read(sys.argv[2]) + + inv = dict([(''.join(["%05x" % int(x, 0x10) for x in v[4].split(' ')]), + [k, v[0]]) +- for k,v in ud.items() ++ for k,v in list(ud.items()) + if v[4] and not re.search('<[a-zA-Z]+> *', v[4]) and not k in exclusions]) + + table = 0 +@@ -162,7 +162,7 @@ def add(table, k, v): + + top = createTable() + +-for k,v in inv.items(): ++for k,v in list(inv.items()): + add(tables[top], k, v) + + next_table = [] +diff --git a/lib/wind/gen-punycode-examples.py b/lib/wind/gen-punycode-examples.py +index f2eddbb37..44d2c5d9a 100644 +--- a/lib/wind/gen-punycode-examples.py ++++ b/lib/wind/gen-punycode-examples.py +@@ -40,7 +40,7 @@ import sys + import generate + + if len(sys.argv) != 3: +- print("usage: %s rfc3492.txt" % sys.argv[0]) ++ print(("usage: %s rfc3492.txt" % sys.argv[0])) + sys.exit(1) + + f = open(sys.argv[1], 'r') +diff --git a/lib/wind/stringprep.py b/lib/wind/stringprep.py +index cff4d02a7..73c9d43c2 100644 +--- a/lib/wind/stringprep.py ++++ b/lib/wind/stringprep.py +@@ -38,7 +38,7 @@ import re + import string + + def _merge_table(res, source): +- for table in source.keys(): ++ for table in list(source.keys()): + res[table] = res.get(table, []) + source.get(table, []) + + name_error = ['C.1.2', 'C.2.2', 'C.3', 'C.4', 'C.5', 'C.6', 'C.7', 'C.8', 'C.9'] +@@ -57,21 +57,21 @@ def symbols(tabledict, tables): + list = list + tabledict.get(x, []) + if len(list) == 0: + return "" +- return "|".join(map(lambda x: "WIND_PROFILE_%s" % (x.upper()), list)) ++ return "|".join(["WIND_PROFILE_%s" % (x.upper()) for x in list]) + + def get_errorlist(): + d = dict() +- _merge_table(d, dict(map(lambda x: [x, ['name']], name_error))) +- _merge_table(d, dict(map(lambda x: [x, ['ldap']], ldap_error))) +- _merge_table(d, dict(map(lambda x: [x, ['sasl']], sasl_error))) ++ _merge_table(d, dict([[x, ['name']] for x in name_error])) ++ _merge_table(d, dict([[x, ['ldap']] for x in ldap_error])) ++ _merge_table(d, dict([[x, ['sasl']] for x in sasl_error])) + return d + + def get_maplist(): + d = dict() +- _merge_table(d, dict(map(lambda x: [x, ['name']], name_map))) +- _merge_table(d, dict(map(lambda x: [x, ['ldap']], ldap_map))) +- _merge_table(d, dict(map(lambda x: [x, ['ldap_case']], ldap_case_map))) +- _merge_table(d, dict(map(lambda x: [x, ['sasl']], sasl_map))) ++ _merge_table(d, dict([[x, ['name']] for x in name_map])) ++ _merge_table(d, dict([[x, ['ldap']] for x in ldap_map])) ++ _merge_table(d, dict([[x, ['ldap_case']] for x in ldap_case_map])) ++ _merge_table(d, dict([[x, ['sasl']] for x in sasl_map])) + return d + + def sort_merge_trans(trans): diff --git a/heimdal-7.7.0-configure.patch b/heimdal-7.7.0-configure.patch new file mode 100644 index 0000000..23f116c --- /dev/null +++ b/heimdal-7.7.0-configure.patch @@ -0,0 +1,17 @@ +--- a/cf/check-var.m4 2013-04-24 20:07:35.000000000 -0600 ++++ b/cf/check-var.m4 2020-01-07 11:36:36.493955390 -0700 +@@ -6,12 +6,12 @@ AC_MSG_CHECKING(for $1) + AC_CACHE_VAL(ac_cv_var_$1, [ + m4_ifval([$2],[ + AC_LINK_IFELSE([AC_LANG_PROGRAM([[$2 +- void * foo(void) { return &$1; }]],[[foo()]])], ++ __attribute__ ((used)) void * foo(void) { return &$1; }]],[[foo()]])], + [ac_cv_var_$1=yes],[ac_cv_var_$1=no])]) + if test "$ac_cv_var_$1" != yes ; then + AC_LINK_IFELSE([AC_LANG_PROGRAM([[$2 + extern int $1; +-int foo(void) { return $1; }]],[[foo()]])], ++__attribute__ ((used)) int foo(void) { return $1; }]],[[foo()]])], + [ac_cv_var_$1=yes],[ac_cv_var_$1=no]) + fi + ]) diff --git a/heimdal-7.8.0-1b57b62d-ac272.patch b/heimdal-7.8.0-1b57b62d-ac272.patch new file mode 100644 index 0000000..3308699 --- /dev/null +++ b/heimdal-7.8.0-1b57b62d-ac272.patch @@ -0,0 +1,21 @@ +commit 1b57b62d82a478c1fade350f0fb1d57031a8734e +Author: Bernd Kuhls +Date: Sat Feb 10 09:33:48 2024 +0100 + + cf/largefile.m4: Fix build with autoconf-2.72 + + Fixes https://github.com/heimdal/heimdal/issues/1201 + +diff --git a/cf/largefile.m4 b/cf/largefile.m4 +index 5c54897be..cdbbc5543 100644 +--- a/cf/largefile.m4 ++++ b/cf/largefile.m4 +@@ -10,7 +10,7 @@ dnl with generated code, such as lex + if test "$enable_largefile" != no -a "$ac_cv_sys_large_files" != no; then + CPPFLAGS="$CPPFLAGS -D_LARGE_FILES=$ac_cv_sys_large_files" + fi +-if test "$enable_largefile" != no -a "$ac_cv_sys_file_offset_bits" != no; then ++if test "$enable_largefile" != no -a "$ac_cv_sys_file_offset_bits" != no && test -n "$ac_cv_sys_file_offset_bits"; then + CPPFLAGS="$CPPFLAGS -D_FILE_OFFSET_BITS=$ac_cv_sys_file_offset_bits" + fi + ]) diff --git a/heimdal-7.8.0-e93a1357-slapdtest.patch b/heimdal-7.8.0-e93a1357-slapdtest.patch new file mode 100644 index 0000000..8faa4e8 --- /dev/null +++ b/heimdal-7.8.0-e93a1357-slapdtest.patch @@ -0,0 +1,31 @@ +From e93a13576532db5d46b365b73829e6c1600d48ff Mon Sep 17 00:00:00 2001 +From: Nicolas Williams +Date: Thu, 27 Dec 2018 13:32:46 -0600 +Subject: [PATCH] Fix check-ldap slapd start race + +We start slapd in the foreground (-d0) but backgrounded in the shell, +then we wait 4 seconds. This causes a race condition however. This +commit makes the slapd-init script more robust and limits the wait to +however many seconds (up to 30) that slapd needs to start service. + +diff --git a/tests/ldap/slapd-init.in b/tests/ldap/slapd-init.in +index a3975aa67..f6e9fe93a 100644 +--- a/tests/ldap/slapd-init.in ++++ b/tests/ldap/slapd-init.in +@@ -44,5 +44,15 @@ cp "`which slapd`" . || true # fails if running + + echo "starting slapd" + ./slapd -d0 -f "${srcdir}/slapd.conf" -h ldapi://.%2Fldap-socket & ++slapd_pid=$! ++ ++tries=0 ++while kill -0 $slapd_pid && [ ! -S ldap-socket ] && ++ ! ldapsearch -l 2 -w '' -D '' -b "o=TEST,dc=H5L,dc=SE" -s base -H ldapi://.%2Fldap-socket >/dev/null && ++ [ $tries -lt 30 ]; do ++ sleep 1 ++ tries=`expr 1 + $tries` ++done + +-sleep 4 ++kill -0 $slapd_pid || exit 1 ++[ -S ldap-socket ] || exit 1 diff --git a/heimdal-bashrc b/heimdal-bashrc new file mode 100644 index 0000000..ceb7de6 --- /dev/null +++ b/heimdal-bashrc @@ -0,0 +1,7 @@ +alias kinit="/usr/bin/kinit.heimdal" +alias kdestroy="/usr/bin/kdestroy.heimdal" +alias klist="/usr/bin/klist.heimdal" +alias kpasswd="/usr/bin/kpasswd.heimdal" +alias kadmin="/usr/sbin/kadmin.heimdal" +alias krb5-config="/usr/bin/krb5-config.heimdal" +alias ktutil="/usr/sbin/ktutil.heimdal" diff --git a/heimdal-configure-c99.patch b/heimdal-configure-c99.patch new file mode 100644 index 0000000..b78b3c5 --- /dev/null +++ b/heimdal-configure-c99.patch @@ -0,0 +1,32 @@ +Avoid implicit function declarations in the configure tests, to +prevent build failures with future compilers. + +Submitted upstream: + +diff --git a/cf/find-func-no-libs2.m4 b/cf/find-func-no-libs2.m4 +index 5e5ed0e69ba60f7b..a6b3ad6d347adc94 100644 +--- a/cf/find-func-no-libs2.m4 ++++ b/cf/find-func-no-libs2.m4 +@@ -21,7 +21,7 @@ if eval "test \"\$ac_cv_func_$1\" != yes" ; then + *) ac_lib="-l$ac_lib" ;; + esac + LIBS="$6 $ac_lib $5 $ac_save_LIBS" +- AC_LINK_IFELSE([AC_LANG_PROGRAM([[$3]],[[$1($4)]])],[eval "if test -n \"$ac_lib\";then ac_cv_funclib_$1=$ac_lib; else ac_cv_funclib_$1=yes; fi";break]) ++ AC_LINK_IFELSE([AC_LANG_PROGRAM([[char $1 (void);]],[[$1()]])],[eval "if test -n \"$ac_lib\";then ac_cv_funclib_$1=$ac_lib; else ac_cv_funclib_$1=yes; fi";break]) + done + eval "ac_cv_funclib_$1=\${ac_cv_funclib_$1-no}" + LIBS="$ac_save_LIBS" +diff --git a/cf/have-struct-field.m4 b/cf/have-struct-field.m4 +index bb7bcefbcc68a08c..3962d850645f88e4 100644 +--- a/cf/have-struct-field.m4 ++++ b/cf/have-struct-field.m4 +@@ -7,7 +7,8 @@ dnl AC_HAVE_STRUCT_FIELD(struct, field, headers) + AC_DEFUN([AC_HAVE_STRUCT_FIELD], [ + define(cache_val, translit(ac_cv_type_$1_$2, [A-Z ], [a-z_])) + AC_CACHE_CHECK([for $2 in $1], cache_val,[ +-AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[$3]], ++AC_COMPILE_IFELSE([AC_LANG_PROGRAM([[#include ++$3]], + [[$1 x; memset(&x, 0, sizeof(x)); x.$2]])], + [cache_val=yes], + [cache_val=no]) diff --git a/heimdal-ipropd-master.service b/heimdal-ipropd-master.service new file mode 100644 index 0000000..7ab4f1f --- /dev/null +++ b/heimdal-ipropd-master.service @@ -0,0 +1,13 @@ +[Unit] +Description=Heimdal ipropd-master incremental propagation service +Documentation=man:iprop(8) info:heimdal http://www.h5l.org/ +After=syslog.target network.target network-online.target +Wants=network-online.target + +[Service] +Type=forking +ExecStart=/usr/libexec/ipropd-master --detach +PIDFile=/var/run/ipropd-master.pid + +[Install] +WantedBy=multi-user.target diff --git a/heimdal-ipropd-slave-wrapper b/heimdal-ipropd-slave-wrapper new file mode 100755 index 0000000..6b7e2b4 --- /dev/null +++ b/heimdal-ipropd-slave-wrapper @@ -0,0 +1,12 @@ +#!/bin/bash + +set -e; set -o pipefail + +. /etc/sysconfig/heimdal + +if [[ -z "$MASTER" ]]; then + echo >&2 "MASTER must be specified in /etc/sysconfig/heimdal" + exit 1 +fi + +exec /usr/libexec/ipropd-slave --detach "$MASTER" diff --git a/heimdal-ipropd-slave.service b/heimdal-ipropd-slave.service new file mode 100644 index 0000000..aed25d9 --- /dev/null +++ b/heimdal-ipropd-slave.service @@ -0,0 +1,13 @@ +[Unit] +Description=Heimdal ipropd-slave incremental propagation service +Documentation=man:iprop(8) info:heimdal http://www.h5l.org/ +After=syslog.target network.target network-online.target +Wants=network-online.target + +[Service] +Type=forking +ExecStart=/usr/libexec/ipropd-slave-wrapper +PIDFile=/var/run/ipropd-slave.pid + +[Install] +WantedBy=multi-user.target diff --git a/heimdal-kadmind.service b/heimdal-kadmind.service new file mode 100644 index 0000000..4e350f9 --- /dev/null +++ b/heimdal-kadmind.service @@ -0,0 +1,13 @@ +[Unit] +Description=Heimdal kadmind remote administration service +Documentation=man:heimdal-kadmind(8) info:heimdal http://www.h5l.org/ +After=syslog.target network.target network-online.target +Wants=network-online.target + +[Service] +Type=simple +ExecStart=/usr/libexec/heimdal-kadmind +PIDFile=/var/run/heimdal-kadmind.pid + +[Install] +WantedBy=multi-user.target diff --git a/heimdal-kdc.conf b/heimdal-kdc.conf new file mode 100644 index 0000000..0cc6488 --- /dev/null +++ b/heimdal-kdc.conf @@ -0,0 +1,10 @@ +[logging] + default = FILE:/var/log/heimdal/heimdal.log + kdc = FILE:/var/log/heimdal/kdc.log + admin_server = FILE:/var/log/heimdal/kadmind.log + +[kdc] + enable-http = true + +[kadmin] + require-preauth = true diff --git a/heimdal-kdc.service b/heimdal-kdc.service new file mode 100644 index 0000000..ed0d851 --- /dev/null +++ b/heimdal-kdc.service @@ -0,0 +1,13 @@ +[Unit] +Description=Heimdal KDC is a Kerberos 5 Key Distribution Center server +Documentation=man:kdc(8) info:heimdal http://www.h5l.org/ +After=syslog.target network.target network-online.target +Wants=network-online.target + +[Service] +Type=simple +ExecStart=/usr/libexec/kdc +PIDFile=/var/run/kdc.pid + +[Install] +WantedBy=multi-user.target diff --git a/heimdal-kpasswdd.service b/heimdal-kpasswdd.service new file mode 100644 index 0000000..0cc5d7b --- /dev/null +++ b/heimdal-kpasswdd.service @@ -0,0 +1,13 @@ +[Unit] +Description=Heimdal kpasswdd allows users to change their KDC passwords +Documentation=man:kpasswdd(8) info:heimdal http://www.h5l.org/ +After=syslog.target network.target network-online.target +Wants=network-online.target + +[Service] +Type=simple +ExecStart=/usr/libexec/kpasswdd +PIDFile=/var/run/kpasswdd.pid + +[Install] +WantedBy=multi-user.target diff --git a/heimdal.csh b/heimdal.csh new file mode 100644 index 0000000..cc7836a --- /dev/null +++ b/heimdal.csh @@ -0,0 +1,3 @@ +if ( "${path}" !~ */usr/lib/heimdal/bin* ) then + set path = ( /usr/lib/heimdal/bin $path ) +endif diff --git a/heimdal.logrotate b/heimdal.logrotate new file mode 100644 index 0000000..8b9fc01 --- /dev/null +++ b/heimdal.logrotate @@ -0,0 +1,9 @@ +/var/log/heimdal/*.log { + compress + delaycompress + maxage 100 + minsize 100M + missingok + notifempty +} + diff --git a/heimdal.sh b/heimdal.sh new file mode 100644 index 0000000..4e9b14a --- /dev/null +++ b/heimdal.sh @@ -0,0 +1,3 @@ +if ! echo ${PATH} | /bin/grep -q /usr/lib/heimdal/bin ; then + PATH=/usr/lib/heimdal/bin:${PATH} +fi diff --git a/heimdal.spec b/heimdal.spec new file mode 100644 index 0000000..ccf485b --- /dev/null +++ b/heimdal.spec @@ -0,0 +1,442 @@ +%global _hardened_build 1 +%global prefix %{_libdir}/%{name} +%global exec_prefix %{_exec_prefix}/lib/%{name} + +Name: heimdal +Version: 7.8.0 +Release: %autorelease +Summary: A Kerberos 5 implementation without export restrictions +# Tracked at https://github.com/abstrm/heimdal/blob/heimdal-7.8.0-spdx/doc/copyright.texi +License: BSD-2-Clause AND BSD-3-Clause AND HPND-export-US AND HPND-export2-US AND LicenseRef-Fedora-Public-Domain +URL: http://www.heimdal.software/heimdal +Source0: https://github.com/%{name}/%{name}/releases/download/%{name}-%{version}/%{name}-%{version}.tar.gz +Source3: %{name}.sysconfig +Source4: %{name}.sh +Source5: %{name}.csh +Source9: krb5.conf.sample +Source10: %{name}.logrotate +Source11: %{name}-bashrc +Source25: %{name}-kdc.conf +Source26: %{name}-kdc.service +Source27: %{name}-ipropd-master.service +Source28: %{name}-ipropd-slave.service +Source29: %{name}-kadmind.service +Source30: %{name}-kpasswdd.service +Source31: %{name}-ipropd-slave-wrapper + +# klist, kswitch, and kvno are symlinks to "heimtools", and this utility needs +# to know how to interpret the "heimdal-" prefixes. +Patch1: heimdal-1.6.0-c25f45a-rename-commands.patch +Patch4: heimdal-7.7.0-configure.patch +Patch5: heimdal-7.7.0-58c8ad96-py3.patch +Patch6: heimdal-configure-c99.patch +Patch7: heimdal-7.8.0-1b57b62d-ac272.patch +Patch8: heimdal-7.8.0-e93a1357-slapdtest.patch + +BuildRequires: gettext +BuildRequires: bison +BuildRequires: flex +BuildRequires: libedit-devel +BuildRequires: libtool +BuildRequires: ncurses-devel +BuildRequires: openldap-devel +#Required for tests/ldap +%if (0%{?rhel}) +# but not available on RHEL 8 +%else +BuildRequires: openldap-servers +%endif +BuildRequires: pam-devel +BuildRequires: perl(JSON) +BuildRequires: sqlite-devel +BuildRequires: texinfo +BuildRequires: libcom_err-devel +BuildRequires: libcap-ng-devel +BuildRequires: libdb-devel +BuildRequires: doxygen +BuildRequires: graphviz +BuildRequires: python3 +BuildRequires: groff-base +BuildRequires: systemd-units +BuildRequires: make +BuildRequires: libxcrypt-devel + +# Bundled libtommath (https://bugzilla.redhat.com/1118462) +Provides: bundled(libtommath) = 0.42.0 + +%description +Kerberos 5 is a network authentication and single sign-on system. +Heimdal is a free Kerberos 5 implementation without export restrictions +written from the spec (rfc1510 and successors) including advanced features +like thread safety, IPv6, master-slave replication of Kerberos Key +Distribution Center server and support for ticket delegation (S4U2Self, +S4U2Proxy). +This package can coexist with MIT Kerberos 5 packages. Hesiod is disabled +by default since it is deemed too big a security risk by the packager. + +%package workstation +Summary: Heimdal kerberos programs for use on workstations + +%description workstation +This package contains Heimdal Kerberos 5 programs and utilities for +use on workstations (kinit, klist, kdestroy, kpasswd) + +%package server +Summary: Heimdal kerberos server +Requires: logrotate +Requires(preun): systemd +Requires(postun): systemd +Requires(post): systemd +Provides: heimdal-kdc = %{version}-%{release} +Obsoletes: heimdal-kdc < 1.5 + +%description server +This package contains the master Heimdal kerberos Key Distribution +Center (KDC), admin interface server (admind) and master-slave +synchronisation daemons. Install this package if you intend to +set up Kerberos server. + +%package libs +Summary: Heimdal kerberos shared libraries +Requires(post): info +Requires(preun): info + +%description libs +This package contains shared libraries required by several of the other +Heimdal packages. + +%package devel +Summary: Header and other development files for Heimdal kerberos + +%description devel +Contains files needed to compile and link software using the Heimdal +kerberos headers/libraries. + +%package static +Summary: Static libraries for Heimdal kerberos +Requires: %{name}-devel = %{version}-%{release} + +%description static +Contains files needed to statically link software using the Heimdal +kerberos headers/libraries. + +%package path +Summary: Heimdal kerberos PATH manipulation +Requires: %{name}-libs +# For /etc/profile.d +Requires: setup + +%description path +This package prepends the Heimdal binary directory to the beginning of +PATH. + +%prep +%setup -q +%patch -P1 -p1 -b .cmds +%patch -P4 -p1 -b .config +%patch -P5 -p1 -b .2to3 +%patch -P6 -p1 +%patch -P7 -p1 +%patch -P8 -p1 + +for f in lib/*/*.py; do + sed -i "$f" -re 's,^#!/usr/(local/|)bin/python,#!/usr/bin/python3,' +done + +# FIXME check-slapd fails +for f in tests/Makefile.{in,am}; do sed -i $f -re 's, ldap , ,'; done + +./autogen.sh + +%build +%ifarch i386 +%global build_fix "-march=i686" +%else +%global build_fix "" +%endif +autoreconf -ivf +%configure \ + --prefix=%{_prefix} \ + --includedir=%{_includedir}/%{name} \ + --libdir=%{prefix}/lib \ + --enable-static \ + --enable-shared \ + --enable-pthread-support \ + --without-x \ + --without-hesiod \ + --with-ipv6 \ + --enable-kcm \ + --enable-pk-init \ + --with-openldap=%{_prefix} \ + --with-sqlite3=%{_prefix} \ + --with-libedit=%{_prefix} \ + LIBS="-ltermcap" \ + CFLAGS="-fPIC %{optflags} %{build_fix}" +%make_build -C include krb5-types.h +%make_build +%make_build -C doc html + +# po/localefiles is not in the tarball, which causes install to fail +touch po/localefiles +%make_build -C po mo + +%check +%make_build -j1 check + +%install +%make_install +# install the init files +# install systemd service files +mkdir -p %{buildroot}%{_unitdir} +pushd %{buildroot}%{_unitdir} + install -p -D -m 644 %{SOURCE26} heimdal-kdc.service + install -p -D -m 644 %{SOURCE27} heimdal-ipropd-master.service + install -p -D -m 644 %{SOURCE28} heimdal-ipropd-slave.service + install -p -D -m 644 %{SOURCE29} heimdal-kadmind.service + install -p -D -m 644 %{SOURCE30} heimdal-kpasswdd.service +popd +install -p -D -m 755 %{SOURCE31} %{buildroot}%{_libexecdir}/ipropd-slave-wrapper +install -p -D -m 644 %{SOURCE3} %{buildroot}%{_sysconfdir}/sysconfig/heimdal +install -p -D -m 644 %{SOURCE4} %{buildroot}%{_sysconfdir}/profile.d/heimdal.sh +install -p -D -m 644 %{SOURCE5} %{buildroot}%{_sysconfdir}/profile.d/heimdal.csh +install -p -D -m 644 %{SOURCE10} %{buildroot}%{_sysconfdir}/logrotate.d/heimdal +mkdir -p %{buildroot}%{_localstatedir}/heimdal/ +install -p -D -m 755 %{SOURCE25} %{buildroot}%{_sysconfdir}/heimdal-kdc.conf +ln -s %{_sysconfdir}/heimdal-kdc.conf %{buildroot}%{_localstatedir}/heimdal/kdc.conf +echo "# see man heimdal-kadmind(8)" > %{buildroot}%{_sysconfdir}/heimdal-kadmind.acl +ln -s %{_sysconfdir}/heimdal-kadmind.acl %{buildroot}%{_localstatedir}/heimdal/kadmind.acl +touch %{buildroot}%{_sysconfdir}/heimdal-slaves +ln -s %{_sysconfdir}/heimdal-slaves %{buildroot}%{_localstatedir}/heimdal/slaves +install -d -m 700 %{buildroot}%{_localstatedir}/log/heimdal +install -d -m 755 %{buildroot}/%{_pkgdocdir} +install -p -D -m 644 LICENSE %{buildroot}/%{_pkgdocdir}/LICENSE +install -p -D -m 644 %{SOURCE9} %{buildroot}/%{_pkgdocdir}/krb5.conf.sample +install -p -D -m 644 %{SOURCE11} %{buildroot}/%{_pkgdocdir}/bashrc +rm -rf %{buildroot}%{_infodir}/dir +# NOTICE: no support for X11 +rm -f %{buildroot}%{_mandir}/man1/kx.1* +rm -f %{buildroot}%{_mandir}/man1/rxtelnet.1* +rm -f %{buildroot}%{_mandir}/man1/rxterm.1* +rm -f %{buildroot}%{_mandir}/man1/tenletxr.1* +rm -f %{buildroot}%{_mandir}/man1/xnlock.1* +rm -f %{buildroot}%{_mandir}/man8/kxd.8* +# Remove CAT files, they are not needed +rm -rf %{buildroot}%{_mandir}/cat* +# Remove libtool archives +find %{buildroot} -type f -name '*.la' -exec rm -f {} ';' + +mkdir -p %{buildroot}%{_sysconfdir}/ld.so.conf.d/ +cat >> %{buildroot}%{_sysconfdir}/ld.so.conf.d/%{name}-%{_arch}.conf << EOF +%{prefix}/lib +EOF + +mkdir -p %{buildroot}%{exec_prefix}/bin +mkdir -p %{buildroot}%{_mandir}/%{name}/man{1,5,8} + +# rename clashes with other pkgs from to heimdal- +for prog in kadmin kadmind kdestroy kinit klist kpasswd krb5-config ktutil su pagsh compile_et +do + if [ -e %{buildroot}%{_bindir}/${prog} ]; then + mv %{buildroot}%{_bindir}/{,%{name}-}${prog} + ln -s %{_bindir}/%{name}-${prog} %{buildroot}%{exec_prefix}/bin/${prog} + elif [ -e %{buildroot}%{_sbindir}/${prog} ]; then + mv %{buildroot}%{_sbindir}/{,%{name}-}${prog} + ln -s %{_sbindir}/%{name}-${prog} %{buildroot}%{exec_prefix}/bin/${prog} + elif [ -e %{buildroot}%{_libexecdir}/${prog} ]; then + mv %{buildroot}%{_libexecdir}/{,%{name}-}${prog} + fi + + if [ -e %{buildroot}%{_mandir}/man1/${prog}.1 ]; then + mv %{buildroot}%{_mandir}/man1/{,%{name}-}${prog}.1 + elif [ -e %{buildroot}%{_mandir}/man8/${prog}.8 ]; then + mv %{buildroot}%{_mandir}/man8/{,%{name}-}${prog}.8 + fi +done + +# If we have the prefixed name in one pkg we want it in all. +mv %{buildroot}%{_bindir}/{,%{name}-}kswitch +ln -s %{_bindir}/%{name}-kswitch %{buildroot}%{exec_prefix}/bin/kswitch +mv %{buildroot}%{_mandir}/man1/{,%{name}-}kswitch.1 + +ln -s %{name}-kinit %{buildroot}%{_bindir}/kauth + +mv %{buildroot}%{_mandir}/man5/{,%{name}-}krb5.conf.5 + +rm %{buildroot}%{_mandir}/man5/qop.5 +ln -s mech.5.gz %{buildroot}%{_mandir}/man5/qop.5.gz + +sha256sum %{buildroot}%{_mandir}/man3/*.3 | sort >man3hash +firsthash="X"; firstname="X" +while read hash path; do + name="${path##*/}" + if [ "$hash" != "$firsthash" ]; then + firsthash="$hash" + firstname="${path##*/}" + else + rm "$path" + ln -s "$firstname".gz "$path".gz + fi +done