Group :: System/Base
RPM: linux-pam
Main Changelog Spec Patches Sources Download Gear Bugs and FR Repocop
7 may 2023 Dmitry V. Levin <ldv at altlinux.org> 1.5.3-alt1
- v1.5.2 -> v1.5.3.
- v1.5.1-67-g49e3ffcb -> v1.5.2.
- v1.5.1-43-gf220cace -> v1.5.1-67-g49e3ffcb.
- v1.5.1 -> v1.5.1-43-gf220cace.
- v1.5.0 -> v1.5.1.
- v1.4.0-52-g650273e7 -> v1.5.0.
Note that pam_tally and pam_tally2 were removed in favour of pam_faillock. - Packaged pam_tty_audit module.
- v1.4.0 -> v1.4.0-52-g650273e7.
- v1.3.1-324-geec5fe0d -> v1.4.0.
- v1.3.1-223-gc2c0434b -> v1.3.1-324-geec5fe0d.
New module: pam_faillock.
Note that pam_tally and pam_tally2 are deprecated in favour of pam_faillock.
- v1.3.1-212-g76916913 -> v1.3.1-223-gc2c0434b (closes: #38389).
- v1.3.1-210-gf8fc7504 -> v1.3.1-212-g76916913.
- v1.3.1-5-g955b3e2 -> v1.3.1-210-gf8fc7504.
New modules: pam_setquota, pam_usertype.
- Fixed Russian translation (closes: #35128).
- v1.3.1 -> v1.3.1-5-g955b3e2 (fixes grammar of messages printed via pam_prompt).
- Updated Russian translation.
- v1.3.0-23-g94f529d4 -> v1.3.1.
- /sbin/pam_tally2 --reset: avoid creating a missing tallylog file (closes: #34035).
- Packaged %ghost /var/log/tallylog file.
- v1.3.0-17-g7d0c508 -> v1.3.0-23-g94f529d4.
- pam_sepermit: changed sepermit lock directory to /var/lock/sepermit.
- v1.3.0-4-gdce30cd -> v1.3.0-17-g7d0c508.
- Enabled pam_keyinit module (closes: #33558).
- v1.1.8-54-g5df44a3 -> v1.3.0-4-gdce30cd.
- Updated to v1.1.8-54-g5df44a3.
- Updated to v1.1.8-32-g9dcead8.
- Updated to v1.1.8-29-g316e993.
- Updated to v1.1.8-15-g24f3a88.
- Updated to v1.1.8-6-g5865f52.
- Updated to v1.1.6-5-g0603b28.
- Updated to 1.1.6.
- Updated to Linux-PAM-1_1_5-26-g3c69856.
- Updated to 1.1.5.
- pam_mkhomedir: changed default umask from 0022 to 0077 (closes: #25247).
- Backported pam_selinux fixes from HEAD.
- Rebuilt for debuginfo.
- Updated to Linux-PAM-1_1_3 (fixes CVE-2010-3853).
- Updated to Linux-PAM-1_1_2-13-g4d9616d.
- pam_selinux: Refactored, implemented "restore" option.
- macros.d/pam: Removed %config flag.
- Updated to Linux-PAM-1_1_2-6-g843807a
(fixes CVE-2010-3430 and CVE-2010-3431).
- Made rpm-macros-pam* noarch.
- Updated to Linux-PAM-1_1_2 (fixes CVE-2010-3316).
- Updated to Linux-PAM-1_1_1-16-ge305200.
- Enabled build with SELinux.
- Updated Linux-PAM to Linux-PAM-1_1_1.
- Moved pam-redhat to separate package.
- Moved rpm macros to separate subpackage rpm-macros-pam.
- NMU: removed v4l and dvb permissions control from pam0_console
- Moved "make check" to %check section.
- libpam: Added libpam(optional_module) to provides list.
- pam_console: Create system group "scanner" and
use it in rules (closes: #20477).
- Updated Linux-PAM to Linux-PAM-1_1_0.
- Updated pam-redhat to 0.99.10-1.
- pam_console %post: Create xgrp system group.
- libpam/pam_audit.c (_pam_audit_writelog): Removed unreliable getuid() check.
- Replaced all calls to exit(3) in child processes
with calls to _exit(2).
- Enabled audit support by default.
- Updated Linux-PAM to Linux-PAM-1_0_4.
- Updated Linux-PAM to Linux-PAM-1_0_3.
- Packaged -doc subpackage as noarch.
- Removed obsolete %post_ldconfig_sys/%postun_ldconfig calls.
- Updated Linux-PAM to Linux-PAM-1_0_2.
- Fixed build with fresh autoconf.
- Updated Linux-PAM to Linux-PAM-1_0_1.
- Updated Linux-PAM to Linux-PAM-1_0_0 (bugfix only).
- Enabled nls support by default.
- Updated Linux-PAM to 0.99.10.0-4-gb453d28; most essential changes:
+ New substack directive in config file syntax.
+ New PAM items: PAM_XDISPLAY and PAM_XAUTHDATA.
+ Finaly removed deprecated pam_rhosts_auth module.
+ misc_conv no longer blocks SIGINT.
+ pam_limits: Added support for limits.d directory. - Updated pam-redhat to 0.99.8-1.
- Enabled new modules: pam_faildelay, pam_namespace.
- pam_limits:
+ Moved default limits from limits.conf to limits.d/50-defaults.conf
+ Raised nproc limit from 256/512 to 512/1024. - pam_console:
+ Moved default permission definitions from console.perms
to console.perms.d/50-default.perms - pam_console_apply: Fixed garbage output on error path (#4634).
- 50-default.perms: Changed <dri> permissions (#6831).
- 50-default.perms (joystick): Added /dev/input/js[0-9]* (#7669).
- pam_console no longer needs glib (#8791).
- Backported several fixes from Linux-PAM 0.99.7.1.
- Updated Linux-PAM to 0.99.6.3.
- Packaged /etc/environment file.
- Updated Linux-PAM to 0.99.6.2:
- pam_umask: Enabled packaging.
- pam_rhosts: New module which replaces pam_rhosts_auth.
- Enhanced documentation for PAM functions and modules.
- Updated Linux-PAM to cvs snapshot 20060523.
- Updated Linux-PAM to 0.99.4.0.
- Backported a few fixes from cvs.
- Updated Linux-PAM to 0.99.3.0.
- Updated Linux-PAM to cvs snapshot 20060111.
- Rebuilt for new style PAM dependencies generated by rpm-build-4.0.4-alt55.
- Updated Linux-PAM to 0.99.2.1.
- Updated %_pam_modules_dir (fixes #8630).
- Updated Linux-PAM to cvs snapshot 20051124.
- Updated Linux-PAM to cvs snapshot 20051118.
- Updated Linux-PAM to cvs snapshot 20051004.
- Merged upstream patches:
owl-strdup-cleanup
- Updated Linux-PAM to cvs snapshot 20050930.
- Fixed several memory leaks in few modules.
- Updated Linux-PAM to 0.99.1.0.
- Merged upstream patches:
owl-pam_mail
owl-pam_nologin
owl-pam_xauth
- Updated Linux-PAM to cvs snapshot 20050921.
- Merged upstream patches:
owl-attribute
owl-pam_issue
owl-pam_lastlog-fixes
owl-pam_limits
owl-pam_userdb
owl-sprintf - Fixed pam_xauth.
- Updated Linux-PAM to cvs snapshot 20050918.
- Merged upstream patches:
owl-pam_access
owl-pammodutil-makefile - Fixed pam_mail and pam_nologin.
- Updated Linux-PAM to cvs snapshot 20050917.
- Merged upstream patches:
owl-conv-warning
owl-pam_deny
owl-pam_env
owl-pam_motd
owl-pam_permit
owl-pam_start
owl-pam_warn - Fixed pam_issue.
- Updated Linux-PAM to cvs snapshot 20050915.
- Merged upstream patches:
owl-pam_ext
owl-libpam_misc-makefile
owl-pam_filter-upperLOWER
owl-pam_ftp
owl-pam_lastlog
owl-pam_tally
owl-pam_time
owl-pam_userdb - Enhanced errors diagnostics.
- Fixed compilation warnings.
- Added more const and attribute tags to function prototypes.
- Fixed pam_lastlog.
- Updated Linux-PAM to cvs snapshot 20050906.
- Merged upstream patches:
owl-tmp,
owl-pam_get_user-cache-failures,
owl-man,
owl-pam_securetty,
owl-pam_limits,
owl-pam_motd,
owl-configure,
owl-pam_filter,
owl-pammodutil-attribute. - Updated patches.
- Disabled packaging of the static library.
- Finished Linux-PAM migration to pam_syslog/pam_prompt.
- pam0_console: fixed console.handlers (#7752).
- Restricted list of global symbols exported by libraries.
- Cleaned up conversation wrappers.
- Raised nprocs limits in limits.conf (#5636).
- Added pam_sm_acct_mgmt for pam_mkhomedir module (#6989).
- Changed modules logging to eliminate disunion in behaviour and
avoid openlog/closelog calls for each logging function invocation. - Restricted list of global symbols exported by PAM modules to
standard set of six pam_sm_* functions.
- Updated Linux-PAM to 0.80.
- Updated pam-redhat to 0.80-1.
- Disabled build and packaging of the pam_stack module.
- Reviewed patches, removed obsolete ones, updated all the rest.
- Fixed multilib (closes #5091).
- pam_console: Fixed /dev/sg* permissions (#4742).
- Added multilib support (#4891).
- console.perms: added /dev/dri/* to <dri> (#2507).
- console.perms: fixed typo in <console> (#3343).
- pam_userdb: build with libdb4 (#4080).
- Build with %optflags_shared.
- /etc/rpm/macros.d/pam: reverted previous change.
- pam_limits: don't invoke setrlimit(2) on limits which are not
set explicitly as simply resetting RLIMIT_FSIZE to what
appears to be its current value may decrease the actual
limit with LFS (Owl). - Added buildreq substitution rules.
- /etc/rpm/macros.d/pam: updated (#3050).
- pam_wheel: patched to never rely on getlogin(3).
- pam_console: added "/dev/snd/*" to console.perms <sound> list.
- Renamed:
pam_console0 -> pam0_console
pam_stack0 -> pam0_stack
pam_timestamp0 -> pam0_timestamp - Updated PAM Policy file.
- Updated rpm macros file.
- Renamed:
libpam -> libpam0
libpam-devel -> libpam0-devel
libpam-devel-static -> libpam0-devel-static
pam_console -> pam_console0
pam_stack -> pam_stack0
pam_timestamp -> pam_timestamp0 - Relocated /etc/pam.d/other from this package to pam-common.
- Relocated pam_{deny,permit}.so modules to libpam0 subpackage.
- Added Linux-PAM-specific rpm macros file.
- Updated PAM Policy file.
- Implemented pam include config support.
- Moved pam_stack to separate subpackage.
- Cleaned up build a bit.
- Build with --disable-read-both-confs
(when /etc/pam.d/ exists, don't look at /etc/pam.conf). - Moved pam_timestamp to separate subpackage.
- Relocated Linux-PAM documentation to /usr/share/doc/Linux-PAM-1.5.3.
- Updated pam_xauth to pam-redhat-0.75-48.
- pam_xauth: removed wildcards support introduced in pam-redhat-0.75-48.
- Patched pam_motd to behave on errors (Owl).
- Updated pam_timestamp* to pam-redhat-0.75-40.
- Fixed library symlinks generation.
- Use subst instead of perl for build.
- Updated devel-static requirements.
- Simplified read_string patch.
- Readded documentation in PostScript format.
- Dropped buildrequires on libcrypt.so.1(GLIBC_2.2.2), no longer needed
since we don't build pam_unix/pam_pwdb. - Added patches from Owl:
+ Moved pam.d and pam.conf man pages to section 5 where they belong.
+ pam_limits: support stacking for account management (as well as for
session setup), be fail-close on configuration file reads, report the
"too many logins" via PAM conversation rather than direct printf(3). - Updated pam-redhat to -38:
+ pam_xauth: fix cases where DISPLAY is "localhost:screen" and
the xauth key is actually stored using the system's hostname;
+ pam_timestamp fixes;
+ added pam_timestamp_check.
- Updated console.perms <dri> rules.
- Relaxed /etc/security/console.apps permissions a bit.
- Fixed pam_console %triggerpostun script.
- Fixed /etc/security/console.* permissions.
- Updated pam-redhat to -27 (added pam_timestamp).
- Relocated helpers back to /sbin/.
- Updated console.perms to new scheme.
- Moved pam_console stuff to separate subpackage.
- Run /sbin/pam_console_apply in pam_console %post.
- Merged RH patches (rh release 20).
- Merged Owl patches (owl release 14).
- Dropped: pam_unix, pam_pwdb, pam_cracklib.
- Merged RH patches (rh release 12, pam_stack still from 5).
- console.perms: corrected console class description.
- Moved cracklib module to separate subpackage.
- fixed and relocated docs.
- pam_stack: revert to old version (from rh release 5) for now.
- Moved changable system-auth config to pam-config package.
- Relocated helper programs to /sbin.
- Rebuilt to get more dependencies.
- Moved /var/lock/console /var/run/console.
- Merged RH patches (rh release 10).
- Removed versioned dependence on glibc package.
- Added requires on libcrypt.so.1(GLIBC_2.2.1).
- More sanity checks in pam_unix_passwd.c
- Fixed more errors in pam_console/chmod.c
- Fixed recent typo in pam_unix/support.h
- 0.75 (rh release 2).
- Attempt to fix loop in pam_console.
- Fixed pam_unix-chkpwd helper.
- 0.75 (rh release 1).
- Moved static libraries to devel-static subpackage.
- Merged RH patches (rh release 12).
- Libification.
- Merged RH patches (rh release 10).
- changed console.perms:
<console> 0600 <burner> 0600 root.cdwriter
- Enhanced unix_chkpwd to support LOGNAME environment variable.
- Merged RH patches (rh release 5).
- 0.74 (sync with Linux-PAM and pam-redhat).
- Moved development libraries from /lib to /usr/lib64.
- Use libc_crypt as crypt function (glibc >= 2.2.1-ipl0.3mdk).
- Integrated new feaures of glibc >= 2.2.1-ipl0.2mdk:
+ added blowfish crypt support for pam_unix (libcrypt);
+ dropped BSDIcrypt support for pam_unix (it was never used);
+ set default crypt to blowfish in system-auth.
- Updated console.perms patch.
- Built with db2.
- Merge RH changes (26-->37).
- Added pam_sameuid module.
- Merge last RH changes (by Nalin Dahyabhai <nalin@redhat.com>):
+ clean up logging in pam_xauth;
+ mova README.* files in txt subdirectory;
+ add pam_tally's application to allow counts to be reset;
+ move pam_filter modules to /lib/security/pam_filter;
+ add DRI and nvidia devices to console.perms. - Fixed:
+ pam_stack now passes delay back.
- Added:
+ BSDIcrypt support for pam_unix;
+ pam_limits in system-auth.
- Merge last RH changes (by Nalin Dahyabhai <nalin@redhat.com>):
+ add a broken_shadow option to pam_unix;
+ add all module README files to the documentation list;
+ fix pam_stack debug and losing-track-of-the-result bug;
+ rework pam_console's usage of syslog to actually be sane (#14646);
+ take the LOG_ERR flag off of some of pam_console's new messages. - Merge last MDK changes:
+ set all sound stuff to audio group;
+ add cdburner permissions;
+ add /etc/pam.d/system-auth;
+ noreplace configs.
- Merge with last MDK changes.
- Merge with last RH changes.
- Added: BSDIcrypt support.
- Package split into pam, pam-devel and pam-doc packages
- RE adaptions.
- Fixes:
+ read_string bugfix
+ real buildroot packaging - more documentation included
- Fandra adaptions.
- Fix pam_xauth bug #6191.
- Add a patch to accept 'pts/N' in /etc/securetty as a match for tty '5'
(which is what other pieces of the system think it is). Fixes bug #7641.
- argh, turn off gratuitous debugging
- update to 0.72
- fix pam_unix password-changing bug
- fix pam_unix's cracklib support
- change package URL
- don't allow '/' on service_name
- enhance the pam_userdb module some more
- add documenatation
- a tiny change to pam_console to make it not loose track of console users
- a few fixes to pam_xauth to make it more robust
- pam_console: added <xconsole> to manage /dev/console
- pam_xauth: New refcounting implementation based on idea from Stephen Tweedie
- added video4linux devices to /etc/security/console.perms
- added joystick lines to /etc/security/console.perms
- fixed a couple segfaults in pam_xauth uncovered by yesterday's fix...
- many bug fixes in pam_xauth
- pam_console can now handle broken applications that do not set
the PAM_TTY item.
- use gcc -shared to link the shared libs
- fixed glob/regexp confusion in pam_console, added kbd and fixed fb devices
- added pam_xauth module
- pam_lastlog does wtmp handling now
- added option parsing to pam_console
- added framebuffer devices to default console.perms settings
- fixed empty passwd handling in pam_pwdb
- changed /dev/cdrom default user permissions back to 0600 in console.perms
because some cdrom players open O_RDWR.
- added /dev/jaz and /dev/zip to console.perms
- changed the default user permissions for /dev/cdrom to 0400 in console.perms
- fixed a few bugs in pam_console
- pam_console authentication working
- added /etc/security/console.apps directory
- added pam_console files to filelist
- upgraded to 0.66, some source cleanups
- add patch from Savochkin Andrey Vladimirovich <saw@msu.ru> for umask
security risk
- upgrade to ver 0.65
- build the package out of internal CVS server