/[smeserver]/rpms/e-smith-base+ldap/sme7/e-smith-base+ldap-4.19.1-nss_policy-post_install-ssl_fix.patch
ViewVC logotype

Contents of /rpms/e-smith-base+ldap/sme7/e-smith-base+ldap-4.19.1-nss_policy-post_install-ssl_fix.patch

Parent Directory Parent Directory | Revision Log Revision Log | View Revision Graph Revision Graph


Revision 1.1 - (show annotations) (download)
Wed Apr 2 18:34:17 2008 UTC (16 years, 3 months ago) by slords
Branch: MAIN
CVS Tags: e-smith-base+ldap-4_19_1-7_el4_sme, e-smith-base+ldap-4_19_1-30_el4_sme, e-smith-base+ldap-4_19_1-18_el4_sme, e-smith-base+ldap-4_19_1-28_el4_sme, e-smith-base+ldap-4_19_1-13_el4_sme, e-smith-base+ldap-4_19_1-19_el4_sme, e-smith-base+ldap-4_19_1-20_el4_sme, e-smith-base+ldap-4_19_1-23_el4_sme, e-smith-base+ldap-4_19_1-12_el4_sme, e-smith-base+ldap-4_19_1-14_el4_sme, e-smith-base+ldap-4_19_1-9_el4_sme, e-smith-base+ldap-4_19_1-10_el4_sme, e-smith-base+ldap-4_19_1-24_el4_sme, e-smith-base+ldap-4_19_1-22_el4_sme, e-smith-base+ldap-4_19_1-8_el4_sme, e-smith-base+ldap-4_19_1-6_el4_sme, e-smith-base+ldap-4_19_1-26_el4_sme, e-smith-base+ldap-4_19_1-16_el4_sme, e-smith-base+ldap-4_19_1-21_el4_sme, e-smith-base+ldap-4_19_1-25_el4_sme, e-smith-base+ldap-4_19_1-29_el4_sme, e-smith-base+ldap-4_19_1-11_el4_sme, e-smith-base+ldap-4_19_1-17_el4_sme
* Wed Apr 2 2008 Sebastien F. <sebast@firewall-services.com> 4.19.1-6
- Set nss "bind_policy" to "soft" to be able to access to
  /etc/{passwd,groups,shadow} informations when ldap is down.
- Set /etc/openldap/ldap.conf host to "localhost" and remove unnecessary
  use of SSL. [SME: 1543].
- Cleanly handle need of ldap directory generation after e-smith-base+ldap
  package: add prop "generateDb" to ldap key and modify /var/service/ldap/run.

1 diff -Nur -x '*.orig' -x '*.rej' e-smith-base+ldap-4.19.1/root/etc/e-smith/db/configuration/defaults/ldap/generateDb mezzanine_patched_e-smith-base+ldap-4.19.1/root/etc/e-smith/db/configuration/defaults/ldap/generateDb
2 --- e-smith-base+ldap-4.19.1/root/etc/e-smith/db/configuration/defaults/ldap/generateDb 1969-12-31 17:00:00.000000000 -0700
3 +++ mezzanine_patched_e-smith-base+ldap-4.19.1/root/etc/e-smith/db/configuration/defaults/ldap/generateDb 2008-04-02 10:43:54.000000000 -0600
4 @@ -0,0 +1 @@
5 +yes
6 diff -Nur -x '*.orig' -x '*.rej' e-smith-base+ldap-4.19.1/root/etc/e-smith/templates/etc/ldap.conf/55bind_policy mezzanine_patched_e-smith-base+ldap-4.19.1/root/etc/e-smith/templates/etc/ldap.conf/55bind_policy
7 --- e-smith-base+ldap-4.19.1/root/etc/e-smith/templates/etc/ldap.conf/55bind_policy 1969-12-31 17:00:00.000000000 -0700
8 +++ mezzanine_patched_e-smith-base+ldap-4.19.1/root/etc/e-smith/templates/etc/ldap.conf/55bind_policy 2008-04-02 10:43:54.000000000 -0600
9 @@ -0,0 +1,2 @@
10 +# Allow read /etc/{passwd,groups,shadow} files when ldap is down.
11 +bind_policy soft
12 diff -Nur -x '*.orig' -x '*.rej' e-smith-base+ldap-4.19.1/root/etc/e-smith/templates/etc/ldap.conf/55initgroups_ignoreusers mezzanine_patched_e-smith-base+ldap-4.19.1/root/etc/e-smith/templates/etc/ldap.conf/55initgroups_ignoreusers
13 --- e-smith-base+ldap-4.19.1/root/etc/e-smith/templates/etc/ldap.conf/55initgroups_ignoreusers 2008-04-02 10:45:15.000000000 -0600
14 +++ mezzanine_patched_e-smith-base+ldap-4.19.1/root/etc/e-smith/templates/etc/ldap.conf/55initgroups_ignoreusers 1969-12-31 17:00:00.000000000 -0700
15 @@ -1 +0,0 @@
16 -nss_initgroups_ignoreusers ldap
17 diff -Nur -x '*.orig' -x '*.rej' e-smith-base+ldap-4.19.1/root/etc/e-smith/templates/etc/openldap/ldap.conf/12tls mezzanine_patched_e-smith-base+ldap-4.19.1/root/etc/e-smith/templates/etc/openldap/ldap.conf/12tls
18 --- e-smith-base+ldap-4.19.1/root/etc/e-smith/templates/etc/openldap/ldap.conf/12tls 2008-04-02 10:45:15.000000000 -0600
19 +++ mezzanine_patched_e-smith-base+ldap-4.19.1/root/etc/e-smith/templates/etc/openldap/ldap.conf/12tls 1969-12-31 17:00:00.000000000 -0700
20 @@ -1,3 +0,0 @@
21 -TLS_CACERT /var/service/ldap/ssl/slapd.pem
22 -TLS_REQCERT always
23 -TLS_CIPHER_SUITE HIGH:MEDIUM:+SSLv2
24 diff -Nur -x '*.orig' -x '*.rej' e-smith-base+ldap-4.19.1/root/var/service/ldap/run mezzanine_patched_e-smith-base+ldap-4.19.1/root/var/service/ldap/run
25 --- e-smith-base+ldap-4.19.1/root/var/service/ldap/run 2008-04-02 10:45:17.000000000 -0600
26 +++ mezzanine_patched_e-smith-base+ldap-4.19.1/root/var/service/ldap/run 2008-04-02 10:43:59.000000000 -0600
27 @@ -2,6 +2,7 @@
28
29 domain=$(/sbin/e-smith/config get DomainName)
30 system=$(/sbin/e-smith/config get SystemName)
31 +generatedb=$(/sbin/e-smith/config getprop ldap generateDb)
32 ldif="/home/e-smith/db/ldap/$domain.ldif"
33
34 ./control/1
35 @@ -18,6 +19,14 @@
36 fi
37 fi
38
39 +# Ldap authentication post install
40 +if [ "$generatedb" == "yes" ]
41 +then
42 + find /var/lib/ldap -type f | xargs -i mv "{}" "{}.old"
43 + rm -f "$old_ldif" "$ldif"
44 + /sbin/e-smith/config setprop ldap generateDb no
45 +fi
46 +
47 # Set up symlink for ldap dump at shutdown
48 ln -sf $ldif ./ldif
49

admin@koozali.org
ViewVC Help
Powered by ViewVC 1.2.1 RSS 2.0 feed