1*c19800e8SDoug Rabson2008-08-14  Love Hornquist Astrand  <[email protected]>
21c43270aSJacques Vidrine
3*c19800e8SDoug Rabson	* krb5/accept_sec_context.c: If there is a initiator subkey, copy
4*c19800e8SDoug Rabson	that to acceptor subkey to match windows behavior. From Metze.
5*c19800e8SDoug Rabson
6*c19800e8SDoug Rabson2008-08-02  Love Hörnquist Åstrand  <[email protected]>
7*c19800e8SDoug Rabson
8*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: Catch error
9*c19800e8SDoug Rabson
10*c19800e8SDoug Rabson	* krb5/inquire_sec_context_by_oid.c: Catch store failure.
11*c19800e8SDoug Rabson
12*c19800e8SDoug Rabson	* mech/gss_canonicalize_name.c: Not init m, return never
13*c19800e8SDoug Rabson	used (overwritten later).
14*c19800e8SDoug Rabson
15*c19800e8SDoug Rabson2008-07-25  Love Hörnquist Åstrand  <[email protected]>
16*c19800e8SDoug Rabson
17*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: Use krb5_cc_get_config.
18*c19800e8SDoug Rabson
19*c19800e8SDoug Rabson2008-07-25  Love Hörnquist Åstrand  <[email protected]>
20*c19800e8SDoug Rabson
21*c19800e8SDoug Rabson	* krb5/init_sec_context.c: Match the orignal patch I got from
22*c19800e8SDoug Rabson	metze, seems that DCE-STYLE is even more weirer then what I though
23*c19800e8SDoug Rabson	when I merged the patch.
24*c19800e8SDoug Rabson
25*c19800e8SDoug Rabson2008-06-02  Love Hörnquist Åstrand  <[email protected]>
26*c19800e8SDoug Rabson
27*c19800e8SDoug Rabson	* krb5/init_sec_context.c: Don't add asn1 wrapping to token when
28*c19800e8SDoug Rabson	using DCE_STYLE.  Patch from Stefan Metzmacher.
29*c19800e8SDoug Rabson
30*c19800e8SDoug Rabson2008-05-27  Love Hörnquist Åstrand  <[email protected]>
31*c19800e8SDoug Rabson
32*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: use krb5_get_error_message
33*c19800e8SDoug Rabson
34*c19800e8SDoug Rabson2008-05-05  Love Hörnquist Åstrand  <[email protected]>
35*c19800e8SDoug Rabson
36*c19800e8SDoug Rabson	* spnego/spnego_locl.h: Add back "mech/utils.h", its needed for
37*c19800e8SDoug Rabson	oid/buffer functions.
38*c19800e8SDoug Rabson
39*c19800e8SDoug Rabson2008-05-02  Love Hörnquist Åstrand  <[email protected]>
40*c19800e8SDoug Rabson
41*c19800e8SDoug Rabson	* spnego: Changes from doug barton to make spnego indepedant of
42*c19800e8SDoug Rabson	the heimdal version of the plugin system.
43*c19800e8SDoug Rabson
44*c19800e8SDoug Rabson2008-04-27  Love Hörnquist Åstrand  <[email protected]>
45*c19800e8SDoug Rabson
46*c19800e8SDoug Rabson	* krb5: use DES_set_key_unchecked()
47*c19800e8SDoug Rabson
48*c19800e8SDoug Rabson2008-04-17  Love Hörnquist Åstrand  <[email protected]>
49*c19800e8SDoug Rabson
50*c19800e8SDoug Rabson	* add __declspec() for windows.
51*c19800e8SDoug Rabson
52*c19800e8SDoug Rabson2008-04-15  Love Hörnquist Åstrand  <[email protected]>
53*c19800e8SDoug Rabson
54*c19800e8SDoug Rabson	* krb5/import_sec_context.c: Use tmp to read ac->flags value to
55*c19800e8SDoug Rabson	avoid warning.
56*c19800e8SDoug Rabson
57*c19800e8SDoug Rabson2008-04-07  Love Hörnquist Åstrand  <[email protected]>
58*c19800e8SDoug Rabson
59*c19800e8SDoug Rabson	* mech/gss_mech_switch.c: Use unsigned where appropriate.
60*c19800e8SDoug Rabson
61*c19800e8SDoug Rabson2008-03-14  Love Hörnquist Åstrand  <[email protected]>
62*c19800e8SDoug Rabson
63*c19800e8SDoug Rabson	* test_context.c: Add test for gsskrb5_register_acceptor_identity.
64*c19800e8SDoug Rabson
65*c19800e8SDoug Rabson2008-03-09  Love Hörnquist Åstrand  <[email protected]>
66*c19800e8SDoug Rabson
67*c19800e8SDoug Rabson	* krb5/init_sec_context.c (init_auth): use right variable to
68*c19800e8SDoug Rabson	detect if we want to free or not.
69*c19800e8SDoug Rabson
70*c19800e8SDoug Rabson2008-02-26  Love Hörnquist Åstrand  <[email protected]>
71*c19800e8SDoug Rabson
72*c19800e8SDoug Rabson	* Makefile.am: add missing \
73*c19800e8SDoug Rabson
74*c19800e8SDoug Rabson	* Makefile.am: reshuffle depenencies
75*c19800e8SDoug Rabson
76*c19800e8SDoug Rabson	* Add flag to krb5 to not add GSS-API INT|CONF to the negotiation
77*c19800e8SDoug Rabson
78*c19800e8SDoug Rabson2008-02-21  Love Hörnquist Åstrand  <[email protected]>
79*c19800e8SDoug Rabson
80*c19800e8SDoug Rabson	* make the SPNEGO mech store the error itself instead, works for
81*c19800e8SDoug Rabson	everything except other stackable mechs
82*c19800e8SDoug Rabson
83*c19800e8SDoug Rabson2008-02-18  Love Hörnquist Åstrand  <[email protected]>
84*c19800e8SDoug Rabson
85*c19800e8SDoug Rabson	* spnego/init_sec_context.c (spnego_reply): if the reply token was
86*c19800e8SDoug Rabson	of length 0, make it the same as no token. Pointed out by Zeqing
87*c19800e8SDoug Rabson	Xia.
88*c19800e8SDoug Rabson
89*c19800e8SDoug Rabson	* krb5/acquire_cred.c (acquire_initiator_cred): handle the
90*c19800e8SDoug Rabson	credential cache better, use destroy/close when appriate and for
91*c19800e8SDoug Rabson	all cases. Thanks to Michael Allen for point out the memory-leak
92*c19800e8SDoug Rabson	that I also fixed.
93*c19800e8SDoug Rabson
94*c19800e8SDoug Rabson2008-02-03  Love Hörnquist Åstrand  <[email protected]>
95*c19800e8SDoug Rabson
96*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Make error reporting somewhat more
97*c19800e8SDoug Rabson	correct for SPNEGO.
98*c19800e8SDoug Rabson
99*c19800e8SDoug Rabson2008-01-27  Love Hörnquist Åstrand  <[email protected]>
100*c19800e8SDoug Rabson
101*c19800e8SDoug Rabson	* test_common.c: Improve the error message.
102*c19800e8SDoug Rabson
103*c19800e8SDoug Rabson2008-01-24  Love Hörnquist Åstrand  <[email protected]>
104*c19800e8SDoug Rabson
105*c19800e8SDoug Rabson	* ntlm/accept_sec_context.c: Avoid free-ing type1 message before
106*c19800e8SDoug Rabson	its allocated.
107*c19800e8SDoug Rabson
108*c19800e8SDoug Rabson2008-01-13  Love Hörnquist Åstrand  <[email protected]>
109*c19800e8SDoug Rabson
110*c19800e8SDoug Rabson	* test_ntlm.c: Test source name (and make the acceptor in ntlm gss
111*c19800e8SDoug Rabson	mech useful).
112*c19800e8SDoug Rabson
113*c19800e8SDoug Rabson2007-12-30  Love Hörnquist Åstrand  <[email protected]>
114*c19800e8SDoug Rabson
115*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: Don't confuse target name and source
116*c19800e8SDoug Rabson	name, make regressiont tests pass again.
117*c19800e8SDoug Rabson
118*c19800e8SDoug Rabson2007-12-29  Love Hörnquist Åstrand  <[email protected]>
119*c19800e8SDoug Rabson
120*c19800e8SDoug Rabson	* ntlm: clean up name handling
121*c19800e8SDoug Rabson
122*c19800e8SDoug Rabson2007-12-04  Love Hörnquist Åstrand  <[email protected]>
123*c19800e8SDoug Rabson
124*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: Use credential if it was passed in.
125*c19800e8SDoug Rabson
126*c19800e8SDoug Rabson	* ntlm/acquire_cred.c: Check if there is initial creds with
127*c19800e8SDoug Rabson	_gss_ntlm_get_user_cred().
128*c19800e8SDoug Rabson
129*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: Add _gss_ntlm_get_user_info() that
130*c19800e8SDoug Rabson	return the user info so it can be used by external modules.
131*c19800e8SDoug Rabson
132*c19800e8SDoug Rabson	* ntlm/inquire_cred.c: use the right error code.
133*c19800e8SDoug Rabson
134*c19800e8SDoug Rabson	* ntlm/inquire_cred.c: Return GSS_C_NO_CREDENTIAL if there is no
135*c19800e8SDoug Rabson	credential, ntlm have (not yet) a default credential.
136*c19800e8SDoug Rabson
137*c19800e8SDoug Rabson	* mech/gss_release_oid_set.c: Avoid trying to deref NULL, from
138*c19800e8SDoug Rabson	Phil Fisher.
139*c19800e8SDoug Rabson
140*c19800e8SDoug Rabson2007-12-03  Love Hörnquist Åstrand  <[email protected]>
141*c19800e8SDoug Rabson
142*c19800e8SDoug Rabson	* test_acquire_cred.c: Always try to fetch cred (even with
143*c19800e8SDoug Rabson	GSS_C_NO_NAME).
144*c19800e8SDoug Rabson
145*c19800e8SDoug Rabson2007-08-09  Love Hörnquist Åstrand  <[email protected]>
146*c19800e8SDoug Rabson
147*c19800e8SDoug Rabson	* mech/gss_krb5.c: Readd gss_krb5_get_tkt_flags.
148*c19800e8SDoug Rabson
149*c19800e8SDoug Rabson2007-08-08  Love Hörnquist Åstrand  <[email protected]>
150*c19800e8SDoug Rabson
151*c19800e8SDoug Rabson	* spnego/compat.c (_gss_spnego_internal_delete_sec_context):
152*c19800e8SDoug Rabson	release ctx->target_name too From Rafal Malinowski.
153*c19800e8SDoug Rabson
154*c19800e8SDoug Rabson2007-07-26  Love Hörnquist Åstrand  <[email protected]>
155*c19800e8SDoug Rabson
156*c19800e8SDoug Rabson	* mech/gss_mech_switch.c: Don't try to do dlopen if system doesn't
157*c19800e8SDoug Rabson	have dlopen. From Rune of Chalmers.
158*c19800e8SDoug Rabson
159*c19800e8SDoug Rabson2007-07-10  Love Hörnquist Åstrand  <[email protected]>
160*c19800e8SDoug Rabson
161*c19800e8SDoug Rabson	* mech/gss_duplicate_name.c: New signature of _gss_find_mn.
162*c19800e8SDoug Rabson
163*c19800e8SDoug Rabson	* mech/gss_init_sec_context.c: New signature of _gss_find_mn.
164*c19800e8SDoug Rabson
165*c19800e8SDoug Rabson	* mech/gss_acquire_cred.c: New signature of _gss_find_mn.
166*c19800e8SDoug Rabson
167*c19800e8SDoug Rabson	* mech/name.h: New signature of _gss_find_mn.
168*c19800e8SDoug Rabson
169*c19800e8SDoug Rabson	* mech/gss_canonicalize_name.c: New signature of _gss_find_mn.
170*c19800e8SDoug Rabson
171*c19800e8SDoug Rabson	* mech/gss_compare_name.c: New signature of _gss_find_mn.
172*c19800e8SDoug Rabson
173*c19800e8SDoug Rabson	* mech/gss_add_cred.c: New signature of _gss_find_mn.
174*c19800e8SDoug Rabson
175*c19800e8SDoug Rabson	* mech/gss_names.c (_gss_find_mn): Return an error code for
176*c19800e8SDoug Rabson	caller.
177*c19800e8SDoug Rabson
178*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: remove checks that are done by the
179*c19800e8SDoug Rabson	previous function.
180*c19800e8SDoug Rabson
181*c19800e8SDoug Rabson	* Makefile.am: New library version.
182*c19800e8SDoug Rabson
183*c19800e8SDoug Rabson2007-07-04  Love Hörnquist Åstrand  <[email protected]>
184*c19800e8SDoug Rabson
185*c19800e8SDoug Rabson	* mech/gss_oid_to_str.c: Refuse to print GSS_C_NULL_OID, from
186*c19800e8SDoug Rabson	Rafal Malinowski.
187*c19800e8SDoug Rabson
188*c19800e8SDoug Rabson	* spnego/spnego.asn1: Indent and make NegTokenInit and
189*c19800e8SDoug Rabson	NegTokenResp extendable.
190*c19800e8SDoug Rabson
191*c19800e8SDoug Rabson2007-06-21  Love Hörnquist Åstrand  <[email protected]>
192*c19800e8SDoug Rabson
193*c19800e8SDoug Rabson	* ntlm/inquire_cred.c: Implement _gss_ntlm_inquire_cred.
194*c19800e8SDoug Rabson
195*c19800e8SDoug Rabson	* mech/gss_display_status.c: Provide message for GSS_S_COMPLETE.
196*c19800e8SDoug Rabson
197*c19800e8SDoug Rabson	* mech/context.c: If the canned string is "", its no use to the
198*c19800e8SDoug Rabson	user, make it fall back to the default error string.
199*c19800e8SDoug Rabson
200*c19800e8SDoug Rabson2007-06-20  Love Hörnquist Åstrand  <[email protected]>
201*c19800e8SDoug Rabson
202*c19800e8SDoug Rabson	* mech/gss_display_name.c (gss_display_name): no name ->
203*c19800e8SDoug Rabson	fail. From Rafal Malinswski.
204*c19800e8SDoug Rabson
205*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Wrap name in a spnego_name instead
206*c19800e8SDoug Rabson	of just a copy of the underlaying object. From Rafal Malinswski.
207*c19800e8SDoug Rabson
208*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Handle underlaying mech not
209*c19800e8SDoug Rabson	returning mn.
210*c19800e8SDoug Rabson
211*c19800e8SDoug Rabson	* mech/gss_accept_sec_context.c: Handle underlaying mech not
212*c19800e8SDoug Rabson	returning mn.
213*c19800e8SDoug Rabson
214*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Make sure src_name is always set to
215*c19800e8SDoug Rabson	GSS_C_NO_NAME when returning.
216*c19800e8SDoug Rabson
217*c19800e8SDoug Rabson	* krb5/acquire_cred.c (acquire_acceptor_cred): don't claim
218*c19800e8SDoug Rabson	everything is well on failure.  From Phil Fisher.
219*c19800e8SDoug Rabson
220*c19800e8SDoug Rabson	* mech/gss_duplicate_name.c: catch error (and ignore it)
221*c19800e8SDoug Rabson
222*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: Use heim_ntlm_calculate_ntlm2_sess.
223*c19800e8SDoug Rabson
224*c19800e8SDoug Rabson	* mech/gss_accept_sec_context.c: Only wrap the delegated cred if
225*c19800e8SDoug Rabson	we got a delegated mech cred.  From Rafal Malinowski.
226*c19800e8SDoug Rabson
227*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Only wrap the delegated cred if we
228*c19800e8SDoug Rabson	are going to return it to the consumer.  From Rafal Malinowski.
229*c19800e8SDoug Rabson
230*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Fixed memory leak pointed out by
231*c19800e8SDoug Rabson	Rafal Malinowski, also while here moved to use NegotiationToken
232*c19800e8SDoug Rabson	for decoding.
233*c19800e8SDoug Rabson
234*c19800e8SDoug Rabson2007-06-18  Love Hörnquist Åstrand  <[email protected]>
235*c19800e8SDoug Rabson
236*c19800e8SDoug Rabson	* krb5/prf.c (_gsskrb5_pseudo_random): add missing break.
237*c19800e8SDoug Rabson
238*c19800e8SDoug Rabson	* krb5/release_name.c: Set *minor_status unconditionallty, its
239*c19800e8SDoug Rabson	done later anyway.
240*c19800e8SDoug Rabson
241*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Init get_mic to 0.
242*c19800e8SDoug Rabson
243*c19800e8SDoug Rabson	* mech/gss_set_cred_option.c: Free memory in failure case, found
244*c19800e8SDoug Rabson	by beam.
245*c19800e8SDoug Rabson
246*c19800e8SDoug Rabson	* mech/gss_inquire_context.c: Handle mech_type being NULL.
247*c19800e8SDoug Rabson
248*c19800e8SDoug Rabson	* mech/gss_inquire_cred_by_mech.c: Handle cred_name being NULL.
249*c19800e8SDoug Rabson
250*c19800e8SDoug Rabson	* mech/gss_krb5.c: Free memory in error case, found by beam.
251*c19800e8SDoug Rabson
252*c19800e8SDoug Rabson2007-06-12  Love Hörnquist Åstrand  <[email protected]>
253*c19800e8SDoug Rabson
254*c19800e8SDoug Rabson	* ntlm/inquire_context.c: Use ctx->gssflags for flags.
255*c19800e8SDoug Rabson
256*c19800e8SDoug Rabson	* krb5/display_name.c: Use KRB5_PRINCIPAL_UNPARSE_DISPLAY, this is
257*c19800e8SDoug Rabson	not ment for machine consumption.
258*c19800e8SDoug Rabson
259*c19800e8SDoug Rabson2007-06-09  Love Hörnquist Åstrand  <[email protected]>
260*c19800e8SDoug Rabson
261*c19800e8SDoug Rabson	* ntlm/digest.c (kdc_alloc): free memory on failure, pointed out
262*c19800e8SDoug Rabson	by Rafal Malinowski.
263*c19800e8SDoug Rabson
264*c19800e8SDoug Rabson	* ntlm/digest.c (kdc_destroy): free context when done, pointed out
265*c19800e8SDoug Rabson	by Rafal Malinowski.
266*c19800e8SDoug Rabson
267*c19800e8SDoug Rabson	* spnego/context_stubs.c (_gss_spnego_display_name): if input_name
268*c19800e8SDoug Rabson	is null, fail.  From Rafal Malinowski.
269*c19800e8SDoug Rabson
270*c19800e8SDoug Rabson2007-06-04  Love Hörnquist Åstrand  <[email protected]>
271*c19800e8SDoug Rabson
272*c19800e8SDoug Rabson	* ntlm/digest.c: Free memory when done.
273*c19800e8SDoug Rabson
274*c19800e8SDoug Rabson2007-06-02  Love Hörnquist Åstrand  <[email protected]>
275*c19800e8SDoug Rabson
276*c19800e8SDoug Rabson	* test_ntlm.c: Test both with and without keyex.
277*c19800e8SDoug Rabson
278*c19800e8SDoug Rabson	* ntlm/digest.c: If we didn't set session key, don't expect one
279*c19800e8SDoug Rabson	back.
280*c19800e8SDoug Rabson
281*c19800e8SDoug Rabson	* test_ntlm.c: Set keyex flag and calculate session key.
282*c19800e8SDoug Rabson
283*c19800e8SDoug Rabson2007-05-31  Love Hörnquist Åstrand  <[email protected]>
284*c19800e8SDoug Rabson
285*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Use the return value before is
286*c19800e8SDoug Rabson	overwritten by later calls.  From Rafal Malinowski
287*c19800e8SDoug Rabson
288*c19800e8SDoug Rabson	* krb5/release_cred.c: Give an minor_status argument to
289*c19800e8SDoug Rabson	gss_release_oid_set.  From Rafal Malinowski
290*c19800e8SDoug Rabson
291*c19800e8SDoug Rabson2007-05-30  Love Hörnquist Åstrand  <[email protected]>
292*c19800e8SDoug Rabson
293*c19800e8SDoug Rabson	* ntlm/accept_sec_context.c: Catch errors and return the up the
294*c19800e8SDoug Rabson	stack.
295*c19800e8SDoug Rabson
296*c19800e8SDoug Rabson	* test_kcred.c: more testing of lifetimes
297*c19800e8SDoug Rabson
298*c19800e8SDoug Rabson2007-05-17  Love Hörnquist Åstrand  <[email protected]>
299*c19800e8SDoug Rabson
300*c19800e8SDoug Rabson	* Makefile.am: Drop the gss oid_set function for the krb5 mech,
301*c19800e8SDoug Rabson	use the mech glue versions instead. Pointed out by Rafal
302*c19800e8SDoug Rabson	Malinowski.
303*c19800e8SDoug Rabson
304*c19800e8SDoug Rabson	* krb5: Use gss oid_set functions from mechglue
305*c19800e8SDoug Rabson
306*c19800e8SDoug Rabson2007-05-14  Love Hörnquist Åstrand  <[email protected]>
307*c19800e8SDoug Rabson
308*c19800e8SDoug Rabson	* ntlm/accept_sec_context.c: Set session key only if we are
309*c19800e8SDoug Rabson	returned a session key. Found by David Love.
310*c19800e8SDoug Rabson
311*c19800e8SDoug Rabson2007-05-13  Love Hörnquist Åstrand  <[email protected]>
312*c19800e8SDoug Rabson
313*c19800e8SDoug Rabson	* krb5/prf.c: switched MIN to min to make compile on solaris,
314*c19800e8SDoug Rabson	pointed out by David Love.
315*c19800e8SDoug Rabson
316*c19800e8SDoug Rabson2007-05-09 Love Hörnquist Åstrand <[email protected]>
317*c19800e8SDoug Rabson
318*c19800e8SDoug Rabson	* krb5/inquire_cred_by_mech.c: Fill in all of the variables if
319*c19800e8SDoug Rabson	they are passed in. Pointed out by Phil Fisher.
320*c19800e8SDoug Rabson
321*c19800e8SDoug Rabson2007-05-08  Love Hörnquist Åstrand  <[email protected]>
322*c19800e8SDoug Rabson
323*c19800e8SDoug Rabson	* krb5/inquire_cred.c: Fix copy and paste error, bug spotted by
324*c19800e8SDoug Rabson	from Phil Fisher.
325*c19800e8SDoug Rabson
326*c19800e8SDoug Rabson	* mech: dont keep track of gc_usage, just figure it out at
327*c19800e8SDoug Rabson	gss_inquire_cred() time
328*c19800e8SDoug Rabson
329*c19800e8SDoug Rabson	* mech/gss_mech_switch.c (add_builtin): ok for
330*c19800e8SDoug Rabson	__gss_mech_initialize() to return NULL
331*c19800e8SDoug Rabson
332*c19800e8SDoug Rabson	* test_kcred.c: more correct tests
333*c19800e8SDoug Rabson
334*c19800e8SDoug Rabson	* spnego/cred_stubs.c (gss_inquire_cred*): wrap the name with a
335*c19800e8SDoug Rabson	spnego_name.
336*c19800e8SDoug Rabson
337*c19800e8SDoug Rabson	* ntlm/inquire_cred.c: make ntlm gss_inquire_cred fail for now,
338*c19800e8SDoug Rabson	need to find default cred and friends.
339*c19800e8SDoug Rabson
340*c19800e8SDoug Rabson	* krb5/inquire_cred_by_mech.c: reimplement
341*c19800e8SDoug Rabson
342*c19800e8SDoug Rabson2007-05-07  Love Hörnquist Åstrand  <[email protected]>
343*c19800e8SDoug Rabson
344*c19800e8SDoug Rabson	* ntlm/acquire_cred.c: drop unused variable.
345*c19800e8SDoug Rabson
346*c19800e8SDoug Rabson	* ntlm/acquire_cred.c: Reimplement.
347*c19800e8SDoug Rabson
348*c19800e8SDoug Rabson	* Makefile.am: add ntlm/digest.c
349*c19800e8SDoug Rabson
350*c19800e8SDoug Rabson	* ntlm: split out backend ntlm server processing
351*c19800e8SDoug Rabson
352*c19800e8SDoug Rabson2007-04-24  Love Hörnquist Åstrand  <[email protected]>
353*c19800e8SDoug Rabson
354*c19800e8SDoug Rabson	* ntlm/delete_sec_context.c (_gss_ntlm_delete_sec_context): free
355*c19800e8SDoug Rabson	credcache when done
356*c19800e8SDoug Rabson
357*c19800e8SDoug Rabson2007-04-22  Love Hörnquist Åstrand  <[email protected]>
358*c19800e8SDoug Rabson
359*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: ntlm-key credential entry is prefix with @
360*c19800e8SDoug Rabson
361*c19800e8SDoug Rabson	* ntlm/init_sec_context.c (get_user_ccache): pick up the ntlm
362*c19800e8SDoug Rabson	creds from the krb5 credential cache.
363*c19800e8SDoug Rabson
364*c19800e8SDoug Rabson2007-04-21  Love Hörnquist Åstrand  <[email protected]>
365*c19800e8SDoug Rabson
366*c19800e8SDoug Rabson	* ntlm/delete_sec_context.c: free the key stored in the context
367*c19800e8SDoug Rabson
368*c19800e8SDoug Rabson	* ntlm/ntlm.h: switch password for a key
369*c19800e8SDoug Rabson
370*c19800e8SDoug Rabson	* test_oid.c: Switch oid to one that is exported.
371*c19800e8SDoug Rabson
372*c19800e8SDoug Rabson2007-04-20  Love Hörnquist Åstrand  <[email protected]>
373*c19800e8SDoug Rabson
374*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: move where hash is calculated to make
375*c19800e8SDoug Rabson	it easier to add ccache support.
376*c19800e8SDoug Rabson
377*c19800e8SDoug Rabson	* Makefile.am: Add version-script.map to EXTRA_DIST.
378*c19800e8SDoug Rabson
379*c19800e8SDoug Rabson2007-04-19  Love Hörnquist Åstrand  <[email protected]>
380*c19800e8SDoug Rabson
381*c19800e8SDoug Rabson	* Makefile.am: Unconfuse newer versions of automake that doesn't
382*c19800e8SDoug Rabson	know the diffrence between depenences and setting variables. foo:
383*c19800e8SDoug Rabson	vs foo=.
384*c19800e8SDoug Rabson
385*c19800e8SDoug Rabson	* test_ntlm.c: delete sec context when done.
386*c19800e8SDoug Rabson
387*c19800e8SDoug Rabson	* version-script.map: export more symbols.
388*c19800e8SDoug Rabson
389*c19800e8SDoug Rabson	* Makefile.am: add version script if ld supports it
390*c19800e8SDoug Rabson
391*c19800e8SDoug Rabson	* version-script.map: add version script if ld supports it
392*c19800e8SDoug Rabson
393*c19800e8SDoug Rabson2007-04-18  Love Hörnquist Åstrand  <[email protected]>
394*c19800e8SDoug Rabson
395*c19800e8SDoug Rabson	* Makefile.am: test_acquire_cred need test_common.[ch]
396*c19800e8SDoug Rabson
397*c19800e8SDoug Rabson	* test_acquire_cred.c: add more test options.
398*c19800e8SDoug Rabson
399*c19800e8SDoug Rabson	* krb5/external.c: add GSS_KRB5_CCACHE_NAME_X
400*c19800e8SDoug Rabson
401*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: add GSS_KRB5_CCACHE_NAME_X
402*c19800e8SDoug Rabson
403*c19800e8SDoug Rabson	* krb5/set_sec_context_option.c: refactor code, implement
404*c19800e8SDoug Rabson	GSS_KRB5_CCACHE_NAME_X
405*c19800e8SDoug Rabson
406*c19800e8SDoug Rabson	* mech/gss_krb5.c: reimplement gss_krb5_ccache_name
407*c19800e8SDoug Rabson
408*c19800e8SDoug Rabson2007-04-17  Love Hörnquist Åstrand <[email protected]>
409*c19800e8SDoug Rabson
410*c19800e8SDoug Rabson	* spnego/cred_stubs.c: Need to import spnego name before we can
411*c19800e8SDoug Rabson	use it as a gss_name_t.
412*c19800e8SDoug Rabson
413*c19800e8SDoug Rabson	* test_acquire_cred.c: use this test as part of the regression
414*c19800e8SDoug Rabson	suite.
415*c19800e8SDoug Rabson
416*c19800e8SDoug Rabson	* mech/gss_acquire_cred.c (gss_acquire_cred): dont init
417*c19800e8SDoug Rabson	cred->gc_mc every time in the loop.
418*c19800e8SDoug Rabson
419*c19800e8SDoug Rabson2007-04-15  Love Hörnquist Åstrand  <[email protected]>
420*c19800e8SDoug Rabson
421*c19800e8SDoug Rabson	* Makefile.am: add test_common.h
422*c19800e8SDoug Rabson
423*c19800e8SDoug Rabson2007-02-16  Love Hörnquist Åstrand  <[email protected]>
424*c19800e8SDoug Rabson
425*c19800e8SDoug Rabson	* gss_acquire_cred.3: Add link for
426*c19800e8SDoug Rabson	gsskrb5_register_acceptor_identity.
427*c19800e8SDoug Rabson
428*c19800e8SDoug Rabson2007-02-08  Love Hörnquist Åstrand  <[email protected]>
429*c19800e8SDoug Rabson
430*c19800e8SDoug Rabson	* krb5/copy_ccache.c: Try to leak less memory in the failure case.
431*c19800e8SDoug Rabson
432*c19800e8SDoug Rabson2007-01-31  Love Hörnquist Åstrand  <[email protected]>
433*c19800e8SDoug Rabson
434*c19800e8SDoug Rabson	* mech/gss_display_status.c: Use right printf formater.
435*c19800e8SDoug Rabson
436*c19800e8SDoug Rabson	* test_*.[ch]: split out the error printing function and try to
437*c19800e8SDoug Rabson	return better errors
438*c19800e8SDoug Rabson
439*c19800e8SDoug Rabson2007-01-30  Love Hörnquist Åstrand  <[email protected]>
440*c19800e8SDoug Rabson
441*c19800e8SDoug Rabson	* krb5/init_sec_context.c: revert 1.75: (init_auth): only turn on
442*c19800e8SDoug Rabson	GSS_C_CONF_FLAG and GSS_C_INT_FLAG if the caller requseted it.
443*c19800e8SDoug Rabson
444*c19800e8SDoug Rabson	This is because Kerberos always support INT|CONF, matches behavior
445*c19800e8SDoug Rabson	with MS and MIT. The creates problems for the GSS-SPNEGO mech.
446*c19800e8SDoug Rabson
447*c19800e8SDoug Rabson2007-01-24  Love Hörnquist Åstrand  <[email protected]>
448*c19800e8SDoug Rabson
449*c19800e8SDoug Rabson	* krb5/prf.c: constrain desired_output_len
450*c19800e8SDoug Rabson
451*c19800e8SDoug Rabson	* krb5/external.c (krb5_mech): add _gsskrb5_pseudo_random
452*c19800e8SDoug Rabson
453*c19800e8SDoug Rabson	* mech/gss_pseudo_random.c: Catch error from underlaying mech on
454*c19800e8SDoug Rabson	failure.
455*c19800e8SDoug Rabson
456*c19800e8SDoug Rabson	* Makefile.am: Add krb5/prf.c
457*c19800e8SDoug Rabson
458*c19800e8SDoug Rabson	* krb5/prf.c: gss_pseudo_random for krb5
459*c19800e8SDoug Rabson
460*c19800e8SDoug Rabson	* test_context.c: Checks for gss_pseudo_random.
461*c19800e8SDoug Rabson
462*c19800e8SDoug Rabson	* krb5/gkrb5_err.et: add KG_INPUT_TOO_LONG
463*c19800e8SDoug Rabson
464*c19800e8SDoug Rabson	* Makefile.am: Add mech/gss_pseudo_random.c
465*c19800e8SDoug Rabson
466*c19800e8SDoug Rabson	* gssapi/gssapi.h: try to load pseudo_random
467*c19800e8SDoug Rabson
468*c19800e8SDoug Rabson	* mech/gss_mech_switch.c: try to load pseudo_random
469*c19800e8SDoug Rabson
470*c19800e8SDoug Rabson	* mech/gss_pseudo_random.c: Add gss_pseudo_random.
471*c19800e8SDoug Rabson
472*c19800e8SDoug Rabson	* gssapi_mech.h: Add hook for gm_pseudo_random.
473*c19800e8SDoug Rabson
474*c19800e8SDoug Rabson2007-01-17  Love Hörnquist Åstrand  <[email protected]>
475*c19800e8SDoug Rabson
476*c19800e8SDoug Rabson	* test_context.c: Don't assume bufer from gss_display_status is
477*c19800e8SDoug Rabson	ok.
478*c19800e8SDoug Rabson
479*c19800e8SDoug Rabson	* mech/gss_wrap_size_limit.c: Reset out variables.
480*c19800e8SDoug Rabson
481*c19800e8SDoug Rabson	* mech/gss_wrap.c: Reset out variables.
482*c19800e8SDoug Rabson
483*c19800e8SDoug Rabson	* mech/gss_verify_mic.c: Reset out variables.
484*c19800e8SDoug Rabson
485*c19800e8SDoug Rabson	* mech/gss_utils.c: Reset out variables.
486*c19800e8SDoug Rabson
487*c19800e8SDoug Rabson	* mech/gss_release_oid_set.c: Reset out variables.
488*c19800e8SDoug Rabson
489*c19800e8SDoug Rabson	* mech/gss_release_cred.c: Reset out variables.
490*c19800e8SDoug Rabson
491*c19800e8SDoug Rabson	* mech/gss_release_buffer.c: Reset variables.
492*c19800e8SDoug Rabson
493*c19800e8SDoug Rabson	* mech/gss_oid_to_str.c: Reset out variables.
494*c19800e8SDoug Rabson
495*c19800e8SDoug Rabson	* mech/gss_inquire_sec_context_by_oid.c: Fix reset out variables.
496*c19800e8SDoug Rabson
497*c19800e8SDoug Rabson	* mech/gss_mech_switch.c: Reset out variables.
498*c19800e8SDoug Rabson
499*c19800e8SDoug Rabson	* mech/gss_inquire_sec_context_by_oid.c: Reset out variables.
500*c19800e8SDoug Rabson
501*c19800e8SDoug Rabson	* mech/gss_inquire_names_for_mech.c: Reset out variables.
502*c19800e8SDoug Rabson
503*c19800e8SDoug Rabson	* mech/gss_inquire_cred_by_oid.c: Reset out variables.
504*c19800e8SDoug Rabson
505*c19800e8SDoug Rabson	* mech/gss_inquire_cred_by_oid.c: Reset out variables.
506*c19800e8SDoug Rabson
507*c19800e8SDoug Rabson	* mech/gss_inquire_cred_by_mech.c: Reset out variables.
508*c19800e8SDoug Rabson
509*c19800e8SDoug Rabson	* mech/gss_inquire_cred.c: Reset out variables, fix memory leak.
510*c19800e8SDoug Rabson
511*c19800e8SDoug Rabson	* mech/gss_inquire_context.c: Reset out variables.
512*c19800e8SDoug Rabson
513*c19800e8SDoug Rabson	* mech/gss_init_sec_context.c: Zero out outbuffer on failure.
514*c19800e8SDoug Rabson
515*c19800e8SDoug Rabson	* mech/gss_import_name.c: Reset out variables.
516*c19800e8SDoug Rabson
517*c19800e8SDoug Rabson	* mech/gss_import_name.c: Reset out variables.
518*c19800e8SDoug Rabson
519*c19800e8SDoug Rabson	* mech/gss_get_mic.c: Reset out variables.
520*c19800e8SDoug Rabson
521*c19800e8SDoug Rabson	* mech/gss_export_name.c: Reset out variables.
522*c19800e8SDoug Rabson
523*c19800e8SDoug Rabson	* mech/gss_encapsulate_token.c: Reset out variables.
524*c19800e8SDoug Rabson
525*c19800e8SDoug Rabson	* mech/gss_duplicate_oid.c: Reset out variables.
526*c19800e8SDoug Rabson
527*c19800e8SDoug Rabson	* mech/gss_duplicate_oid.c: Reset out variables.
528*c19800e8SDoug Rabson
529*c19800e8SDoug Rabson	* mech/gss_duplicate_name.c: Reset out variables.
530*c19800e8SDoug Rabson
531*c19800e8SDoug Rabson	* mech/gss_display_status.c: Reset out variables.
532*c19800e8SDoug Rabson
533*c19800e8SDoug Rabson	* mech/gss_display_name.c: Reset out variables.
534*c19800e8SDoug Rabson
535*c19800e8SDoug Rabson	* mech/gss_delete_sec_context.c: Reset out variables using propper
536*c19800e8SDoug Rabson	macros.
537*c19800e8SDoug Rabson
538*c19800e8SDoug Rabson	* mech/gss_decapsulate_token.c: Reset out variables using propper
539*c19800e8SDoug Rabson	macros.
540*c19800e8SDoug Rabson
541*c19800e8SDoug Rabson	* mech/gss_add_cred.c: Reset out variables.
542*c19800e8SDoug Rabson
543*c19800e8SDoug Rabson	* mech/gss_acquire_cred.c: Reset out variables.
544*c19800e8SDoug Rabson
545*c19800e8SDoug Rabson	* mech/gss_accept_sec_context.c: Reset out variables using propper
546*c19800e8SDoug Rabson	macros.
547*c19800e8SDoug Rabson
548*c19800e8SDoug Rabson	* mech/gss_init_sec_context.c: Reset out variables.
549*c19800e8SDoug Rabson
550*c19800e8SDoug Rabson	* mech/mech_locl.h (_mg_buffer_zero): new macro that zaps a
551*c19800e8SDoug Rabson	gss_buffer_t
552*c19800e8SDoug Rabson
553*c19800e8SDoug Rabson2007-01-16  Love Hörnquist Åstrand  <[email protected]>
554*c19800e8SDoug Rabson
555*c19800e8SDoug Rabson	* mech: sprinkel _gss_mg_error
556*c19800e8SDoug Rabson
557*c19800e8SDoug Rabson	* mech/gss_display_status.c (gss_display_status): use
558*c19800e8SDoug Rabson	_gss_mg_get_error to fetch the error from underlaying mech, if it
559*c19800e8SDoug Rabson	failes, let do the regular dance for GSS-CODE version and a
560*c19800e8SDoug Rabson	generic print-the-error code for MECH-CODE.
561*c19800e8SDoug Rabson
562*c19800e8SDoug Rabson	* mech/gss_oid_to_str.c: Don't include the NUL in the length of
563*c19800e8SDoug Rabson	the string.
564*c19800e8SDoug Rabson
565*c19800e8SDoug Rabson	* mech/context.h: Protoypes for _gss_mg_.
566*c19800e8SDoug Rabson
567*c19800e8SDoug Rabson	* mech/context.c: Glue to catch the error from the lower gss-api
568*c19800e8SDoug Rabson	layer and save that for later so gss_display_status() can show the
569*c19800e8SDoug Rabson	error.
570*c19800e8SDoug Rabson
571*c19800e8SDoug Rabson	* gss.c: Detect NTLM.
572*c19800e8SDoug Rabson
573*c19800e8SDoug Rabson2007-01-11  Love Hörnquist Åstrand  <[email protected]>
574*c19800e8SDoug Rabson
575*c19800e8SDoug Rabson	* mech/gss_accept_sec_context.c: spelling
576*c19800e8SDoug Rabson
577*c19800e8SDoug Rabson2007-01-04  Love Hörnquist Åstrand  <[email protected]>
578*c19800e8SDoug Rabson
579*c19800e8SDoug Rabson	* Makefile.am: Include build (private) prototypes header files.
580*c19800e8SDoug Rabson
581*c19800e8SDoug Rabson	* Makefile.am (ntlmsrc): add ntlm/ntlm-private.h
582*c19800e8SDoug Rabson
583*c19800e8SDoug Rabson2006-12-28  Love Hörnquist Åstrand  <[email protected]>
584*c19800e8SDoug Rabson
585*c19800e8SDoug Rabson	* ntlm/accept_sec_context.c: Pass signseal argument to
586*c19800e8SDoug Rabson	_gss_ntlm_set_key.
587*c19800e8SDoug Rabson
588*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: Pass signseal argument to
589*c19800e8SDoug Rabson	_gss_ntlm_set_key.
590*c19800e8SDoug Rabson
591*c19800e8SDoug Rabson	* ntlm/crypto.c (_gss_ntlm_set_key): add signseal argument
592*c19800e8SDoug Rabson
593*c19800e8SDoug Rabson	* test_ntlm.c: add ntlmv2 test
594*c19800e8SDoug Rabson
595*c19800e8SDoug Rabson	* ntlm/ntlm.h: break out struct ntlmv2_key;
596*c19800e8SDoug Rabson
597*c19800e8SDoug Rabson	* ntlm/crypto.c (_gss_ntlm_set_key): set ntlm v2 keys.
598*c19800e8SDoug Rabson
599*c19800e8SDoug Rabson	* ntlm/accept_sec_context.c: Set dummy ntlmv2 keys and Check TI.
600*c19800e8SDoug Rabson
601*c19800e8SDoug Rabson	* ntlm/ntlm.h: NTLMv2 keys.
602*c19800e8SDoug Rabson
603*c19800e8SDoug Rabson	* ntlm/crypto.c: NTLMv2 sign and verify.
604*c19800e8SDoug Rabson
605*c19800e8SDoug Rabson2006-12-20  Love Hörnquist Åstrand  <[email protected]>
606*c19800e8SDoug Rabson
607*c19800e8SDoug Rabson	* ntlm/accept_sec_context.c: Don't send targetinfo now.
608*c19800e8SDoug Rabson
609*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: Build ntlmv2 answer buffer.
610*c19800e8SDoug Rabson
611*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: Leak less memory.
612*c19800e8SDoug Rabson
613*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: Announce that we support key exchange.
614*c19800e8SDoug Rabson
615*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: Add NTLM_NEG_NTLM2_SESSION, NTLMv2
616*c19800e8SDoug Rabson	session security (disable because missing sign and seal).
617*c19800e8SDoug Rabson
618*c19800e8SDoug Rabson2006-12-19  Love Hörnquist Åstrand  <[email protected]>
619*c19800e8SDoug Rabson
620*c19800e8SDoug Rabson	* ntlm/accept_sec_context.c: split RC4 send and recv keystreams
621*c19800e8SDoug Rabson
622*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: split RC4 send and recv keystreams
623*c19800e8SDoug Rabson
624*c19800e8SDoug Rabson	* ntlm/ntlm.h: split RC4 send and recv keystreams
625*c19800e8SDoug Rabson
626*c19800e8SDoug Rabson	* ntlm/crypto.c: Implement SEAL.
627*c19800e8SDoug Rabson
628*c19800e8SDoug Rabson	* ntlm/crypto.c: move gss_wrap/gss_unwrap here
629*c19800e8SDoug Rabson
630*c19800e8SDoug Rabson	* test_context.c: request INT and CONF from the gss layer, test
631*c19800e8SDoug Rabson	get and verify MIC.
632*c19800e8SDoug Rabson
633*c19800e8SDoug Rabson	* ntlm/ntlm.h: add crypto bits.
634*c19800e8SDoug Rabson
635*c19800e8SDoug Rabson	* ntlm/accept_sec_context.c: Save session master key.
636*c19800e8SDoug Rabson
637*c19800e8SDoug Rabson	* Makefile.am: Move get and verify mic to the same file (crypto.c)
638*c19800e8SDoug Rabson	since they share code.
639*c19800e8SDoug Rabson
640*c19800e8SDoug Rabson	* ntlm/crypto.c: Move get and verify mic to the same file since
641*c19800e8SDoug Rabson	they share code, implement NTLM v1 and dummy signatures.
642*c19800e8SDoug Rabson
643*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: pass on GSS_C_CONF_FLAG and
644*c19800e8SDoug Rabson	GSS_C_INTEG_FLAG, save the session master key
645*c19800e8SDoug Rabson
646*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: try using gss_accept_sec_context()
647*c19800e8SDoug Rabson	on the opportunistic token instead of guessing the acceptor name
648*c19800e8SDoug Rabson	and do gss_acquire_cred, this make SPNEGO work like before.
649*c19800e8SDoug Rabson
650*c19800e8SDoug Rabson2006-12-18  Love Hörnquist Åstrand  <[email protected]>
651*c19800e8SDoug Rabson
652*c19800e8SDoug Rabson	* ntlm/init_sec_context.c: Calculate the NTLM version 1 "master"
653*c19800e8SDoug Rabson	key.
654*c19800e8SDoug Rabson
655*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Resurect negHints for the acceptor
656*c19800e8SDoug Rabson	sends first packet.
657*c19800e8SDoug Rabson
658*c19800e8SDoug Rabson	* Makefile.am: Add "windows" versions of the NegTokenInitWin and
659*c19800e8SDoug Rabson	friends.
660*c19800e8SDoug Rabson
661*c19800e8SDoug Rabson	* test_context.c: add --wrapunwrap flag
662*c19800e8SDoug Rabson
663*c19800e8SDoug Rabson	* spnego/compat.c: move _gss_spnego_indicate_mechtypelist() to
664*c19800e8SDoug Rabson	compat.c, use the sequence types of MechTypeList, make
665*c19800e8SDoug Rabson	add_mech_type() static.
666*c19800e8SDoug Rabson
667*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: move
668*c19800e8SDoug Rabson	_gss_spnego_indicate_mechtypelist() to compat.c
669*c19800e8SDoug Rabson
670*c19800e8SDoug Rabson	* Makefile.am: Generate sequence code for MechTypeList
671*c19800e8SDoug Rabson
672*c19800e8SDoug Rabson	* spnego: check that the generated acceptor mechlist is acceptable too
673*c19800e8SDoug Rabson
674*c19800e8SDoug Rabson	* spnego/init_sec_context.c: Abstract out the initiator filter
675*c19800e8SDoug Rabson	function, it will be needed for the acceptor too.
676*c19800e8SDoug Rabson
677*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Abstract out the initiator filter
678*c19800e8SDoug Rabson	function, it will be needed for the acceptor too. Remove negHints.
679*c19800e8SDoug Rabson
680*c19800e8SDoug Rabson	* test_context.c: allow asserting return mech
681*c19800e8SDoug Rabson
682*c19800e8SDoug Rabson	* ntlm/accept_sec_context.c: add _gss_ntlm_allocate_ctx
683*c19800e8SDoug Rabson
684*c19800e8SDoug Rabson	* ntlm/acquire_cred.c: Check that the KDC seem to there and
685*c19800e8SDoug Rabson	answering us, we can't do better then that wen checking if we will
686*c19800e8SDoug Rabson	accept the credential.
687*c19800e8SDoug Rabson
688*c19800e8SDoug Rabson	* ntlm/get_mic.c: return GSS_S_UNAVAILABLE
689*c19800e8SDoug Rabson
690*c19800e8SDoug Rabson	* mech/utils.h: add _gss_free_oid, reverse of _gss_copy_oid
691*c19800e8SDoug Rabson
692*c19800e8SDoug Rabson	* mech/gss_utils.c: add _gss_free_oid, reverse of _gss_copy_oid
693*c19800e8SDoug Rabson
694*c19800e8SDoug Rabson	* spnego/spnego.asn1: Its very sad, but NegHints its are not part
695*c19800e8SDoug Rabson	of the NegTokenInit, this makes SPNEGO acceptor life a lot harder.
696*c19800e8SDoug Rabson
697*c19800e8SDoug Rabson	* spnego: try harder to handle names better. handle missing
698*c19800e8SDoug Rabson	acceptor and initator creds better (ie dont propose/accept mech
699*c19800e8SDoug Rabson	that there are no credentials for) split NegTokenInit and
700*c19800e8SDoug Rabson	NegTokenResp in acceptor
701*c19800e8SDoug Rabson
702*c19800e8SDoug Rabson2006-12-16  Love Hörnquist Åstrand  <[email protected]>
703*c19800e8SDoug Rabson
704*c19800e8SDoug Rabson	* ntlm/import_name.c: Allocate the buffer from the right length.
705*c19800e8SDoug Rabson
706*c19800e8SDoug Rabson2006-12-15  Love Hörnquist Åstrand  <[email protected]>
707*c19800e8SDoug Rabson
708*c19800e8SDoug Rabson	* ntlm/init_sec_context.c (init_sec_context): Tell the other side
709*c19800e8SDoug Rabson	what domain we think we are talking to.
710*c19800e8SDoug Rabson
711*c19800e8SDoug Rabson	* ntlm/delete_sec_context.c: free username and password
712*c19800e8SDoug Rabson
713*c19800e8SDoug Rabson	* ntlm/release_name.c (_gss_ntlm_release_name): free name.
714*c19800e8SDoug Rabson
715*c19800e8SDoug Rabson	* ntlm/import_name.c (_gss_ntlm_import_name): add support for
716*c19800e8SDoug Rabson	GSS_C_NT_HOSTBASED_SERVICE names
717*c19800e8SDoug Rabson
718*c19800e8SDoug Rabson	* ntlm/ntlm.h: Add ntlm_name.
719*c19800e8SDoug Rabson
720*c19800e8SDoug Rabson	* test_context.c: allow testing of ntlm.
721*c19800e8SDoug Rabson
722*c19800e8SDoug Rabson	* gssapi_mech.h: add __gss_ntlm_initialize
723*c19800e8SDoug Rabson
724*c19800e8SDoug Rabson	* ntlm/accept_sec_context.c (handle_type3): verify that the kdc
725*c19800e8SDoug Rabson	approved of the ntlm exchange too
726*c19800e8SDoug Rabson
727*c19800e8SDoug Rabson	* mech/gss_mech_switch.c: Add the builtin ntlm mech
728*c19800e8SDoug Rabson
729*c19800e8SDoug Rabson	* test_ntlm.c: NTLM test app.
730*c19800e8SDoug Rabson
731*c19800e8SDoug Rabson	* mech/gss_accept_sec_context.c: Add detection of NTLMSSP.
732*c19800e8SDoug Rabson
733*c19800e8SDoug Rabson	* gssapi/gssapi.h: add ntlm mech oid
734*c19800e8SDoug Rabson
735*c19800e8SDoug Rabson	* ntlm/external.c: Switch OID to the ms ntlmssp oid
736*c19800e8SDoug Rabson
737*c19800e8SDoug Rabson	* Makefile.am: Add ntlm gss-api module.
738*c19800e8SDoug Rabson
739*c19800e8SDoug Rabson	* ntlm/accept_sec_context.c: Catch more error errors.
740*c19800e8SDoug Rabson
741*c19800e8SDoug Rabson	* ntlm/accept_sec_context.c: Check after a credential to use.
742*c19800e8SDoug Rabson
743*c19800e8SDoug Rabson2006-12-14  Love Hörnquist Åstrand  <[email protected]>
744*c19800e8SDoug Rabson
745*c19800e8SDoug Rabson	* krb5/set_sec_context_option.c (GSS_KRB5_SET_DEFAULT_REALM_X):
746*c19800e8SDoug Rabson	don't fail on success.  Bug report from Stefan Metzmacher.
747*c19800e8SDoug Rabson
748*c19800e8SDoug Rabson2006-12-13  Love Hörnquist Åstrand  <[email protected]>
749*c19800e8SDoug Rabson
750*c19800e8SDoug Rabson	* krb5/init_sec_context.c (init_auth): only turn on
751*c19800e8SDoug Rabson	GSS_C_CONF_FLAG and GSS_C_INT_FLAG if the caller requseted it.
752*c19800e8SDoug Rabson	From Stefan Metzmacher.
753*c19800e8SDoug Rabson
754*c19800e8SDoug Rabson2006-12-11  Love Hörnquist Åstrand  <[email protected]>
755*c19800e8SDoug Rabson
756*c19800e8SDoug Rabson	* Makefile.am (libgssapi_la_OBJECTS): depends on gssapi_asn1.h
757*c19800e8SDoug Rabson	spnego_asn1.h.
758*c19800e8SDoug Rabson
759*c19800e8SDoug Rabson2006-11-20  Love Hörnquist Åstrand  <[email protected]>
760*c19800e8SDoug Rabson
761*c19800e8SDoug Rabson	* krb5/acquire_cred.c: Make krb5_get_init_creds_opt_free take a
762*c19800e8SDoug Rabson	context argument.
763*c19800e8SDoug Rabson
764*c19800e8SDoug Rabson2006-11-16  Love Hörnquist Åstrand <[email protected]>
765*c19800e8SDoug Rabson
766*c19800e8SDoug Rabson	* test_context.c: Test that token keys are the same, return
767*c19800e8SDoug Rabson	actual_mech.
768*c19800e8SDoug Rabson
769*c19800e8SDoug Rabson2006-11-15  Love Hörnquist Åstrand <[email protected]>
770*c19800e8SDoug Rabson
771*c19800e8SDoug Rabson	* spnego/spnego_locl.h: Make bitfields unsigned, add maybe_open.
772*c19800e8SDoug Rabson
773*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Use ASN.1 encoder functions to
774*c19800e8SDoug Rabson	encode CHOICE structure now that we can handle it.
775*c19800e8SDoug Rabson
776*c19800e8SDoug Rabson	* spnego/init_sec_context.c: Use ASN.1 encoder functions to encode
777*c19800e8SDoug Rabson	CHOICE structure now that we can handle it.
778*c19800e8SDoug Rabson
779*c19800e8SDoug Rabson	* spnego/accept_sec_context.c (_gss_spnego_accept_sec_context):
780*c19800e8SDoug Rabson	send back ad accept_completed when the security context is ->open,
781*c19800e8SDoug Rabson	w/o this the client doesn't know that the server have completed
782*c19800e8SDoug Rabson	the transaction.
783*c19800e8SDoug Rabson
784*c19800e8SDoug Rabson	* test_context.c: Add delegate flag and check that the delegated
785*c19800e8SDoug Rabson	cred works.
786*c19800e8SDoug Rabson
787*c19800e8SDoug Rabson	* spnego/init_sec_context.c: Keep track of the opportunistic token
788*c19800e8SDoug Rabson	in the inital message, it might be a complete gss-api context, in
789*c19800e8SDoug Rabson	that case we'll get back accept_completed without any token. With
790*c19800e8SDoug Rabson	this change, krb5 w/o mutual authentication works.
791*c19800e8SDoug Rabson
792*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Use ASN.1 encoder functions to
793*c19800e8SDoug Rabson	encode CHOICE structure now that we can handle it.
794*c19800e8SDoug Rabson
795*c19800e8SDoug Rabson	* spnego/accept_sec_context.c: Filter out SPNEGO from the out
796*c19800e8SDoug Rabson	supported mechs list and make sure we don't select that for the
797*c19800e8SDoug Rabson	preferred mechamism.
798*c19800e8SDoug Rabson
799*c19800e8SDoug Rabson2006-11-14  Love Hörnquist Åstrand  <[email protected]>
800*c19800e8SDoug Rabson
801*c19800e8SDoug Rabson	* mech/gss_init_sec_context.c (_gss_mech_cred_find): break out the
802*c19800e8SDoug Rabson	cred finding to its own function
803*c19800e8SDoug Rabson
804*c19800e8SDoug Rabson	* krb5/wrap.c: Better error strings, from Andrew Bartlet.
805*c19800e8SDoug Rabson
806*c19800e8SDoug Rabson2006-11-13  Love Hörnquist Åstrand  <[email protected]>
807*c19800e8SDoug Rabson
808*c19800e8SDoug Rabson	* test_context.c: Create our own krb5_context.
809*c19800e8SDoug Rabson
810*c19800e8SDoug Rabson	* krb5: Switch from using a specific error message context in the
811*c19800e8SDoug Rabson	TLS to have a whole krb5_context in TLS. This have some
812*c19800e8SDoug Rabson	interestion side-effekts for the configruration setting options
813*c19800e8SDoug Rabson	since they operate on per-thread basis now.
814*c19800e8SDoug Rabson
815*c19800e8SDoug Rabson	* mech/gss_set_cred_option.c: When calling ->gm_set_cred_option
816*c19800e8SDoug Rabson	and checking for success, use GSS_S_COMPLETE. From Andrew Bartlet.
817*c19800e8SDoug Rabson
818*c19800e8SDoug Rabson2006-11-12  Love Hörnquist Åstrand  <[email protected]>
819*c19800e8SDoug Rabson
820*c19800e8SDoug Rabson	* Makefile.am: Help solaris make even more.
821*c19800e8SDoug Rabson
822*c19800e8SDoug Rabson	* Makefile.am: Help solaris make.
823*c19800e8SDoug Rabson
824*c19800e8SDoug Rabson2006-11-09  Love Hörnquist Åstrand  <[email protected]>
825*c19800e8SDoug Rabson
826*c19800e8SDoug Rabson	* Makefile.am: remove include $(srcdir)/Makefile-digest.am for now
827*c19800e8SDoug Rabson
828*c19800e8SDoug Rabson	* mech/gss_accept_sec_context.c: Try better guessing what is mech
829*c19800e8SDoug Rabson	we are going to select by looking harder at the input_token, idea
830*c19800e8SDoug Rabson	from Luke Howard's mechglue branch.
831*c19800e8SDoug Rabson
832*c19800e8SDoug Rabson	* Makefile.am: libgssapi_la_OBJECTS: add depency on gkrb5_err.h
833*c19800e8SDoug Rabson
834*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: add GSS_KRB5_SET_ALLOWABLE_ENCTYPES_X
835*c19800e8SDoug Rabson
836*c19800e8SDoug Rabson	* mech/gss_krb5.c: implement gss_krb5_set_allowable_enctypes
837*c19800e8SDoug Rabson
838*c19800e8SDoug Rabson	* gssapi/gssapi.h: GSS_KRB5_S_
839*c19800e8SDoug Rabson
840*c19800e8SDoug Rabson	* krb5/gsskrb5_locl.h: Include <gkrb5_err.h>.
841*c19800e8SDoug Rabson
842*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: Add gss_krb5_set_allowable_enctypes.
843*c19800e8SDoug Rabson
844*c19800e8SDoug Rabson	* Makefile.am: Build and install gkrb5_err.h
845*c19800e8SDoug Rabson
846*c19800e8SDoug Rabson	* krb5/gkrb5_err.et: Move the GSS_KRB5_S error here.
847*c19800e8SDoug Rabson
848*c19800e8SDoug Rabson2006-11-08  Love Hörnquist Åstrand  <[email protected]>
849*c19800e8SDoug Rabson
850*c19800e8SDoug Rabson	* mech/gss_krb5.c: Add gsskrb5_set_default_realm.
851*c19800e8SDoug Rabson
852*c19800e8SDoug Rabson	* krb5/set_sec_context_option.c: Support
853*c19800e8SDoug Rabson	GSS_KRB5_SET_DEFAULT_REALM_X.
854*c19800e8SDoug Rabson
855*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: add GSS_KRB5_SET_DEFAULT_REALM_X
856*c19800e8SDoug Rabson
857*c19800e8SDoug Rabson	* krb5/external.c: add GSS_KRB5_SET_DEFAULT_REALM_X
858*c19800e8SDoug Rabson
859*c19800e8SDoug Rabson2006-11-07  Love Hörnquist Åstrand  <[email protected]>
860*c19800e8SDoug Rabson
861*c19800e8SDoug Rabson	* test_context.c: rename krb5_[gs]et_time_wrap to
862*c19800e8SDoug Rabson	krb5_[gs]et_max_time_skew
863*c19800e8SDoug Rabson
864*c19800e8SDoug Rabson	* krb5/copy_ccache.c: _gsskrb5_extract_authz_data_from_sec_context
865*c19800e8SDoug Rabson	no longer used, bye bye
866*c19800e8SDoug Rabson
867*c19800e8SDoug Rabson	* mech/gss_krb5.c: No depenency of the krb5 gssapi mech.
868*c19800e8SDoug Rabson
869*c19800e8SDoug Rabson	* mech/gss_krb5.c (gsskrb5_extract_authtime_from_sec_context): use
870*c19800e8SDoug Rabson	_gsskrb5_decode_om_uint32. From Andrew Bartlet.
871*c19800e8SDoug Rabson
872*c19800e8SDoug Rabson	* mech/gss_krb5.c: Add dummy gss_krb5_set_allowable_enctypes for
873*c19800e8SDoug Rabson	now.
874*c19800e8SDoug Rabson
875*c19800e8SDoug Rabson	* spnego/spnego_locl.h: Include <roken.h> for compatiblity.
876*c19800e8SDoug Rabson
877*c19800e8SDoug Rabson	* krb5/arcfour.c: Use IS_DCE_STYLE flag. There is no padding in
878*c19800e8SDoug Rabson	DCE-STYLE, don't try to use to.  From Andrew Bartlett.
879*c19800e8SDoug Rabson
880*c19800e8SDoug Rabson	* test_context.c: test wrap/unwrap, add flag for dce-style and
881*c19800e8SDoug Rabson	mutual auth, also support multi-roundtrip sessions
882*c19800e8SDoug Rabson
883*c19800e8SDoug Rabson	* krb5/gsskrb5_locl.h: Add IS_DCE_STYLE macro.
884*c19800e8SDoug Rabson
885*c19800e8SDoug Rabson	* krb5/accept_sec_context.c (gsskrb5_acceptor_start): use
886*c19800e8SDoug Rabson	krb5_rd_req_ctx
887*c19800e8SDoug Rabson
888*c19800e8SDoug Rabson	* mech/gss_krb5.c (gsskrb5_get_subkey): return the per message
889*c19800e8SDoug Rabson	token subkey
890*c19800e8SDoug Rabson
891*c19800e8SDoug Rabson	* krb5/inquire_sec_context_by_oid.c: check if there is any key at
892*c19800e8SDoug Rabson	all
893*c19800e8SDoug Rabson
894*c19800e8SDoug Rabson2006-11-06  Love Hörnquist Åstrand <[email protected]>
895*c19800e8SDoug Rabson
896*c19800e8SDoug Rabson	* krb5/inquire_sec_context_by_oid.c: Set more error strings, use
897*c19800e8SDoug Rabson	right enum for acceptor subkey.  From Andrew Bartlett.
898*c19800e8SDoug Rabson
899*c19800e8SDoug Rabson2006-11-04  Love Hörnquist Åstrand  <[email protected]>
900*c19800e8SDoug Rabson
901*c19800e8SDoug Rabson	* test_context.c: Test gsskrb5_extract_service_keyblock, needed in
902*c19800e8SDoug Rabson	PAC valication.  From Andrew Bartlett
903*c19800e8SDoug Rabson
904*c19800e8SDoug Rabson	* mech/gss_krb5.c: Add gsskrb5_extract_authz_data_from_sec_context
905*c19800e8SDoug Rabson	and keyblock extraction functions.
906*c19800e8SDoug Rabson
907*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: Add extraction of keyblock function, from
908*c19800e8SDoug Rabson	Andrew Bartlett.
909*c19800e8SDoug Rabson
910*c19800e8SDoug Rabson	* krb5/external.c: Add GSS_KRB5_GET_SERVICE_KEYBLOCK_X
911*c19800e8SDoug Rabson
912*c19800e8SDoug Rabson2006-11-03  Love Hörnquist Åstrand  <[email protected]>
913*c19800e8SDoug Rabson
914*c19800e8SDoug Rabson	* test_context.c: Rename various routines and constants from
915*c19800e8SDoug Rabson	canonize to canonicalize.  From Andrew Bartlett
916*c19800e8SDoug Rabson
917*c19800e8SDoug Rabson	* mech/gss_krb5.c: Rename various routines and constants from
918*c19800e8SDoug Rabson	canonize to canonicalize.  From Andrew Bartlett
919*c19800e8SDoug Rabson
920*c19800e8SDoug Rabson	* krb5/set_sec_context_option.c: Rename various routines and
921*c19800e8SDoug Rabson	constants from canonize to canonicalize.  From Andrew Bartlett
922*c19800e8SDoug Rabson
923*c19800e8SDoug Rabson	* krb5/external.c: Rename various routines and constants from
924*c19800e8SDoug Rabson	canonize to canonicalize.  From Andrew Bartlett
925*c19800e8SDoug Rabson
926*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: Rename various routines and constants from
927*c19800e8SDoug Rabson	canonize to canonicalize.  From Andrew Bartlett
928*c19800e8SDoug Rabson
929*c19800e8SDoug Rabson2006-10-25  Love Hörnquist Åstrand  <[email protected]>
930*c19800e8SDoug Rabson
931*c19800e8SDoug Rabson	* krb5/accept_sec_context.c (gsskrb5_accept_delegated_token): need
932*c19800e8SDoug Rabson	to free ccache
933*c19800e8SDoug Rabson
934*c19800e8SDoug Rabson2006-10-24  Love Hörnquist Åstrand  <[email protected]>
935*c19800e8SDoug Rabson
936*c19800e8SDoug Rabson	* test_context.c (loop): free target_name
937*c19800e8SDoug Rabson
938*c19800e8SDoug Rabson	* mech/gss_accept_sec_context.c: SLIST_INIT the ->gc_mc'
939*c19800e8SDoug Rabson
940*c19800e8SDoug Rabson	* mech/gss_acquire_cred.c : SLIST_INIT the ->gc_mc'
941*c19800e8SDoug Rabson
942*c19800e8SDoug Rabson	* krb5/init_sec_context.c: Avoid leaking memory.
943*c19800e8SDoug Rabson
944*c19800e8SDoug Rabson	* mech/gss_buffer_set.c (gss_release_buffer_set): don't leak the
945*c19800e8SDoug Rabson	->elements memory.
946*c19800e8SDoug Rabson
947*c19800e8SDoug Rabson	* test_context.c: make compile
948*c19800e8SDoug Rabson
949*c19800e8SDoug Rabson	* krb5/cfx.c (_gssapi_verify_mic_cfx): always free crypto context.
950*c19800e8SDoug Rabson
951*c19800e8SDoug Rabson	* krb5/set_cred_option.c (import_cred): free sp
952*c19800e8SDoug Rabson
953*c19800e8SDoug Rabson2006-10-22  Love Hörnquist Åstrand  <[email protected]>
954*c19800e8SDoug Rabson
955*c19800e8SDoug Rabson	* mech/gss_add_oid_set_member.c: Use old implementation of
956*c19800e8SDoug Rabson	gss_add_oid_set_member, it leaks less memory.
957*c19800e8SDoug Rabson
958*c19800e8SDoug Rabson	* krb5/test_cfx.c: free krb5_crypto.
959*c19800e8SDoug Rabson
960*c19800e8SDoug Rabson	* krb5/test_cfx.c: free krb5_context
961*c19800e8SDoug Rabson
962*c19800e8SDoug Rabson	* mech/gss_release_name.c (gss_release_name): free input_name
963*c19800e8SDoug Rabson	it-self.
964*c19800e8SDoug Rabson
965*c19800e8SDoug Rabson2006-10-21  Love Hörnquist Åstrand  <[email protected]>
966*c19800e8SDoug Rabson
967*c19800e8SDoug Rabson	* test_context.c: Call setprogname.
968*c19800e8SDoug Rabson
969*c19800e8SDoug Rabson	* mech/gss_krb5.c: Add gsskrb5_extract_authtime_from_sec_context.
970*c19800e8SDoug Rabson
971*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: add
972*c19800e8SDoug Rabson	gsskrb5_extract_authtime_from_sec_context
973*c19800e8SDoug Rabson
974*c19800e8SDoug Rabson2006-10-20  Love Hörnquist Åstrand  <[email protected]>
975*c19800e8SDoug Rabson
976*c19800e8SDoug Rabson	* krb5/inquire_sec_context_by_oid.c: Add get_authtime.
977*c19800e8SDoug Rabson
978*c19800e8SDoug Rabson	* krb5/external.c: add GSS_KRB5_GET_AUTHTIME_X
979*c19800e8SDoug Rabson
980*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: add GSS_KRB5_GET_AUTHTIME_X
981*c19800e8SDoug Rabson
982*c19800e8SDoug Rabson	* krb5/set_sec_context_option.c: Implement GSS_KRB5_SEND_TO_KDC_X.
983*c19800e8SDoug Rabson
984*c19800e8SDoug Rabson	* mech/gss_krb5.c: Add gsskrb5_set_send_to_kdc
985*c19800e8SDoug Rabson
986*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: Add GSS_KRB5_SEND_TO_KDC_X and
987*c19800e8SDoug Rabson	gsskrb5_set_send_to_kdc
988*c19800e8SDoug Rabson
989*c19800e8SDoug Rabson	* krb5/external.c: add GSS_KRB5_SEND_TO_KDC_X
990*c19800e8SDoug Rabson
991*c19800e8SDoug Rabson	* Makefile.am: more files
992*c19800e8SDoug Rabson
993*c19800e8SDoug Rabson2006-10-19  Love Hörnquist Åstrand  <[email protected]>
994*c19800e8SDoug Rabson
995*c19800e8SDoug Rabson	* Makefile.am: remove spnego/gssapi_spnego.h, its now in gssapi/
996*c19800e8SDoug Rabson
997*c19800e8SDoug Rabson	* test_context.c: Allow specifing mech.
998*c19800e8SDoug Rabson
999*c19800e8SDoug Rabson	* krb5/external.c: add GSS_SASL_DIGEST_MD5_MECHANISM (for now)
1000*c19800e8SDoug Rabson
1001*c19800e8SDoug Rabson	* gssapi/gssapi.h: Rename GSS_DIGEST_MECHANISM to
1002*c19800e8SDoug Rabson	GSS_SASL_DIGEST_MD5_MECHANISM
1003*c19800e8SDoug Rabson
1004*c19800e8SDoug Rabson2006-10-18  Love Hörnquist Åstrand  <[email protected]>
1005*c19800e8SDoug Rabson
1006*c19800e8SDoug Rabson	* mech/gssapi.asn1: Make it into a heim_any_set, its doesn't
1007*c19800e8SDoug Rabson	except a tag.
1008*c19800e8SDoug Rabson
1009*c19800e8SDoug Rabson	* mech/gssapi.asn1: GSSAPIContextToken is IMPLICIT SEQUENCE
1010*c19800e8SDoug Rabson
1011*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: add GSS_KRB5_GET_ACCEPTOR_SUBKEY_X
1012*c19800e8SDoug Rabson
1013*c19800e8SDoug Rabson	* krb5/external.c: Add GSS_KRB5_GET_ACCEPTOR_SUBKEY_X.
1014*c19800e8SDoug Rabson
1015*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: add GSS_KRB5_GET_INITIATOR_SUBKEY_X and
1016*c19800e8SDoug Rabson	GSS_KRB5_GET_SUBKEY_X
1017*c19800e8SDoug Rabson
1018*c19800e8SDoug Rabson	* krb5/external.c: add GSS_KRB5_GET_INITIATOR_SUBKEY_X,
1019*c19800e8SDoug Rabson	GSS_KRB5_GET_SUBKEY_X
1020*c19800e8SDoug Rabson
1021*c19800e8SDoug Rabson2006-10-17  Love Hörnquist Åstrand  <[email protected]>
1022*c19800e8SDoug Rabson
1023*c19800e8SDoug Rabson	* test_context.c: Support switching on name type oid's
1024*c19800e8SDoug Rabson
1025*c19800e8SDoug Rabson	* test_context.c: add test for dns canon flag
1026*c19800e8SDoug Rabson
1027*c19800e8SDoug Rabson	* mech/gss_krb5.c: Add gsskrb5_set_dns_canonlize.
1028*c19800e8SDoug Rabson
1029*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: remove gss_krb5_compat_des3_mic
1030*c19800e8SDoug Rabson
1031*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: Add gsskrb5_set_dns_canonlize.
1032*c19800e8SDoug Rabson
1033*c19800e8SDoug Rabson	* krb5/set_sec_context_option.c: implement
1034*c19800e8SDoug Rabson	GSS_KRB5_SET_DNS_CANONIZE_X
1035*c19800e8SDoug Rabson
1036*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: add GSS_KRB5_SET_DNS_CANONIZE_X
1037*c19800e8SDoug Rabson
1038*c19800e8SDoug Rabson	* krb5/external.c: add GSS_KRB5_SET_DNS_CANONIZE_X
1039*c19800e8SDoug Rabson
1040*c19800e8SDoug Rabson	* mech/gss_krb5.c: add bits to make lucid context work
1041*c19800e8SDoug Rabson
1042*c19800e8SDoug Rabson2006-10-14  Love Hörnquist Åstrand  <[email protected]>
1043*c19800e8SDoug Rabson
1044*c19800e8SDoug Rabson	* mech/gss_oid_to_str.c: Prefix der primitives with der_.
1045*c19800e8SDoug Rabson
1046*c19800e8SDoug Rabson	* krb5/inquire_sec_context_by_oid.c: Prefix der primitives with
1047*c19800e8SDoug Rabson	der_.
1048*c19800e8SDoug Rabson
1049*c19800e8SDoug Rabson	* krb5/encapsulate.c: Prefix der primitives with der_.
1050*c19800e8SDoug Rabson
1051*c19800e8SDoug Rabson	* mech/gss_oid_to_str.c: New der_print_heim_oid signature.
1052*c19800e8SDoug Rabson
1053*c19800e8SDoug Rabson2006-10-12  Love Hörnquist Åstrand  <[email protected]>
1054*c19800e8SDoug Rabson
1055*c19800e8SDoug Rabson	* Makefile.am: add test_context
1056*c19800e8SDoug Rabson
1057*c19800e8SDoug Rabson	* krb5/inquire_sec_context_by_oid.c: Make it work.
1058*c19800e8SDoug Rabson
1059*c19800e8SDoug Rabson	* test_oid.c: Test lucid oid.
1060*c19800e8SDoug Rabson
1061*c19800e8SDoug Rabson	* gssapi/gssapi.h: Add OM_uint64_t.
1062*c19800e8SDoug Rabson
1063*c19800e8SDoug Rabson	* krb5/inquire_sec_context_by_oid.c: Add lucid interface.
1064*c19800e8SDoug Rabson
1065*c19800e8SDoug Rabson	* krb5/external.c: Add lucid interface, renumber oids to my
1066*c19800e8SDoug Rabson	delegated space.
1067*c19800e8SDoug Rabson
1068*c19800e8SDoug Rabson	* mech/gss_krb5.c: Add lucid interface.
1069*c19800e8SDoug Rabson
1070*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: Add lucid interface.
1071*c19800e8SDoug Rabson
1072*c19800e8SDoug Rabson	* spnego/spnego_locl.h: Maybe include <netdb.h>.
1073*c19800e8SDoug Rabson
1074*c19800e8SDoug Rabson2006-10-09  Love Hörnquist Åstrand  <[email protected]>
1075*c19800e8SDoug Rabson
1076*c19800e8SDoug Rabson	* mech/gss_mech_switch.c: define RTLD_LOCAL to 0 if not defined.
1077*c19800e8SDoug Rabson
1078*c19800e8SDoug Rabson2006-10-08  Love Hörnquist Åstrand  <[email protected]>
1079*c19800e8SDoug Rabson
1080*c19800e8SDoug Rabson	* Makefile.am: install gssapi_krb5.H and gssapi_spnego.h
1081*c19800e8SDoug Rabson
1082*c19800e8SDoug Rabson	* gssapi/gssapi_krb5.h: Move krb5 stuff to <gssapi/gssapi_krb5.h>.
1083*c19800e8SDoug Rabson
1084*c19800e8SDoug Rabson	* gssapi/gssapi.h: Move krb5 stuff to <gssapi/gssapi_krb5.h>.
1085*c19800e8SDoug Rabson
1086*c19800e8SDoug Rabson	* Makefile.am: Drop some -I no longer needed.
1087*c19800e8SDoug Rabson
1088*c19800e8SDoug Rabson	* gssapi/gssapi_spnego.h: Move gssapi_spengo.h over here.
1089*c19800e8SDoug Rabson
1090*c19800e8SDoug Rabson	* krb5: reference all include files using 'krb5/'
1091*c19800e8SDoug Rabson
1092*c19800e8SDoug Rabson2006-10-07  Love Hörnquist Åstrand  <[email protected]>
1093*c19800e8SDoug Rabson
1094*c19800e8SDoug Rabson	* gssapi.h: Add file inclusion protection.
1095*c19800e8SDoug Rabson
1096*c19800e8SDoug Rabson	* gssapi/gssapi.h: Correct header file inclusion protection.
1097*c19800e8SDoug Rabson
1098*c19800e8SDoug Rabson	* gssapi/gssapi.h: Move the gssapi.h from lib/gssapi/ to
1099*c19800e8SDoug Rabson	lib/gssapi/gssapi/ to please automake.
1100*c19800e8SDoug Rabson
1101*c19800e8SDoug Rabson	* spnego/spnego_locl.h: Maybe include <sys/types.h>.
1102*c19800e8SDoug Rabson
1103*c19800e8SDoug Rabson	* mech/mech_locl.h: Include <roken.h>.
1104*c19800e8SDoug Rabson
1105*c19800e8SDoug Rabson	* Makefile.am: split build files into dist_ and noinst_ SOURCES
1106*c19800e8SDoug Rabson
1107*c19800e8SDoug Rabson2006-10-06  Love Hörnquist Åstrand  <[email protected]>
1108*c19800e8SDoug Rabson
1109*c19800e8SDoug Rabson	* gss.c: #if 0 out unused code.
1110*c19800e8SDoug Rabson
1111*c19800e8SDoug Rabson	* mech/gss_mech_switch.c: Cast argument to ctype(3) functions
1112*c19800e8SDoug Rabson	to (unsigned char).
1113*c19800e8SDoug Rabson
1114*c19800e8SDoug Rabson2006-10-05  Love Hörnquist Åstrand  <[email protected]>
1115*c19800e8SDoug Rabson
1116*c19800e8SDoug Rabson	* mech/name.h: remove <sys/queue.h>
1117*c19800e8SDoug Rabson
1118*c19800e8SDoug Rabson	* mech/mech_switch.h: remove <sys/queue.h>
1119*c19800e8SDoug Rabson
1120*c19800e8SDoug Rabson	* mech/cred.h: remove <sys/queue.h>
1121*c19800e8SDoug Rabson
1122*c19800e8SDoug Rabson2006-10-02  Love Hörnquist Åstrand  <[email protected]>
1123*c19800e8SDoug Rabson
1124*c19800e8SDoug Rabson	* krb5/arcfour.c: Thinker more with header lengths.
1125*c19800e8SDoug Rabson
1126*c19800e8SDoug Rabson	* krb5/arcfour.c: Improve the calcucation of header
1127*c19800e8SDoug Rabson	lengths. DCE-STYLE data is also padded so remove if (1 || ...)
1128*c19800e8SDoug Rabson	code.
1129*c19800e8SDoug Rabson
1130*c19800e8SDoug Rabson	* krb5/wrap.c (_gsskrb5_wrap_size_limit): use
1131*c19800e8SDoug Rabson	_gssapi_wrap_size_arcfour for arcfour
1132*c19800e8SDoug Rabson
1133*c19800e8SDoug Rabson	* krb5/arcfour.c: Move _gssapi_wrap_size_arcfour here.
1134*c19800e8SDoug Rabson
1135*c19800e8SDoug Rabson	* Makefile.am: Split all mech to diffrent mechsrc variables.
1136*c19800e8SDoug Rabson
1137*c19800e8SDoug Rabson	* spnego/context_stubs.c: Make internal function static (and
1138*c19800e8SDoug Rabson	rename).
1139*c19800e8SDoug Rabson
1140*c19800e8SDoug Rabson2006-10-01  Love Hörnquist Åstrand  <[email protected]>
1141*c19800e8SDoug Rabson
1142*c19800e8SDoug Rabson	* krb5/inquire_cred.c: Fix "if (x) lock(y)" bug. From Harald
1143*c19800e8SDoug Rabson	Barth.
1144*c19800e8SDoug Rabson
1145*c19800e8SDoug Rabson	* spnego/spnego_locl.h: Include <sys/param.h> for MAXHOSTNAMELEN.
1146*c19800e8SDoug Rabson
1147*c19800e8SDoug Rabson2006-09-25  Love Hörnquist Åstrand  <[email protected]>
1148*c19800e8SDoug Rabson
1149*c19800e8SDoug Rabson	* krb5/arcfour.c: Add wrap support, interrop with itself but not
1150*c19800e8SDoug Rabson	w2k3s-sp1
1151*c19800e8SDoug Rabson
1152*c19800e8SDoug Rabson	* krb5/gsskrb5_locl.h: move the arcfour specific stuff to the
1153*c19800e8SDoug Rabson	arcfour header.
1154*c19800e8SDoug Rabson
1155*c19800e8SDoug Rabson	* krb5/arcfour.c: Support DCE-style unwrap, tested with
1156*c19800e8SDoug Rabson	w2k3server-sp1.
1157*c19800e8SDoug Rabson
1158*c19800e8SDoug Rabson	* mech/gss_accept_sec_context.c (gss_accept_sec_context): if the
1159*c19800e8SDoug Rabson	token doesn't start with [APPLICATION 0] SEQUENCE, lets assume its
1160*c19800e8SDoug Rabson	a DCE-style kerberos 5 connection. XXX this needs to be made
1161*c19800e8SDoug Rabson	better in cause we get another GSS-API protocol violating
1162*c19800e8SDoug Rabson	protocol. It should be possible to detach the Kerberos DCE-style
1163*c19800e8SDoug Rabson	since it starts with a AP-REQ PDU, but that have to wait for now.
1164*c19800e8SDoug Rabson
1165*c19800e8SDoug Rabson2006-09-22  Love Hörnquist Åstrand  <[email protected]>
1166*c19800e8SDoug Rabson
1167*c19800e8SDoug Rabson	* gssapi.h: Add GSS_C flags from
1168*c19800e8SDoug Rabson	draft-brezak-win2k-krb-rc4-hmac-04.txt.
1169*c19800e8SDoug Rabson
1170*c19800e8SDoug Rabson	* krb5/delete_sec_context.c: Free service_keyblock and fwd_data,
1171*c19800e8SDoug Rabson	indent.
1172*c19800e8SDoug Rabson
1173*c19800e8SDoug Rabson	* krb5/accept_sec_context.c: Merge of the acceptor part from the
1174*c19800e8SDoug Rabson	samba patch by Stefan Metzmacher and Andrew Bartlet.
1175*c19800e8SDoug Rabson
1176*c19800e8SDoug Rabson	* krb5/init_sec_context.c: Add GSS_C_DCE_STYLE.
1177*c19800e8SDoug Rabson
1178*c19800e8SDoug Rabson	* krb5/{init_sec_context.c,gsskrb5_locl.h}: merge most of the
1179*c19800e8SDoug Rabson	initiator part from the samba patch by Stefan Metzmacher and
1180*c19800e8SDoug Rabson	Andrew Bartlet (still missing DCE/RPC support)
1181*c19800e8SDoug Rabson
1182*c19800e8SDoug Rabson2006-08-28  Love Hörnquist Åstrand  <[email protected]>
1183*c19800e8SDoug Rabson
1184*c19800e8SDoug Rabson	* gss.c (help): use sl_slc_help().
1185*c19800e8SDoug Rabson
1186*c19800e8SDoug Rabson2006-07-22  Love Hörnquist Åstrand  <[email protected]>
1187*c19800e8SDoug Rabson
1188*c19800e8SDoug Rabson	* gss-commands.in: rename command to supported-mechanisms
1189*c19800e8SDoug Rabson
1190*c19800e8SDoug Rabson	* Makefile.am: Make gss objects depend on the slc built
1191*c19800e8SDoug Rabson	gss-commands.h
1192*c19800e8SDoug Rabson
1193*c19800e8SDoug Rabson2006-07-20  Love Hörnquist Åstrand  <[email protected]>
1194*c19800e8SDoug Rabson
1195*c19800e8SDoug Rabson	* gss-commands.in: add slc commands for gss
1196*c19800e8SDoug Rabson
1197*c19800e8SDoug Rabson	* krb5/gsskrb5_locl.h: Remove dup prototype of _gsskrb5_init()
1198*c19800e8SDoug Rabson
1199*c19800e8SDoug Rabson	* Makefile.am: Add test_cfx
1200*c19800e8SDoug Rabson
1201*c19800e8SDoug Rabson	* krb5/external.c: add GSS_KRB5_REGISTER_ACCEPTOR_IDENTITY_X
1202*c19800e8SDoug Rabson
1203*c19800e8SDoug Rabson	* krb5/set_sec_context_option.c: catch
1204*c19800e8SDoug Rabson	GSS_KRB5_REGISTER_ACCEPTOR_IDENTITY_X
1205*c19800e8SDoug Rabson
1206*c19800e8SDoug Rabson	* krb5/accept_sec_context.c: reimplement
1207*c19800e8SDoug Rabson	gsskrb5_register_acceptor_identity
1208*c19800e8SDoug Rabson
1209*c19800e8SDoug Rabson	* mech/gss_krb5.c: implement gsskrb5_register_acceptor_identity
1210*c19800e8SDoug Rabson
1211*c19800e8SDoug Rabson	* mech/gss_inquire_mechs_for_name.c: call _gss_load_mech
1212*c19800e8SDoug Rabson
1213*c19800e8SDoug Rabson	* mech/gss_inquire_cred.c (gss_inquire_cred): call _gss_load_mech
1214*c19800e8SDoug Rabson
1215*c19800e8SDoug Rabson	* mech/gss_mech_switch.c: Make _gss_load_mech() atomic and run
1216*c19800e8SDoug Rabson	only once, this have the side effect that _gss_mechs and
1217*c19800e8SDoug Rabson	_gss_mech_oids is only initialized once, so if just the users of
1218*c19800e8SDoug Rabson	these two global variables calls _gss_load_mech() first, it will
1219*c19800e8SDoug Rabson	act as a barrier and make sure the variables are never changed and
1220*c19800e8SDoug Rabson	we don't need to lock them.
1221*c19800e8SDoug Rabson
1222*c19800e8SDoug Rabson	* mech/utils.h: no need to mark functions extern.
1223*c19800e8SDoug Rabson
1224*c19800e8SDoug Rabson	* mech/name.h: no need to mark _gss_find_mn extern.
1225*c19800e8SDoug Rabson
1226*c19800e8SDoug Rabson2006-07-19  Love Hörnquist Åstrand <[email protected]>
1227*c19800e8SDoug Rabson
1228*c19800e8SDoug Rabson	* krb5/cfx.c: Redo the wrap length calculations.
1229*c19800e8SDoug Rabson
1230*c19800e8SDoug Rabson	* krb5/test_cfx.c: test max_wrap_size in cfx.c
1231*c19800e8SDoug Rabson
1232*c19800e8SDoug Rabson	* mech/gss_display_status.c: Handle more error codes.
1233*c19800e8SDoug Rabson
1234*c19800e8SDoug Rabson2006-07-07  Love Hörnquist Åstrand  <[email protected]>
1235*c19800e8SDoug Rabson
1236*c19800e8SDoug Rabson	* mech/mech_locl.h: Include <krb5-types.h> and "mechqueue.h"
1237*c19800e8SDoug Rabson
1238*c19800e8SDoug Rabson	* mech/mechqueue.h: Add SLIST macros.
1239*c19800e8SDoug Rabson
1240*c19800e8SDoug Rabson	* krb5/inquire_context.c: Don't free return values on success.
1241*c19800e8SDoug Rabson
1242*c19800e8SDoug Rabson	* krb5/inquire_cred.c (_gsskrb5_inquire_cred): When cred provided
1243*c19800e8SDoug Rabson	is the default cred, acquire the acceptor cred and initator cred
1244*c19800e8SDoug Rabson	in two diffrent steps and then query them for the information,
1245*c19800e8SDoug Rabson	this way, the code wont fail if there are no keytab, but there is
1246*c19800e8SDoug Rabson	a credential cache.
1247*c19800e8SDoug Rabson
1248*c19800e8SDoug Rabson	* mech/gss_inquire_cred.c: move the check if we found any cred
1249*c19800e8SDoug Rabson	where it matter for both cases
1250*c19800e8SDoug Rabson	(default cred and provided cred)
1251*c19800e8SDoug Rabson
1252*c19800e8SDoug Rabson	* mech/gss_init_sec_context.c: If the desired mechanism can't
1253*c19800e8SDoug Rabson	convert the name to a MN, fail with GSS_S_BAD_NAME rather then a
1254*c19800e8SDoug Rabson	NULL de-reference.
1255*c19800e8SDoug Rabson
1256*c19800e8SDoug Rabson2006-07-06  Love Hörnquist Åstrand  <[email protected]>
1257*c19800e8SDoug Rabson
1258*c19800e8SDoug Rabson	* spnego/external.c: readd gss_spnego_inquire_names_for_mech
1259*c19800e8SDoug Rabson
1260*c19800e8SDoug Rabson	* spnego/spnego_locl.h: reimplement
1261*c19800e8SDoug Rabson	gss_spnego_inquire_names_for_mech add support function
1262*c19800e8SDoug Rabson	_gss_spnego_supported_mechs
1263*c19800e8SDoug Rabson
1264*c19800e8SDoug Rabson	* spnego/context_stubs.h: reimplement
1265*c19800e8SDoug Rabson	gss_spnego_inquire_names_for_mech add support function
1266*c19800e8SDoug Rabson	_gss_spnego_supported_mechs
1267*c19800e8SDoug Rabson
1268*c19800e8SDoug Rabson	* spnego/context_stubs.c: drop gss_spnego_indicate_mechs
1269*c19800e8SDoug Rabson
1270*c19800e8SDoug Rabson	* mech/gss_indicate_mechs.c: if the underlaying mech doesn't
1271*c19800e8SDoug Rabson	support gss_indicate_mechs, use the oid in the mechswitch
1272*c19800e8SDoug Rabson	structure
1273*c19800e8SDoug Rabson
1274*c19800e8SDoug Rabson	* spnego/external.c: let the mech glue layer implement
1275*c19800e8SDoug Rabson	gss_indicate_mechs
1276*c19800e8SDoug Rabson
1277*c19800e8SDoug Rabson	* spnego/cred_stubs.c (gss_spnego_acquire_cred): don't care about
1278*c19800e8SDoug Rabson	desired_mechs, get our own list with indicate_mechs and remove
1279*c19800e8SDoug Rabson	ourself.
1280*c19800e8SDoug Rabson
1281*c19800e8SDoug Rabson2006-07-05 Love Hörnquist Åstrand <[email protected]>
1282*c19800e8SDoug Rabson
1283*c19800e8SDoug Rabson	* spnego/external.c: remove gss_spnego_inquire_names_for_mech, let
1284*c19800e8SDoug Rabson	the mechglue layer implement it
1285*c19800e8SDoug Rabson
1286*c19800e8SDoug Rabson	* spnego/context_stubs.c: remove gss_spnego_inquire_names_for_mech, let
1287*c19800e8SDoug Rabson	the mechglue layer implement it
1288*c19800e8SDoug Rabson
1289*c19800e8SDoug Rabson	* spnego/spnego_locl.c: remove gss_spnego_inquire_names_for_mech, let
1290*c19800e8SDoug Rabson	the mechglue layer implement it
1291*c19800e8SDoug Rabson
1292*c19800e8SDoug Rabson2006-07-01  Love Hörnquist Åstrand  <[email protected]>
1293*c19800e8SDoug Rabson
1294*c19800e8SDoug Rabson	* mech/gss_set_cred_option.c: fix argument to gss_release_cred
1295*c19800e8SDoug Rabson
1296*c19800e8SDoug Rabson2006-06-30  Love Hörnquist Åstrand  <[email protected]>
1297*c19800e8SDoug Rabson
1298*c19800e8SDoug Rabson	* krb5/init_sec_context.c: Make work on compilers that are
1299*c19800e8SDoug Rabson	somewhat more picky then gcc4 (like gcc2.95)
1300*c19800e8SDoug Rabson
1301*c19800e8SDoug Rabson	* krb5/init_sec_context.c (do_delegation): use KDCOptions2int to
1302*c19800e8SDoug Rabson	convert fwd_flags to an integer, since otherwise int2KDCOptions in
1303*c19800e8SDoug Rabson	krb5_get_forwarded_creds wont do the right thing.
1304*c19800e8SDoug Rabson
1305*c19800e8SDoug Rabson	* mech/gss_set_cred_option.c (gss_set_cred_option): free memory on
1306*c19800e8SDoug Rabson	failure
1307*c19800e8SDoug Rabson
1308*c19800e8SDoug Rabson	* krb5/set_sec_context_option.c (_gsskrb5_set_sec_context_option):
1309*c19800e8SDoug Rabson	init global kerberos context
1310*c19800e8SDoug Rabson
1311*c19800e8SDoug Rabson	* krb5/set_cred_option.c (_gsskrb5_set_cred_option): init global
1312*c19800e8SDoug Rabson	kerberos context
1313*c19800e8SDoug Rabson
1314*c19800e8SDoug Rabson	* mech/gss_accept_sec_context.c: Insert the delegated sub cred on
1315*c19800e8SDoug Rabson	the delegated cred handle, not cred handle
1316*c19800e8SDoug Rabson
1317*c19800e8SDoug Rabson	* mech/gss_accept_sec_context.c (gss_accept_sec_context): handle
1318*c19800e8SDoug Rabson	the case where ret_flags == NULL
1319*c19800e8SDoug Rabson
1320*c19800e8SDoug Rabson	* mech/gss_mech_switch.c (add_builtin): set
1321*c19800e8SDoug Rabson	_gss_mech_switch->gm_mech_oid
1322*c19800e8SDoug Rabson
1323*c19800e8SDoug Rabson	* mech/gss_set_cred_option.c (gss_set_cred_option): laod mechs
1324*c19800e8SDoug Rabson
1325*c19800e8SDoug Rabson	* test_cred.c (gss_print_errors): don't try to print error when
1326*c19800e8SDoug Rabson	gss_display_status failed
1327*c19800e8SDoug Rabson
1328*c19800e8SDoug Rabson	* Makefile.am: Add mech/gss_release_oid.c
1329*c19800e8SDoug Rabson
1330*c19800e8SDoug Rabson	* mech/gss_release_oid.c: Add gss_release_oid, reverse of
1331*c19800e8SDoug Rabson	gss_duplicate_oid
1332*c19800e8SDoug Rabson
1333*c19800e8SDoug Rabson	* spnego/compat.c: preferred_mech_type was allocated with
1334*c19800e8SDoug Rabson	gss_duplicate_oid in one place and assigned static varianbles a
1335*c19800e8SDoug Rabson	the second place. change that static assignement to
1336*c19800e8SDoug Rabson	gss_duplicate_oid and bring back gss_release_oid.
1337*c19800e8SDoug Rabson
1338*c19800e8SDoug Rabson	* spnego/compat.c (_gss_spnego_delete_sec_context): don't release
1339*c19800e8SDoug Rabson	preferred_mech_type and negotiated_mech_type, they where never
1340*c19800e8SDoug Rabson	allocated from the begining.
1341*c19800e8SDoug Rabson
1342*c19800e8SDoug Rabson2006-06-29  Love Hörnquist Åstrand  <[email protected]>
1343*c19800e8SDoug Rabson
1344*c19800e8SDoug Rabson	* mech/gss_import_name.c (gss_import_name): avoid
1345*c19800e8SDoug Rabson	type-punned/strict aliasing rules
1346*c19800e8SDoug Rabson
1347*c19800e8SDoug Rabson	* mech/gss_add_cred.c: avoid type-punned/strict aliasing rules
1348*c19800e8SDoug Rabson
1349*c19800e8SDoug Rabson	* gssapi.h: Make gss_name_t an opaque type.
1350*c19800e8SDoug Rabson
1351*c19800e8SDoug Rabson	* krb5: make gss_name_t an opaque type
1352*c19800e8SDoug Rabson
1353*c19800e8SDoug Rabson	* krb5/set_cred_option.c: Add
1354*c19800e8SDoug Rabson
1355*c19800e8SDoug Rabson	* mech/gss_set_cred_option.c (gss_set_cred_option): support the
1356*c19800e8SDoug Rabson	case where *cred_handle == NULL
1357*c19800e8SDoug Rabson
1358*c19800e8SDoug Rabson	* mech/gss_krb5.c (gss_krb5_import_cred): make sure cred is
1359*c19800e8SDoug Rabson	GSS_C_NO_CREDENTIAL on failure.
1360*c19800e8SDoug Rabson
1361*c19800e8SDoug Rabson	* mech/gss_acquire_cred.c (gss_acquire_cred): if desired_mechs is
1362*c19800e8SDoug Rabson	NO_OID_SET, there is a need to load the mechs, so always do that.
1363*c19800e8SDoug Rabson
1364*c19800e8SDoug Rabson2006-06-28  Love Hörnquist Åstrand  <[email protected]>
1365*c19800e8SDoug Rabson
1366*c19800e8SDoug Rabson	* krb5/inquire_cred_by_oid.c: Reimplement GSS_KRB5_COPY_CCACHE_X
1367*c19800e8SDoug Rabson	to instead pass a fullname to the credential, then resolve and
1368*c19800e8SDoug Rabson	copy out the content, and then close the cred.
1369*c19800e8SDoug Rabson
1370*c19800e8SDoug Rabson	* mech/gss_krb5.c: Reimplement GSS_KRB5_COPY_CCACHE_X to instead
1371*c19800e8SDoug Rabson	pass a fullname to the credential, then resolve and copy out the
1372*c19800e8SDoug Rabson	content, and then close the cred.
1373*c19800e8SDoug Rabson
1374*c19800e8SDoug Rabson	* krb5/inquire_cred_by_oid.c: make "work", GSS_KRB5_COPY_CCACHE_X
1375*c19800e8SDoug Rabson	interface needs to be re-done, currently its utterly broken.
1376*c19800e8SDoug Rabson
1377*c19800e8SDoug Rabson	* mech/gss_set_cred_option.c: Make work.
1378*c19800e8SDoug Rabson
1379*c19800e8SDoug Rabson	* krb5/external.c: Add _gsskrb5_set_{sec_context,cred}_option
1380*c19800e8SDoug Rabson
1381*c19800e8SDoug Rabson	* mech/gss_krb5.c (gss_krb5_import_cred): implement
1382*c19800e8SDoug Rabson
1383*c19800e8SDoug Rabson	* Makefile.am: Add gss_set_{sec_context,cred}_option and sort
1384*c19800e8SDoug Rabson
1385*c19800e8SDoug Rabson	* mech/gss_set_{sec_context,cred}_option.c: add
1386*c19800e8SDoug Rabson
1387*c19800e8SDoug Rabson	* gssapi.h: Add GSS_KRB5_IMPORT_CRED_X
1388*c19800e8SDoug Rabson
1389*c19800e8SDoug Rabson	* test_*.c: make compile again
1390*c19800e8SDoug Rabson
1391*c19800e8SDoug Rabson	* Makefile.am: Add lib dependencies and test programs
1392*c19800e8SDoug Rabson
1393*c19800e8SDoug Rabson	* spnego: remove dependency on libkrb5
1394*c19800e8SDoug Rabson
1395*c19800e8SDoug Rabson	* mech: Bug fixes, cleanup, compiler warnings, restructure code.
1396*c19800e8SDoug Rabson
1397*c19800e8SDoug Rabson	* spnego: Rename gss_context_id_t and gss_cred_id_t to local names
1398*c19800e8SDoug Rabson
1399*c19800e8SDoug Rabson	* krb5: repro copy the krb5 files here
1400*c19800e8SDoug Rabson
1401*c19800e8SDoug Rabson	* mech: import Doug Rabson mechglue from freebsd
1402*c19800e8SDoug Rabson
1403*c19800e8SDoug Rabson	* spnego: Import Luke Howard's SPNEGO from the mechglue branch
1404*c19800e8SDoug Rabson
1405*c19800e8SDoug Rabson2006-06-22  Love Hörnquist Åstrand  <[email protected]>
1406*c19800e8SDoug Rabson
1407*c19800e8SDoug Rabson	* gssapi.h: Add oid_to_str.
1408*c19800e8SDoug Rabson
1409*c19800e8SDoug Rabson	* Makefile.am: add oid_to_str and test_oid
1410*c19800e8SDoug Rabson
1411*c19800e8SDoug Rabson	* oid_to_str.c: Add gss_oid_to_str
1412*c19800e8SDoug Rabson
1413*c19800e8SDoug Rabson	* test_oid.c: Add test for gss_oid_to_str()
1414*c19800e8SDoug Rabson
1415*c19800e8SDoug Rabson2006-05-13  Love Hörnquist Åstrand  <[email protected]>
1416*c19800e8SDoug Rabson
1417*c19800e8SDoug Rabson	* verify_mic.c: Less pointer signedness warnings.
1418*c19800e8SDoug Rabson
1419*c19800e8SDoug Rabson	* unwrap.c: Less pointer signedness warnings.
1420*c19800e8SDoug Rabson
1421*c19800e8SDoug Rabson	* arcfour.c: Less pointer signedness warnings.
1422*c19800e8SDoug Rabson
1423*c19800e8SDoug Rabson	* gssapi_locl.h: Use const void * to instead of unsigned char * to
1424*c19800e8SDoug Rabson	avoid pointer signedness warnings.
1425*c19800e8SDoug Rabson
1426*c19800e8SDoug Rabson	* encapsulate.c: Use const void * to instead of unsigned char * to
1427*c19800e8SDoug Rabson	avoid pointer signedness warnings.
1428*c19800e8SDoug Rabson
1429*c19800e8SDoug Rabson	* decapsulate.c: Use const void * to instead of unsigned char * to
1430*c19800e8SDoug Rabson	avoid pointer signedness warnings.
1431*c19800e8SDoug Rabson
1432*c19800e8SDoug Rabson	* decapsulate.c: Less pointer signedness warnings.
1433*c19800e8SDoug Rabson
1434*c19800e8SDoug Rabson	* cfx.c: Less pointer signedness warnings.
1435*c19800e8SDoug Rabson
1436*c19800e8SDoug Rabson	* init_sec_context.c: Less pointer signedness warnings (partly by
1437*c19800e8SDoug Rabson	using the new asn.1 CHOICE decoder)
1438*c19800e8SDoug Rabson
1439*c19800e8SDoug Rabson	* import_sec_context.c: Less pointer signedness warnings.
1440*c19800e8SDoug Rabson
1441*c19800e8SDoug Rabson2006-05-09  Love Hörnquist Åstrand  <[email protected]>
1442*c19800e8SDoug Rabson
1443*c19800e8SDoug Rabson	* accept_sec_context.c (gsskrb5_is_cfx): always set is_cfx. From
1444*c19800e8SDoug Rabson	Andrew Abartlet.
1445*c19800e8SDoug Rabson
1446*c19800e8SDoug Rabson2006-05-08  Love Hörnquist Åstrand  <[email protected]>
1447*c19800e8SDoug Rabson
1448*c19800e8SDoug Rabson	* get_mic.c (mic_des3): make sure message_buffer doesn't point to
1449*c19800e8SDoug Rabson	free()ed memory on failure. Pointed out by IBM checker.
1450*c19800e8SDoug Rabson
1451*c19800e8SDoug Rabson2006-05-05  Love Hörnquist Åstrand  <[email protected]>
1452*c19800e8SDoug Rabson
1453*c19800e8SDoug Rabson	* Rename u_intXX_t to uintXX_t
1454*c19800e8SDoug Rabson
1455*c19800e8SDoug Rabson2006-05-04 Love Hörnquist Åstrand <[email protected]>
1456*c19800e8SDoug Rabson
1457*c19800e8SDoug Rabson	* cfx.c: Less pointer signedness warnings.
1458*c19800e8SDoug Rabson
1459*c19800e8SDoug Rabson	* arcfour.c: Avoid pointer signedness warnings.
1460*c19800e8SDoug Rabson
1461*c19800e8SDoug Rabson	* gssapi_locl.h (gssapi_decode_*): make data argument const void *
1462*c19800e8SDoug Rabson
1463*c19800e8SDoug Rabson	* 8003.c (gssapi_decode_*): make data argument const void *
1464*c19800e8SDoug Rabson
1465*c19800e8SDoug Rabson2006-04-12  Love Hörnquist Åstrand  <[email protected]>
1466*c19800e8SDoug Rabson
1467*c19800e8SDoug Rabson	* export_sec_context.c: Export sequence order element. From Wynn
1468*c19800e8SDoug Rabson	Wilkes <[email protected]>.
1469*c19800e8SDoug Rabson
1470*c19800e8SDoug Rabson	* import_sec_context.c: Import sequence order element. From Wynn
1471*c19800e8SDoug Rabson	Wilkes <[email protected]>.
1472*c19800e8SDoug Rabson
1473*c19800e8SDoug Rabson	* sequence.c (_gssapi_msg_order_import,_gssapi_msg_order_export):
1474*c19800e8SDoug Rabson	New functions, used by {import,export}_sec_context.  From Wynn
1475*c19800e8SDoug Rabson	Wilkes <[email protected]>.
1476*c19800e8SDoug Rabson
1477*c19800e8SDoug Rabson	* test_sequence.c: Add test for import/export sequence.
1478*c19800e8SDoug Rabson
1479*c19800e8SDoug Rabson2006-04-09  Love Hörnquist Åstrand  <[email protected]>
1480*c19800e8SDoug Rabson
1481*c19800e8SDoug Rabson	* add_cred.c: Check that cred != GSS_C_NO_CREDENTIAL, this is a
1482*c19800e8SDoug Rabson	standard conformance failure, but much better then a crash.
1483*c19800e8SDoug Rabson
1484*c19800e8SDoug Rabson2006-04-02  Love Hörnquist Åstrand  <[email protected]>
1485*c19800e8SDoug Rabson
1486*c19800e8SDoug Rabson	* get_mic.c (get_mic*)_: make sure message_token is cleaned on
1487*c19800e8SDoug Rabson	error, found by IBM checker.
1488*c19800e8SDoug Rabson
1489*c19800e8SDoug Rabson	* wrap.c (wrap*): Reset output_buffer on error, found by IBM
1490*c19800e8SDoug Rabson	checker.
1491*c19800e8SDoug Rabson
1492*c19800e8SDoug Rabson2006-02-15  Love Hörnquist Åstrand  <[email protected]>
1493*c19800e8SDoug Rabson
1494*c19800e8SDoug Rabson	* import_name.c: Accept both GSS_C_NT_HOSTBASED_SERVICE and
1495*c19800e8SDoug Rabson	GSS_C_NT_HOSTBASED_SERVICE_X as nametype for hostbased names.
1496*c19800e8SDoug Rabson
1497*c19800e8SDoug Rabson2006-01-16  Love Hörnquist Åstrand  <[email protected]>
1498*c19800e8SDoug Rabson
1499*c19800e8SDoug Rabson	* delete_sec_context.c (gss_delete_sec_context): if the context
1500*c19800e8SDoug Rabson	handle is GSS_C_NO_CONTEXT, don't fall over.
1501*c19800e8SDoug Rabson
1502*c19800e8SDoug Rabson2005-12-12  Love Hörnquist Åstrand  <[email protected]>
1503*c19800e8SDoug Rabson
1504*c19800e8SDoug Rabson	* gss_acquire_cred.3: Replace gss_krb5_import_ccache with
1505*c19800e8SDoug Rabson	gss_krb5_import_cred and add more references
1506*c19800e8SDoug Rabson
1507*c19800e8SDoug Rabson2005-12-05  Love Hörnquist Åstrand  <[email protected]>
1508*c19800e8SDoug Rabson
1509*c19800e8SDoug Rabson	* gssapi.h: Change gss_krb5_import_ccache to gss_krb5_import_cred,
1510*c19800e8SDoug Rabson	it can handle keytabs too.
1511*c19800e8SDoug Rabson
1512*c19800e8SDoug Rabson	* add_cred.c (gss_add_cred): avoid deadlock
1513*c19800e8SDoug Rabson
1514*c19800e8SDoug Rabson	* context_time.c (gssapi_lifetime_left): define the 0 lifetime as
1515*c19800e8SDoug Rabson	GSS_C_INDEFINITE.
1516*c19800e8SDoug Rabson
1517*c19800e8SDoug Rabson2005-12-01  Love Hörnquist Åstrand  <[email protected]>
1518*c19800e8SDoug Rabson
1519*c19800e8SDoug Rabson	* acquire_cred.c (acquire_acceptor_cred): only check if principal
1520*c19800e8SDoug Rabson	exists if we got called with principal as an argument.
1521*c19800e8SDoug Rabson
1522*c19800e8SDoug Rabson	* acquire_cred.c (acquire_acceptor_cred): check that the acceptor
1523*c19800e8SDoug Rabson	exists in the keytab before returning ok.
1524*c19800e8SDoug Rabson
1525*c19800e8SDoug Rabson2005-11-29  Love Hörnquist Åstrand  <[email protected]>
1526*c19800e8SDoug Rabson
1527*c19800e8SDoug Rabson	* copy_ccache.c (gss_krb5_import_cred): fix buglet, from Andrew
1528*c19800e8SDoug Rabson	Bartlett.
1529*c19800e8SDoug Rabson
1530*c19800e8SDoug Rabson2005-11-25  Love Hörnquist Åstrand  <[email protected]>
1531*c19800e8SDoug Rabson
1532*c19800e8SDoug Rabson	* test_kcred.c: Rename gss_krb5_import_ccache to
1533*c19800e8SDoug Rabson	gss_krb5_import_cred.
1534*c19800e8SDoug Rabson
1535*c19800e8SDoug Rabson	* copy_ccache.c: Rename gss_krb5_import_ccache to
1536*c19800e8SDoug Rabson	gss_krb5_import_cred and let it grow code to handle keytabs too.
1537*c19800e8SDoug Rabson
1538*c19800e8SDoug Rabson2005-11-02  Love Hörnquist Åstrand  <[email protected]>
1539*c19800e8SDoug Rabson
1540*c19800e8SDoug Rabson	* init_sec_context.c: Change sematics of ok-as-delegate to match
1541*c19800e8SDoug Rabson	windows if
1542*c19800e8SDoug Rabson	[gssapi]realm/ok-as-delegate=true is set, otherwise keep old
1543*c19800e8SDoug Rabson	sematics.
1544*c19800e8SDoug Rabson
1545*c19800e8SDoug Rabson	* release_cred.c (gss_release_cred): use
1546*c19800e8SDoug Rabson	GSS_CF_DESTROY_CRED_ON_RELEASE to decide if the cache should be
1547*c19800e8SDoug Rabson	krb5_cc_destroy-ed
1548*c19800e8SDoug Rabson
1549*c19800e8SDoug Rabson	* acquire_cred.c (acquire_initiator_cred):
1550*c19800e8SDoug Rabson	GSS_CF_DESTROY_CRED_ON_RELEASE on created credentials.
1551*c19800e8SDoug Rabson
1552*c19800e8SDoug Rabson	* accept_sec_context.c (gsskrb5_accept_delegated_token): rewrite
1553*c19800e8SDoug Rabson	to use gss_krb5_import_ccache
1554*c19800e8SDoug Rabson
1555*c19800e8SDoug Rabson2005-11-01  Love Hörnquist Åstrand  <[email protected]>
1556*c19800e8SDoug Rabson
1557*c19800e8SDoug Rabson	* arcfour.c: Remove signedness warnings.
1558*c19800e8SDoug Rabson
1559*c19800e8SDoug Rabson2005-10-31  Love Hörnquist Åstrand  <[email protected]>
1560*c19800e8SDoug Rabson
1561*c19800e8SDoug Rabson	* gss_acquire_cred.3: Document that gss_krb5_import_ccache is copy
1562*c19800e8SDoug Rabson	by reference.
1563*c19800e8SDoug Rabson
1564*c19800e8SDoug Rabson	* copy_ccache.c (gss_krb5_import_ccache): Instead of making a copy
1565*c19800e8SDoug Rabson	of the ccache, make a reference by getting the name and resolving
1566*c19800e8SDoug Rabson	the name. This way the cache is shared, this flipp side is of
1567*c19800e8SDoug Rabson	course that if someone calls krb5_cc_destroy the cache is lost for
1568*c19800e8SDoug Rabson	everyone.
1569*c19800e8SDoug Rabson
1570*c19800e8SDoug Rabson	* test_kcred.c: Remove memory leaks.
1571*c19800e8SDoug Rabson
1572*c19800e8SDoug Rabson2005-10-26  Love Hörnquist Åstrand  <[email protected]>
1573*c19800e8SDoug Rabson
1574*c19800e8SDoug Rabson	* Makefile.am: build test_kcred
1575*c19800e8SDoug Rabson
1576*c19800e8SDoug Rabson	* gss_acquire_cred.3: Document gss_krb5_import_ccache
1577*c19800e8SDoug Rabson
1578*c19800e8SDoug Rabson	* gssapi.3: Sort and add gss_krb5_import_ccache.
1579*c19800e8SDoug Rabson
1580*c19800e8SDoug Rabson	* acquire_cred.c (_gssapi_krb5_ccache_lifetime): break out code
1581*c19800e8SDoug Rabson	used to extract lifetime from a credential cache
1582*c19800e8SDoug Rabson
1583*c19800e8SDoug Rabson	* gssapi_locl.h: Add _gssapi_krb5_ccache_lifetime, used to extract
1584*c19800e8SDoug Rabson	lifetime from a credential cache.
1585*c19800e8SDoug Rabson
1586*c19800e8SDoug Rabson	* gssapi.h: add gss_krb5_import_ccache, reverse of
1587*c19800e8SDoug Rabson	gss_krb5_copy_ccache
1588*c19800e8SDoug Rabson
1589*c19800e8SDoug Rabson	* copy_ccache.c: add gss_krb5_import_ccache, reverse of
1590*c19800e8SDoug Rabson	gss_krb5_copy_ccache
1591*c19800e8SDoug Rabson
1592*c19800e8SDoug Rabson	* test_kcred.c: test gss_krb5_import_ccache
1593*c19800e8SDoug Rabson
1594*c19800e8SDoug Rabson2005-10-21  Love Hörnquist Åstrand  <[email protected]>
1595*c19800e8SDoug Rabson
1596*c19800e8SDoug Rabson	* acquire_cred.c (acquire_initiator_cred): use krb5_cc_cache_match
1597*c19800e8SDoug Rabson	to find a matching creditial cache, if that failes, fallback to
1598*c19800e8SDoug Rabson	the default cache.
1599*c19800e8SDoug Rabson
1600*c19800e8SDoug Rabson2005-10-12  Love Hörnquist Åstrand  <[email protected]>
1601*c19800e8SDoug Rabson
1602*c19800e8SDoug Rabson	* gssapi_locl.h: Add gssapi_krb5_set_status and
1603*c19800e8SDoug Rabson	gssapi_krb5_clear_status
1604*c19800e8SDoug Rabson
1605*c19800e8SDoug Rabson	* init_sec_context.c (spnego_reply): Don't pass back raw Kerberos
1606*c19800e8SDoug Rabson	errors, use GSS-API errors instead. From Michael B Allen.
1607*c19800e8SDoug Rabson
1608*c19800e8SDoug Rabson	* display_status.c: Add gssapi_krb5_clear_status,
1609*c19800e8SDoug Rabson	gssapi_krb5_set_status for handling error messages.
1610*c19800e8SDoug Rabson
1611*c19800e8SDoug Rabson2005-08-23  Love Hörnquist Åstrand  <[email protected]>
1612*c19800e8SDoug Rabson
1613*c19800e8SDoug Rabson	* external.c: Use rk_UNCONST to avoid const warning.
1614*c19800e8SDoug Rabson
1615*c19800e8SDoug Rabson	* display_status.c: Constify strings to avoid warnings.
1616*c19800e8SDoug Rabson
1617*c19800e8SDoug Rabson2005-08-11 Love Hörnquist Åstrand  <[email protected]>
1618*c19800e8SDoug Rabson
1619*c19800e8SDoug Rabson	* init_sec_context.c: avoid warnings, update (c)
1620*c19800e8SDoug Rabson
1621*c19800e8SDoug Rabson2005-07-13  Love Hörnquist Åstrand  <[email protected]>
1622*c19800e8SDoug Rabson
1623*c19800e8SDoug Rabson	* init_sec_context.c (spnego_initial): use NegotiationToken
1624*c19800e8SDoug Rabson	encoder now that we have one with the new asn1. compiler.
1625*c19800e8SDoug Rabson
1626*c19800e8SDoug Rabson	* Makefile.am: the new asn.1 compiler includes the modules name in
1627*c19800e8SDoug Rabson	the depend file
1628*c19800e8SDoug Rabson
1629*c19800e8SDoug Rabson2005-06-16  Love Hörnquist Åstrand  <[email protected]>
1630*c19800e8SDoug Rabson
1631*c19800e8SDoug Rabson	* decapsulate.c: use rk_UNCONST
1632*c19800e8SDoug Rabson
1633*c19800e8SDoug Rabson	* ccache_name.c: rename to avoid shadowing
1634*c19800e8SDoug Rabson
1635*c19800e8SDoug Rabson	* gssapi_locl.h: give kret in GSSAPI_KRB5_INIT a more unique name
1636*c19800e8SDoug Rabson
1637*c19800e8SDoug Rabson	* process_context_token.c: use rk_UNCONST to unconstify
1638*c19800e8SDoug Rabson
1639*c19800e8SDoug Rabson	* test_cred.c: rename optind to optidx
1640*c19800e8SDoug Rabson
1641*c19800e8SDoug Rabson2005-05-30  Love Hörnquist Åstrand  <[email protected]>
1642*c19800e8SDoug Rabson
1643*c19800e8SDoug Rabson	* init_sec_context.c (init_auth): honor ok-as-delegate if local
1644*c19800e8SDoug Rabson	configuration approves
1645*c19800e8SDoug Rabson
1646*c19800e8SDoug Rabson	* gssapi_locl.h: prototype for _gss_check_compat
1647*c19800e8SDoug Rabson
1648*c19800e8SDoug Rabson	* compat.c: export check_compat as _gss_check_compat
1649*c19800e8SDoug Rabson
1650*c19800e8SDoug Rabson2005-05-29  Love Hörnquist Åstrand  <[email protected]>
1651*c19800e8SDoug Rabson
1652*c19800e8SDoug Rabson	* init_sec_context.c: Prefix Der_class with ASN1_C_ to avoid
1653*c19800e8SDoug Rabson	problems with system headerfiles that pollute the name space.
1654*c19800e8SDoug Rabson
1655*c19800e8SDoug Rabson	* accept_sec_context.c: Prefix Der_class with ASN1_C_ to avoid
1656*c19800e8SDoug Rabson	problems with system headerfiles that pollute the name space.
1657*c19800e8SDoug Rabson
1658*c19800e8SDoug Rabson2005-05-17  Love Hörnquist Åstrand  <[email protected]>
1659*c19800e8SDoug Rabson
1660*c19800e8SDoug Rabson	* init_sec_context.c (init_auth): set
1661*c19800e8SDoug Rabson	KRB5_AUTH_CONTEXT_CLEAR_FORWARDED_CRED (for java compatibility),
1662*c19800e8SDoug Rabson	also while here, use krb5_auth_con_addflags
1663*c19800e8SDoug Rabson
1664*c19800e8SDoug Rabson2005-05-06  Love Hörnquist Åstrand  <[email protected]>
1665*c19800e8SDoug Rabson
1666*c19800e8SDoug Rabson	* arcfour.c (_gssapi_wrap_arcfour): fix calculating the encap
1667*c19800e8SDoug Rabson	length. From: Tom Maher <[email protected]>
1668*c19800e8SDoug Rabson
1669*c19800e8SDoug Rabson2005-05-02  Dave Love  <[email protected]>
1670*c19800e8SDoug Rabson
1671*c19800e8SDoug Rabson	* test_cred.c (main): Call setprogname.
1672*c19800e8SDoug Rabson
1673*c19800e8SDoug Rabson2005-04-27  Love Hörnquist Åstrand  <[email protected]>
1674*c19800e8SDoug Rabson
1675*c19800e8SDoug Rabson	* prefix all sequence symbols with _, they are not part of the
1676*c19800e8SDoug Rabson	GSS-API api. By comment from Wynn Wilkes <[email protected]>
1677*c19800e8SDoug Rabson
1678*c19800e8SDoug Rabson2005-04-10  Love Hörnquist Åstrand  <[email protected]>
1679*c19800e8SDoug Rabson
1680*c19800e8SDoug Rabson	* accept_sec_context.c: break out the processing of the delegated
1681*c19800e8SDoug Rabson	credential to a separate function to make error handling easier,
1682*c19800e8SDoug Rabson	move the credential handling to after other setup is done
1683*c19800e8SDoug Rabson
1684*c19800e8SDoug Rabson	* test_sequence.c: make less verbose in case of success
1685*c19800e8SDoug Rabson
1686*c19800e8SDoug Rabson	* Makefile.am: add test_sequence to TESTS
1687*c19800e8SDoug Rabson
1688*c19800e8SDoug Rabson2005-04-01  Love Hörnquist Åstrand  <[email protected]>
1689*c19800e8SDoug Rabson
1690*c19800e8SDoug Rabson	* 8003.c (gssapi_krb5_verify_8003_checksum): check that cksum
1691*c19800e8SDoug Rabson	isn't NULL From: Nicolas Pouvesle <[email protected]>
1692*c19800e8SDoug Rabson
1693*c19800e8SDoug Rabson2005-03-21  Love Hörnquist Åstrand  <[email protected]>
1694*c19800e8SDoug Rabson
1695*c19800e8SDoug Rabson	* Makefile.am: use $(LIB_roken)
1696*c19800e8SDoug Rabson
1697*c19800e8SDoug Rabson2005-03-16  Love Hörnquist Åstrand  <[email protected]>
1698*c19800e8SDoug Rabson
1699*c19800e8SDoug Rabson	* display_status.c (gssapi_krb5_set_error_string): pass in the
1700*c19800e8SDoug Rabson	krb5_context to krb5_free_error_string
1701*c19800e8SDoug Rabson
1702*c19800e8SDoug Rabson2005-03-15  Love Hörnquist Åstrand  <[email protected]>
1703*c19800e8SDoug Rabson
1704*c19800e8SDoug Rabson	* display_status.c (gssapi_krb5_set_error_string): don't misuse
1705*c19800e8SDoug Rabson	the krb5_get_error_string api
1706*c19800e8SDoug Rabson
1707*c19800e8SDoug Rabson2005-03-01  Love Hörnquist Åstrand  <[email protected]>
1708*c19800e8SDoug Rabson
1709*c19800e8SDoug Rabson	* compat.c (_gss_DES3_get_mic_compat): don't unlock mutex
1710*c19800e8SDoug Rabson	here. Bug reported by Stefan Metzmacher <[email protected]>
1711*c19800e8SDoug Rabson
1712*c19800e8SDoug Rabson2005-02-21  Luke Howard  <[email protected]>
1713*c19800e8SDoug Rabson
1714*c19800e8SDoug Rabson	* init_sec_context.c: don't call krb5_get_credentials() with
1715*c19800e8SDoug Rabson	  KRB5_TC_MATCH_KEYTYPE, it can lead to the credentials cache
1716*c19800e8SDoug Rabson	  growing indefinitely as no key is found with KEYTYPE_NULL
1717*c19800e8SDoug Rabson
1718*c19800e8SDoug Rabson	* compat.c: remove GSS_C_EXPECTING_MECH_LIST_MIC_FLAG, it is
1719*c19800e8SDoug Rabson	  no longer used (however the mechListMIC behaviour is broken,
1720*c19800e8SDoug Rabson	  rfc2478bis support requires the code in the mechglue branch)
1721*c19800e8SDoug Rabson
1722*c19800e8SDoug Rabson	* init_sec_context.c: remove GSS_C_EXPECTING_MECH_LIST_MIC_FLAG
1723*c19800e8SDoug Rabson
1724*c19800e8SDoug Rabson	* gssapi.h: remove GSS_C_EXPECTING_MECH_LIST_MIC_FLAG
1725*c19800e8SDoug Rabson
1726*c19800e8SDoug Rabson2005-01-05  Luke Howard  <[email protected]>
1727*c19800e8SDoug Rabson
1728*c19800e8SDoug Rabson	* 8003.c: use symbolic name for checksum type
1729*c19800e8SDoug Rabson
1730*c19800e8SDoug Rabson	* accept_sec_context.c: allow client to indicate
1731*c19800e8SDoug Rabson	  that subkey should be used
1732*c19800e8SDoug Rabson
1733*c19800e8SDoug Rabson	* acquire_cred.c: plug leak
1734*c19800e8SDoug Rabson
1735*c19800e8SDoug Rabson	* get_mic.c: use gss_krb5_get_subkey() instead
1736*c19800e8SDoug Rabson	  of gss_krb5_get_{local,remote}key(), support
1737*c19800e8SDoug Rabson	  KEYTYPE_ARCFOUR_56
1738*c19800e8SDoug Rabson
1739*c19800e8SDoug Rabson	* gssapi_local.c: use gss_krb5_get_subkey(),
1740*c19800e8SDoug Rabson	  support KEYTYPE_ARCFOUR_56
1741*c19800e8SDoug Rabson
1742*c19800e8SDoug Rabson	* import_sec_context.c: plug leak
1743*c19800e8SDoug Rabson
1744*c19800e8SDoug Rabson	* unwrap.c: use gss_krb5_get_subkey(),
1745*c19800e8SDoug Rabson	  support KEYTYPE_ARCFOUR_56
1746*c19800e8SDoug Rabson
1747*c19800e8SDoug Rabson	* verify_mic.c: use gss_krb5_get_subkey(),
1748*c19800e8SDoug Rabson	  support KEYTYPE_ARCFOUR_56
1749*c19800e8SDoug Rabson
1750*c19800e8SDoug Rabson	* wrap.c: use gss_krb5_get_subkey(),
1751*c19800e8SDoug Rabson	  support KEYTYPE_ARCFOUR_56
1752*c19800e8SDoug Rabson
1753*c19800e8SDoug Rabson2004-11-30  Love Hörnquist Åstrand  <[email protected]>
1754*c19800e8SDoug Rabson
1755*c19800e8SDoug Rabson	* inquire_cred.c: Reverse order of HEIMDAL_MUTEX_unlock and
1756*c19800e8SDoug Rabson	gss_release_cred to avoid deadlock, from Luke Howard
1757*c19800e8SDoug Rabson	<[email protected]>.
1758*c19800e8SDoug Rabson
1759*c19800e8SDoug Rabson2004-09-06  Love Hörnquist Åstrand  <[email protected]>
1760*c19800e8SDoug Rabson
1761*c19800e8SDoug Rabson	* gss_acquire_cred.3: gss_krb5_extract_authz_data_from_sec_context
1762*c19800e8SDoug Rabson	was renamed to gsskrb5_extract_authz_data_from_sec_context
1763*c19800e8SDoug Rabson
1764*c19800e8SDoug Rabson2004-08-07  Love Hörnquist Åstrand  <[email protected]>
1765*c19800e8SDoug Rabson
1766*c19800e8SDoug Rabson	* unwrap.c: mutex buglet, From: Luke Howard <[email protected]>
1767*c19800e8SDoug Rabson
1768*c19800e8SDoug Rabson	* arcfour.c: mutex buglet, From: Luke Howard <[email protected]>
1769*c19800e8SDoug Rabson
1770*c19800e8SDoug Rabson2004-05-06  Love Hörnquist Åstrand  <[email protected]>
1771*c19800e8SDoug Rabson
1772*c19800e8SDoug Rabson	* gssapi.3: spelling from Josef El-Rayes <[email protected]> while
1773*c19800e8SDoug Rabson	here, write some text about the SPNEGO situation
1774*c19800e8SDoug Rabson
1775*c19800e8SDoug Rabson2004-04-08  Love Hörnquist Åstrand  <[email protected]>
1776*c19800e8SDoug Rabson
1777*c19800e8SDoug Rabson	* cfx.c: s/CTXAcceptorSubkey/CFXAcceptorSubkey/
1778*c19800e8SDoug Rabson
1779*c19800e8SDoug Rabson2004-04-07  Love Hörnquist Åstrand  <[email protected]>
1780*c19800e8SDoug Rabson
1781*c19800e8SDoug Rabson	* gssapi.h: add GSS_C_EXPECTING_MECH_LIST_MIC_FLAG From: Luke
1782*c19800e8SDoug Rabson	Howard <[email protected]>
1783*c19800e8SDoug Rabson
1784*c19800e8SDoug Rabson	* init_sec_context.c (spnego_reply): use
1785*c19800e8SDoug Rabson	_gss_spnego_require_mechlist_mic to figure out if we need to check
1786*c19800e8SDoug Rabson	MechListMIC; From: Luke Howard <[email protected]>
1787*c19800e8SDoug Rabson
1788*c19800e8SDoug Rabson	* accept_sec_context.c (send_accept): use
1789*c19800e8SDoug Rabson	_gss_spnego_require_mechlist_mic to figure out if we need to send
1790*c19800e8SDoug Rabson	MechListMIC; From: Luke Howard <[email protected]>
1791*c19800e8SDoug Rabson
1792*c19800e8SDoug Rabson	* gssapi_locl.h: add _gss_spnego_require_mechlist_mic
1793*c19800e8SDoug Rabson	From: Luke Howard <[email protected]>
1794*c19800e8SDoug Rabson
1795*c19800e8SDoug Rabson	* compat.c: add _gss_spnego_require_mechlist_mic for compatibility
1796*c19800e8SDoug Rabson	with MS SPNEGO, From: Luke Howard <[email protected]>
1797*c19800e8SDoug Rabson
1798*c19800e8SDoug Rabson2004-04-05  Love Hörnquist Åstrand  <[email protected]>
1799*c19800e8SDoug Rabson
1800*c19800e8SDoug Rabson	* accept_sec_context.c (gsskrb5_is_cfx): krb5_keyblock->keytype is
1801*c19800e8SDoug Rabson	an enctype, not keytype
18021c43270aSJacques Vidrine
18031c43270aSJacques Vidrine	* accept_sec_context.c: use ASN1_MALLOC_ENCODE
1804*c19800e8SDoug Rabson
18051c43270aSJacques Vidrine	* init_sec_context.c: avoid the malloc loop and just allocate the
1806*c19800e8SDoug Rabson	propper amount of data
1807*c19800e8SDoug Rabson
1808*c19800e8SDoug Rabson	* init_sec_context.c (spnego_initial): handle mech_token better
1809*c19800e8SDoug Rabson
1810*c19800e8SDoug Rabson2004-03-19  Love Hörnquist Åstrand  <[email protected]>
1811*c19800e8SDoug Rabson
1812*c19800e8SDoug Rabson	* gssapi.h: add gss_krb5_get_tkt_flags
1813*c19800e8SDoug Rabson
1814*c19800e8SDoug Rabson	* Makefile.am: add ticket_flags.c
1815*c19800e8SDoug Rabson
1816*c19800e8SDoug Rabson	* ticket_flags.c: Get ticket-flags from acceptor ticket From: Luke
1817*c19800e8SDoug Rabson	Howard <[email protected]>
1818*c19800e8SDoug Rabson
1819*c19800e8SDoug Rabson	* gss_acquire_cred.3: document gss_krb5_get_tkt_flags
1820*c19800e8SDoug Rabson
1821*c19800e8SDoug Rabson2004-03-14  Love Hörnquist Åstrand  <[email protected]>
18221c43270aSJacques Vidrine
18231c43270aSJacques Vidrine	* acquire_cred.c (gss_acquire_cred): check usage before even
18241c43270aSJacques Vidrine	bothering to process it, add both keytab and initial tgt if
1825*c19800e8SDoug Rabson	requested
1826*c19800e8SDoug Rabson
1827*c19800e8SDoug Rabson	* wrap.c: support cfx, try to handle acceptor asserted subkey
1828*c19800e8SDoug Rabson
1829*c19800e8SDoug Rabson	* unwrap.c: support cfx, try to handle acceptor asserted subkey
1830*c19800e8SDoug Rabson
1831*c19800e8SDoug Rabson	* verify_mic.c: support cfx
1832*c19800e8SDoug Rabson
1833*c19800e8SDoug Rabson	* get_mic.c: support cfx
1834*c19800e8SDoug Rabson
1835*c19800e8SDoug Rabson	* test_sequence.c: handle changed signature of
1836*c19800e8SDoug Rabson	gssapi_msg_order_create
1837*c19800e8SDoug Rabson
1838*c19800e8SDoug Rabson	* import_sec_context.c: handle acceptor asserted subkey
1839*c19800e8SDoug Rabson
1840*c19800e8SDoug Rabson	* init_sec_context.c: handle acceptor asserted subkey
1841*c19800e8SDoug Rabson
1842*c19800e8SDoug Rabson	* accept_sec_context.c: handle acceptor asserted subkey
1843*c19800e8SDoug Rabson
1844*c19800e8SDoug Rabson	* sequence.c: add dummy use_64 argument to gssapi_msg_order_create
1845*c19800e8SDoug Rabson
1846*c19800e8SDoug Rabson	* gssapi_locl.h: add partial support for CFX
1847*c19800e8SDoug Rabson
1848*c19800e8SDoug Rabson	* Makefile.am (noinst_PROGRAMS) += test_cred
1849*c19800e8SDoug Rabson
1850*c19800e8SDoug Rabson	* test_cred.c: gssapi credential testing
1851*c19800e8SDoug Rabson
1852*c19800e8SDoug Rabson	* test_acquire_cred.c: fix comment
1853*c19800e8SDoug Rabson
1854*c19800e8SDoug Rabson2004-03-07  Love Hörnquist Åstrand  <[email protected]>
1855*c19800e8SDoug Rabson
1856*c19800e8SDoug Rabson	* arcfour.h: drop structures for message formats, no longer used
1857*c19800e8SDoug Rabson
1858*c19800e8SDoug Rabson	* arcfour.c: comment describing message formats
1859*c19800e8SDoug Rabson
1860*c19800e8SDoug Rabson	* accept_sec_context.c (spnego_accept_sec_context): make sure the
18611c43270aSJacques Vidrine	length of the choice element doesn't overrun us
18621c43270aSJacques Vidrine
18631c43270aSJacques Vidrine	* init_sec_context.c (spnego_reply): make sure the length of the
1864*c19800e8SDoug Rabson	choice element doesn't overrun us
1865*c19800e8SDoug Rabson
18661c43270aSJacques Vidrine	* spnego.asn1: move NegotiationToken to avoid warning
1867*c19800e8SDoug Rabson
1868*c19800e8SDoug Rabson	* spnego.asn1: uncomment NegotiationToken
18691c43270aSJacques Vidrine
18701c43270aSJacques Vidrine	* Makefile.am: spnego_files += asn1_NegotiationToken.x
18711c43270aSJacques Vidrine
1872*c19800e8SDoug Rabson2004-01-25  Love Hörnquist Åstrand  <[email protected]>
18731c43270aSJacques Vidrine
1874*c19800e8SDoug Rabson	* gssapi.h: add gss_krb5_ccache_name
18751c43270aSJacques Vidrine
1876*c19800e8SDoug Rabson	* Makefile.am (libgssapi_la_SOURCES): += ccache_name.c
1877*c19800e8SDoug Rabson
1878*c19800e8SDoug Rabson	* ccache_name.c (gss_krb5_ccache_name): help function enable to
18791c43270aSJacques Vidrine	set krb5 name, using out_name argument makes function no longer
1880*c19800e8SDoug Rabson	thread-safe
1881*c19800e8SDoug Rabson
18821c43270aSJacques Vidrine	* gssapi.3: add missing gss_krb5_ references
1883*c19800e8SDoug Rabson
18841c43270aSJacques Vidrine	* gss_acquire_cred.3: document gss_krb5_ccache_name
1885*c19800e8SDoug Rabson
1886*c19800e8SDoug Rabson2003-12-12  Love Hörnquist Åstrand  <[email protected]>
1887*c19800e8SDoug Rabson
18881c43270aSJacques Vidrine	* cfx.c: make rrc a modulus operation if its longer then the
1889*c19800e8SDoug Rabson	length of the message, noticed by Sam Hartman
1890*c19800e8SDoug Rabson
18911c43270aSJacques Vidrine2003-12-07  Love Hörnquist Åstrand  <[email protected]>
1892*c19800e8SDoug Rabson
18931c43270aSJacques Vidrine	* accept_sec_context.c: use krb5_auth_con_addflags
1894*c19800e8SDoug Rabson
1895*c19800e8SDoug Rabson2003-12-05  Love Hörnquist Åstrand  <[email protected]>
18961c43270aSJacques Vidrine
1897*c19800e8SDoug Rabson	* cfx.c: Wrap token id was in wrong order, found by Sam Hartman
18981c43270aSJacques Vidrine
1899*c19800e8SDoug Rabson2003-12-04  Love Hörnquist Åstrand  <[email protected]>
1900*c19800e8SDoug Rabson
1901*c19800e8SDoug Rabson	* cfx.c: add AcceptorSubkey (but no code understand it yet) ignore
1902*c19800e8SDoug Rabson	unknown token flags
1903*c19800e8SDoug Rabson
1904*c19800e8SDoug Rabson2003-11-22  Love Hörnquist Åstrand  <[email protected]>
1905*c19800e8SDoug Rabson
1906*c19800e8SDoug Rabson	* accept_sec_context.c: Don't require timestamp to be set on
1907*c19800e8SDoug Rabson	delegated token, its already protected by the outer token (and
1908*c19800e8SDoug Rabson	windows doesn't alway send it) Pointed out by Zi-Bin Yang
1909*c19800e8SDoug Rabson	<[email protected]> on heimdal-discuss
1910*c19800e8SDoug Rabson
1911*c19800e8SDoug Rabson2003-11-14  Love Hörnquist Åstrand  <[email protected]>
1912*c19800e8SDoug Rabson
1913*c19800e8SDoug Rabson	* cfx.c: fix {} error, pointed out by Liqiang Zhu
1914*c19800e8SDoug Rabson
1915*c19800e8SDoug Rabson2003-11-10  Love Hörnquist Åstrand  <[email protected]>
1916*c19800e8SDoug Rabson
1917*c19800e8SDoug Rabson	* cfx.c: Sequence number should be stored in bigendian order From:
1918*c19800e8SDoug Rabson	Luke Howard <[email protected]>
1919*c19800e8SDoug Rabson
1920*c19800e8SDoug Rabson2003-11-09  Love Hörnquist Åstrand  <[email protected]>
1921*c19800e8SDoug Rabson
1922*c19800e8SDoug Rabson	* delete_sec_context.c (gss_delete_sec_context): don't free
1923*c19800e8SDoug Rabson	ticket, krb5_free_ticket does that now
1924*c19800e8SDoug Rabson
1925*c19800e8SDoug Rabson2003-11-06  Love Hörnquist Åstrand  <[email protected]>
1926*c19800e8SDoug Rabson
1927*c19800e8SDoug Rabson	* cfx.c: checksum the header last in MIC token, update to -03
1928*c19800e8SDoug Rabson	From: Luke Howard <[email protected]>
1929*c19800e8SDoug Rabson
1930*c19800e8SDoug Rabson2003-10-07  Love Hörnquist Åstrand  <[email protected]>
1931*c19800e8SDoug Rabson
1932*c19800e8SDoug Rabson	* add_cred.c: If its a MEMORY cc, make a copy. We need to do this
1933*c19800e8SDoug Rabson	since now gss_release_cred will destroy the cred. This should be
1934*c19800e8SDoug Rabson	really be solved a better way.
1935*c19800e8SDoug Rabson
1936*c19800e8SDoug Rabson	* acquire_cred.c (gss_release_cred): if its a mcc, destroy it
1937*c19800e8SDoug Rabson	rather the just release it Found by: "Zi-Bin Yang"
1938*c19800e8SDoug Rabson	<[email protected]>
1939*c19800e8SDoug Rabson
1940*c19800e8SDoug Rabson	* acquire_cred.c (acquire_initiator_cred): use kret instead of ret
1941*c19800e8SDoug Rabson	where appropriate
1942*c19800e8SDoug Rabson
1943*c19800e8SDoug Rabson2003-09-30  Love Hörnquist Åstrand  <[email protected]>
1944*c19800e8SDoug Rabson
1945*c19800e8SDoug Rabson	* gss_acquire_cred.3: spelling
1946*c19800e8SDoug Rabson	From: jmc <[email protected]>
1947*c19800e8SDoug Rabson
1948*c19800e8SDoug Rabson2003-09-23  Love Hörnquist Åstrand  <[email protected]>
1949*c19800e8SDoug Rabson
1950*c19800e8SDoug Rabson	* cfx.c: - EC and RRC are big-endian, not little-endian - The
1951*c19800e8SDoug Rabson	default is now to rotate regardless of GSS_C_DCE_STYLE. There are
1952*c19800e8SDoug Rabson	no longer any references to GSS_C_DCE_STYLE.  - rrc_rotate()
1953*c19800e8SDoug Rabson	avoids allocating memory on the heap if rrc <= 256
1954*c19800e8SDoug Rabson	From: Luke Howard <[email protected]>
1955*c19800e8SDoug Rabson
1956*c19800e8SDoug Rabson2003-09-22  Love Hörnquist Åstrand  <[email protected]>
1957*c19800e8SDoug Rabson
1958*c19800e8SDoug Rabson	* cfx.[ch]: rrc_rotate() was untested and broken, fix it.
1959*c19800e8SDoug Rabson	Set and verify wrap Token->Filler.
1960*c19800e8SDoug Rabson	Correct token ID for wrap tokens,
1961*c19800e8SDoug Rabson	were accidentally swapped with delete tokens.
1962*c19800e8SDoug Rabson	From: Luke Howard <[email protected]>
1963*c19800e8SDoug Rabson
1964*c19800e8SDoug Rabson2003-09-21  Love Hörnquist Åstrand  <[email protected]>
1965*c19800e8SDoug Rabson
1966*c19800e8SDoug Rabson	* cfx.[ch]: no ASN.1-ish header on per-message tokens
1967*c19800e8SDoug Rabson	From: Luke Howard <[email protected]>
1968*c19800e8SDoug Rabson
1969*c19800e8SDoug Rabson2003-09-19  Love Hörnquist Åstrand  <[email protected]>
1970*c19800e8SDoug Rabson
1971*c19800e8SDoug Rabson	* arcfour.h: remove depenency on gss_arcfour_mic_token and
1972*c19800e8SDoug Rabson	gss_arcfour_warp_token
1973*c19800e8SDoug Rabson
1974*c19800e8SDoug Rabson	* arcfour.c: remove depenency on gss_arcfour_mic_token and
1975*c19800e8SDoug Rabson	gss_arcfour_warp_token
1976*c19800e8SDoug Rabson
1977*c19800e8SDoug Rabson2003-09-18  Love Hörnquist Åstrand  <[email protected]>
1978*c19800e8SDoug Rabson
1979*c19800e8SDoug Rabson	* 8003.c: remove #if 0'ed code
1980*c19800e8SDoug Rabson
1981*c19800e8SDoug Rabson2003-09-17  Love Hörnquist Åstrand  <[email protected]>
1982*c19800e8SDoug Rabson
1983*c19800e8SDoug Rabson	* accept_sec_context.c (gsskrb5_accept_sec_context): set sequence
1984*c19800e8SDoug Rabson	number when not requesting mutual auth From: Luke Howard
1985*c19800e8SDoug Rabson	<[email protected]>
1986*c19800e8SDoug Rabson
1987*c19800e8SDoug Rabson	* init_sec_context.c (init_auth): set sequence number when not
1988*c19800e8SDoug Rabson	requesting mutual auth From: Luke Howard <[email protected]>
1989*c19800e8SDoug Rabson
1990*c19800e8SDoug Rabson2003-09-16  Love Hörnquist Åstrand  <[email protected]>
1991*c19800e8SDoug Rabson
1992*c19800e8SDoug Rabson	* arcfour.c (*): set minor_status
1993*c19800e8SDoug Rabson	(gss_wrap): set conf_state to conf_req_flags on success
1994*c19800e8SDoug Rabson	From: Luke Howard <[email protected]>
1995*c19800e8SDoug Rabson
1996*c19800e8SDoug Rabson	* wrap.c (gss_wrap_size_limit): use existing function From: Luke
1997*c19800e8SDoug Rabson	Howard <[email protected]>
1998*c19800e8SDoug Rabson
1999*c19800e8SDoug Rabson2003-09-12  Love Hörnquist Åstrand  <[email protected]>
2000*c19800e8SDoug Rabson
2001*c19800e8SDoug Rabson	* indicate_mechs.c (gss_indicate_mechs): in case of error, free
2002*c19800e8SDoug Rabson	mech_set
2003*c19800e8SDoug Rabson
2004*c19800e8SDoug Rabson	* indicate_mechs.c (gss_indicate_mechs): add SPNEGO
2005*c19800e8SDoug Rabson
2006*c19800e8SDoug Rabson2003-09-10  Love Hörnquist Åstrand  <[email protected]>
2007*c19800e8SDoug Rabson
2008*c19800e8SDoug Rabson	* init_sec_context.c (spnego_initial): catch errors and return
2009*c19800e8SDoug Rabson	them
2010*c19800e8SDoug Rabson
2011*c19800e8SDoug Rabson	* init_sec_context.c (spnego_initial): add #if 0 out version of
2012*c19800e8SDoug Rabson	the CHOICE branch encoding, also where here, free no longer used
2013*c19800e8SDoug Rabson	memory
2014*c19800e8SDoug Rabson
2015*c19800e8SDoug Rabson2003-09-09  Love Hörnquist Åstrand  <[email protected]>
2016*c19800e8SDoug Rabson
2017*c19800e8SDoug Rabson	* gss_acquire_cred.3: support GSS_SPNEGO_MECHANISM
2018*c19800e8SDoug Rabson
2019*c19800e8SDoug Rabson	* accept_sec_context.c: SPNEGO doesn't include gss wrapping on
2020*c19800e8SDoug Rabson	SubsequentContextToken like the Kerberos 5 mech does.
2021*c19800e8SDoug Rabson
2022*c19800e8SDoug Rabson	* init_sec_context.c (spnego_reply): SPNEGO doesn't include gss
2023*c19800e8SDoug Rabson	wrapping on SubsequentContextToken like the Kerberos 5 mech
2024*c19800e8SDoug Rabson	does. Lets check for it anyway.
2025*c19800e8SDoug Rabson
2026*c19800e8SDoug Rabson	* accept_sec_context.c: Add support for SPNEGO on the initator
2027*c19800e8SDoug Rabson	side.  Implementation initially from Assar Westerlund, passes
2028*c19800e8SDoug Rabson	though quite a lot of hands before I commited it.
2029*c19800e8SDoug Rabson
2030*c19800e8SDoug Rabson	* init_sec_context.c: Add support for SPNEGO on the initator side.
2031*c19800e8SDoug Rabson	Tested with ldap server on a Windows 2000 DC. Implementation
2032*c19800e8SDoug Rabson	initially from Assar Westerlund, passes though quite a lot of
2033*c19800e8SDoug Rabson	hands before I commited it.
2034*c19800e8SDoug Rabson
2035*c19800e8SDoug Rabson	* gssapi.h: export GSS_SPNEGO_MECHANISM
2036*c19800e8SDoug Rabson
2037*c19800e8SDoug Rabson	* gssapi_locl.h: include spnego_as.h add prototype for
2038*c19800e8SDoug Rabson	gssapi_krb5_get_mech
2039*c19800e8SDoug Rabson
2040*c19800e8SDoug Rabson	* decapsulate.c (gssapi_krb5_get_mech): make non static
2041*c19800e8SDoug Rabson
2042*c19800e8SDoug Rabson	* Makefile.am: build SPNEGO file
2043*c19800e8SDoug Rabson
2044*c19800e8SDoug Rabson2003-09-08  Love Hörnquist Åstrand  <[email protected]>
2045*c19800e8SDoug Rabson
2046*c19800e8SDoug Rabson	* external.c: SPENGO and IAKERB oids
2047*c19800e8SDoug Rabson
2048*c19800e8SDoug Rabson	* spnego.asn1: SPENGO ASN1
2049*c19800e8SDoug Rabson
2050*c19800e8SDoug Rabson2003-09-05  Love Hörnquist Åstrand  <[email protected]>
2051*c19800e8SDoug Rabson
2052*c19800e8SDoug Rabson	* cfx.c: RRC also need to be zero before wraping them
2053*c19800e8SDoug Rabson	From: Luke Howard <[email protected]>
2054*c19800e8SDoug Rabson
2055*c19800e8SDoug Rabson2003-09-04  Love Hörnquist Åstrand  <[email protected]>
2056*c19800e8SDoug Rabson
2057*c19800e8SDoug Rabson	* encapsulate.c (gssapi_krb5_encap_length): don't return void
2058*c19800e8SDoug Rabson
2059*c19800e8SDoug Rabson2003-09-03  Love Hörnquist Åstrand  <[email protected]>
2060*c19800e8SDoug Rabson
2061*c19800e8SDoug Rabson	* verify_mic.c: switch from the des_ to the DES_ api
2062*c19800e8SDoug Rabson
2063*c19800e8SDoug Rabson	* get_mic.c: switch from the des_ to the DES_ api
2064*c19800e8SDoug Rabson
2065*c19800e8SDoug Rabson	* unwrap.c: switch from the des_ to the DES_ api
2066*c19800e8SDoug Rabson
2067*c19800e8SDoug Rabson	* wrap.c: switch from the des_ to the DES_ api
2068*c19800e8SDoug Rabson
2069*c19800e8SDoug Rabson	* cfx.c: EC is not included in the checksum since the length might
2070*c19800e8SDoug Rabson	change depending on the data.  From: Luke Howard <[email protected]>
2071*c19800e8SDoug Rabson
2072*c19800e8SDoug Rabson	* acquire_cred.c: use
2073*c19800e8SDoug Rabson	krb5_get_init_creds_opt_alloc/krb5_get_init_creds_opt_free
2074*c19800e8SDoug Rabson
2075*c19800e8SDoug Rabson2003-09-01  Love Hörnquist Åstrand  <[email protected]>
2076*c19800e8SDoug Rabson
2077*c19800e8SDoug Rabson	* copy_ccache.c: rename
2078*c19800e8SDoug Rabson	gss_krb5_extract_authz_data_from_sec_context to
2079*c19800e8SDoug Rabson	gsskrb5_extract_authz_data_from_sec_context
2080*c19800e8SDoug Rabson
2081*c19800e8SDoug Rabson	* gssapi.h: rename gss_krb5_extract_authz_data_from_sec_context to
2082*c19800e8SDoug Rabson	gsskrb5_extract_authz_data_from_sec_context
2083*c19800e8SDoug Rabson
2084*c19800e8SDoug Rabson2003-08-31  Love Hörnquist Åstrand  <[email protected]>
2085*c19800e8SDoug Rabson
2086*c19800e8SDoug Rabson	* copy_ccache.c (gss_krb5_extract_authz_data_from_sec_context):
2087*c19800e8SDoug Rabson	check that we have a ticket before we start to use it
2088*c19800e8SDoug Rabson
2089*c19800e8SDoug Rabson	* gss_acquire_cred.3: document
2090*c19800e8SDoug Rabson	gss_krb5_extract_authz_data_from_sec_context
2091*c19800e8SDoug Rabson
2092*c19800e8SDoug Rabson	* gssapi.h (gss_krb5_extract_authz_data_from_sec_context):
2093*c19800e8SDoug Rabson	return the kerberos authorizationdata, from idea of Luke Howard
2094*c19800e8SDoug Rabson
2095*c19800e8SDoug Rabson	* copy_ccache.c (gss_krb5_extract_authz_data_from_sec_context):
2096*c19800e8SDoug Rabson	return the kerberos authorizationdata, from idea of Luke Howard
2097*c19800e8SDoug Rabson
2098*c19800e8SDoug Rabson	* verify_mic.c (gss_verify_mic_internal): switch type and key
2099*c19800e8SDoug Rabson	argument
2100*c19800e8SDoug Rabson
2101*c19800e8SDoug Rabson2003-08-30  Love Hörnquist Åstrand  <[email protected]>
2102*c19800e8SDoug Rabson
2103*c19800e8SDoug Rabson	* cfx.[ch]: draft-ietf-krb-wg-gssapi-cfx-01.txt implemetation
2104*c19800e8SDoug Rabson	From: Luke Howard <[email protected]>
2105*c19800e8SDoug Rabson
2106*c19800e8SDoug Rabson2003-08-28  Love Hörnquist Åstrand  <[email protected]>
2107*c19800e8SDoug Rabson
2108*c19800e8SDoug Rabson	* arcfour.c (arcfour_mic_cksum): use free_Checksum to free the
2109*c19800e8SDoug Rabson	checksum
2110*c19800e8SDoug Rabson
2111*c19800e8SDoug Rabson	* arcfour.h: swap two last arguments to verify_mic for consistency
2112*c19800e8SDoug Rabson	with des3
2113*c19800e8SDoug Rabson
2114*c19800e8SDoug Rabson	* wrap.c,unwrap.c,get_mic.c,verify_mic.c,cfx.c,cfx.h:
2115*c19800e8SDoug Rabson	prefix cfx symbols with _gssapi_
2116*c19800e8SDoug Rabson
2117*c19800e8SDoug Rabson	* arcfour.c: release the right buffer
2118*c19800e8SDoug Rabson
2119*c19800e8SDoug Rabson	* arcfour.c: rename token structure in consistency with rest of
2120*c19800e8SDoug Rabson	GSS-API From: Luke Howard <[email protected]>
2121*c19800e8SDoug Rabson
2122*c19800e8SDoug Rabson	* unwrap.c (unwrap_des3): use _gssapi_verify_pad
2123*c19800e8SDoug Rabson	(unwrap_des): use _gssapi_verify_pad
2124*c19800e8SDoug Rabson
2125*c19800e8SDoug Rabson	* arcfour.c (_gssapi_wrap_arcfour): set the correct padding
2126*c19800e8SDoug Rabson	(_gssapi_unwrap_arcfour): verify and strip padding
2127*c19800e8SDoug Rabson
2128*c19800e8SDoug Rabson	* gssapi_locl.h: added _gssapi_verify_pad
2129*c19800e8SDoug Rabson
2130*c19800e8SDoug Rabson	* decapsulate.c (_gssapi_verify_pad): verify padding of a gss
2131*c19800e8SDoug Rabson	wrapped message and return its length
2132*c19800e8SDoug Rabson
2133*c19800e8SDoug Rabson	* arcfour.c: support KEYTYPE_ARCFOUR_56 keys, from Luke Howard
2134*c19800e8SDoug Rabson	<[email protected]>
2135*c19800e8SDoug Rabson
2136*c19800e8SDoug Rabson	* arcfour.c: use right seal alg, inherit keytype from parent key
2137*c19800e8SDoug Rabson
2138*c19800e8SDoug Rabson	* arcfour.c: include the confounder in the checksum use the right
2139*c19800e8SDoug Rabson	key usage number for warped/unwraped tokens
2140*c19800e8SDoug Rabson
2141*c19800e8SDoug Rabson	* gssapi.h: add gss_krb5_nt_general_name as an mit compat glue
2142*c19800e8SDoug Rabson	(same as GSS_KRB5_NT_PRINCIPAL_NAME)
2143*c19800e8SDoug Rabson
2144*c19800e8SDoug Rabson	* unwrap.c: hook in arcfour unwrap
2145*c19800e8SDoug Rabson
2146*c19800e8SDoug Rabson	* wrap.c: hook in arcfour wrap
2147*c19800e8SDoug Rabson
2148*c19800e8SDoug Rabson	* verify_mic.c: hook in arcfour verify_mic
2149*c19800e8SDoug Rabson
2150*c19800e8SDoug Rabson	* get_mic.c: hook in arcfour get_mic
2151*c19800e8SDoug Rabson
2152*c19800e8SDoug Rabson	* arcfour.c: implement wrap/unwarp
2153*c19800e8SDoug Rabson
2154*c19800e8SDoug Rabson	* gssapi_locl.h: add gssapi_{en,de}code_be_om_uint32
2155*c19800e8SDoug Rabson
2156*c19800e8SDoug Rabson	* 8003.c: add gssapi_{en,de}code_be_om_uint32
2157*c19800e8SDoug Rabson
2158*c19800e8SDoug Rabson2003-08-27  Love Hörnquist Åstrand  <[email protected]>
2159*c19800e8SDoug Rabson
2160*c19800e8SDoug Rabson	* arcfour.c (_gssapi_verify_mic_arcfour): Do the checksum on right
2161*c19800e8SDoug Rabson	area. Swap filler check, it was reversed.
2162*c19800e8SDoug Rabson
2163*c19800e8SDoug Rabson	* Makefile.am (libgssapi_la_SOURCES): += arcfour.c
2164*c19800e8SDoug Rabson
2165*c19800e8SDoug Rabson	* gssapi_locl.h: include "arcfour.h"
2166*c19800e8SDoug Rabson
2167*c19800e8SDoug Rabson	* arcfour.c: arcfour gss-api mech, get_mic/verify_mic working
2168*c19800e8SDoug Rabson
2169*c19800e8SDoug Rabson	* arcfour.h: arcfour gss-api mech, get_mic/verify_mic working
2170*c19800e8SDoug Rabson
2171*c19800e8SDoug Rabson2003-08-26  Love Hörnquist Åstrand  <[email protected]>
2172*c19800e8SDoug Rabson
2173*c19800e8SDoug Rabson	* gssapi_locl.h: always include cfx.h add prototype for
2174*c19800e8SDoug Rabson	_gssapi_decapsulate
2175*c19800e8SDoug Rabson
2176*c19800e8SDoug Rabson	* cfx.[ch]: Implementation of draft-ietf-krb-wg-gssapi-cfx-00.txt
2177*c19800e8SDoug Rabson	from Luke Howard <[email protected]>
2178*c19800e8SDoug Rabson
2179*c19800e8SDoug Rabson	* decapsulate.c: add _gssapi_decapsulate, from Luke Howard
2180*c19800e8SDoug Rabson	<[email protected]>
2181*c19800e8SDoug Rabson
2182*c19800e8SDoug Rabson2003-08-25  Love Hörnquist Åstrand  <[email protected]>
2183*c19800e8SDoug Rabson
2184*c19800e8SDoug Rabson	* unwrap.c: encap/decap now takes a oid if the enctype/keytype is
2185*c19800e8SDoug Rabson	arcfour, return error add hook for cfx
2186*c19800e8SDoug Rabson
2187*c19800e8SDoug Rabson	* verify_mic.c: encap/decap now takes a oid if the enctype/keytype
2188*c19800e8SDoug Rabson	is arcfour, return error add hook for cfx
2189*c19800e8SDoug Rabson
2190*c19800e8SDoug Rabson	* get_mic.c: encap/decap now takes a oid if the enctype/keytype is
2191*c19800e8SDoug Rabson	arcfour, return error add hook for cfx
2192*c19800e8SDoug Rabson
2193*c19800e8SDoug Rabson	* accept_sec_context.c: encap/decap now takes a oid
2194*c19800e8SDoug Rabson
2195*c19800e8SDoug Rabson	* init_sec_context.c: encap/decap now takes a oid
2196*c19800e8SDoug Rabson
2197*c19800e8SDoug Rabson	* gssapi_locl.h: include cfx.h if we need it lifetime is a
2198*c19800e8SDoug Rabson	OM_uint32, depend on gssapi interface add all new encap/decap
2199*c19800e8SDoug Rabson	functions
22001c43270aSJacques Vidrine
22011c43270aSJacques Vidrine	* decapsulate.c: add decap functions that doesn't take the token
2202*c19800e8SDoug Rabson	type also make all decap function take the oid mech that they
2203*c19800e8SDoug Rabson	should use
22041c43270aSJacques Vidrine
2205*c19800e8SDoug Rabson	* encapsulate.c: add encap functions that doesn't take the token
2206*c19800e8SDoug Rabson	type also make all encap function take the oid mech that they
2207*c19800e8SDoug Rabson	should use
2208*c19800e8SDoug Rabson
2209*c19800e8SDoug Rabson	* sequence.c (elem_insert): fix a off by one index counter
2210bbd80c28SJacques Vidrine
2211*c19800e8SDoug Rabson	* inquire_cred.c (gss_inquire_cred): handle cred_handle being
2212*c19800e8SDoug Rabson	GSS_C_NO_CREDENTIAL and use the default cred then.
2213*c19800e8SDoug Rabson
2214*c19800e8SDoug Rabson2003-08-19  Love Hörnquist Åstrand  <[email protected]>
2215*c19800e8SDoug Rabson
2216*c19800e8SDoug Rabson	* gss_acquire_cred.3: break out extensions and document
2217*c19800e8SDoug Rabson	gsskrb5_register_acceptor_identity
2218*c19800e8SDoug Rabson
2219*c19800e8SDoug Rabson2003-08-18  Love Hörnquist Åstrand  <[email protected]>
2220*c19800e8SDoug Rabson
2221*c19800e8SDoug Rabson	* test_acquire_cred.c (print_time): time is returned in seconds
2222*c19800e8SDoug Rabson	from now, not unix time
2223*c19800e8SDoug Rabson
2224*c19800e8SDoug Rabson2003-08-17  Love Hörnquist Åstrand  <[email protected]>
2225*c19800e8SDoug Rabson
2226*c19800e8SDoug Rabson	* compat.c (check_compat): avoid leaking principal when finding a
2227*c19800e8SDoug Rabson	match
2228*c19800e8SDoug Rabson
2229*c19800e8SDoug Rabson	* address_to_krb5addr.c: sa_size argument to krb5_addr2sockaddr is
2230*c19800e8SDoug Rabson	a krb5_socklen_t
2231*c19800e8SDoug Rabson
2232*c19800e8SDoug Rabson	* acquire_cred.c (gss_acquire_cred): 4th argument to
2233*c19800e8SDoug Rabson	gss_test_oid_set_member is a int
2234*c19800e8SDoug Rabson
2235bbd80c28SJacques Vidrine2003-07-22  Love Hörnquist Åstrand  <[email protected]>
2236bbd80c28SJacques Vidrine
2237bbd80c28SJacques Vidrine	* init_sec_context.c (repl_mutual): don't set kerberos error where
2238bbd80c28SJacques Vidrine	there was no kerberos error
2239bbd80c28SJacques Vidrine
2240*c19800e8SDoug Rabson	* gssapi_locl.h: Add destruction/creation prototypes and structure
2241*c19800e8SDoug Rabson	for the thread specific storage.
2242bbd80c28SJacques Vidrine
2243*c19800e8SDoug Rabson	* display_status.c: use thread specific storage to set/get the
2244bbd80c28SJacques Vidrine	kerberos error message
2245*c19800e8SDoug Rabson
2246*c19800e8SDoug Rabson	* init.c: Provide locking around the creation of the global
2247bbd80c28SJacques Vidrine	krb5_context. Add destruction/creation functions for the thread
2248*c19800e8SDoug Rabson	specific storage that the error string handling is using.
2249bbd80c28SJacques Vidrine
2250*c19800e8SDoug Rabson2003-07-20  Love Hörnquist Åstrand  <[email protected]>
2251*c19800e8SDoug Rabson
2252bbd80c28SJacques Vidrine	* gss_acquire_cred.3: add missing prototype and missing .Ft
2253*c19800e8SDoug Rabson	arguments
2254*c19800e8SDoug Rabson
2255*c19800e8SDoug Rabson2003-06-17  Love Hörnquist Åstrand  <[email protected]>
2256*c19800e8SDoug Rabson
2257*c19800e8SDoug Rabson	* verify_mic.c: reorder code so sequence numbers can can be used
2258*c19800e8SDoug Rabson
2259*c19800e8SDoug Rabson	* unwrap.c: reorder code so sequence numbers can can be used
2260*c19800e8SDoug Rabson
2261*c19800e8SDoug Rabson	* sequence.c: remove unused function, indent, add
2262*c19800e8SDoug Rabson	gssapi_msg_order_f that filter gss flags to gss_msg_order flags
2263bbd80c28SJacques Vidrine
2264bbd80c28SJacques Vidrine	* gssapi_locl.h: prototypes for
2265*c19800e8SDoug Rabson	gssapi_{encode_om_uint32,decode_om_uint32} add sequence number
2266*c19800e8SDoug Rabson	verifier prototypes
2267*c19800e8SDoug Rabson
2268*c19800e8SDoug Rabson	* delete_sec_context.c: destroy sequence number verifier
2269bbd80c28SJacques Vidrine
2270bbd80c28SJacques Vidrine	* init_sec_context.c: remember to free data use sequence number
2271*c19800e8SDoug Rabson	verifier
2272*c19800e8SDoug Rabson
2273bbd80c28SJacques Vidrine	* accept_sec_context.c: don't clear output_token twice remember to
2274bbd80c28SJacques Vidrine	free data use sequence number verifier
2275bbd80c28SJacques Vidrine
2276*c19800e8SDoug Rabson	* 8003.c: export and rename encode_om_uint32/decode_om_uint32 and
2277*c19800e8SDoug Rabson	start to use them
2278*c19800e8SDoug Rabson
2279*c19800e8SDoug Rabson2003-06-09  Johan Danielsson  <[email protected]>
2280*c19800e8SDoug Rabson
2281bbd80c28SJacques Vidrine	* Makefile.am: can't have sequence.c in two different places
2282bbd80c28SJacques Vidrine
2283*c19800e8SDoug Rabson2003-06-06  Love Hörnquist Åstrand  <[email protected]>
2284*c19800e8SDoug Rabson
2285bbd80c28SJacques Vidrine	* test_sequence.c: check rollover, print summery
2286bbd80c28SJacques Vidrine
2287bbd80c28SJacques Vidrine	* wrap.c (sub_wrap_size): gss_wrap_size_limit() has
2288bbd80c28SJacques Vidrine	req_output_size and max_input_size around the wrong way -- it
2289bbd80c28SJacques Vidrine	returns the output token size for a given input size, rather than
2290bbd80c28SJacques Vidrine	the maximum input size for a given output token size.
2291bbd80c28SJacques Vidrine
2292bbd80c28SJacques Vidrine	From: Luke Howard <[email protected]>
2293bbd80c28SJacques Vidrine
2294bbd80c28SJacques Vidrine2003-06-05  Love Hörnquist Åstrand  <[email protected]>
2295bbd80c28SJacques Vidrine
2296bbd80c28SJacques Vidrine	* gssapi_locl.h: add prototypes for sequence.c
2297bbd80c28SJacques Vidrine
2298bbd80c28SJacques Vidrine	* Makefile.am (libgssapi_la_SOURCES): add sequence.c
2299bbd80c28SJacques Vidrine	(test_sequence): build
2300bbd80c28SJacques Vidrine
2301bbd80c28SJacques Vidrine	* sequence.c: sequence number checks, order and replay
2302bbd80c28SJacques Vidrine	* test_sequence.c: sequence number checks, order and replay
2303bbd80c28SJacques Vidrine
2304bbd80c28SJacques Vidrine2003-06-03  Love Hörnquist Åstrand  <[email protected]>
2305bbd80c28SJacques Vidrine
2306bbd80c28SJacques Vidrine	* accept_sec_context.c (gss_accept_sec_context): make sure time is
2307bbd80c28SJacques Vidrine	returned in seconds from now, not in kerberos time
2308bbd80c28SJacques Vidrine
2309bbd80c28SJacques Vidrine	* acquire_cred.c (gss_aquire_cred): make sure time is returned in
2310bbd80c28SJacques Vidrine	seconds from now, not in kerberos time
2311bbd80c28SJacques Vidrine
2312bbd80c28SJacques Vidrine	* init_sec_context.c (init_auth): if the cred is expired before we
2313bbd80c28SJacques Vidrine	tries to create a token, fail so the peer doesn't need reject us
2314bbd80c28SJacques Vidrine	(*): make sure time is returned in seconds from now,
2315bbd80c28SJacques Vidrine	not in kerberos time
2316bbd80c28SJacques Vidrine	(repl_mutual): remember to unlock the context mutex
2317bbd80c28SJacques Vidrine
2318bbd80c28SJacques Vidrine	* context_time.c (gss_context_time): remove unused variable
2319bbd80c28SJacques Vidrine
2320bbd80c28SJacques Vidrine	* verify_mic.c: make sure minor_status is always set, pointed out
2321bbd80c28SJacques Vidrine	by Luke Howard <[email protected]>
2322bbd80c28SJacques Vidrine
2323bbd80c28SJacques Vidrine2003-05-21  Love Hörnquist Åstrand  <[email protected]>
2324bbd80c28SJacques Vidrine
2325bbd80c28SJacques Vidrine	* *.[ch]: do some basic locking (no reference counting so contexts
2326bbd80c28SJacques Vidrine	  can be removed while still used)
2327bbd80c28SJacques Vidrine	- don't export gss_ctx_id_t_desc_struct and gss_cred_id_t_desc_struct
2328bbd80c28SJacques Vidrine	- make sure all lifetime are returned in seconds left until expired,
2329bbd80c28SJacques Vidrine	  not in unix epoch
2330bbd80c28SJacques Vidrine
2331bbd80c28SJacques Vidrine	* gss_acquire_cred.3: document argument lifetime_rec to function
2332bbd80c28SJacques Vidrine	gss_inquire_context
2333bbd80c28SJacques Vidrine
2334bbd80c28SJacques Vidrine2003-05-17  Love Hörnquist Åstrand  <[email protected]>
2335bbd80c28SJacques Vidrine
2336bbd80c28SJacques Vidrine	* test_acquire_cred.c: test gss_add_cred more then once
2337bbd80c28SJacques Vidrine
2338bbd80c28SJacques Vidrine2003-05-06  Love Hörnquist Åstrand  <[email protected]>
2339bbd80c28SJacques Vidrine
2340bbd80c28SJacques Vidrine	* gssapi.h: if __cplusplus, wrap the extern variable (just to be
2341bbd80c28SJacques Vidrine	safe) and functions in extern "C" { }
2342bbd80c28SJacques Vidrine
2343bbd80c28SJacques Vidrine2003-04-30  Love Hörnquist Åstrand  <[email protected]>
2344bbd80c28SJacques Vidrine
2345bbd80c28SJacques Vidrine	* gssapi.3: more about the des3 mic mess
2346bbd80c28SJacques Vidrine
2347bbd80c28SJacques Vidrine	* verify_mic.c (verify_mic_des3): always check if the mic is the
2348bbd80c28SJacques Vidrine	correct mic or the mic that old heimdal would have generated
2349bbd80c28SJacques Vidrine
2350bbd80c28SJacques Vidrine2003-04-28  Jacques Vidrine  <[email protected]>
2351bbd80c28SJacques Vidrine
2352bbd80c28SJacques Vidrine	* verify_mic.c (verify_mic_des3): If MIC verification fails,
2353bbd80c28SJacques Vidrine	retry using the `old' MIC computation (with zero IV).
2354bbd80c28SJacques Vidrine
2355bbd80c28SJacques Vidrine2003-04-26  Love Hörnquist Åstrand  <[email protected]>
2356bbd80c28SJacques Vidrine
2357bbd80c28SJacques Vidrine	* gss_acquire_cred.3: more about difference between comparing IN
2358bbd80c28SJacques Vidrine	and MN
2359bbd80c28SJacques Vidrine
2360bbd80c28SJacques Vidrine	* gss_acquire_cred.3: more about name type and access control
2361bbd80c28SJacques Vidrine
2362bbd80c28SJacques Vidrine2003-04-25  Love Hörnquist Åstrand  <[email protected]>
2363bbd80c28SJacques Vidrine
2364bbd80c28SJacques Vidrine	* gss_acquire_cred.3: document gss_context_time
2365bbd80c28SJacques Vidrine
2366bbd80c28SJacques Vidrine	* context_time.c: if lifetime of context have expired, set
2367bbd80c28SJacques Vidrine	time_rec to 0 and return GSS_S_CONTEXT_EXPIRED
2368bbd80c28SJacques Vidrine
2369bbd80c28SJacques Vidrine	* gssapi.3: document [gssapi]correct_des3_mic
2370bbd80c28SJacques Vidrine	[gssapi]broken_des3_mic
2371bbd80c28SJacques Vidrine
2372bbd80c28SJacques Vidrine	* gss_acquire_cred.3: document gss_krb5_compat_des3_mic
2373bbd80c28SJacques Vidrine
2374bbd80c28SJacques Vidrine	* compat.c (gss_krb5_compat_des3_mic): enable turning on/off des3
2375bbd80c28SJacques Vidrine	mic compat
2376bbd80c28SJacques Vidrine	(_gss_DES3_get_mic_compat): handle [gssapi]correct_des3_mic too
2377bbd80c28SJacques Vidrine
2378bbd80c28SJacques Vidrine	* gssapi.h (gss_krb5_compat_des3_mic): new function, turn on/off
2379bbd80c28SJacques Vidrine	des3 mic compat
2380bbd80c28SJacques Vidrine	(GSS_C_KRB5_COMPAT_DES3_MIC): cpp symbol that exists if
2381bbd80c28SJacques Vidrine	gss_krb5_compat_des3_mic exists
2382bbd80c28SJacques Vidrine
2383bbd80c28SJacques Vidrine2003-04-24  Love Hörnquist Åstrand  <[email protected]>
2384bbd80c28SJacques Vidrine
2385bbd80c28SJacques Vidrine	* Makefile.am:  (libgssapi_la_LDFLAGS): update major
2386bbd80c28SJacques Vidrine	version of gssapi for incompatiblity in 3des getmic support
2387bbd80c28SJacques Vidrine
2388bbd80c28SJacques Vidrine2003-04-23  Love Hörnquist Åstrand  <[email protected]>
2389bbd80c28SJacques Vidrine
2390bbd80c28SJacques Vidrine	* Makefile.am: test_acquire_cred_LDADD: use libgssapi.la not
2391bbd80c28SJacques Vidrine	./libgssapi.la (make make -jN work)
2392bbd80c28SJacques Vidrine
2393bbd80c28SJacques Vidrine2003-04-16  Love Hörnquist Åstrand  <[email protected]>
2394bbd80c28SJacques Vidrine
2395bbd80c28SJacques Vidrine	* gssapi.3: spelling
2396bbd80c28SJacques Vidrine
2397bbd80c28SJacques Vidrine	* gss_acquire_cred.3: Change .Fd #include <header.h> to .In
2398bbd80c28SJacques Vidrine	header.h, from Thomas Klausner <[email protected]>
2399bbd80c28SJacques Vidrine
2400bbd80c28SJacques Vidrine
2401bbd80c28SJacques Vidrine2003-04-06  Love Hörnquist Åstrand  <[email protected]>
2402bbd80c28SJacques Vidrine
2403bbd80c28SJacques Vidrine	* gss_acquire_cred.3: spelling
2404bbd80c28SJacques Vidrine
2405bbd80c28SJacques Vidrine	* Makefile.am: remove stuff that sneaked in with last commit
2406bbd80c28SJacques Vidrine
2407bbd80c28SJacques Vidrine	* acquire_cred.c (acquire_initiator_cred): if the requested name
2408bbd80c28SJacques Vidrine	isn't in the ccache, also check keytab.  Extact the krbtgt for the
2409bbd80c28SJacques Vidrine	default realm to check how long the credentials will last.
2410bbd80c28SJacques Vidrine
2411bbd80c28SJacques Vidrine	* add_cred.c (gss_add_cred): don't create a new ccache, just open
2412bbd80c28SJacques Vidrine	the old one; better check if output handle is compatible with new
2413bbd80c28SJacques Vidrine	(copied) handle
2414bbd80c28SJacques Vidrine
2415bbd80c28SJacques Vidrine	* test_acquire_cred.c: test gss_add_cred too
2416bbd80c28SJacques Vidrine
2417bbd80c28SJacques Vidrine2003-04-03  Love Hörnquist Åstrand  <[email protected]>
2418bbd80c28SJacques Vidrine
2419bbd80c28SJacques Vidrine	* Makefile.am: build test_acquire_cred
2420bbd80c28SJacques Vidrine
2421bbd80c28SJacques Vidrine	* test_acquire_cred.c: simple gss_acquire_cred test
2422bbd80c28SJacques Vidrine
2423bbd80c28SJacques Vidrine2003-04-02  Love Hörnquist Åstrand  <[email protected]>
2424bbd80c28SJacques Vidrine
2425bbd80c28SJacques Vidrine	* gss_acquire_cred.3: s/gssapi/GSS-API/
2426bbd80c28SJacques Vidrine
2427bbd80c28SJacques Vidrine2003-03-19  Love Hörnquist Åstrand  <[email protected]>
2428bbd80c28SJacques Vidrine
2429bbd80c28SJacques Vidrine	* gss_acquire_cred.3: document v1 interface (and that they are
2430bbd80c28SJacques Vidrine	obsolete)
2431bbd80c28SJacques Vidrine
2432bbd80c28SJacques Vidrine2003-03-18  Love Hörnquist Åstrand  <[email protected]>
2433bbd80c28SJacques Vidrine
2434bbd80c28SJacques Vidrine	* gss_acquire_cred.3: list supported mechanism and nametypes
2435bbd80c28SJacques Vidrine
2436bbd80c28SJacques Vidrine2003-03-16  Love Hörnquist Åstrand  <[email protected]>
2437bbd80c28SJacques Vidrine
2438bbd80c28SJacques Vidrine	* gss_acquire_cred.3: text about gss_display_name
2439bbd80c28SJacques Vidrine
2440bbd80c28SJacques Vidrine	* Makefile.am (libgssapi_la_LDFLAGS): bump to 3:6:2
2441bbd80c28SJacques Vidrine	(libgssapi_la_SOURCES): add all new functions
2442bbd80c28SJacques Vidrine
2443bbd80c28SJacques Vidrine	* gssapi.3: now that we have a functions, uncomment the missing
2444bbd80c28SJacques Vidrine	ones
2445bbd80c28SJacques Vidrine
2446bbd80c28SJacques Vidrine	* gss_acquire_cred.3: now that we have a functions, uncomment the
2447bbd80c28SJacques Vidrine	missing ones
2448bbd80c28SJacques Vidrine
2449bbd80c28SJacques Vidrine	* process_context_token.c: implement gss_process_context_token
2450bbd80c28SJacques Vidrine
2451bbd80c28SJacques Vidrine	* inquire_names_for_mech.c: implement gss_inquire_names_for_mech
2452bbd80c28SJacques Vidrine
2453bbd80c28SJacques Vidrine	* inquire_mechs_for_name.c: implement gss_inquire_mechs_for_name
2454bbd80c28SJacques Vidrine
2455bbd80c28SJacques Vidrine	* inquire_cred_by_mech.c: implement gss_inquire_cred_by_mech
2456bbd80c28SJacques Vidrine
2457bbd80c28SJacques Vidrine	* add_cred.c: implement gss_add_cred
2458bbd80c28SJacques Vidrine
2459bbd80c28SJacques Vidrine	* acquire_cred.c (gss_acquire_cred): more testing of input
2460bbd80c28SJacques Vidrine	argument, make sure output arguments are ok, since we don't know
2461bbd80c28SJacques Vidrine	the time_rec (for now), set it to time_req
2462bbd80c28SJacques Vidrine
2463bbd80c28SJacques Vidrine	* export_sec_context.c: send lifetime, also set minor_status
2464bbd80c28SJacques Vidrine
2465bbd80c28SJacques Vidrine	* get_mic.c: set minor_status
2466bbd80c28SJacques Vidrine
2467bbd80c28SJacques Vidrine	* import_sec_context.c (gss_import_sec_context): add error
2468bbd80c28SJacques Vidrine	checking, pick up lifetime (if there is no lifetime, use
2469bbd80c28SJacques Vidrine	GSS_C_INDEFINITE)
2470bbd80c28SJacques Vidrine
2471bbd80c28SJacques Vidrine	* init_sec_context.c: take care to set export value to something
2472bbd80c28SJacques Vidrine	sane before we start so caller will have harmless values in them
2473bbd80c28SJacques Vidrine	if then function fails
2474bbd80c28SJacques Vidrine
2475bbd80c28SJacques Vidrine	* release_buffer.c (gss_release_buffer): set minor_status
2476bbd80c28SJacques Vidrine
2477bbd80c28SJacques Vidrine	* wrap.c: make sure minor_status get set
2478bbd80c28SJacques Vidrine
2479bbd80c28SJacques Vidrine	* verify_mic.c (gss_verify_mic_internal): rename verify_mic to
2480bbd80c28SJacques Vidrine	gss_verify_mic_internal and let it take the type as an argument,
2481bbd80c28SJacques Vidrine	(gss_verify_mic): call gss_verify_mic_internal
2482bbd80c28SJacques Vidrine	set minor_status
2483bbd80c28SJacques Vidrine
2484bbd80c28SJacques Vidrine	* unwrap.c: set minor_status
2485bbd80c28SJacques Vidrine
2486bbd80c28SJacques Vidrine	* test_oid_set_member.c (gss_test_oid_set_member): use
2487bbd80c28SJacques Vidrine	gss_oid_equal
2488bbd80c28SJacques Vidrine
2489bbd80c28SJacques Vidrine	* release_oid_set.c (gss_release_oid_set): set minor_status
2490bbd80c28SJacques Vidrine
2491bbd80c28SJacques Vidrine	* release_name.c (gss_release_name): set minor_status
2492bbd80c28SJacques Vidrine
2493bbd80c28SJacques Vidrine	* release_cred.c (gss_release_cred): set minor_status
2494bbd80c28SJacques Vidrine
2495bbd80c28SJacques Vidrine	* add_oid_set_member.c (gss_add_oid_set_member): set minor_status
2496bbd80c28SJacques Vidrine
2497bbd80c28SJacques Vidrine	* compare_name.c (gss_compare_name): set minor_status
2498bbd80c28SJacques Vidrine
2499bbd80c28SJacques Vidrine	* compat.c (check_compat): make sure ret have a defined value
2500bbd80c28SJacques Vidrine
2501bbd80c28SJacques Vidrine	* context_time.c (gss_context_time): set minor_status
25020cadf2f4SJacques Vidrine
25030cadf2f4SJacques Vidrine	* copy_ccache.c (gss_krb5_copy_ccache): set minor_status
25040cadf2f4SJacques Vidrine
25050cadf2f4SJacques Vidrine	* create_emtpy_oid_set.c (gss_create_empty_oid_set): set
25060cadf2f4SJacques Vidrine	minor_status
25070cadf2f4SJacques Vidrine
25080cadf2f4SJacques Vidrine	* delete_sec_context.c (gss_delete_sec_context): set minor_status
25090cadf2f4SJacques Vidrine
25100cadf2f4SJacques Vidrine	* display_name.c (gss_display_name): set minor_status
25110cadf2f4SJacques Vidrine
25128373020dSJacques Vidrine	* display_status.c (gss_display_status): use gss_oid_equal, handle
25138373020dSJacques Vidrine	supplementary errors
25148373020dSJacques Vidrine
25158373020dSJacques Vidrine	* duplicate_name.c (gss_duplicate_name): set minor_status
25168373020dSJacques Vidrine
25178373020dSJacques Vidrine	* inquire_context.c (gss_inquire_context): set lifetime_rec now
25188373020dSJacques Vidrine	when we know it, set minor_status
25198373020dSJacques Vidrine
25208373020dSJacques Vidrine	* inquire_cred.c (gss_inquire_cred): take care to set export value
25218373020dSJacques Vidrine	to something sane before we start so caller will have harmless
25228373020dSJacques Vidrine	values in them if the function fails
25238373020dSJacques Vidrine
25248373020dSJacques Vidrine	* accept_sec_context.c (gss_accept_sec_context): take care to set
25258373020dSJacques Vidrine	export value to something sane before we start so caller will have
25268373020dSJacques Vidrine	harmless values in them if then function fails, set lifetime from
25278373020dSJacques Vidrine	ticket expiration date
25288373020dSJacques Vidrine
25298373020dSJacques Vidrine	* indicate_mechs.c (gss_indicate_mechs): use
25308373020dSJacques Vidrine	gss_create_empty_oid_set and gss_add_oid_set_member
25318373020dSJacques Vidrine
25328373020dSJacques Vidrine	* gssapi.h (gss_ctx_id_t_desc): store the lifetime in the cred,
25338373020dSJacques Vidrine	since there is no ticket transfered in the exported context
25348373020dSJacques Vidrine
25358373020dSJacques Vidrine	* export_name.c (gss_export_name): export name with
25368373020dSJacques Vidrine	GSS_C_NT_EXPORT_NAME wrapping, not just the principal
25378373020dSJacques Vidrine
25388373020dSJacques Vidrine	* import_name.c (import_export_name): new function, parses a
25398373020dSJacques Vidrine	GSS_C_NT_EXPORT_NAME
25408373020dSJacques Vidrine	(import_krb5_name): factor out common code of parsing krb5 name
25418373020dSJacques Vidrine	(gss_oid_equal): rename from oid_equal
25428373020dSJacques Vidrine
25438373020dSJacques Vidrine	* gssapi_locl.h: add prototypes for gss_oid_equal and
25448373020dSJacques Vidrine	gss_verify_mic_internal
25458373020dSJacques Vidrine
25464137ff4cSJacques Vidrine	* gssapi.h: comment out the argument names
25474137ff4cSJacques Vidrine
25484137ff4cSJacques Vidrine2003-03-15  Love Hörnquist Åstrand  <[email protected]>
25494137ff4cSJacques Vidrine
25504137ff4cSJacques Vidrine	* gssapi.3: add LIST OF FUNCTIONS and copyright/license
25514137ff4cSJacques Vidrine
25524137ff4cSJacques Vidrine	* Makefile.am: s/gss_aquire_cred.3/gss_acquire_cred.3/
25534137ff4cSJacques Vidrine
25544137ff4cSJacques Vidrine	* Makefile.am: man_MANS += gss_aquire_cred.3
25554137ff4cSJacques Vidrine
25564137ff4cSJacques Vidrine2003-03-14  Love Hörnquist Åstrand  <[email protected]>
25574137ff4cSJacques Vidrine
25584137ff4cSJacques Vidrine	* gss_aquire_cred.3: the gssapi api manpage
25594137ff4cSJacques Vidrine
25604137ff4cSJacques Vidrine2003-03-03  Love Hörnquist Åstrand  <[email protected]>
25614137ff4cSJacques Vidrine
25624137ff4cSJacques Vidrine	* inquire_context.c: (gss_inquire_context): rename argument open
25634137ff4cSJacques Vidrine	to open_context
25644137ff4cSJacques Vidrine
25654137ff4cSJacques Vidrine	* gssapi.h (gss_inquire_context): rename argument open to open_context
25664137ff4cSJacques Vidrine
25674137ff4cSJacques Vidrine2003-02-27  Love Hörnquist Åstrand  <[email protected]>
25684137ff4cSJacques Vidrine
25694137ff4cSJacques Vidrine	* init_sec_context.c (do_delegation): remove unused variable
25704137ff4cSJacques Vidrine	subkey
25714137ff4cSJacques Vidrine
25724137ff4cSJacques Vidrine	* gssapi.3: all 0.5.x version had broken token delegation
25734137ff4cSJacques Vidrine
25744137ff4cSJacques Vidrine2003-02-21  Love Hörnquist Åstrand  <[email protected]>
25754137ff4cSJacques Vidrine
25764137ff4cSJacques Vidrine	* (init_auth): only generate one subkey
25774137ff4cSJacques Vidrine
25784137ff4cSJacques Vidrine2003-01-27  Love Hörnquist Åstrand  <[email protected]>
25794137ff4cSJacques Vidrine
25804137ff4cSJacques Vidrine	* verify_mic.c (verify_mic_des3): fix 3des verify_mic to conform
25814137ff4cSJacques Vidrine	to rfc (and mit kerberos), provide backward compat hook
25824137ff4cSJacques Vidrine
25834137ff4cSJacques Vidrine	* get_mic.c (mic_des3): fix 3des get_mic to conform to rfc (and
25844137ff4cSJacques Vidrine	mit kerberos), provide backward compat hook
25854137ff4cSJacques Vidrine
25864137ff4cSJacques Vidrine	* init_sec_context.c (init_auth): check if we need compat for
25874137ff4cSJacques Vidrine	older get_mic/verify_mic
25884137ff4cSJacques Vidrine
25894137ff4cSJacques Vidrine	* gssapi_locl.h: add prototype for _gss_DES3_get_mic_compat
25904137ff4cSJacques Vidrine
25914137ff4cSJacques Vidrine	* gssapi.h (more_flags): add COMPAT_OLD_DES3
25924137ff4cSJacques Vidrine
25934137ff4cSJacques Vidrine	* Makefile.am: add gssapi.3 and compat.c
25944137ff4cSJacques Vidrine
25954137ff4cSJacques Vidrine	* gssapi.3: add gssapi COMPATIBILITY documentation
25964137ff4cSJacques Vidrine
25974137ff4cSJacques Vidrine	* accept_sec_context.c (gss_accept_sec_context): check if we need
25984137ff4cSJacques Vidrine	compat for older get_mic/verify_mic
25994137ff4cSJacques Vidrine
26004137ff4cSJacques Vidrine	* compat.c: check for compatiblity with other heimdal's 3des
26014137ff4cSJacques Vidrine	get_mic/verify_mic
26024137ff4cSJacques Vidrine
26034137ff4cSJacques Vidrine2002-10-31  Johan Danielsson  <[email protected]>
26044137ff4cSJacques Vidrine
26054137ff4cSJacques Vidrine	* check return value from gssapi_krb5_init
26064137ff4cSJacques Vidrine
26074137ff4cSJacques Vidrine	* 8003.c (gssapi_krb5_verify_8003_checksum): check size of input
26084137ff4cSJacques Vidrine
26094137ff4cSJacques Vidrine2002-09-03  Johan Danielsson  <[email protected]>
26104137ff4cSJacques Vidrine
26114137ff4cSJacques Vidrine	* wrap.c (wrap_des3): use ETYPE_DES3_CBC_NONE
26124137ff4cSJacques Vidrine
26134137ff4cSJacques Vidrine	* unwrap.c (unwrap_des3): use ETYPE_DES3_CBC_NONE
26144137ff4cSJacques Vidrine
26154137ff4cSJacques Vidrine2002-09-02  Johan Danielsson  <[email protected]>
26164137ff4cSJacques Vidrine
26174137ff4cSJacques Vidrine	* init_sec_context.c: we need to generate a local subkey here
2618adb0ddaeSAssar Westerlund
2619adb0ddaeSAssar Westerlund2002-08-20  Jacques Vidrine <[email protected]>
2620adb0ddaeSAssar Westerlund
2621adb0ddaeSAssar Westerlund	* acquire_cred.c, inquire_cred.c, release_cred.c: Use default
2622adb0ddaeSAssar Westerlund	  credential resolution if gss_acquire_cred is called with
2623adb0ddaeSAssar Westerlund	  GSS_C_NO_NAME.
2624adb0ddaeSAssar Westerlund
2625adb0ddaeSAssar Westerlund2002-06-20  Jacques Vidrine <[email protected]>
2626adb0ddaeSAssar Westerlund
2627adb0ddaeSAssar Westerlund	* import_name.c: Compare name types by value if pointers do
2628adb0ddaeSAssar Westerlund	  not match.  Reported by: "Douglas E. Engert" <[email protected]>
2629adb0ddaeSAssar Westerlund
2630adb0ddaeSAssar Westerlund2002-05-20  Jacques Vidrine <[email protected]>
2631adb0ddaeSAssar Westerlund
2632adb0ddaeSAssar Westerlund	* verify_mic.c (gss_verify_mic), unwrap.c (gss_unwrap): initialize
2633adb0ddaeSAssar Westerlund	  the qop_state parameter.  from Doug Rabson <[email protected]>
2634adb0ddaeSAssar Westerlund
2635adb0ddaeSAssar Westerlund2002-05-09  Jacques Vidrine <[email protected]>
2636adb0ddaeSAssar Westerlund
2637adb0ddaeSAssar Westerlund	* acquire_cred.c: handle GSS_C_INITIATE/GSS_C_ACCEPT/GSS_C_BOTH
2638adb0ddaeSAssar Westerlund
2639adb0ddaeSAssar Westerlund2002-05-08  Jacques Vidrine <[email protected]>
2640adb0ddaeSAssar Westerlund
2641adb0ddaeSAssar Westerlund	* acquire_cred.c: initialize gssapi; handle null desired_name
2642adb0ddaeSAssar Westerlund
2643adb0ddaeSAssar Westerlund2002-03-22  Johan Danielsson  <[email protected]>
2644adb0ddaeSAssar Westerlund
2645adb0ddaeSAssar Westerlund	* Makefile.am: remove non-functional stuff accidentally committed
2646adb0ddaeSAssar Westerlund
2647adb0ddaeSAssar Westerlund2002-03-11  Assar Westerlund  <[email protected]>
2648adb0ddaeSAssar Westerlund
2649adb0ddaeSAssar Westerlund	* Makefile.am (libgssapi_la_LDFLAGS): bump version to 3:5:2
2650adb0ddaeSAssar Westerlund	* 8003.c (gssapi_krb5_verify_8003_checksum): handle zero channel
2651adb0ddaeSAssar Westerlund	bindings
2652adb0ddaeSAssar Westerlund
2653adb0ddaeSAssar Westerlund2001-10-31  Jacques Vidrine <[email protected]>
2654adb0ddaeSAssar Westerlund
2655adb0ddaeSAssar Westerlund	* get_mic.c (mic_des3): MIC computation using DES3/SHA1
2656adb0ddaeSAssar Westerlund	was bogusly appending the message buffer to the result,
2657adb0ddaeSAssar Westerlund	overwriting a heap buffer in the process.
26585e9cd1aeSAssar Westerlund
26595e9cd1aeSAssar Westerlund2001-08-29  Assar Westerlund  <[email protected]>
26605e9cd1aeSAssar Westerlund
26615e9cd1aeSAssar Westerlund	* 8003.c (gssapi_krb5_verify_8003_checksum,
26625e9cd1aeSAssar Westerlund	gssapi_krb5_create_8003_checksum): make more consistent by always
26635e9cd1aeSAssar Westerlund	returning an gssapi error and setting minor status.  update
26645e9cd1aeSAssar Westerlund	callers
26655e9cd1aeSAssar Westerlund
26665e9cd1aeSAssar Westerlund2001-08-28  Jacques Vidrine  <[email protected]>
26675e9cd1aeSAssar Westerlund
26685e9cd1aeSAssar Westerlund	* accept_sec_context.c: Create a cache for delegated credentials
26695e9cd1aeSAssar Westerlund	  when needed.
26705e9cd1aeSAssar Westerlund
26715e9cd1aeSAssar Westerlund2001-08-28  Assar Westerlund  <[email protected]>
26725e9cd1aeSAssar Westerlund
26735e9cd1aeSAssar Westerlund	* Makefile.am (libgssapi_la_LDFLAGS): set version to 3:4:2
26745e9cd1aeSAssar Westerlund
26755e9cd1aeSAssar Westerlund2001-08-23  Assar Westerlund  <[email protected]>
26765e9cd1aeSAssar Westerlund
26775e9cd1aeSAssar Westerlund	*  *.c: handle minor_status more consistently
26785e9cd1aeSAssar Westerlund
26795e9cd1aeSAssar Westerlund	* display_status.c (gss_display_status): handle krb5_get_err_text
26805e9cd1aeSAssar Westerlund	failing
26815e9cd1aeSAssar Westerlund
26825e9cd1aeSAssar Westerlund2001-08-15  Johan Danielsson  <[email protected]>
26835e9cd1aeSAssar Westerlund
26845e9cd1aeSAssar Westerlund	* gssapi_locl.h: fix prototype for gssapi_krb5_init
26855e9cd1aeSAssar Westerlund
26865e9cd1aeSAssar Westerlund2001-08-13  Johan Danielsson  <[email protected]>
26875e9cd1aeSAssar Westerlund
26885e9cd1aeSAssar Westerlund	* accept_sec_context.c (gsskrb5_register_acceptor_identity): init
26895e9cd1aeSAssar Westerlund	context and check return value from kt_resolve
26905e9cd1aeSAssar Westerlund
26915e9cd1aeSAssar Westerlund	* init.c: return error code
26925e9cd1aeSAssar Westerlund
26935e9cd1aeSAssar Westerlund2001-07-19  Assar Westerlund  <[email protected]>
26945e9cd1aeSAssar Westerlund
26955e9cd1aeSAssar Westerlund	* Makefile.am (libgssapi_la_LDFLAGS): update to 3:3:2
26965e9cd1aeSAssar Westerlund
26975e9cd1aeSAssar Westerlund2001-07-12  Assar Westerlund  <[email protected]>
26985e9cd1aeSAssar Westerlund
26995e9cd1aeSAssar Westerlund	* Makefile.am (libgssapi_la_LIBADD): add required library
27005e9cd1aeSAssar Westerlund	dependencies
27015e9cd1aeSAssar Westerlund
27025e9cd1aeSAssar Westerlund2001-07-06  Assar Westerlund  <[email protected]>
27035e9cd1aeSAssar Westerlund
27045e9cd1aeSAssar Westerlund	* accept_sec_context.c (gsskrb5_register_acceptor_identity): set
27055e9cd1aeSAssar Westerlund	the keytab to be used for gss_acquire_cred too'
27065e9cd1aeSAssar Westerlund
27075e9cd1aeSAssar Westerlund2001-07-03  Assar Westerlund  <[email protected]>
27085e9cd1aeSAssar Westerlund
27095e9cd1aeSAssar Westerlund	* Makefile.am (libgssapi_la_LDFLAGS): set version to 3:2:2
27105e9cd1aeSAssar Westerlund
27115e9cd1aeSAssar Westerlund2001-06-18  Assar Westerlund  <[email protected]>
27125e9cd1aeSAssar Westerlund
27135e9cd1aeSAssar Westerlund	* wrap.c: replace gss_krb5_getsomekey with gss_krb5_get_localkey
27145e9cd1aeSAssar Westerlund	and gss_krb5_get_remotekey
27155e9cd1aeSAssar Westerlund	* verify_mic.c: update krb5_auth_con function names use
27165e9cd1aeSAssar Westerlund	gss_krb5_get_remotekey
27175e9cd1aeSAssar Westerlund	* unwrap.c: replace gss_krb5_getsomekey with gss_krb5_get_localkey
27185e9cd1aeSAssar Westerlund	and gss_krb5_get_remotekey
27195e9cd1aeSAssar Westerlund	* gssapi_locl.h (gss_krb5_get_remotekey, gss_krb5_get_localkey):
27205e9cd1aeSAssar Westerlund	add prototypes
27215e9cd1aeSAssar Westerlund	* get_mic.c: update krb5_auth_con function names. use
27225e9cd1aeSAssar Westerlund	gss_krb5_get_localkey
27235e9cd1aeSAssar Westerlund	* accept_sec_context.c: update krb5_auth_con function names
27245e9cd1aeSAssar Westerlund
27255e9cd1aeSAssar Westerlund2001-05-17  Assar Westerlund  <[email protected]>
27265e9cd1aeSAssar Westerlund
27275e9cd1aeSAssar Westerlund	* Makefile.am: bump version to 3:1:2
27285e9cd1aeSAssar Westerlund
27295e9cd1aeSAssar Westerlund2001-05-14  Assar Westerlund  <[email protected]>
27305e9cd1aeSAssar Westerlund
27315e9cd1aeSAssar Westerlund	* address_to_krb5addr.c: adapt to new address functions
27325e9cd1aeSAssar Westerlund
27335e9cd1aeSAssar Westerlund2001-05-11  Assar Westerlund  <[email protected]>
27345e9cd1aeSAssar Westerlund
27355e9cd1aeSAssar Westerlund	* try to return the error string from libkrb5 where applicable
27365e9cd1aeSAssar Westerlund
27375e9cd1aeSAssar Westerlund2001-05-08  Assar Westerlund  <[email protected]>
27385e9cd1aeSAssar Westerlund
27395e9cd1aeSAssar Westerlund	* delete_sec_context.c (gss_delete_sec_context): remember to free
27405e9cd1aeSAssar Westerlund	the memory used by the ticket itself. from <[email protected]>
27415e9cd1aeSAssar Westerlund
27425e9cd1aeSAssar Westerlund2001-05-04  Assar Westerlund  <[email protected]>
27435e9cd1aeSAssar Westerlund
27445e9cd1aeSAssar Westerlund	* gssapi_locl.h: add config.h for completeness
27455e9cd1aeSAssar Westerlund	* gssapi.h: remove config.h, this is an installed header file
27465e9cd1aeSAssar Westerlund	sys/types.h is not needed either
27475e9cd1aeSAssar Westerlund
27485e9cd1aeSAssar Westerlund2001-03-12  Assar Westerlund  <[email protected]>
27495e9cd1aeSAssar Westerlund
27505e9cd1aeSAssar Westerlund	* acquire_cred.c (gss_acquire_cred): remove memory leaks.  from
27515e9cd1aeSAssar Westerlund	Jason R Thorpe <[email protected]>
27525e9cd1aeSAssar Westerlund
27535e9cd1aeSAssar Westerlund2001-02-18  Assar Westerlund  <[email protected]>
27545e9cd1aeSAssar Westerlund
27555e9cd1aeSAssar Westerlund	* accept_sec_context.c (gss_accept_sec_context): either return
27565e9cd1aeSAssar Westerlund	gss_name NULL-ed or set
27575e9cd1aeSAssar Westerlund
27585e9cd1aeSAssar Westerlund	* import_name.c: set minor_status in some cases where it was not
27595e9cd1aeSAssar Westerlund	done
27605e9cd1aeSAssar Westerlund
2761283d988cSMark Murray2001-02-15  Assar Westerlund  <[email protected]>
2762283d988cSMark Murray
2763283d988cSMark Murray	* wrap.c: use krb5_generate_random_block for the confounders
2764283d988cSMark Murray
2765283d988cSMark Murray2001-01-30  Assar Westerlund  <[email protected]>
2766283d988cSMark Murray
2767283d988cSMark Murray	* Makefile.am (libgssapi_la_LDFLAGS): bump version to 3:0:2
2768283d988cSMark Murray	* acquire_cred.c, init_sec_context.c, release_cred.c: add support
2769283d988cSMark Murray	for getting creds from a keytab, from [email protected]
2770283d988cSMark Murray
2771283d988cSMark Murray	* copy_ccache.c: add gss_krb5_copy_ccache
2772283d988cSMark Murray
2773283d988cSMark Murray2001-01-27  Assar Westerlund  <[email protected]>
2774283d988cSMark Murray
2775283d988cSMark Murray	* get_mic.c: cast parameters to des function to non-const pointers
2776283d988cSMark Murray 	to handle the case where these functions actually take non-const
2777283d988cSMark Murray 	des_cblock *
2778283d988cSMark Murray
2779283d988cSMark Murray2001-01-09  Assar Westerlund  <[email protected]>
2780283d988cSMark Murray
2781283d988cSMark Murray	* accept_sec_context.c (gss_accept_sec_context): use krb5_rd_cred2
2782283d988cSMark Murray	instead of krb5_rd_cred
2783283d988cSMark Murray
2784283d988cSMark Murray2000-12-11  Assar Westerlund  <[email protected]>
278513e3f4d6SMark Murray
278613e3f4d6SMark Murray	* Makefile.am (libgssapi_la_LDFLAGS): bump to 2:3:1
278713e3f4d6SMark Murray
278813e3f4d6SMark Murray2000-12-08  Assar Westerlund  <[email protected]>
278913e3f4d6SMark Murray
279013e3f4d6SMark Murray	* wrap.c (wrap_des3): use the checksum as ivec when encrypting the
279113e3f4d6SMark Murray	sequence number
279213e3f4d6SMark Murray	* unwrap.c (unwrap_des3): use the checksum as ivec when encrypting
279313e3f4d6SMark Murray	the sequence number
279413e3f4d6SMark Murray	* init_sec_context.c (init_auth): always zero fwd_data
279513e3f4d6SMark Murray
279613e3f4d6SMark Murray2000-12-06  Johan Danielsson  <[email protected]>
279713e3f4d6SMark Murray
279813e3f4d6SMark Murray	* accept_sec_context.c: de-pointerise auth_context parameter to
279913e3f4d6SMark Murray	krb5_mk_rep
280013e3f4d6SMark Murray
280113e3f4d6SMark Murray2000-11-15  Assar Westerlund  <[email protected]>
280213e3f4d6SMark Murray
280313e3f4d6SMark Murray	* init_sec_context.c (init_auth): update to new
2804b528cefcSMark Murray	krb5_build_authenticator
2805b528cefcSMark Murray
2806b528cefcSMark Murray2000-09-19  Assar Westerlund  <[email protected]>
2807b528cefcSMark Murray
2808b528cefcSMark Murray	* Makefile.am (libgssapi_la_LDFLAGS): bump to 2:2:1
2809b528cefcSMark Murray
2810b528cefcSMark Murray2000-08-27  Assar Westerlund  <[email protected]>
2811b528cefcSMark Murray
2812b528cefcSMark Murray	* init_sec_context.c: actually pay attention to `time_req'
2813b528cefcSMark Murray	* init_sec_context.c: re-organize.  leak less memory.
2814b528cefcSMark Murray	* gssapi_locl.h (gssapi_krb5_encapsulate, gss_krb5_getsomekey):
2815b528cefcSMark Murray	update prototypes add assert.h
2816b528cefcSMark Murray	* gssapi.h (GSS_KRB5_CONF_C_QOP_DES, GSS_KRB5_CONF_C_QOP_DES3_KD):
2817b528cefcSMark Murray	add
2818b528cefcSMark Murray	* verify_mic.c: re-organize and add 3DES code
2819b528cefcSMark Murray	* wrap.c: re-organize and add 3DES code
2820b528cefcSMark Murray	* unwrap.c: re-organize and add 3DES code
2821b528cefcSMark Murray	* get_mic.c: re-organize and add 3DES code
2822b528cefcSMark Murray	* encapsulate.c (gssapi_krb5_encapsulate): do not free `in_data',
2823b528cefcSMark Murray	let the caller do that.  fix the callers.
2824b528cefcSMark Murray
2825b528cefcSMark Murray2000-08-16  Assar Westerlund  <[email protected]>
2826b528cefcSMark Murray
2827b528cefcSMark Murray	* Makefile.am: bump version to 2:1:1
2828b528cefcSMark Murray
2829b528cefcSMark Murray2000-07-29  Assar Westerlund  <[email protected]>
2830b528cefcSMark Murray
2831b528cefcSMark Murray	* decapsulate.c (gssapi_krb5_verify_header): sanity-check length
2832b528cefcSMark Murray
2833b528cefcSMark Murray2000-07-25  Johan Danielsson  <[email protected]>
2834b528cefcSMark Murray
2835b528cefcSMark Murray	* Makefile.am: bump version to 2:0:1
2836b528cefcSMark Murray
2837b528cefcSMark Murray2000-07-22  Assar Westerlund  <[email protected]>
2838b528cefcSMark Murray
2839b528cefcSMark Murray	* gssapi.h: update OID for GSS_C_NT_HOSTBASED_SERVICE and other
2840b528cefcSMark Murray	details from rfc2744
2841b528cefcSMark Murray
2842b528cefcSMark Murray2000-06-29  Assar Westerlund  <[email protected]>
2843b528cefcSMark Murray
2844b528cefcSMark Murray	* address_to_krb5addr.c (gss_address_to_krb5addr): actually use
2845b528cefcSMark Murray	`int' instead of `sa_family_t' for the address family.
2846b528cefcSMark Murray
2847b528cefcSMark Murray2000-06-21  Assar Westerlund  <[email protected]>
2848b528cefcSMark Murray
2849b528cefcSMark Murray	* add support for token delegation.  From Daniel Kouril
2850b528cefcSMark Murray	<[email protected]> and Miroslav Ruda <[email protected]>
2851b528cefcSMark Murray
2852b528cefcSMark Murray2000-05-15  Assar Westerlund  <[email protected]>
2853b528cefcSMark Murray
2854b528cefcSMark Murray	* Makefile.am (libgssapi_la_LDFLAGS): set version to 1:1:1
2855b528cefcSMark Murray
2856b528cefcSMark Murray2000-04-12  Assar Westerlund  <[email protected]>
2857b528cefcSMark Murray
2858b528cefcSMark Murray	* release_oid_set.c (gss_release_oid_set): clear set for
2859b528cefcSMark Murray	robustness.  From GOMBAS Gabor <[email protected]>
2860b528cefcSMark Murray	* release_name.c (gss_release_name): reset input_name for
2861b528cefcSMark Murray	robustness.  From GOMBAS Gabor <[email protected]>
2862b528cefcSMark Murray	* release_buffer.c (gss_release_buffer): set value to NULL to be
2863b528cefcSMark Murray	more robust.  From GOMBAS Gabor <[email protected]>
2864	* add_oid_set_member.c (gss_add_oid_set_member): actually check if
2865	the oid is a member first.  leave the oid_set unchanged if realloc
2866	fails.
2867
28682000-02-13  Assar Westerlund  <[email protected]>
2869
2870	* Makefile.am: set version to 1:0:1
2871
28722000-02-12  Assar Westerlund  <[email protected]>
2873
2874	* gssapi_locl.h: add flags for import/export
2875	* import_sec_context.c (import_sec_context: add flags for what
2876	fields are included.  do not include the authenticator for now.
2877	* export_sec_context.c (export_sec_context: add flags for what
2878	fields are included.  do not include the authenticator for now.
2879	* accept_sec_context.c (gss_accept_sec_context): set target in
2880	context_handle
2881
28822000-02-11  Assar Westerlund  <[email protected]>
2883
2884	* delete_sec_context.c (gss_delete_sec_context): set context to
2885	GSS_C_NO_CONTEXT
2886
2887	* Makefile.am: add {export,import}_sec_context.c
2888	* export_sec_context.c: new file
2889	* import_sec_context.c: new file
2890	* accept_sec_context.c (gss_accept_sec_context): set trans flag
2891
28922000-02-07  Assar Westerlund  <[email protected]>
2893
2894	* Makefile.am: set version to 0:5:0
2895
28962000-01-26  Assar Westerlund  <[email protected]>
2897
2898	* delete_sec_context.c (gss_delete_sec_context): handle a NULL
2899	output_token
2900
2901	* wrap.c: update to pseudo-standard APIs for md4,md5,sha.  some
2902	changes to libdes calls to make them more portable.
2903	* verify_mic.c: update to pseudo-standard APIs for md4,md5,sha.
2904	some changes to libdes calls to make them more portable.
2905	* unwrap.c: update to pseudo-standard APIs for md4,md5,sha.  some
2906	changes to libdes calls to make them more portable.
2907	* get_mic.c: update to pseudo-standard APIs for md4,md5,sha.  some
2908	changes to libdes calls to make them more portable.
2909	* 8003.c: update to pseudo-standard APIs for md4,md5,sha.
2910
29112000-01-06  Assar Westerlund  <[email protected]>
2912
2913	* Makefile.am: set version to 0:4:0
2914
29151999-12-26  Assar Westerlund  <[email protected]>
2916
2917	* accept_sec_context.c (gss_accept_sec_context): always set
2918 	`output_token'
2919	* init_sec_context.c (init_auth): always initialize `output_token'
2920	* delete_sec_context.c (gss_delete_sec_context): always set
2921 	`output_token'
2922
29231999-12-06  Assar Westerlund  <[email protected]>
2924
2925	* Makefile.am: bump version to 0:3:0
2926
29271999-10-20  Assar Westerlund  <[email protected]>
2928
2929	* Makefile.am: set version to 0:2:0
2930
29311999-09-21  Assar Westerlund  <[email protected]>
2932
2933	* init_sec_context.c (gss_init_sec_context): initialize `ticket'
2934
2935	* gssapi.h (gss_ctx_id_t_desc): add ticket in here.  ick.
2936
2937	* delete_sec_context.c (gss_delete_sec_context): free ticket
2938
2939	* accept_sec_context.c (gss_accept_sec_context): stove away
2940 	`krb5_ticket' in context so that ugly programs such as
2941 	gss_nt_server can get at it.  uck.
2942
29431999-09-20  Johan Danielsson  <[email protected]>
2944
2945	* accept_sec_context.c: set minor_status
2946
29471999-08-04  Assar Westerlund  <[email protected]>
2948
2949	* display_status.c (calling_error, routine_error): right shift the
2950 	code to make it possible to index into the arrays
2951
29521999-07-28  Assar Westerlund  <[email protected]>
2953
2954	* gssapi.h (GSS_C_AF_INET6): add
2955
2956	* import_name.c (import_hostbased_name): set minor_status
2957
29581999-07-26  Assar Westerlund  <[email protected]>
2959
2960	* Makefile.am: set version to 0:1:0
2961
2962Wed Apr  7 14:05:15 1999  Johan Danielsson  <[email protected]>
2963
2964	* display_status.c: set minor_status
2965
2966	* init_sec_context.c: set minor_status
2967
2968	* lib/gssapi/init.c: remove donep (check gssapi_krb5_context
2969 	directly)
2970
2971