pam-krb5 2.5

The PAM module was freeing the return value of pam_get_item when changing passwords, which is an explicit no-no (since PAM frees the memory internally). This was exposed with the use_authtok support for password changes and reported (with a patch!) by Arne Nordmark while I was on vacation.

That's now fixed, and since I hate to do a release without knocking something off of the TODO list, I also implemented the stricter authorization checking in pam_sm_acct_mgmt from the NetBSD version of the PAM module (well, not done quite the same, but similar). There are also a few other minor bug fixes and improvements.

You can get the latest version from the pam-krb5 distribution page. I also modified my release script to generate MD5 checksum files and (more usefully) PGP signatures for all tarball releases that didn't have them, so this release is also signed. I added a link to the signature on the software page and removed the FTP link; the software is still also available via FTP, but FTP is rather obsolete and it was cluttering the page.

At some point, now, I need to go back and sign all the other current tarballs of releases and then update all my other software pages accordingly.

Posted: 2006-11-03 20:49 — Why no comments?

Last spun 2013-07-01 from thread modified 2013-01-04