Subject: CVS commit: pkgsrc/www/ap-auth-ldap
To: None <pkgsrc-changes@NetBSD.org>
From: Klaus Klein <kleink@netbsd.org>
List: pkgsrc-changes
Date: 01/15/2006 16:25:41
Module Name:	pkgsrc
Committed By:	kleink
Date:		Sun Jan 15 16:25:41 UTC 2006

Modified Files:
	pkgsrc/www/ap-auth-ldap: Makefile distinfo
	pkgsrc/www/ap-auth-ldap/patches: patch-aa

Log Message:
Update to ap-auth-ldap to 1.6.1; changes since 1.6.0 include:

     * Fixed security bug that could allow attacker to execute arbitrary
       commands as the apache user. [Digital Armaments, seregon at bughunter
       dot net]

     * Fixed bug that sometimes resulted in segfaults during periodic cache
       cleanup. [Stefan Gaffga]
     * Add AuthLDAPVersion option to specify which LDAP version to use on
       LDAP server. [Hans Petter Selasky]
     * Support ldaps:// urls automatically under OpenLDAP. No need to compile
       with --with-ssl; this is just to enable SSL with the Netscape SDK.
       [Andrew McAllister, Malcolm Locke]
     * Fixed bug where auth_ldap didn't always rebind as the AuthLDAPBindDN
       after doing an authorization. [Stephen Lombardo, Brent Putnam, Ace
       Suares, Ted Cabeen, others].
     * Fixed bug where we forgot to note a failed auth attempt which would
       result in the browser never giving the user a second chance to enter a
       password. [Thanks to many other people]


To generate a diff of this commit:
cvs rdiff -r1.23 -r1.24 pkgsrc/www/ap-auth-ldap/Makefile
cvs rdiff -r1.5 -r1.6 pkgsrc/www/ap-auth-ldap/distinfo
cvs rdiff -r1.1 -r1.2 pkgsrc/www/ap-auth-ldap/patches/patch-aa

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.