~ubuntu-branches/ubuntu/maverick/samba/maverick-security

« back to all changes in this revision

Viewing changes to source/nsswitch/pam_winbind.c

  • Committer: Bazaar Package Importer
  • Author(s): Andrew Mitchell
  • Date: 2009-05-18 13:26:04 UTC
  • mfrom: (0.28.5 sid)
  • Revision ID: james.westby@ubuntu.com-20090518132604-ebyuqimgymtr3h0k
Tags: 2:3.3.4-2ubuntu1
* Merge from debian unstable, remaining changes:
  + debian/patches/VERSION.patch:
    - setup SAMBA_VERSION_SUFFIX to Ubuntu.
  + debian/smb.conf:
    - add "(Samba, Ubuntu)" to server string.
    - comment out the default [homes] share, and add a comment about
      "valid users = %S" to show users how to restrict access to
      \\server\username to only username.
    - Set 'usershare allow guests', so that usershare admins are
      allowed to create public shares in addition to authenticated
      ones.
    - add map to guest = Bad user, maps bad username to guest access.
  + debian/samba-common.config:
    - Do not change priority to high if dhclient3 is installed.
    - Use priority medium instead of high for the workgroup question.
  + debian/samba-common.postinst: Add more informative error message for
    the case where smb.conf was manually deleted (LP: #312449)
  + debian/mksambapasswd.awk:
    - Do not add user with UID less than 1000 to smbpasswd.
  + debian/control:
    - Make libwbclient0 replace/conflict with hardy's likewise-open.
    - Don't build against ctdb.
    - Add suggests keyutils for smbfs. (LP: #300221)
  + debian/rules:
    - enable "native" PIE hardening.
    - remove --with-ctdb and --with-cluster-support=yes
  + Add ufw integration:
    - Created debian/samba.ufw profile.
    - debian/rules, debian/samba.dirs, debian/samba.files: install 
      profile
    - debian/control: have samba sugguest ufw.
* Dropped patches:
  + debian/patches/fix-upstream-bug-6186.patch: Merged upstream

Show diffs side-by-side

added added

removed removed

Lines of Context:
2318
2318
        const char *user;
2319
2319
        wbcErr wbc_status = WBC_ERR_SUCCESS;
2320
2320
 
 
2321
        ZERO_STRUCT(logoff);
 
2322
 
2321
2323
        retval = _pam_winbind_init_context(pamh, flags, argc, argv, &ctx);
2322
2324
        if (retval) {
2323
2325
                goto out;
2365
2367
                wbc_flags = WBFLAG_PAM_KRB5 |
2366
2368
                        WBFLAG_PAM_CONTACT_TRUSTDOM;
2367
2369
 
2368
 
                ZERO_STRUCT(logoff);
2369
 
 
2370
2370
                logoff.username         = user;
2371
2371
 
2372
2372
                if (ccname) {
2406
2406
                                                     user, "wbcLogoffUser");
2407
2407
                wbcFreeMemory(error);
2408
2408
                wbcFreeMemory(logoff.blobs);
 
2409
                logoff.blobs = NULL;
2409
2410
 
2410
2411
                if (!WBC_ERROR_IS_OK(wbc_status)) {
2411
2412
                        _pam_log(ctx, LOG_INFO,