Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 25384 - OpenAFS latest is 1.2.9a _not_ 1.3.2-r1
Summary: OpenAFS latest is 1.2.9a _not_ 1.3.2-r1
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Linux bug wranglers
URL: http://openafs.org/release/latest.html
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2003-07-27 13:34 UTC by Nick Palmer
Modified: 2003-07-29 05:45 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
Ebuild for OpenAFS 1.2.9a (openafs-1.2.9a.ebuild,2.90 KB, text/plain)
2003-07-27 13:35 UTC, Nick Palmer
Details
Ebuild for OpenAFS 1.2.9a (openafs-1.2.9a.ebuild,2.90 KB, text/plain)
2003-07-27 13:36 UTC, Nick Palmer
Details
Ebuild for OpenAFS 1.2.9a (openafs-1.2.9a.ebuild,2.90 KB, application/octet-stream)
2003-07-27 13:36 UTC, Nick Palmer
Details
Patch for pinstall for 1.2.9a (pinstall-1.2.9a.patch,527 bytes, patch)
2003-07-27 13:38 UTC, Nick Palmer
Details | Diff
Digest for 1.2.9a. (digest-openafs-1.2.9a,72 bytes, text/plain)
2003-07-27 13:39 UTC, Nick Palmer
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Nick Palmer 2003-07-27 13:34:27 UTC
The 1.3.1 and 1.3.2 versions of AFS are versions that came out prematurely. I am
not privy to exactly how all that went down. However, the latest release is
1.2.9a, according to the openafs.org website. The 1.3.2-r1 and 1.3.2 ebuilds
should be marked ~x86, and the 1.2.9a ebuild I will attach should be marked as
the latest stable release.

Note that the bug in pinstall is still there. I will also attach a new patch for
this bug.
Comment 1 Nick Palmer 2003-07-27 13:35:52 UTC
Created attachment 15091 [details]
Ebuild for OpenAFS 1.2.9a

Attaching the ebuild for 1.2.9a.
Comment 2 Nick Palmer 2003-07-27 13:36:10 UTC
Created attachment 15092 [details]
Ebuild for OpenAFS 1.2.9a

Attaching the ebuild for 1.2.9a.
Comment 3 Nick Palmer 2003-07-27 13:36:22 UTC
Created attachment 15093 [details]
Ebuild for OpenAFS 1.2.9a

Attaching the ebuild for 1.2.9a.
Comment 4 Nick Palmer 2003-07-27 13:38:34 UTC
Created attachment 15094 [details, diff]
Patch for pinstall for 1.2.9a

Sorry for the multiple attachements of teh ebuild. Got an error posting it so
retried, and it ended up in here multiple times. Marked the duplicates as
obsolete.
Comment 5 Nick Palmer 2003-07-27 13:39:34 UTC
Created attachment 15095 [details]
Digest for 1.2.9a.

Digest for 1.2.9a.
Comment 6 Martin Holzer (RETIRED) gentoo-dev 2003-07-27 14:11:32 UTC
please follow GLSA

http://forums.gentoo.org/viewtopic.php?t=44890
Comment 7 hinman 2003-07-29 05:45:15 UTC
1.2.9.a fixes the vulnerability that is listed in 

http://forums.gentoo.org/viewtopic.php?t=44890

You have to follow the link to the OpenAFS advisory @

http://www.openafs.org/pages/security/OPENAFS-SA-2003-001.txt

And in the Fixes section you find
FIXES
=====

The OpenAFS project recomments that all users of kaserver disable all
cross-realm authentication, by either deleting cross-realm keys (using
"kas delete"; simply disabling the keys is insufficient), upgrading to
OpenAFS 1.2.9 when it becomes available (where kaserver cross-realm
authentication is disabled by default), or applying this kaserver patch,
which disables cross-realm authentication in kaserver by default:

So it looks like 1.2.9a is safe (or at least as safe as 1.3.2).