Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 98848 - Bring back mit-krb5-1.3.6-r2
Summary: Bring back mit-krb5-1.3.6-r2
Status: RESOLVED DUPLICATE of bug 98303
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: x86 Linux
: High critical (vote)
Assignee: Gentoo Kerberos Maintainers
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-07-12 22:31 UTC by Wolf Giesen (RETIRED)
Modified: 2005-07-13 04:50 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Wolf Giesen (RETIRED) gentoo-dev 2005-07-12 22:31:02 UTC
mit-krb5-1.4.1 breaks Samba 3.0.14a in ADS mode, see bug #98303. Downgrading to
mit-krb5-1.3.6-r2 solves the problem. I know it's a security risk, but the other
option is a system that is *broken*.

Now 1.3.6-r2 disappeared from the portage tree -> no way for people to get their
systems working again.

Reproducible: Always
Steps to Reproduce:
Please see bug #98303
Actual Results:  
Cannot downgrade to get Samba working in ADS mode again.

Expected Results:  
Fix Samba with krb-1.4.1; in the meantime, keep 1.3.6-r2 around.
Comment 1 Greg Tassone 2005-07-12 22:38:46 UTC
I'm not sure, but this may have to do with the following MAJOR security breach
in this package -- just resolved today:

http://bugs.gentoo.org/show_bug.cgi?id=98799
Comment 2 Wolf Giesen (RETIRED) gentoo-dev 2005-07-13 00:48:59 UTC
Well, for me a non-working system is a more severe breakage than a security hole
in a network I trust 98%.

I *cannot* run use mit-krb-1.4.1 unless the Samba issue is fixed. This is
*critical* in my production environment.
Comment 3 Wolf Giesen (RETIRED) gentoo-dev 2005-07-13 02:07:37 UTC
mit-krb5-1.4.1-r2 does *not* fix the Samba problem!
Comment 4 Jakub Moc (RETIRED) gentoo-dev 2005-07-13 02:22:33 UTC
Grab it from WebCVS and put it into your overlay if you want it...

http://www.gentoo.org/cgi-bin/viewcvs.cgi/app-crypt/mit-krb5/
Comment 5 Wolf Giesen (RETIRED) gentoo-dev 2005-07-13 02:28:46 UTC
I managed to get it back from one of my servers that was not synced yet.

Now, I do understand you'd want the new version out ASAP, but if we need to have
samba working with krb, are those of us supposed to find out and do it manually
like I did?

I can't really decide here, but I think pulling the old version completely was
not the best move. Convince me otherwise .-/
Comment 6 Wolf Giesen (RETIRED) gentoo-dev 2005-07-13 02:41:35 UTC
BTW: Can no longer build PHP with kerberos support with 1.4.1.
Comment 7 Greg Tassone 2005-07-13 02:49:55 UTC
(In reply to comment #6)
> BTW: Can no longer build PHP with kerberos support with 1.4.1.

Quick aside:  I'm having this as well.  I've seen one similar forum thread so
far, but I think the recent upgrade has made it more wide-spread now.
Comment 8 Jakub Moc (RETIRED) gentoo-dev 2005-07-13 02:52:13 UTC
(In reply to comment #6)
> BTW: Can no longer build PHP with kerberos support with 1.4.1.

This is really not much productive to moan here... I don't know if there is a
bug open for the PHP problem; if not, then open a new bug and post the error
messages and whatnot there, please.
Comment 9 Jakub Moc (RETIRED) gentoo-dev 2005-07-13 02:57:34 UTC
Wrt comment #6 and comment #7: does Bug 98842 describe the problem w/ PHP and
new mit-krb5 version? 
Comment 10 Wolf Giesen (RETIRED) gentoo-dev 2005-07-13 02:58:20 UTC
Well, it does not build with -kerberos, either. Complains about libcrpyto.
But set that aside, as it is not the main problem here. (Yet :-)
Comment 11 Wolf Giesen (RETIRED) gentoo-dev 2005-07-13 03:02:29 UTC
To #9: Yes I guess it does. Looks like what I get.
Comment 12 Wolf Giesen (RETIRED) gentoo-dev 2005-07-13 03:03:52 UTC
What didn't work was building with -kerberos in package.use
Comment 13 Wolf Giesen (RETIRED) gentoo-dev 2005-07-13 03:15:54 UTC
My fault. Workaround in #98842 is viable.
Comment 14 Greg Tassone 2005-07-13 03:21:44 UTC
(In reply to comment #9)
> Wrt comment #6 and comment #7: does Bug 98842 describe the problem w/ PHP and
> new mit-krb5 version? 

Yes, this describes the PHP problem perfectly.  The key error is in the config file:
---------------
/usr/lib/gcc-lib/i686-pc-linux-gnu/3.3.5-20050130/../../../../i686-pc-linux-gnu/bin/ld:
cannot find -lgssapi
collect2: ld returned 1 exit status
---------------

The line:
cannot find -lgssapi

appears to be the key problem (part of the kerberos package).  Removing the
kerberos USE flag from the build compiles the package perfectly for me.  I'll
add to that bug as well.
Comment 15 Greg Tassone 2005-07-13 03:22:57 UTC
(In reply to comment #8)
> (In reply to comment #6)
> > BTW: Can no longer build PHP with kerberos support with 1.4.1.
> 
> This is really not much productive to moan here... 

FYI:  I only wanted to quickly let you know that it appears the new package may
be affecting more than this bug here...
Comment 16 Seemant Kulleen (RETIRED) gentoo-dev 2005-07-13 04:31:29 UTC
Wgi, give me a few hours to sort out samba + mit 1.4.1.  I'm sorry for your
inconvenience (I really am!).  If I'm unable to put a fix out, I'll backport the
security fixes on 1.3.6 and put out 1.3.6-r3 for you.  I'm only asking that you
bear with me for a few hours.

*** This bug has been marked as a duplicate of 98303 ***
Comment 17 Wolf Giesen (RETIRED) gentoo-dev 2005-07-13 04:50:43 UTC
Of course. Thanks a lot for the effort!