aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorStuart Shelton <stuart@shelton.me>2017-12-20 15:55:18 +0000
committerStuart Shelton <stuart@shelton.me>2017-12-20 15:55:18 +0000
commit73bc548b6e5c7a56ff4f22671726d1136c2ff4fd (patch)
tree082c2cbd3cf4bdcda516a2414ebfc73d5ca1721d /app-crypt
parentUpdate net-nds/openldap-2.4.44 (diff)
downloadsrcshelton-73bc548b6e5c7a56ff4f22671726d1136c2ff4fd.tar.gz
srcshelton-73bc548b6e5c7a56ff4f22671726d1136c2ff4fd.tar.bz2
srcshelton-73bc548b6e5c7a56ff4f22671726d1136c2ff4fd.zip
Add app-crypt/mit-krb5-1.15.2-r1
Diffstat (limited to 'app-crypt')
-rw-r--r--app-crypt/mit-krb5/Manifest2
-rw-r--r--app-crypt/mit-krb5/files/mit-krb5-1.15.2-fix-pkinit.patch98
-rw-r--r--app-crypt/mit-krb5/mit-krb5-1.15.2-r1.ebuild155
3 files changed, 255 insertions, 0 deletions
diff --git a/app-crypt/mit-krb5/Manifest b/app-crypt/mit-krb5/Manifest
index 09498458..17bf075d 100644
--- a/app-crypt/mit-krb5/Manifest
+++ b/app-crypt/mit-krb5/Manifest
@@ -9,6 +9,7 @@ AUX mit-krb5-1.12_warn_cflags.patch 448 SHA256 67d3c91061933bd5393b9a6ee8fe2e3f5
AUX mit-krb5-1.12_x32.patch 431 SHA256 c51b2602eb8a35d3520692455494cd9028cc927d33c85a28087e99c2989d9adc SHA512 8105894ad1fe144c7f7375580f00c8a1a33b666706bfcf01271f56477ef1970cf56d8bcc5eb8f9538f723a4fef670d2fb0dd17d29c7d22afc08a1152dac74879 WHIRLPOOL d6cf57a1e5a06f9d11c0507af7feb5c7dd51131babcfb9de8430980b7892c1b9cb2d8e862c314d24a6b6ed230318bbdaf696d79afd458332eeba7a98eb3d7f34
AUX mit-krb5-1.14.2-redeclared-ttyname.patch 660 SHA256 dc55c696421dedbc8b9933d05792b85e009195c464aa689f372acb714682bc73 SHA512 90a2adedcdca4e2079daaa613e2d4f08e948ccfaf56aba19a08b4cbe2257a6a60dcfd5bbc4b19ca64f584759b1a374d1894729a423e636bfec1969a675a1628e WHIRLPOOL 3dc18520d2dc3ccb80a1aada18635178c6920d59a496ac5ea404ca37f03580665486f5a8b7ee11601dc44fc9df77cb48035f231df3e13dec8cb56885a4ae9b0d
AUX mit-krb5-1.14.4-disable-nls.patch 1247 SHA256 1921304d585bbbcacbd5012a4ef6b696041aead8768c53b25c974f9b441ca901 SHA512 5fecc719c5c8a1f5c971443d42561615b8fb8c6b99b735a633c7479f109cfb6852eee5179e267a1e2576e52faf2311395ddabdb47f749b573ead3ddd86714e2e WHIRLPOOL 53d09ca0d1e1f49e2815dedd9b502707b268cebc73315fe87eb379c63c2967a7027a2457f90227e4bec851075bfde08a1a418eee976f4022c13e236f51677e91
+AUX mit-krb5-1.15.2-fix-pkinit.patch 3196 SHA256 7a21fd09ea4405bcca8baeb1da3239e932fc1d9a5ff57b116616baddad3307bd SHA512 d7b3f33f25e610b24f2854892d75016dfa5b5e34fac24600df80b91194f5fe2e6dbc35ea3a9a772e0dcdf7659263a56230e767fe393d32796c61b3bd5bb2de69 WHIRLPOOL 285d525bd8cc1e453ad0074627fb41c784e2a537e0f23657133d0e2e64be739d0c452faf5300daee67f4dc6d5386cb3fb1b984e4d74f60b6d3fcbda31a8ae48f
AUX mit-krb5-CVE-2014-5353.patch 820 SHA256 dbe25b16592a11e4c04652f0fc0267cf09bf7d6536b1eae063022ea2f90c4c81 SHA512 db45cf33516483024cc11242d35b011c750c61c77fc4baaa952172d36a2484f2ffee0bc6170e3d54ac34155f284bb40d73bbb9843fc78cfc127807efb960b8ea WHIRLPOOL 27150b91e0b9d055caff9bd6e8bb736e0bf25836ad719384a1b1456c70a48f64c815dabe445ccfe7eb42280ae7d91440994c2ce46cf9ca77195621ed0ece399a
AUX mit-krb5-CVE-2014-5354.patch 2344 SHA256 8cb9458dba6bd3e195c95d09097d69a2dedf687a7f5111f9d4ba54498b1e524c SHA512 134e3efb0fc9e562ba47b8ac013f62c6e3fa438ee8df1b68426303c8892f647aa74a6476be80d54ed7a1dd68dc60430f1bd15d6a04ae840a3c7fbe5a9f86298d WHIRLPOOL 611fe25ea4e9e5ffef5fab294843f1fd566c0cb5dbbd9e75879159ab902c42b0b127b451c35e50797cb36d8af2f131661773b0b856eaf762f8081310de4d498e
AUX mit-krb5-config_LDFLAGS.patch 466 SHA256 fbb4d9be71ef536a344d415b9c56ea42c5c2a2ef02ec3a866d9da47b3acd93d3 SHA512 9a1ca9b33e7708346eda78d199fdc51f0d7bd08d3d65ea15a19955a6155ab71b8ee0c8989859d6dff293a141f197ea19394a91b3b641181140a289b743e0f0e7 WHIRLPOOL f6c58e652c4c365c4f28894d404413a075cc6c5323f83b18d711dc831bb574623db371ccbc1a5aae0ddf030a1b85e1ad50c06f5904ae5554bb4026e464a2c75f
@@ -38,4 +39,5 @@ EBUILD mit-krb5-1.13.2.ebuild 3833 SHA256 b82c44999dbad0d6e797713c769bae89b0798d
EBUILD mit-krb5-1.13.ebuild 3895 SHA256 c15017751d09ff6095b5e6cce2415c13a74d2281f3da39fc9f14694eed512149 SHA512 d265c55c77d82eca123d5bf0a50e6a545b690d8021b3c088d8ddc4f43ca9685104d9fc30dc685cfe9504000c09df8abe431bb96729dea6a743e2af74e15d8424 WHIRLPOOL affba0ab24ac20733bcb7098b0b6b71ab2d9331bfa5ad930bc9bd8e46cf9b152158a546a5282ed9cd8abff40779e59f1936fab9f1872a0eed1053be1ca3bbb70
EBUILD mit-krb5-1.14.1.ebuild 4029 SHA256 7306ef12e4a90b89f701868d3502b787acf5a2f86c431e381e7040a5bfb47fa2 SHA512 809155514b7dd3df5c7e1f41b63365bbf574d50c0b331f3ea6220fae65b5ad8d5eff8566bc049ba1058714a850741e2b89f2f499efeb008d5fb89b0bfa3af0a1 WHIRLPOOL ca567968ebd3ed546dbd40fb7ea4c4803e8c4f11abad811e2533b69c11ac2f6739d086e751966486a303d6cb12b02c9990208ff220b452a8daa54010063ec2c5
EBUILD mit-krb5-1.14.2.ebuild 4186 SHA256 bb9eadfb75004c4365e3217d4967f4e0ec8fc0c2ff8e0dd5a6cb2cd231d79c7c SHA512 d9c65a953e7bc4bf44b6caadd38a975f97bc20888d70cf01081ae310a348371f6f28fb9316ba11bb847e32c5e3791bff3e1c3b39beb471623151cba1b2ab24d7 WHIRLPOOL 565207191e62ce98612c6f907ea8ca3320bc1459cb9ebe2b77ea5386b026a7bc65bc463366937dd2ef9c389d019227e12386daef0bae3dedc8c286484514c6ef
+EBUILD mit-krb5-1.15.2-r1.ebuild 4109 SHA256 1be06b01726acc659906ebd98cc3086b244846ce7b8d0d9417906f1c454ec470 SHA512 7926cee1f69f5e6bd36612871dbfbf1427e2cf48693396c2f18dc1a6609e5aa4bd88d7c030d4fa5ffbe89d3e7c3c1c6663d6249c3649e9ec5969e0f721773a88 WHIRLPOOL 6c7955c8ff5f3043fcf776f2d24d01a7f13b3d4050afce626f7773e4b62d7b23bd3f4bf39d530d1f6acbc36f0aebd752d70e9c3a4bd8d3697c29c6fc07728410
EBUILD mit-krb5-1.15.2.ebuild 4050 SHA256 78a32ce2c818a6ef55cbd5ed50b9566cecd9d1f7dca89d06cb7998250a9f6574 SHA512 c4f8621964980b1c954399cbdefc10699736eaf457d5ddbe0af8b62e513a81ae610b66658f6f12416f9adead9310773db19d5441b88fe948077cf287346b99bc WHIRLPOOL ca50a6e8989c48a921a9ca38af8ca007ba8bae35807b69c5243b01506f2417b66d989cc47149b43948b8a3aa972220f498db056237ba7fd127a711d0e297e8f0
diff --git a/app-crypt/mit-krb5/files/mit-krb5-1.15.2-fix-pkinit.patch b/app-crypt/mit-krb5/files/mit-krb5-1.15.2-fix-pkinit.patch
new file mode 100644
index 00000000..4f721d4d
--- /dev/null
+++ b/app-crypt/mit-krb5/files/mit-krb5-1.15.2-fix-pkinit.patch
@@ -0,0 +1,98 @@
+diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
+index 74fffbf321..4b86a6f302 100644
+--- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
++++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c
+@@ -5145,33 +5145,29 @@ crypto_retieve_X509_key_usage(krb5_context context,
+ return retval;
+ }
+
+-/*
+- * Return a string format of an X509_NAME in buf where
+- * size is an in/out parameter. On input it is the size
+- * of the buffer, and on output it is the actual length
+- * of the name.
+- * If buf is NULL, returns the length req'd to hold name
+- */
+-static char *
+-X509_NAME_oneline_ex(X509_NAME * a,
+- char *buf,
+- unsigned int *size,
+- unsigned long flag)
++static krb5_error_code
++rfc2253_name(X509_NAME *name, char **str_out)
+ {
+- BIO *out = NULL;
++ BIO *b = NULL;
++ char *str;
+
+- out = BIO_new(BIO_s_mem ());
+- if (X509_NAME_print_ex(out, a, 0, flag) > 0) {
+- if (buf != NULL && (*size) > (unsigned int) BIO_number_written(out)) {
+- memset(buf, 0, *size);
+- BIO_read(out, buf, (int) BIO_number_written(out));
+- }
+- else {
+- *size = BIO_number_written(out);
+- }
+- }
+- BIO_free(out);
+- return (buf);
++ *str_out = NULL;
++ b = BIO_new(BIO_s_mem());
++ if (b == NULL)
++ return ENOMEM;
++ if (X509_NAME_print_ex(b, name, 0, XN_FLAG_SEP_COMMA_PLUS) < 0)
++ goto error;
++ str = calloc(BIO_number_written(b) + 1, 1);
++ if (str == NULL)
++ goto error;
++ BIO_read(b, str, BIO_number_written(b));
++ BIO_free(b);
++ *str_out = str;
++ return 0;
++
++error:
++ BIO_free(b);
++ return ENOMEM;
+ }
+
+ /*
+@@ -5187,8 +5183,6 @@ crypto_cert_get_matching_data(krb5_context context,
+ krb5_principal *pkinit_sans =NULL, *upn_sans = NULL;
+ struct _pkinit_cert_data *cd = (struct _pkinit_cert_data *)ch;
+ unsigned int i, j;
+- char buf[DN_BUF_LEN];
+- unsigned int bufsize = sizeof(buf);
+
+ if (cd == NULL || cd->magic != CERT_MAGIC)
+ return EINVAL;
+@@ -5201,23 +5195,14 @@ crypto_cert_get_matching_data(krb5_context context,
+
+ md->ch = ch;
+
+- /* get the subject name (in rfc2253 format) */
+- X509_NAME_oneline_ex(X509_get_subject_name(cd->cred->cert),
+- buf, &bufsize, XN_FLAG_SEP_COMMA_PLUS);
+- md->subject_dn = strdup(buf);
+- if (md->subject_dn == NULL) {
+- retval = ENOMEM;
++ retval = rfc2253_name(X509_get_subject_name(cd->cred->cert),
++ &md->subject_dn);
++ if (retval)
+ goto cleanup;
+- }
+-
+- /* get the issuer name (in rfc2253 format) */
+- X509_NAME_oneline_ex(X509_get_issuer_name(cd->cred->cert),
+- buf, &bufsize, XN_FLAG_SEP_COMMA_PLUS);
+- md->issuer_dn = strdup(buf);
+- if (md->issuer_dn == NULL) {
+- retval = ENOMEM;
++ retval = rfc2253_name(X509_get_issuer_name(cd->cred->cert),
++ &md->issuer_dn);
++ if (retval)
+ goto cleanup;
+- }
+
+ /* get the san data */
+ retval = crypto_retrieve_X509_sans(context, cd->plgctx, cd->reqctx,
diff --git a/app-crypt/mit-krb5/mit-krb5-1.15.2-r1.ebuild b/app-crypt/mit-krb5/mit-krb5-1.15.2-r1.ebuild
new file mode 100644
index 00000000..f73fe274
--- /dev/null
+++ b/app-crypt/mit-krb5/mit-krb5-1.15.2-r1.ebuild
@@ -0,0 +1,155 @@
+# Copyright 1999-2017 Gentoo Foundation
+# Distributed under the terms of the GNU General Public License v2
+
+EAPI=6
+
+PYTHON_COMPAT=( python2_7 )
+inherit autotools eutils flag-o-matic python-any-r1 versionator multilib-minimal
+
+MY_P="${P/mit-}"
+P_DIR=$(get_version_component_range 1-2)
+DESCRIPTION="MIT Kerberos V"
+HOMEPAGE="http://web.mit.edu/kerberos/www/"
+SRC_URI="http://web.mit.edu/kerberos/dist/krb5/${P_DIR}/${MY_P}.tar.gz"
+
+LICENSE="openafs-krb5-a BSD MIT OPENLDAP BSD-2 HPND BSD-4 ISC RSA CC-BY-SA-3.0 || ( BSD-2 GPL-2+ )"
+SLOT="0"
+KEYWORDS="~alpha amd64 arm ~arm64 hppa ~ia64 ~mips ppc ppc64 ~s390 ~sh ~sparc x86"
+IUSE="doc +keyutils libressl nls openldap +pkinit sep-usr selinux +threads test xinetd"
+
+CDEPEND="
+ !!app-crypt/heimdal
+ >=sys-libs/e2fsprogs-libs-1.42.9[${MULTILIB_USEDEP}]
+ || (
+ >=dev-libs/libverto-0.2.5[libev,${MULTILIB_USEDEP}]
+ >=dev-libs/libverto-0.2.5[libevent,${MULTILIB_USEDEP}]
+ >=dev-libs/libverto-0.2.5[tevent,${MULTILIB_USEDEP}]
+ )
+ keyutils? ( >=sys-apps/keyutils-1.5.8[${MULTILIB_USEDEP}] )
+ openldap? ( >=net-nds/openldap-2.4.38-r1[${MULTILIB_USEDEP}] )
+ pkinit? (
+ !libressl? ( >=dev-libs/openssl-1.0.1h-r2:0[${MULTILIB_USEDEP}] )
+ libressl? ( dev-libs/libressl[${MULTILIB_USEDEP}] )
+ )
+ xinetd? ( sys-apps/xinetd )
+ abi_x86_32? (
+ !<=app-emulation/emul-linux-x86-baselibs-20140508-r1
+ !app-emulation/emul-linux-x86-baselibs[-abi_x86_32(-)]
+ )"
+DEPEND="${CDEPEND}
+ ${PYTHON_DEPS}
+ virtual/yacc
+ doc? ( virtual/latex-base )
+ test? (
+ ${PYTHON_DEPS}
+ dev-lang/tcl:0
+ dev-util/dejagnu
+ )"
+RDEPEND="${CDEPEND}
+ selinux? ( sec-policy/selinux-kerberos )"
+
+S=${WORKDIR}/${MY_P}/src
+
+MULTILIB_CHOST_TOOLS=(
+ /usr/bin/krb5-config
+)
+
+src_prepare() {
+ eapply "${FILESDIR}/${PN}-1.12_warn_cflags.patch"
+ eapply -p2 "${FILESDIR}/${PN}-config_LDFLAGS.patch"
+ eapply -p0 "${FILESDIR}/${PN}-1.14.2-redeclared-ttyname.patch"
+ eapply "${FILESDIR}/${PN}-1.14.4-disable-nls.patch"
+ eapply -p2 "${FILESDIR}/${PN}-1.15.2-fix-pkinit.patch"
+ eapply "${FILESDIR}/${PN}-1.12_x32.patch"
+
+ # Make sure we always use the system copies.
+ rm -rf util/{et,ss,verto}
+ sed -i 's:^[[:space:]]*util/verto$::' configure.in || die
+
+ eapply_user
+ eautoreconf
+}
+
+src_configure() {
+ # QA
+ append-flags -fno-strict-aliasing
+ append-flags -fno-strict-overflow
+
+ multilib-minimal_src_configure
+}
+
+multilib_src_configure() {
+ use keyutils || export ac_cv_header_keyutils_h=no
+ ECONF_SOURCE=${S} \
+ WARN_CFLAGS="set" \
+ econf \
+ $(use_with openldap ldap) \
+ "$(multilib_native_use_with test tcl "${EPREFIX}/usr")" \
+ $(use_enable nls) \
+ $(use_enable pkinit) \
+ $(use_enable threads thread-support) \
+ --without-hesiod \
+ --enable-shared \
+ --with-system-et \
+ --with-system-ss \
+ --enable-dns-for-realm \
+ --enable-kdc-lookaside-cache \
+ --with-system-verto \
+ --disable-rpath
+}
+
+multilib_src_compile() {
+ emake -j1
+}
+
+multilib_src_test() {
+ multilib_is_native_abi && emake -j1 check
+}
+
+multilib_src_install() {
+ emake \
+ DESTDIR="${D}" \
+ EXAMPLEDIR="${EPREFIX}/usr/share/doc/${PF}/examples" \
+ install
+
+ if use sep-usr && multilib_is_native_abi; then
+ # need the libs in /
+ gen_usr_ldscript -a gssapi_krb5 k5crypto krb5 krb5support
+ fi
+}
+
+multilib_src_install_all() {
+ # default database dir
+ keepdir /var/lib/krb5kdc
+
+ cd ..
+ dodoc README
+
+ if use doc; then
+ dohtml -r doc/html
+ docinto pdf
+ dodoc doc/pdf/*.pdf
+ fi
+
+ newinitd "${FILESDIR}"/mit-krb5kadmind.initd-r2 mit-krb5kadmind
+ newinitd "${FILESDIR}"/mit-krb5kdc.initd-r2 mit-krb5kdc
+ newinitd "${FILESDIR}"/mit-krb5kpropd.initd-r2 mit-krb5kpropd
+ newconfd "${FILESDIR}"/mit-krb5kadmind.confd mit-krb5kadmind
+ newconfd "${FILESDIR}"/mit-krb5kdc.confd mit-krb5kdc
+ newconfd "${FILESDIR}"/mit-krb5kpropd.confd mit-krb5kpropd
+
+ insinto /etc
+ newins "${ED}/usr/share/doc/${PF}/examples/krb5.conf" krb5.conf.example
+ insinto /var/lib/krb5kdc
+ newins "${ED}/usr/share/doc/${PF}/examples/kdc.conf" kdc.conf.example
+
+ if use openldap ; then
+ insinto /etc/openldap/schema
+ doins "${S}/plugins/kdb/ldap/libkdb_ldap/kerberos.schema"
+ fi
+
+ if use xinetd ; then
+ insinto /etc/xinetd.d
+ newins "${FILESDIR}/kpropd.xinetd" kpropd
+ fi
+}