Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

libldap-2_4-2-2.4.48-48.4 RPM for x86_64

From OpenSuSE Tumbleweed for x86_64

Name: libldap-2_4-2 Distribution: openSUSE Tumbleweed
Version: 2.4.48 Vendor: openSUSE
Release: 48.4 Build date: Mon Dec 2 19:32:46 2019
Group: Productivity/Networking/LDAP/Clients Build host: build32
Size: 422320 Source RPM: openldap2-2.4.48-48.4.src.rpm
Summary: OpenLDAP Client Libraries
This package contains the OpenLDAP client libraries.






* Fri Aug 02 2019 Martin Liška <>
  - Use FAT LTO objects in order to provide proper static library.
* Thu Jul 25 2019
  - removal of SuSEfirewall2 service, since SuSEfirewall2 has been replaced by
    firewalld, see [1].
* Wed Jul 24 2019 Michael Ströder <>
  - Update to upstream release 2.4.48 with security fixes:
    * CVE-2019-13057 (ITS#9038):
      rootdn of any db can assert any identity
    * CVE-2019-13565 (ITS#9052):
      Unauthorized access caused by incorrect handling of SASL SSF values
  - Fix CVE-2017-17740 by disabling nops overlay not maintained by upstream
    (see also bsc#1073313, comment #36)
  - Removed obsolete patches:
    * 0002-openldap-its8727-plug-ber-leaks.patch
    * 0017-Fix-segfault-in-nops.patch
    OpenLDAP 2.4.48 (2019/07/24)
    Added libldap OpenSSL Elliptic Curve support (ITS#7595)
    Added libldap Expose OpenLDAP specific interfaces via openldap.h (ITS#8671)
    Added slapd-monitor support for slapd-mdb (ITS#7770)
    Fixed liblber leaks (ITS#8727)
    Fixed liblber with partial flush (ITS#8864)
    Fixed libldap ASYNC TLS so it works (ITS#8957,ITS#8980)
    Fixed libldap ASYNC connections with Solaris 10 (ITS#8968)
    Fixed libldap with SASL_NOCANON=on and ldapi connections (ITS#7585)
    Fixed libldap to be able to unset syncrepl TLS options (ITS#7042)
    Fixed libldap race condition in ldap_int_initialize (ITS#7996, ITS#8450)
    Fixed libldap return code in ldap_create_assertion_control_value (ITS#8674)
    Fixed libldap to correctly disable IPv6 when configured to do so (ITS#8754)
    Fixed libldap to correctly close TLS connection (ITS#8755)
    Fixed libldap with non-blocking TLS and referals (ITS#8167)
    Fixed libldap_r handling of deprecated OpenSSL function (ITS#8353)
    Fixed liblunicode case correspondance (ITS#8508)
    Fixed slapd with an idletimeout of less than four seconds (ITS#8952)
    Fixed slapd config parser variable for Windows64 (ITS#9012)
    Fixed slapd syncrepl fallback handling with delta-syncrepl (ITS#9015)
    Fixed slapd telephoneNumberNormalize, cert DN validation (ITS#8999)
    Fixed slapd syncrepl for relax with delta-syncrepl (ITS#8037)
    Fixed slapd to restrict rootDN proxyauthz to its own databases (ITS#9038)
    Fixed slapd to initialize SASL SSF per connection (ITS#9052)
    Fixed slapo-accesslog with SLAP_MOD_SOFT modifications (ITS#8990)
    Fixed slapd-ldap starttls connections timeout behavior (ITS#8963)
    Fixed slapd-ldap segfault when entry result doesn't match filter (ITS#8997)
    Fixed slapd-meta conversion from slapd.conf to cn=config (ITS#8743)
    Fixed slapd-meta assertion when network interface goes down (ITS#8841)
    Fixed slapd-mdb fix bitshift integer overflow (ITS#8989)
    Fixed slapd-mdb index cleanup with cn=config (ITS#8472)
    Fixed slapd-mdb to improve performance with alias deref (ITS#7657)
    Fixed slapo-accesslog possible assert with exops (ITS#8971)
    Fixed slapo-chain to correctly reject multiple chaining URIs (ITS#8637)
    Fixed slapo-chain conversion from slapd.conf to cn=config (ITS#8799)
    Fixed slapo-memberof conversion from slapd.conf to cn=config (ITS#8663)
    Fixed slapo-memberof for group name change to itself (ITS#9000)
    Fixed slapo-ppolicy behavior when pwdInHistory is changed (ITS#8349)
    Fixed slapo-rwm to not free original filter (ITS#8964)
    Fixed slapo-syncprov contextCSN generation (ITS#9015)
    Build Environment
      Fixed slapd to only link to BDB libraries with static build (ITS#8948)
      Fixed libldap implicit declaration with LDAP_CONNECTIONLESS (ITS#8794)
      Fixed libldap double inclusion of limits.h in cyrus.c (ITS#9041)
      General - Fixed minor typos (ITS#8764, ITS#8761)
      admin24 - Miscellaneous updates promoting mdb and fixing examples (ITS#9031)
      slapd.access(5) - Note MDB is the primary backend (ITS#8881)
      slapd.backends(5) - Note MDB is the recommended backend (ITS#8771)
      slapd-ldap(5) - Document starttls parameter (ITS#8693)
      Added slapo-lastbind capability to forward authTimestamp updates (ITS#7721)
* Tue May 14 2019 William Brown <>
  - bsc#1111388 - incorrect post script call causes tmpfiles create not to
    be run.
* Sun Mar 10 2019 Michael Ströder <>
  - Corrected moduleload to get a working configuration
    right after package installation.
* Fri Jan 04 2019 Michael Ströder <>
  - added back-ported fix for OpenLDAP ITS#8727
    (file 0002-openldap-its8727-plug-ber-leaks.patch)
* Thu Dec 20 2018 Michael Ströder <>
  - Update to upstream release 2.4.47
  - Removed obsolete patches:
    * 0006-No-Build-date-and-time-in-binaries.dif
      (upstream now uses SOURCE_DATE_EPOCH for reproducable builds)
    * 0012-ITS8051-sockdnpat.patch
    * 0014-ITS-8714-Send-out-EXTENDED-operation-message-from-back-sock.patch
    OpenLDAP 2.4.47 Release (2018/12/19)
      Added slapd-sock DN qualifier for subtrees to be processed (ITS#8051)
      Added slapd-sock ability to send extended operations to external listeners (ITS#8714)
      Fixed liblber to avoid incremental access to user-supplied bv in dupbv (ITS#8752)
      Fixed libldap dn to domain parsing with bad input (ITS#8842)
      Fixed slapd slapcat to correctly honor -g option (ITS#8667)
      Fixed slapd to correctly handle NO_SUCH_OBJECT with dynamic groups (ITS#8923)
      Fixed slapd to check status of rdnNormalize (ITS#8932)
      Fixed slapd cn=config when modifying slapo-syncprov config (ITS#8616)
      Fixed slapd sasl authz-policy "all" behavior (ITS#8909)
      Fixed slapd sasl minor typo (ITS#8918)
      Fixed slapd to correctly hide hidden DBs in the rootDSE (ITS#8912)
      Fixed slapd domainScope control to match Microsoft specification (ITS#8840)
      Fixed slapd-bdb/hdb/mdb to not convert certain IDLs to ranges (ITS#8868)
      Fixed slapo-accesslog deadlock during cleanup (ITS#8752)
      Fixed slapo-memberof cn=config modifications (ITS#8663)
      Fixed slapo-ppolicy with multimaster replication (ITS#8927)
      Fixed slapo-syncprov with NULL modlist (ITS#8843)
      Build Environment
      Added slapd reproducible build support (ITS#8928)
      Fixed missing includes with OpenSSL 1.0.2 (ITS#8809)
      Fixed slapo-pbkdf2 hash generation (ITS#8878)
      admin24 fixed minor typo (ITS#8887)
* Thu Nov 22 2018 Jan Engelhardt <>
  - Replace old $RPM_* shell vars
* Tue Nov 20 2018
  - Fix CVE-2017-17740: when both the nops module and the memberof
    overlay are enabled, attempts to free a buffer that was allocated
    on the stack
    * patch: 0017-Fix-segfault-in-nops.patch
* Mon Nov 12 2018 Dominique Leuenberger <>
  - Emergency fix: move tmpfiles_create post from the library package
    to the main package's post script, which ships the tmpfiles.d
    configuration. Fixes the post script of the library (-p
    /sbin/ldconfig does not allow more statements in the script).
* Thu Nov 08 2018
  - bsc#1111388 openldap and /var/lib/ldap/DB_CONFIG* (transactional-update)
* Fri Oct 26 2018 Michael Ströder <>
  - Fixed broken memory handling in
    affecting error response of slapo-unique
* Fri Aug 17 2018
  - Fix slapd segfaults in mdb_env_reader_dest
    +  with patch 0016-Clear-shared-key-only-in-close-function.patch
    +  (bsc#1089640)
* Fri Jun 29 2018
  - fixed shee-bang in (bsc#1099705)
* Wed Jun 20 2018
  - Added a patch to let slapd return the uniqueness check filter
    used before constraint violation to the client
* Tue Jun 05 2018
  - bsc#1095816 libldap package does not contain and provide libldap anymore
* Thu May 24 2018
  - Don't require systemd explicit, spec file can handle both cases
    correct and in containers we don't have systemd.
* Tue Apr 24 2018
  - bsc#1085064 Packaging issues have been discovered around the which has been corrected:
    - the spec file was wrongly configured, therefore the script has
    never been called
    - the script should create the symlinks first, as slapcat is
    useless on a system which is already affected.
* Fri Apr 06 2018
  - bsc#1085064 Add script "" which
    which removes the configuration item olcModulePath in cn=config
    which is after upgrade from SLE12 to SLE15 holds inappropriate
    information. If the cn=config is being used on a system, the
    conflicting items in slapd.conf are ignored, despite of it, the
    backend DB configuration section has been also commented out in
    the default slapd.conf.
    In case of correct cn=config (the olcModulePath has been already
    removed), the script stops without touching anything.
* Fri Mar 23 2018
  - Upgrade to upstream 2.4.46 release
  - removed obsolete back-port patches:
    * 0013-ITS-8692-let-back-sock-generate-increment-line.patch
    * 0016-ITS-8782-fix-cancel-memleak.patch
    OpenLDAP 2.4.46 Release (2018/03/22)
    Fixed libldap connection delete callbacks when TLS fails to start (ITS#8717)
    Fixed libldap to not reuse tls_session if TLS hostname check fails (ITS#7373)
    Fixed libldap cross-compiling with OpenSSL 1.1 (ITS#8687)
    Fixed libldap OpenSSL 1.1.1 compatibility with BIO_method (ITS#8791)
    Fixed libldap MozNSS CA certificate hash matching (ITS#7374)
    Fixed libldap MozNSS with PEM certs when also using an NSS cert db (ITS#7389)
    Fixed libldap MozNSS initialization (ITS#8484)
    Fixed libldap GnuTLS with GNUTLS_E_AGAIN (ITS#8650)
    Fixed libldap memory leak with cancel operations (ITS#8782)
    Fixed slapd Eventlog registry key creation on 64-bit Windows (ITS#8705)
    Fixed slapd to maintain SSF across SASL binds (ITS#8796)
    Fixed slapd syncrepl deadlock when updating cookie (ITS#8752)
    Fixed slapd syncrepl callback to always be last in the stack (ITS#8752)
    Fixed slapd telephoneNumberNormalize when the value is spaces and hyphens (ITS#8778)
    Fixed slapd CSN queue processing (ITS#8801)
    Fixed slapd-ldap TLS connection timeout with high latency connections (ITS#8720)
    Fixed slapd-ldap to ignore unknown schema when omit-unknown-schema is set (ITS#7520)
    Fixed slapd-mdb with an optimization for long lived read transactions (ITS#8226)
    Fixed slapd-meta assert when olcDbRewrite is modified (ITS#8404)
    Fixed slapd-sock with LDAP_MOD_INCREMENT operations (ITS#8692)
    Fixed slapo-accesslog cleanup to only occur on failed operations (ITS#8752)
    Fixed slapo-dds entryTTL to actually decrease as per RFC 2589 (ITS#7100)
    Fixed slapo-syncprov memory leak with delete operations (ITS#8690)
    Fixed slapo-syncprov to not clear pending operation when checkpointing (ITS#8444)
    Fixed slapo-syncprov to correctly record contextCSN values in the accesslog (ITS#8100)
    Fixed slapo-syncprov not to log checkpoints to accesslog db (ITS#8607)
    Fixed slapo-syncprov to process changes from this SID on REFRESH (ITS#8800)
    Fixed slapo-syncprov session log parsing to not block other operations (ITS#8486)
    Build Environment
    Fixed Windows build with newer MINGW version (ITS#8697)
    Fixed compiler warnings and removed unused variables (ITS#8578)
    Fixed ldapc++ Control structure (ITS#8583)
    Delete stub manpage for back-ldbm (ITS#8713)
    Fixed ldap_bind(3) to mention the LDAP_SASL_SIMPLE mechanism (ITS#8121)
    Fixed ldap.conf(5) to note SASL_MECH/SASL_REALM are no longer user-only (ITS#8818)
    Fixed slapd-config(5) typo for olcTLSCipherSuite (ITS#8715)
    Fixed slapo-syncprov(5) indexing requirements (ITS#5048)
* Thu Feb 22 2018
  - Use %license (boo#1082318)



Generated by rpm2html 1.8.1

Fabrice Bellet, Fri Jan 3 23:08:53 2020