Your message dated Mon, 13 Oct 2014 21:51:22 +0000
with message-id <[email protected]>
and subject line Bug#700347: fixed in libapache2-mod-auth-tkt 2.1.0+dfsg-1
has caused the Debian Bug report #700347,
regarding libapache2-mod-auth-tkt: Breaks behind AT&T's non-RFC-compliant proxy
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
700347: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=700347
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: libapache2-mod-auth-tkt
Version: 2.1.0-6
Severity: normal
Tags: patch upstream
AT&T apparently has a lovely proxy that strips whitespace from Cookie
headers
http://forums.att.com/t5/Data-Messaging-Features-Internet/3G-proxy-wnsnet-attws-com-strips-HTTP-response-headers/td-p/3294533
We have had some users behind AT&T who were unable to log in, so we
applied the attatched patch to our mod-auth-tkt.
Upstream seems fairly slow these days, so I thought I'd bounce it here
too.
SR
Description: patch for cookie header with whitespace stripped
Some badly behaved proxy/cache servers strip whitespace from headers, which
results in a failure to parse the cookie correctly.
This will allow for that.
Author: Bearnard Hibbins <[email protected]>
Origin: https://github.com/yola/mod_auth_tkt/commit/eecfce3ddff154f804d377d0bdabe8bebdce62a6
Origin: https://github.com/yola/mod_auth_tkt/commit/ed457d9abe2aaba1c81ae21886cdbcc0f9fc3a22
Forwarded: https://github.com/gavincarr/mod_auth_tkt/pull/9
--- a/src/mod_auth_tkt.c
+++ b/src/mod_auth_tkt.c
@@ -610,8 +609,8 @@
value = (char*) cookie;
while ((value = strstr(value, cookie_name))) {
- /* cookie_name must be preceded by a space or be at the very beginning */
- if (value > cookie && *(value-1) != ' ') {
+ /* cookie_name must be preceded by a space or a semicolon or be at the very beginning */
+ if (value > cookie && (*(value-1) != ' ' && *(value-1) != ';')) {
value++;
continue;
}
--- End Message ---
--- Begin Message ---
Source: libapache2-mod-auth-tkt
Source-Version: 2.1.0+dfsg-1
We believe that the bug you reported is fixed in the latest version of
libapache2-mod-auth-tkt, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Ivo De Decker <[email protected]> (supplier of updated libapache2-mod-auth-tkt
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Mon, 13 Oct 2014 23:34:57 +0200
Source: libapache2-mod-auth-tkt
Binary: libapache2-mod-auth-tkt
Architecture: source amd64
Version: 2.1.0+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Ivo De Decker <[email protected]>
Changed-By: Ivo De Decker <[email protected]>
Description:
libapache2-mod-auth-tkt - lightweight single-sign-on authentication module for
Apache
Closes: 700347 721586
Changes:
libapache2-mod-auth-tkt (2.1.0+dfsg-1) unstable; urgency=medium
.
* Repackage upstream tarball to remove binary.
* Update watch file for upstream version suffix.
* Update standards version to 3.9.6 (no changes).
* Add patch to cookie handling to work around broken proxy.
Thanks to Stefano Rivera for the report. Closes: #700347
* Install login script examples. Thanks to Nikolaus Rath for the report.
Closes: #721586
Checksums-Sha1:
d5ef16e44802afde1f3c118a6ea60ff74e844d5a 1909
libapache2-mod-auth-tkt_2.1.0+dfsg-1.dsc
f36b71030646a009544881130d69550016217215 87107
libapache2-mod-auth-tkt_2.1.0+dfsg.orig.tar.gz
5c28aac9b719d493c4c602204ee7ea560ba0ff31 5624
libapache2-mod-auth-tkt_2.1.0+dfsg-1.debian.tar.xz
Checksums-Sha256:
3d7f766ab1e0cdebb2884322251f4adb3aadc0462f783edc65d6a2b44afbd8bb 1909
libapache2-mod-auth-tkt_2.1.0+dfsg-1.dsc
dea414061b6aec181c5c3ee42e58acf54ff57e7d1d3f75d4cc006ab91446df2d 87107
libapache2-mod-auth-tkt_2.1.0+dfsg.orig.tar.gz
4e0f9a578819f703ffaeadefe3553aaf0c642e643af9266775b34f36519ea8c5 5624
libapache2-mod-auth-tkt_2.1.0+dfsg-1.debian.tar.xz
Files:
d03935919f05ea5ee96a480a4b6e5b1f 1909 httpd extra
libapache2-mod-auth-tkt_2.1.0+dfsg-1.dsc
c7264ed652cbeea64cd1763c3e993df2 87107 httpd extra
libapache2-mod-auth-tkt_2.1.0+dfsg.orig.tar.gz
c399aa54a9e9b880b23fc519e32d52f9 5624 httpd extra
libapache2-mod-auth-tkt_2.1.0+dfsg-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAEBAgAGBQJUPEXqAAoJEKxAu1iXBOr8aXgQAJ9L6VvKaNAD41Syk5VrvJha
irtPsMDrZ1hvBrI6pKOwQouu+OMb1ZhtCC6rRsWuzc01D9OpmRieyUfksyG3QnMX
9JTQ6hVsbXU15yT2Sutm0dYHxsSWCHH6KsaijvmdqhdRnNYHmXEySTMnMU4UiutK
GzFTIDFCw+jfKm1JCl451QMLfjKqxm/CwhKrQC4hyHZ0DGNayM6TWY6/BBTtzMFv
W5bOgHgD7qLhUwG2a1fuvg3xAPFjIm2KyLlo/7YC+Tph1T371WnvjNrnhaCSEmqh
nUpKQZI02qDcXYjnWazhw0Kek253tZVdWnVueY7K35lIfvoK8gin4B59yZgJ92m6
xsLC6mMnfPEGLmfupLJpcnposU6cnI4rIpsnCL1dWAc9EewP9rOjj00LGM5wW0nr
E9MjMDyJ/b2uB9chI0oByLlFCyK44rXYFxTO+lQdq3U0GtN/5eW7Oa9TAI1SRf2k
b5NSbL+mF+pbU6YwhxyRj7U/D30b7xL8EQvE73cGKnqpDR19NRcsDUTXIrahTDUf
BGSb14cyzNL0cumeJqSuIPKxNNtH7nZRFmbW5oYLNfhlKN1rW+4tbNK99guajfJV
Fer/sOU7qdCjl4sxCvCIo+kB/OCdC7fLqx0nOx0NivrG6MsmiZQFegsbUpRWSVJA
gteHGmC2waofsoiKfXyF
=X+Tx
-----END PGP SIGNATURE-----
--- End Message ---