Bug#725153: [Pkg-openldap-devel] Bug#725153: openldap, nss, and gnutls

2016-04-09 Thread Ryan Tandy
Control: tag -1 = patch On Sat, Apr 09, 2016 at 06:10:16PM +0300, Timo Aaltonen wrote: 09.04.2016, 09:12, Ryan Tandy kirjoitti: What happens if both copies of libldap somehow end up linked into the same process? I don't know freeipa well enough to imagine a specific scenario, but it probably

Bug#725153: [Pkg-openldap-devel] Bug#725153: openldap, nss, and gnutls

2016-04-09 Thread Timo Aaltonen
09.04.2016, 09:12, Ryan Tandy kirjoitti: > On Fri, Apr 08, 2016 at 08:41:01PM +0300, Timo Aaltonen wrote: > Are you planning to do this in unstable as well, or just in xenial (as > it sounds like it might be a temporary measure)? Luca and I talked about > binNEW a while back, and flagged the

Bug#725153: [Pkg-openldap-devel] Bug#725153: openldap, nss, and gnutls

2016-04-08 Thread Timo Aaltonen
08.04.2016, 20:41, Timo Aaltonen kirjoitti: > 03.04.2016, 12:32, Timo Aaltonen kirjoitti: >> 20.05.2015, 20:43, Ryan Tandy kirjoitti: >>> Hi dkg, >>> >>> On Wed, May 20, 2015 at 12:58:08PM -0400, Daniel Kahn Gillmor wrote: If the work to switch openldap to NSS is strictly because of licensing

Bug#725153: [Pkg-openldap-devel] Bug#725153: openldap, nss, and gnutls

2015-05-21 Thread Holger Levsen
Hi, On Mittwoch, 20. Mai 2015, Ryan Tandy wrote: My understanding was that motivation for the request was wanting to provide a fully-featured freeipa server in Debian, while some of its features (specifically replication) only work properly when using libldap built with nss. actually, it's

Bug#725153: [Pkg-openldap-devel] Bug#725153: openldap, nss, and gnutls

2015-05-20 Thread Ryan Tandy
Hi dkg, On Wed, May 20, 2015 at 12:58:08PM -0400, Daniel Kahn Gillmor wrote: https://bugs.debian.org/725153 suggests moving openldap's TLS backend in debian from gnutls to nss. The reasons given appear to be the older gnutls/gcrypt suid problem (which is quite a serious concern, particularly