[Bug 334374] Re: libnss-ldap should not depend on libpam-ldap

2013-04-26 Thread Daniel Richard G.
Robie, thanks for commenting. Note that the ldap-auth-config package does not preclude alternate forms of managing /etc/ldap.conf. It won't touch an existing config file, nor complain if the one it creates is modified. Also, while this package does not exist in Debian, the file is still created

[Bug 334374] Re: libnss-ldap should not depend on libpam-ldap

2013-04-25 Thread Daniel Richard G.
** Also affects: ldap-auth-client (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libnss-ldap in Ubuntu. https://bugs.launchpad.net/bugs/334374 Title: libnss-ldap should not

[Bug 334374] Re: libnss-ldap should not depend on libpam-ldap

2013-04-25 Thread Daniel Richard G.
I think Thierry's solution in comment #10 is the way to go. It's appropriate for ldap-auth-client to depend on libpam-ldap, because that's the intent of the metapackage. But ldap-auth-config provides /etc/ldap.conf, which you need whether or not you're using LDAP for authentication. (That package

[Bug 1131383] [NEW] Wishlist: $SSH_AUTH_SOCK in $XDG_RUNTIME_DIR

2013-02-21 Thread Daniel Richard G.
Public bug reported: This is a wishlist item for openssh-client 6.0p1-3ubuntu1 in Ubuntu Quantal. Now that XDG_RUNTIME_DIR support is available, it would be nice if the /etc/X11/Xsession.d/90x11-common_ssh-agent X session startup script would check to see if the variable is set, and if so, pass

[Bug 1098294] [NEW] Use of uninitialized value $admin in string eq at ...

2013-01-10 Thread Daniel Richard G.
Public bug reported: When I install krb5-config 2.3 (along with some other Kerberos-related packages) on Ubuntu Quantal, I see this: [...] Get:8 http://$APTHOST/ubuntu/ quantal/universe krb5-user amd64 1.10.1+dfsg-2 [114 kB] Get:9 http://$APTHOST/ubuntu/ quantal/universe kstart amd64 4.1-2

[Bug 483928]

2012-12-05 Thread Daniel Richard G.
I don't think anyone will fault you for having more momentous matters to attend to! As it is, I've gone without doing a network scan for that long anyway. Thanks for formally submitting the patch; hopefully this issue will be put to rest soon. Best of luck with the transition to a retired life,

[Bug 483928]

2012-12-05 Thread Daniel Richard G.
And a year later, this issue still afflicts OpenSSH 6.1p1 (as packaged by Ubuntu). Aab's patch still applies, if fuzzily, and still hardens up ssh-keyscan so that it can deal with my company's network. -- You received this bug notification because you are a member of Ubuntu Server Team, which is

[Bug 483928]

2011-12-01 Thread Daniel Richard G.
Okay, I tried Ubuntu's packaging of OpenSSH (version 1:5.8p1-7ubuntu1) with your patch, and it powered through everything. Here is a list of all the error messages I received: A.B.C.D: Connection closed by remote host Connection closed by A.B.C.D Connection to A.B.C.D timed out while waiting to

[Bug 483928]

2011-12-01 Thread Daniel Richard G.
(In reply to comment #41) The number of ways that key access can be terminated keeps increasing, doesn't it? I hope it won't be necessary to enumerate them all before this bug can be closed! My oops. I have had my focus redirected to other projects and, besides, I'm very lazy (;-}).

[Bug 483928]

2011-11-27 Thread Daniel Richard G.
(In reply to comment #38) I haven't seen this one before. The text you included indicates that ssh-keyscan was processing a Protocol 2 key and it should be using the modified code to do it. Is there any way that you could send me a traceback when the failure occurs? I'll do that, when I'm

[Bug 382832] Re: Need comment for line added to /etc/ldap.conf by nssldap-update-ignoreusers(8)

2011-03-14 Thread Daniel Richard G.
Yes, I'm afraid. Joshua's patch has not yet been committed (as of Natty). -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to libnss-ldap in ubuntu. https://bugs.launchpad.net/bugs/382832 Title: Need comment for line added to

[Bug 483928] Re: ssh-keyscan(1) exits prematurely on some non-fatal errors

2011-02-22 Thread Daniel Richard G.
I'm still seeing this with openssh-client 1:5.5p1-4ubuntu5. From a makefile that invokes ssh-keyscan -v: [...] debug1: SSH2_MSG_KEX_DH_GEX_INIT sent debug1: expecting SSH2_MSG_KEX_DH_GEX_REPLY debug1: match: OpenSSH_3.6.1p2 pat OpenSSH_3.* # A.B.C.D SSH-1.99-OpenSSH_3.6.1p2 debug1: Enabling

[Bug 483928] Re: ssh-keyscan(1) exits prematurely on some non-fatal errors

2011-02-22 Thread Daniel Richard G.
** Bug watch added: OpenSSH Portable Bugzilla #1213 https://bugzilla.mindrot.org/show_bug.cgi?id=1213 ** Also affects: openssh via https://bugzilla.mindrot.org/show_bug.cgi?id=1213 Importance: Unknown Status: Unknown -- You received this bug notification because you are a member

[Bug 660105] Re: when deflate is enabled, please also compress CSS and JS by default?

2011-02-01 Thread Daniel Richard G.
I think this would need an explicit decision to de-support IE6, as far as compressed JS is concerned. (I can't remember offhand which clients couldn't handle compressed CSS; was it anything newer than Netscape 4?) http://www.cforcoding.com/2009/05/supercharging-javascript-part-6.html

[Bug 711465] [NEW] mod_rewrite directives in Location section confusingly disable rewrites in .htaccess

2011-02-01 Thread Daniel Richard G.
Public bug reported: Binary package hint: apache2.2-bin Reporting this against version 2.2.16-1ubuntu3.1 in Maverick. I have apache2 configured in the following way: 1. mod_rewrite is enabled; 2. AllowOverride All is set (on /var/www) to enable the use of .htaccess files; 3. RewriteEngine On

[Bug 711465] Re: mod_rewrite directives in Location section confusingly disable rewrites in .htaccess

2011-02-01 Thread Daniel Richard G.
Adding RewriteOptions inherit doesn't seem to have any effect, whether in the Location section or the .htaccess file. Besides, looking at the documentation... inherit - This forces the current configuration to inherit the configuration of the parent. In per-virtual-server context, this means that

[Bug 382832] Re: Need comment for line added to /etc/ldap.conf by nssldap-update-ignoreusers(8)

2010-09-23 Thread Daniel Richard G.
Yep! That's the idea. I would tack on the (8) man-section suffix to the program name, but at any rate, this is all that's needed. -- Need comment for line added to /etc/ldap.conf by nssldap-update-ignoreusers(8) https://bugs.launchpad.net/bugs/382832 You received this bug notification because

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-05-15 Thread Daniel Richard G.
I don't think moving parts of the user configuration out of the config files is acceptable, and if you disable and then re-enable a module, I don't see any reason that the config options *should* be sticky. I wasn't so much proposing an alternative, just going over the shortcomings I see of this

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-05-14 Thread Daniel Richard G.
Happy to give it a try, Steve. I just commented in that bug report. This is a potential solution, but putting aside the tricky case of what happens if the common-* files have customized options, and then the PAM profile changes?, another problem with this approach is the fragility of the

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-04-13 Thread Daniel Richard G.
I guess I'm a bit baffled by why fixing your PAM configuration is a workaround but installing a custom krb5.conf is a desired configuration step. krb5.conf is a config file under /etc. That's the ideal place to make configuration changes. As it is, right now, adding the minimum_uid bit involves

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-04-13 Thread Daniel Richard G.
They may want to, but I don't think the added complexity of debconf solely for what I believe is a rarely-used option makes sense. [...] I don't think debconf offers much benefit here. Fair enough, though I hope you're not suggesting direct modification of the /etc/pam.d/common-* files as a

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-04-13 Thread Daniel Richard G.
No, it's persistent unless you disable pam_krb5 entirely. Have you tried it? Yeah, where pam-auth-update asks you Override local changes to /etc/pam.d/common-*? I see the man page says something about preserving module options, but if I add an option to (say) common-auth, and re-run p-a-u, the

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-04-13 Thread Daniel Richard G.
Er, how is it silent when pam-auth-update asks you a question? Silent, in the sense that when you run p-a-u, it doesn't indicate that the common-* files have been modified in any way; it just presents you with the same checkbox-list of profiles. You leave everything as-is, hit OK, look at the

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-04-12 Thread Daniel Richard G.
But I suppose that's what NEWS.Debian is for. You could also stick in a debconf notice, like what x11-common had for a while (Major possible upgrade issues). Right -- if you're already distributing a krb5.conf with this setting, surely the same mechanism could be used to override the PAM

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-04-07 Thread Daniel Richard G.
Isn't it possible to use debconf to change around the enabled profiles, via the libpam-runtime/profiles selection? Steve: I'm not sure I understand what you mean by automatically apply ... by the same mechanism. I can set minimum_uid in krb5.conf, but I also have to toss the minimum_uid= options

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-03-31 Thread Daniel Richard G.
You can see why I'm pushing on this. It's pay now, or pay later... no real gain in waiting :-] Ah, yes, users who've been dist-upgrading their Ubuntu installs since Warty... I guess there's no such thing as temporary postinst logic, if those need to be handled. A warning wouldn't be so bad. The

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-03-31 Thread Daniel Richard G.
Thought about the upgrade process a bit. How about this: 1. kerberos-configs starts generating new krb5.conf files with minimum_uid=1000. Then a little later... 2. libpam-krb5 has minimum_uid removed from pam-configs/krb5. On upgrade, it checks to see if this is in krb5.conf. If yes, great. If

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-03-30 Thread Daniel Richard G.
Can we get minimum_uid out of pam-configs/krb5 for Lucid? -- Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ? https://bugs.launchpad.net/bugs/369575 You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to kerberos-configs in ubuntu.

[Bug 382832] Re: Need comment for line added to /etc/ldap.conf by nssldap-update-ignoreusers(8)

2010-03-30 Thread Daniel Richard G.
Hi Dustin. I just noticed you're the author of nssldap-update- ignoreusers(8) ^_^ Does this look like a reasonable thing to add? -- Need comment for line added to /etc/ldap.conf by nssldap-update-ignoreusers(8) https://bugs.launchpad.net/bugs/382832 You received this bug notification because

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-03-30 Thread Daniel Richard G.
I know this isn't a big deal in the larger scheme of things, but it's the difference between being able to use the stock krb5 profile, and having to maintain a custom one. (And remember, the current behavior involves headaches if you have any non-root local users.) Please bring this up with Sam

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-03-30 Thread Daniel Richard G.
No no, the goal is not to have Kerberos users with uid 1000. It's to push minimum_uid higher, so that you can have normal 1000-something-uid local users authenticate without any Kerberos interaction. Same argument as for the root user and ignore_root. As for doing the upgrade, isn't

[Bug 369575] Re: Why is /usr/share/pam-configs/krb5 specifying minimum_uid= ?

2010-03-30 Thread Daniel Richard G.
What about just punting on upgrades altogether, and putting in the rearranged config only on a new install? Could that be done with appropriate postinst magic? Alternately, you could pop up a big scary debconf warning... there's ample precedent for that. -- Why is /usr/share/pam-configs/krb5

[Bug 536930] [NEW] Password changing fails when krb5 pam-config is not first

2010-03-10 Thread Daniel Richard G.
Public bug reported: This concerns libpam-krb5 3.15-1 in Karmic. If you use the krb5 profile for pam-auth-update, password changing works correctly---unless another profile goes above it, and the Password clause is used instead of Password-Initial. (I simulated this by bumping the priority down

[Bug 483928] [NEW] ssh-keyscan(1) exits prematurely on some non-fatal errors

2009-11-16 Thread Daniel Richard G.
Public bug reported: Binary package hint: openssh-client This concerns openssh-client 1:5.1p1-5ubuntu1 in Karmic. I am using ssh-keyscan(1) for its intended purpose: building an ssh_known_hosts file for a large network. Most of the hosts on this network are well-maintained systems, with

[Bug 452461] Re: Cannot elide admin_servers from debconf config

2009-11-01 Thread Daniel Richard G.
Sorry for not following up sooner. I want to set up my /etc/krb5.conf file via debconf, as is currently implemented, but I want to do things a little differently from what the scripts have been written to do. Normally, you'd specify something like this in debconf:

[Bug 452461] Re: Cannot elide admin_servers from debconf config

2009-11-01 Thread Daniel Richard G.
Please let me know if any further information is needed. ** Changed in: kerberos-configs (Ubuntu) Status: Incomplete = New -- Cannot elide admin_servers from debconf config https://bugs.launchpad.net/bugs/452461 You received this bug notification because you are a member of Ubuntu Server

[Bug 400776] Re: ssh-keyscan(1) hangs if broken server does partial handshake

2009-10-15 Thread Daniel Richard G.
The system in question, along with several others, was recently decommissioned and cannot be brought back online. (Honestly, we don't even know which physical machine it was.) This bug was trivially reproducible at the time that the report was filed, but I no longer have the means of doing so.

[Bug 452461] [NEW] Cannot elide admin_servers from debconf config

2009-10-15 Thread Daniel Richard G.
Public bug reported: Binary package hint: krb5-config I want to set up /etc/krb5.conf via debconf so that the file specifies kdc for my Kerberos realm, but not admin_server (nor kpasswd) because I want those to be found via DNS. If I do the logical thing, however---give a value for

[Bug 334374] Re: libnss-ldap should not depend on libpam-ldap

2009-08-16 Thread Daniel Richard G.
This bug report needs a visual aid. ** Attachment added: Current dependency graph (black edge = Depends, red edge = Recommends) http://launchpadlibrarian.net/30386089/depgraph.png -- libnss-ldap should not depend on libpam-ldap https://bugs.launchpad.net/bugs/334374 You received this bug

[Bug 400776] [NEW] ssh-keyscan(1) hangs if broken server does partial handshake

2009-07-17 Thread Daniel Richard G.
Public bug reported: Binary package hint: openssh-client This concerns openssh-client 1:5.1p1-5ubuntu1 in Ubuntu Jaunty. I use ssh-keyscan(1) at a company site to create a global ssh_known_hosts file. I've found, however, that the program comes to a halt when it scans one particular system, an

[Bug 382832] [NEW] Need comment for line added to /etc/ldap.conf by nssldap-update-ignoreusers(8)

2009-06-02 Thread Daniel Richard G.
Public bug reported: Binary package hint: libnss-ldap (This is an issue as of libnss-ldap 261-2.1ubuntu1 in Ubuntu Jaunty.) The nss_initgroups_ignoreusers line added by nssldap-update- ignoreusers(8) to the end of /etc/ldap.conf needs a comment at least indicating what added it. For those who

[Bug 300221] [NEW] Add Recommends: keyutils to smbfs

2008-11-20 Thread Daniel Richard G.
Public bug reported: Binary package hint: smbfs Looking at smbfs 2:3.2.3-1ubuntu3 in Intrepid. Samba's CIFS kernel module (as invoked via mount.cifs(8), in smbfs) makes use of the kernel's new request-key infrastructure, but there is nothing at the package-description level to indicate the

[Bug 236830] Re: cifs does not support kerberos authentication

2008-11-17 Thread Daniel Richard G.
Unfortunately, CIFS with Kerberos auth is broken in Intrepid, due to bug 298208. Has anyone here gotten the upcall business to work in 8.10? -- cifs does not support kerberos authentication https://bugs.launchpad.net/bugs/236830 You received this bug notification because you are a member of