OBSOLETE Patch-ID# 147794-12
Download this patch from My Oracle Support
Your use of the firmware, software and any other materials contained
in this update is subject to My Oracle Support Terms of Use, which
may be viewed at My Oracle Support.
|
For further information on patching best practices and resources, please
see the following links:
|
Copyright (c) 2012, Oracle and/or its affiliates. All rights reserved.
|
Keywords: security kdb5 krb5 libss.so.1 kerberos krb5.conf autologin rsh rlogin rcp rdist telnet
Synopsis: Obsoleted by: 147794-13 SunOS 5.10_x86: Kerberos patch
Date: Feb/15/2014
Install Requirements: Reboot after installing this patch to activate the changes delivered. An alternative may be specified in the Special Install Instructions.
Solaris Release: 10_x86
SunOS Release: 5.10_x86
Unbundled Product:
Unbundled Release:
Xref: This patch available for SPARC as patch 147793
Topic: SunOS 5.10_x86: Kerberos patch
Relevant Architectures: i386
Bugs fixed with this patch:
Changes incorporated in this version: 17792428
Patches accumulated and obsoleted by this patch: 140149-01 140160-03 143938-03 144892-02 146665-02 147716-04 148070-02 148080-01 149501-01
Patches which conflict with this patch:
Patches required with this patch: 118855-36 120012-14 127128-11 144501-19 (or greater)
Obsoleted by:
Files included with this patch:
/kernel/misc/kgss/amd64/kmech_krb5
/kernel/misc/kgss/kmech_krb5
/usr/bin/kdestroy
/usr/bin/kinit
/usr/bin/klist
/usr/bin/rcp
/usr/bin/rdist
/usr/bin/rlogin
/usr/bin/rsh
/usr/include/kerberosv5/krb5.h
/usr/lib/amd64/gss/mech_krb5.so.1
/usr/lib/gss/mech_krb5.so.1
/usr/lib/krb5/kldap.so.1
/usr/lib/krb5/krb5kdc
/usr/lib/krb5/libkadm5clnt.so.1
/usr/lib/krb5/libkadm5srv.so.1
/usr/lib/krb5/libkdb.so.1
/usr/lib/krb5/libkdb_ldap.so.1
/usr/lib/krb5/libss.so.1
/usr/lib/sasl/amd64/gssapi.so.1
/usr/lib/sasl/gssapi.so.1
/usr/lib/security/amd64/pam_krb5.so.1
/usr/lib/security/pam_krb5.so.1
/usr/sbin/in.rlogind
/usr/sbin/in.rshd
/usr/sbin/in.telnetd
/usr/sbin/kadmin
/usr/sbin/kadmin.local
/usr/sbin/kdb5_ldap_util
/usr/sbin/kdb5_util
Problem Description:
17792428 problem with Kerberos utilities
(from 147794-11)
15449097 LDAP backend uses 10ms connection timeout
15567444 fix for kdb LDAP plugin timeout incomplete, still using 10ms
17628214 kadmin.local from Solaris 10 dumps core when displaying Solaris 11 principal (missing salt)
(from 147794-10)
16448392 Solaris krb5 does not support RFC6448 which causes ssh interoperability problem
(from 147794-09)
16887464 problem with Kerberos utilities
(from 147794-08)
16617641 sshd core dump due to an uninitialized krb5_cred variable in mech_krb5 library
(from 147794-07)
15870828 winbindd crashing when trying to get TGT from a KDC (Active Directory)
(from 147794-06)
This revision accumulates generic Sustaining patch 146665-02
into Solaris S10U11 update.
(from 147794-05)
This revision accumulates generic Sustaining patch 147716-04
into Solaris S10U11 update.
(from 147794-04)
6596185 kadmin negates -allow_tix when adding a principal record
7141265 krb5 is not recognizing a duplicate security token when running "gss_accept_sec_context"
(from 147794-03)
This revision accumulates generic Sustaining patches 147716-02
and 148070-02 into Solaris S10U11 update.
(from 147794-02)
6835370 Kerberos replay cache should have better granularity
6960586 Kerberos replay cache intermittently reports authentication errors with FTP sessions
6993588 need to implement the k5buf string modules in Solaris in support of replay hashing fix
(from 147794-01)
This revision accumulates generic Sustaining patch 144892-02
into Solaris S10U11 update.
(from 148080-01)
This revision accumulates generic Sustaining patch 148070-01
into Solaris S10U11 update.
(from 148070-02)
6837512 krb5.h C++ guards are wrong
6956005 "stash" option fails to re-create the stash file if the KDC is set up by kdb5_ldap_util
(from 148070-01)
6680327 kdb5_util/kdb5_ldap_util core dumps and prints incorrect progname on error paths
(from 147716-04)
7136193 problem with Kerberos utilities
(from 147716-03)
7045809 chgpwd.c needs more resyncing to properly support RFC3244
(from 147716-02)
6372525 problem with library libsasl
6372535 krb5gss_unwrap() doesn't output data when the only error is out-of-sequence or replay detection
(from 147716-01)
7021339 nscd crashed in krb5int_sendto() when trying to free memory at an invalid address
(from 144892-02)
6997583 problem with Kerberos kdc
7059086 problem with Kerberos admin
7061008 problem with Kerberos admin
(from 144892-01)
5047971 kadmin could use libtecla for enhanced command history and editing
(from 149501-01)
5060745 rdist core dumps when libumem is used
(from 146665-02)
6574888 principals using delegated credentials are not being registered with ktkt_warnd for auto-renewal
6689008 kwarn_add_warning should not output errors to stderr
7194414 failed to compile when backporting CR 6574888 fix to Solaris 10
(from 146665-01)
This revision accumulates generic Sustaining patch 143938-03
into Solaris S10U10 update.
(from 143938-03)
6994581 r(cmds) and kcfd take too many CPU cycles after upgrade to Solaris 10 Update 7
(from 143938-02)
This revision accumulates generic Sustaining patch 140160-03
into Solaris S10U9 update.
(from 143938-01)
This revision accumulates generic Sustaining patch 140160-02
into Solaris S10U9 update.
(from 140160-03)
6922520 rcp data transfer to local system should improve error testing
(from 140160-02)
6821299 rdist problem with savelink
(from 140160-01)
This revision accumulates generic Sustaining patch 140149-01
into Solaris S10U7 update.
(from 140149-01)
6683649 krb5.conf autologin setting should be valid for rsh/rlogin/rcp/rdist as well as telnet
Patch Installation Instructions:
--------------------------------
Please refer to the man pages for instructions on using 'patchadd'
and 'patchrm' commands provided with Solaris.
The following example installs a patch to a standalone machine:
example# patchadd /var/spool/patch/123456-07
The following example removes a patch from a standalone system:
example# patchrm 123456-07
For additional examples please see the appropriate man pages. Any
other special or non-generic installation instructions should be
described below as special instructions.
Special Install Instructions:
-----------------------------
None.
README -- Last modified date: Thursday, May 15, 2014