-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Format: 1.8 Date: Thu, 10 Aug 2023 16:47:59 +0200 Source: debian-edu-config Architecture: source Version: 2.12.34 Distribution: unstable Urgency: medium Maintainer: Debian Edu Developers <debian-edu@lists.debian.org> Changed-By: Mike Gabriel <sunweaver@debian.org> Closes: 1030116 1039166 1039966 1040015 1041322 1042456 1042940 1043397 Changes: debian-edu-config (2.12.34) unstable; urgency=medium . [ Mike Gabriel ] * Start 2.12.34 development. * debian/debian-edu-config.lintian-overrides: + Update existing overrides (line numbers and such). + Drop missing-systemd-service-for-init.d-script overrides. Systemd service files are now provided. + Drop init.d-script-does-not-implement-status-option override for fetch-ldap-cert. Init script is now gone. * testsuite: Install to pkglibexecdir rather than libexecdir. Thanks lintian. * Makefile: Adjust white-spacing in variable declarations. * Makefile: Use $(NULL) variable at end of file lists. Allow for better git- patch readability. * Convert CRON configuration to systemd timers. * sbin/*-for-netgroup-hosts: Some noop + white-spacing beautifications. * Move d-e-c-*-for-netgroup-hosts scripts to pkglibexecdir. * debian/debian-edu-config.postinst: + Assure runlevel de-registering of init script fetch-ldap-cert. * debian/debian-edu-config.maintscript: + Assure removal of /etc/init.d/fetch-ldap-cert conffile. * debian/debian-edu-config.cron.*: + Only run scripts if they exist. Thanks piuparts. . [ Daniel Teichmann ] * etc/dhcp/dhcp-debian-edu.conf: + ldap-server. 'ldap' -> 'ldap.intern'. (Closes: #1039966). * share/debian-edu-config/tools/gosa-remove: + Fix kadmin.local, Use '-force' to disable interaction via stdin. . [ Guido Berhoerster ] * ldap-tools/ldap-createuser-krb5: + Fix user creation. (Closes: #1042456). Remove Samba NT4 domain support, add samba user using smbpasswd. Add root CA for new users (copied from gosa-create). + Fix new UID/GID selection. Exclude special users (UID/GID >= 10000) when looking for the highest UID/GID. + Add CLI options for uid/gid/department. Also ensure script is run as root. + Add additional attributes based on template users. + Add support for additional groups. + Send welcome email in order to create maildir. Without this the maildir in /var/mail/<user> will not exist and Dovecot will refuse to let the user log in as it cannot create this directory. + Set LDAP password when creating users. This allows users to use GOsa² to change their password. * Add systemd services for configuring Chromium/Firefox from LDAP. Factor out logic from init script into separate script which are then called from both the init script and systemd services. * Add systemd service enabling NAT for thin clients. * Add systemd service for fetching the RootCA file from the main server. * Drop init script for fetching LDAP SSL public key from legacy main servers. This drops support for clients running behind a main server based on Debian Edu stretch. (Closes: #1030116). * Update debian/rules for init scripts and systemd services. (Closes: #1039166). * Generate a random password for the icinga/icingaweb databases. (Closes: #1040015). * update-dlw-krb5-keytabs: Handle missing/empty diskless-workstation-hosts. * Followup fixes for ntpsec transition. * Add systemd support to debian-edu-restart-services: This uses a list of service units which was compiled on a main server + ltsp installation. Uses stop and start to force restart reverse-dependencies. It also makes sure that drop in files are recognized. (Closes: #1042940). * Configure gosa not to use STARTTLS since TLS is already used. ldapTLS configures the use of STARTTLS, not TLS per se which is enabled by the use of ldaps: protocol in URLs. (Closes: #1041322). * Allow root access to cups via SystemGroups. 'root' access is allowed in the default configuration and e.g. necessary for services like debian-edu-cups-queue-autoflush.service to work. (Closes: #1043397). * cf3/promises.cf: fix typo and allow connections from localhost and network. Checksums-Sha1: 27d4c64e319df5b490ab1838148018072b5e7530 2017 debian-edu-config_2.12.34.dsc 14a8058548a537bde7a9df84424c4529d433415c 356584 debian-edu-config_2.12.34.tar.xz 5b1390db22ca008e7896321a95f135d1441b3ff0 6733 debian-edu-config_2.12.34_source.buildinfo Checksums-Sha256: 6cc4c747f85c222aff4c721d3cc9d2046c70fe7ffcad4727aad09e527049888a 2017 debian-edu-config_2.12.34.dsc b8c6765a1735bd81e045c0214443d67035066c40b3e5971474eef17dd47c327f 356584 debian-edu-config_2.12.34.tar.xz 3f540373d71cfa1a01b1539a26e3ef997a3a50602195f2b5c8b8c60b1ebf652b 6733 debian-edu-config_2.12.34_source.buildinfo Files: 463eb95f9f0f80fd44e0c2d0dd6525eb 2017 misc optional debian-edu-config_2.12.34.dsc 397614c86fcc0aeabd6231957c88874b 356584 misc optional debian-edu-config_2.12.34.tar.xz c5efbb82e8bf2687576e065a5a155c74 6733 misc optional debian-edu-config_2.12.34_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJJBAEBCAAzFiEEm/uu6GwKpf+/IgeCmvRrMCV3GzEFAmTVAmYVHHN1bndlYXZl ckBkZWJpYW4ub3JnAAoJEJr0azAldxsxiysQAJ+Ge/17p5Zwu4UEy+6uthXcofa1 rQpiT2S8LsKYSYkdoD/1pZ9twkeZCl7fmo9KzMhomEoBVC075zLwpg8TU1dUhFVM nKm16OMt8ZciiKQymqK3PtXdkawTZkYVfeAwexmRoRew+4pW7wovX1UzPvPduSaP az+amrqQPVDUO76NXqR78JWpkzz4QdFYK4oJHYhtV99HZ7E0whYkKjg2xG+S+pRr aBsWSe/3hTUYAVtH4lyaQr3hfUXZo9cX3yVO+i70+QPqkqs/0doU91oxcxDyVCZa 2akH32baiOBs2xeZGAvOKXHfV4UqcJXjLOrAIubtuCX0VhwEfwiNPWDfhLlq8kKN 4HycR8tdAXYn3WZE2/xGtyluMNZzwLFcUT6FFuWUTfmSECDB+uOvGOTUoLqGhGAJ Ztp/ApA9Edd1j5AwbKvVP44ruYqIYJ6urqUXtg21QdtHo1mE7RTR5lNiUfbiU/Y1 v8A8lNKpUUZv09vPpv853BuuaHPsp6gC1RZtRbk9KQXtucZZboiPvA8ZgomI8w15 G7Vqp05yrmEiKKPd29RqwhtpqlbUWSdE0vajwfRQ/WpopCeysvWzzpV9/a0BiTvZ sY4ejt6jTKmeebw3xFftT7Hb+/S5zCs2o5BgR/23AVUMsgQktCqRE7oK0mhDUsac UuC+QdIaQJsldXK+ =Khx6 -----END PGP SIGNATURE-----