-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Thu, 02 Feb 2012 23:14:09 +0100 Source: debian-edu-config Binary: debian-edu-config debian-edu-config-gosa-netgroups Architecture: source all Version: 1.449 Distribution: unstable Urgency: low Maintainer: Debian Edu Developers <debian-edu@lists.debian.org> Changed-By: Petter Reinholdtsen <pere@debian.org> Description: debian-edu-config - Configuration files for Skolelinux systems debian-edu-config-gosa-netgroups - netgroups plugin for GOsa² Closes: 658076 Changes: debian-edu-config (1.449) unstable; urgency=low . [ Petter Reinholdtsen ] * Remove obsolete mimelnk/applnk/msword.desktop file, as Squeeze handle doc files just fine without it. * Change password hash for the 'admin' LDAP user from {CRYPT} to {SSHA}, to get a hash type understood by GOsa and allow the password to be changed from within GOsa. Both work with LDAP bind. * Add new tool auto-addfirmware to automatically detect firmware needed by kernel modules and install them from non-free. * Add new tool ltsp-addfirmware to make it easier to add required firmware to the LTSP initrd. Based on code from Wolfgang Schweer. * In kerberos-kdc-init, give slapd 5 seconds to start to make sure slapd is operational when kerberos try to talk to it. * Make sure all gosa hook scripts syslog with the script name in the syslog tag. * Make sure the output from kadmin.local in gosa-sync is syslogged when changing password, to make it possible to figure out why when it fail. * Rewrite gosa-sync to avoid exposing the new password in the process list for every local user to see. * Disable workaround for #656309 in libpam-krb5 on Roaming Workstations, as they use libpam-sss and not libpam-krb5. * Re-enable cfengine rules for nslcd.conf and ldap.conf on Roaming Workstation, which was disabled by mistake to drop rule to edit nsswitch.conf. * Rewrite sitesummary2ldapdhcp to present the changes it want to do before activating the changes. * First user related: - Make sure single word full name for first user do not break the installation by setting given and family name to the same word when this happen. - Make sure gecos field for first user in LDAP is ASCII, to match schema constraint. - Move LDAP definition for first user to separete ldif, to make it easier to figure out when loading it fail during installation. - Add more logging when creating the first user, to notice when it fail. * Remove obsolete cfengine rule calling /usr/share/doc/kaffeine/install-css.sh when Internet connectivity is available during installation. The script is no longer present in Squeeze. * Adjust nsswitch check in ldap-client testsuite test to not report incorrect problem on Roaming Workstation. * Add wicd preconnect hook set_wireless_mac_from_eth0 to use the same MAC address for both wired and wireless interfaces, to allow one static DHCP entry to work with both. Based on code from José L. Redrejo Rodríguez. * Add cfengine rule to remove network-manager on Roaming Workstation to give wicd a chance to do its job uninterrupted. * Remove obsolete powerdns code from run-at-firstboot, as we now use bind9. * New tool ldap2bind-updatezonelist to generate /etc/bind/named.conf.ldap2zone, to make sure it is updated when new DNS zones are added to LDAP. * Updates for subnet-change: - Add more debug output. - Add code to edit /etc/exports, /etc/network/interfaces, /etc/samba/smb-debian-edu.conf and /etc/squid/squid.conf. - Add code to update goServer and ipHost LDAP objects. - Adjust code to update DNS to handle A records used by ldap2zone. - Add code to handle moving to smaller subnets by scaling down IP range. - Make sure to update dhcpSharedNetwork LDAP objects too, and complete DHCP part of LDAP update. - Run /usr/share/debian-edu-config/tools/gosa-sync-dns-nfs after updating LDAP to generate new DNS zone files for bind. - Add code to update reverse DNS entries in LDAP. - Call new tool ldap2bind-updatezonelist to make sure /etc/bind/named.conf.ldap2zone list the new reverse IP range. * Fix two perl warnings in our Debian::Edu perl module. * Make sure /etc/wicd/scripts/preconnect/set_wireless_mac_from_eth0 is installed with execute bit set to get it working. * Remove redundant empty attribute macAddress for gatway ipHost object in LDAP. * Call sitesummary-client at the end of the installation, to try to save one reboot when setting up new machines. * Make sure squid-update-cachedir run with a predictable locale, and make it more robust. * Update list of active munin plugins at first boot, to make sure all services present are monitored. . [ Andreas B. Mundt ] * Add 'permitted_enctypes = des-cbc-crc' to krb5.conf. Needed for latest squeeze point release (see #657802) to get NFSv4 with kerberos working. . [ Petter Reinholdtsen ] * Add encryption types used by sssd in the Kerberos setup of the KDC to get Roaming workstations working. Setting 'permitted_enctypes = des-cbc-crc rc4-hmac des3-cbc-sha1-kd aes128-cts-hmac-sha1-96 aes256-cts-hmac-sha1-96', as des-cbc-crc is not used by sssd. This fixes regression introduced trying to fix BTS report #657802. . * Translation updates: - Updates for Dutch web page from Jeroen Schot (Closes: #658076). Checksums-Sha1: 5246f6e89acef20b78e54a2e872be57b290647aa 1447 debian-edu-config_1.449.dsc 062033d11c09e47796e9d2372646323e1c552e8e 498804 debian-edu-config_1.449.tar.gz 3a4a173a9d997db9b3b9e3b124f51f18c23b827c 387388 debian-edu-config_1.449_all.deb 576f7a17a843017b68470ab4993ab8eacfd20300 110766 debian-edu-config-gosa-netgroups_1.449_all.deb Checksums-Sha256: f5b86ceb074d1389a7e3d835818be0a0be9a5f0fe941ad02a41d4f638b42b7f0 1447 debian-edu-config_1.449.dsc 939f6255005cc1bf62c2e8635e7b7ae75c6891a83f8e1135efe37131061d0df6 498804 debian-edu-config_1.449.tar.gz 62bcbf5a4e7f5913d8f455c76268eae0ae5cd0414c44f69c2f6e10ca490bf200 387388 debian-edu-config_1.449_all.deb 561808d7375542ae65e7fecc20889e982fa6ec4b89e6cee94af9f238231d9fa0 110766 debian-edu-config-gosa-netgroups_1.449_all.deb Files: e6e64573ee4492776931be581183ce7a 1447 misc extra debian-edu-config_1.449.dsc 7a5834a2d30a4723b7b16f1f9b841a24 498804 misc extra debian-edu-config_1.449.tar.gz 5353c90a4f24cb403e0847452c8abf7e 387388 misc extra debian-edu-config_1.449_all.deb b499813fab5002cb59f6ba51c72d6246 110766 misc extra debian-edu-config-gosa-netgroups_1.449_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iD8DBQFPKws120zMSyow1ykRAlp6AKCnX7jV58AYUmAsjVGTXJUBs3uBiACeIf33 K9PdUZ2dPtlVBsJK3wUrsDM= =lhc/ -----END PGP SIGNATURE----- Accepted: debian-edu-config-gosa-netgroups_1.449_all.deb to main/d/debian-edu-config/debian-edu-config-gosa-netgroups_1.449_all.deb debian-edu-config_1.449.dsc to main/d/debian-edu-config/debian-edu-config_1.449.dsc debian-edu-config_1.449.tar.gz to main/d/debian-edu-config/debian-edu-config_1.449.tar.gz debian-edu-config_1.449_all.deb to main/d/debian-edu-config/debian-edu-config_1.449_all.deb