examples/LDAP/samba.schema.gz provided by samba-doc package has duplicate attributeType

Bug #7829 reported by Debian Bug Importer
6
Affects Status Importance Assigned to Milestone
samba (Debian)
Fix Released
Unknown
samba (Ubuntu)
Fix Released
Low
Daniel Stone

Bug Description

Automatically imported from Debian bug report #269797 http://bugs.debian.org/269797

Revision history for this message
In , Steve Langasek (vorlon) wrote : Re: libcapi20: capidivert 0.0.2 generates coredump in libcapi / capi_get_cmsg

# 1 definition found
#
# From WordNet (r) 2.0 [wn]:
#
# unrelated
# adj 1: not connected or associated [ant: {related}]
# 2: not connected by kinship [ant: {related}]
#
severity 269767 grave
clone 269797 -1
retitle -1 libcapi20-3: devel files in a library package
severity -1 serious
thanks

The libcapi20-3 package contains libcapi20.so.2, not libcapi20.so.3 as
its name suggests. This looks very much like there have been
incompatible ABI changes without an soname change -- but with a package
name change, which is quite peculiar!. While the package name change
ensures that other packaged software using this library will function
correctly, library maintainers are expected to provide at least minimal
support for local third-party software by not breaking the
one-soname-one-ABI rule.

This package also contains static libs, libtool .la files, and header
files, all of which belong in a -dev package per policy. You have added
a Conflicts: against older versions of the library to ensure that dpkg
doesn't complain about this state of affairs, but it's nevertheless
contrary to the fundamental goals of providing shared library packages.

Since the packages depending on libcapi20-2 in testing also appear to be
in rather sorry shape right now, including one must-go package that
depends on libtiff3g, I'm planning to remove all of these packages from
testing pending resolution of the isdnutils bugs.

Thanks,
--
Steve Langasek
postmodern programmer

Revision history for this message
In , Bastian Blank (waldi) wrote : examples/LDAP/samba.schema.gz - duplicate attributeType

severity 269797 grave
thanks

Samba 3.0.6 needs this new defined attribute type sambaPasswordHistory
for password changes and refuses to change passwords if not available.
The schema file which contains this type is broken.

Not being able to change passwords is a large security problem.

Bastian

--
Conquest is easy. Control is not.
  -- Kirk, "Mirror, Mirror", stardate unknown

Revision history for this message
In , Bastian Blank (waldi) wrote : updated schema file

According to http://us3.samba.org/samba/news/#openLDAP-samba3.0.6, the
fixed schema file is available via
http://us3.samba.org/samba/ftp/samba.schema.

Bastian

--
It would seem that evil retreats when forcibly confronted.
  -- Yarnek of Excalbia, "The Savage Curtain", stardate 5906.5

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Automatically imported from Debian bug report #269797 http://bugs.debian.org/269797

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-Id: <email address hidden>
Date: Fri, 03 Sep 2004 19:08:00 +0400
From: "Nikita V. Youshchenko" <email address hidden>
To: Debian Bug Tracking System <email address hidden>
Subject: examples/LDAP/samba.schema.gz provided by samba-doc package has duplicate
 attributeType

Package: samba-doc
Version: 3.0.6-3
Severity: normal

While setting up samba to use LDAP, I found that samba.schema provided
by the package has a bug, giving same attributeType to 2 attributes
(sambaPasswordHistory and sambaLogonHours).

The result is that if the file is included into slapd configuration,
slapd fails to start.

I've searched the net, and found
http://www.faqchest.com/linux/samba-l/smb-04/smb-0408/smb-040823/smb04082702_04824.html
that advises to change sambaPasswordHistory's attributeType to
1.3.6.1.4.1.7165.2.1.52

-- System Information:
Debian Release: 3.0
  APT prefers testing
  APT policy: (620, 'testing'), (600, 'unstable'), (550, 'experimental')
Architecture: i386 (i686)
Kernel: Linux 2.6.7-1-k7-smp
Locale: LANG=ru_RU.KOI8-R, LC_CTYPE=ru_RU.KOI8-R

-- no debconf information

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-ID: <email address hidden>
Date: Fri, 3 Sep 2004 18:01:08 -0700
From: Steve Langasek <email address hidden>
To: <email address hidden>
Subject: Re: libcapi20: capidivert 0.0.2 generates coredump in libcapi / capi_get_cmsg

--p7qwJlK53pWzbayA
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

# 1 definition found
#
# From WordNet (r) 2.0 [wn]:
#
# unrelated
# adj 1: not connected or associated [ant: {related}]
# 2: not connected by kinship [ant: {related}]
#
severity 269767 grave
clone 269797 -1
retitle -1 libcapi20-3: devel files in a library package
severity -1 serious
thanks

The libcapi20-3 package contains libcapi20.so.2, not libcapi20.so.3 as
its name suggests. This looks very much like there have been
incompatible ABI changes without an soname change -- but with a package
name change, which is quite peculiar!. While the package name change
ensures that other packaged software using this library will function
correctly, library maintainers are expected to provide at least minimal
support for local third-party software by not breaking the
one-soname-one-ABI rule.

This package also contains static libs, libtool .la files, and header
files, all of which belong in a -dev package per policy. You have added
a Conflicts: against older versions of the library to ensure that dpkg
doesn't complain about this state of affairs, but it's nevertheless
contrary to the fundamental goals of providing shared library packages.

Since the packages depending on libcapi20-2 in testing also appear to be
in rather sorry shape right now, including one must-go package that
depends on libtiff3g, I'm planning to remove all of these packages from
testing pending resolution of the isdnutils bugs.

Thanks,
--=20
Steve Langasek
postmodern programmer

--p7qwJlK53pWzbayA
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBORPRKN6ufymYLloRAtOrAKCuN0A3Be6EPIoLchLO7cwyDzof0QCcDJ7p
ca1Q0CHMJQ5RozuZZLzSbw0=
=XcsN
-----END PGP SIGNATURE-----

--p7qwJlK53pWzbayA--

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-ID: <email address hidden>
Date: Tue, 7 Sep 2004 15:58:59 +0200
From: Bastian Blank <email address hidden>
To: <email address hidden>
Cc: <email address hidden>
Subject: examples/LDAP/samba.schema.gz - duplicate attributeType

--CE+1k2dSO48ffgeK
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

severity 269797 grave
thanks

Samba 3.0.6 needs this new defined attribute type sambaPasswordHistory
for password changes and refuses to change passwords if not available.
The schema file which contains this type is broken.

Not being able to change passwords is a large security problem.

Bastian

--=20
Conquest is easy. Control is not.
  -- Kirk, "Mirror, Mirror", stardate unknown

--CE+1k2dSO48ffgeK
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iEYEARECAAYFAkE9vqIACgkQnw66O/MvCNECJACfZ52BoGCzK69n4VFttYzaCBnv
69sAoI87LT1Bhj3XNDXw0cUtrkGzt43o
=HEGX
-----END PGP SIGNATURE-----

--CE+1k2dSO48ffgeK--

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-ID: <email address hidden>
Date: Tue, 7 Sep 2004 16:01:45 +0200
From: Bastian Blank <email address hidden>
To: <email address hidden>
Subject: updated schema file

--XF85m9dhOBO43t/C
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

According to http://us3.samba.org/samba/news/#openLDAP-samba3.0.6, the
fixed schema file is available via
http://us3.samba.org/samba/ftp/samba.schema.

Bastian

--=20
It would seem that evil retreats when forcibly confronted.
  -- Yarnek of Excalbia, "The Savage Curtain", stardate 5906.5

--XF85m9dhOBO43t/C
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iEYEARECAAYFAkE9v0kACgkQnw66O/MvCNHfygCeN8jIa7+V7NpfMP1cTaZV0Oes
X+8An1x/PKsHEXoCDO2Ou7Ydom0SmCMN
=yZ4A
-----END PGP SIGNATURE-----

--XF85m9dhOBO43t/C--

Revision history for this message
In , Eloy Paris (peloy-chapus) wrote : Re: Bug#269797: examples/LDAP/samba.schema.gz - duplicate attributeType

severity 269797 normal
thanks

I am sorry, but I disagree with the change in severity. The schema is
shipped as an example (in the samba-doc package) and therefore is not
installed in /etc automatically. It takes the same effort to fetch a
fresh copy from samba.org than to use the one included in the samba-doc
package.

Having said this, I am preparing a new upload which should be installed
in tomorrow's dinstall run.

Eloy.-

On Tue, Sep 07, 2004 at 03:58:59PM +0200, Bastian Blank wrote:
> severity 269797 grave
> thanks
>
> Samba 3.0.6 needs this new defined attribute type sambaPasswordHistory
> for password changes and refuses to change passwords if not available.
> The schema file which contains this type is broken.
>
> Not being able to change passwords is a large security problem.
>
> Bastian
>
> --
> Conquest is easy. Control is not.
> -- Kirk, "Mirror, Mirror", stardate unknown

Revision history for this message
In , Eloy A. Paris (peloy) wrote : Bug#269797: fixed in samba 3.0.6-4
Download full text (4.2 KiB)

Source: samba
Source-Version: 3.0.6-4

We believe that the bug you reported is fixed in the latest version of
samba, which is due to be installed in the Debian FTP archive:

libpam-smbpass_3.0.6-4_i386.deb
  to pool/main/s/samba/libpam-smbpass_3.0.6-4_i386.deb
libsmbclient-dev_3.0.6-4_i386.deb
  to pool/main/s/samba/libsmbclient-dev_3.0.6-4_i386.deb
libsmbclient_3.0.6-4_i386.deb
  to pool/main/s/samba/libsmbclient_3.0.6-4_i386.deb
python2.3-samba_3.0.6-4_i386.deb
  to pool/main/s/samba/python2.3-samba_3.0.6-4_i386.deb
samba-common_3.0.6-4_i386.deb
  to pool/main/s/samba/samba-common_3.0.6-4_i386.deb
samba-doc_3.0.6-4_all.deb
  to pool/main/s/samba/samba-doc_3.0.6-4_all.deb
samba_3.0.6-4.diff.gz
  to pool/main/s/samba/samba_3.0.6-4.diff.gz
samba_3.0.6-4.dsc
  to pool/main/s/samba/samba_3.0.6-4.dsc
samba_3.0.6-4_i386.deb
  to pool/main/s/samba/samba_3.0.6-4_i386.deb
smbclient_3.0.6-4_i386.deb
  to pool/main/s/samba/smbclient_3.0.6-4_i386.deb
smbfs_3.0.6-4_i386.deb
  to pool/main/s/samba/smbfs_3.0.6-4_i386.deb
swat_3.0.6-4_i386.deb
  to pool/main/s/samba/swat_3.0.6-4_i386.deb
winbind_3.0.6-4_i386.deb
  to pool/main/s/samba/winbind_3.0.6-4_i386.deb

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to <email address hidden>,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Eloy A. Paris <email address hidden> (supplier of updated samba package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing <email address hidden>)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Tue, 7 Sep 2004 15:28:42 -0400
Source: samba
Binary: samba-doc libsmbclient libpam-smbpass swat winbind smbclient samba samba-common libsmbclient-dev python2.3-samba smbfs
Architecture: source i386 all
Version: 3.0.6-4
Distribution: unstable
Urgency: low
Maintainer: Eloy A. Paris <email address hidden>
Changed-By: Eloy A. Paris <email address hidden>
Description:
 libpam-smbpass - pluggable authentication module for SMB password database
 libsmbclient - shared library that allows applications to talk to SMB servers
 libsmbclient-dev - libsmbclient static libraries and headers
 python2.3-samba - Python bindings that allow access to various aspects of Samba
 samba - a LanManager-like file and printer server for Unix
 samba-common - Samba common files used by both the server and the client
 samba-doc - Samba documentation
 smbclient - a LanManager-like simple client for Unix
 smbfs - mount and umount commands for the smbfs (for kernels >= than 2.2.
 swat - Samba Web Administration Tool
 winbind - service to resolve user and group information from Windows NT ser
Closes: 269797
Changes:
 samba (3.0.6-4) unstable; urgency=low
 .
   * Update LDAP schema (closes: #269797).
   * Applied a couple of upstream fixes that will be present in Samba 3.0.7.
Files:
 aa3fe3dba007ff4fbd914dc687f6bdea 919 net optional samba_3.0.6-4.dsc
 c09b6df5ef2e94f06af0a2a8a54fcae2 10...

Read more...

Revision history for this message
Debian Bug Importer (debzilla) wrote :

Message-ID: <email address hidden>
Date: Tue, 7 Sep 2004 15:34:28 -0400
From: "Eloy A. Paris" <email address hidden>
To: Bastian Blank <email address hidden>, <email address hidden>
Cc: <email address hidden>
Subject: Re: Bug#269797: examples/LDAP/samba.schema.gz - duplicate attributeType

severity 269797 normal
thanks

I am sorry, but I disagree with the change in severity. The schema is
shipped as an example (in the samba-doc package) and therefore is not
installed in /etc automatically. It takes the same effort to fetch a
fresh copy from samba.org than to use the one included in the samba-doc
package.

Having said this, I am preparing a new upload which should be installed
in tomorrow's dinstall run.

Eloy.-

On Tue, Sep 07, 2004 at 03:58:59PM +0200, Bastian Blank wrote:
> severity 269797 grave
> thanks
>
> Samba 3.0.6 needs this new defined attribute type sambaPasswordHistory
> for password changes and refuses to change passwords if not available.
> The schema file which contains this type is broken.
>
> Not being able to change passwords is a large security problem.
>
> Bastian
>
> --
> Conquest is easy. Control is not.
> -- Kirk, "Mirror, Mirror", stardate unknown

Revision history for this message
Matt Zimmerman (mdz) wrote :

Documentation/example bug

Revision history for this message
Debian Bug Importer (debzilla) wrote :
Download full text (4.4 KiB)

Message-Id: <email address hidden>
Date: Tue, 07 Sep 2004 16:17:36 -0400
From: <email address hidden> (Eloy A. Paris)
To: <email address hidden>
Subject: Bug#269797: fixed in samba 3.0.6-4

Source: samba
Source-Version: 3.0.6-4

We believe that the bug you reported is fixed in the latest version of
samba, which is due to be installed in the Debian FTP archive:

libpam-smbpass_3.0.6-4_i386.deb
  to pool/main/s/samba/libpam-smbpass_3.0.6-4_i386.deb
libsmbclient-dev_3.0.6-4_i386.deb
  to pool/main/s/samba/libsmbclient-dev_3.0.6-4_i386.deb
libsmbclient_3.0.6-4_i386.deb
  to pool/main/s/samba/libsmbclient_3.0.6-4_i386.deb
python2.3-samba_3.0.6-4_i386.deb
  to pool/main/s/samba/python2.3-samba_3.0.6-4_i386.deb
samba-common_3.0.6-4_i386.deb
  to pool/main/s/samba/samba-common_3.0.6-4_i386.deb
samba-doc_3.0.6-4_all.deb
  to pool/main/s/samba/samba-doc_3.0.6-4_all.deb
samba_3.0.6-4.diff.gz
  to pool/main/s/samba/samba_3.0.6-4.diff.gz
samba_3.0.6-4.dsc
  to pool/main/s/samba/samba_3.0.6-4.dsc
samba_3.0.6-4_i386.deb
  to pool/main/s/samba/samba_3.0.6-4_i386.deb
smbclient_3.0.6-4_i386.deb
  to pool/main/s/samba/smbclient_3.0.6-4_i386.deb
smbfs_3.0.6-4_i386.deb
  to pool/main/s/samba/smbfs_3.0.6-4_i386.deb
swat_3.0.6-4_i386.deb
  to pool/main/s/samba/swat_3.0.6-4_i386.deb
winbind_3.0.6-4_i386.deb
  to pool/main/s/samba/winbind_3.0.6-4_i386.deb

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to <email address hidden>,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Eloy A. Paris <email address hidden> (supplier of updated samba package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing <email address hidden>)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Tue, 7 Sep 2004 15:28:42 -0400
Source: samba
Binary: samba-doc libsmbclient libpam-smbpass swat winbind smbclient samba samba-common libsmbclient-dev python2.3-samba smbfs
Architecture: source i386 all
Version: 3.0.6-4
Distribution: unstable
Urgency: low
Maintainer: Eloy A. Paris <email address hidden>
Changed-By: Eloy A. Paris <email address hidden>
Description:
 libpam-smbpass - pluggable authentication module for SMB password database
 libsmbclient - shared library that allows applications to talk to SMB servers
 libsmbclient-dev - libsmbclient static libraries and headers
 python2.3-samba - Python bindings that allow access to various aspects of Samba
 samba - a LanManager-like file and printer server for Unix
 samba-common - Samba common files used by both the server and the client
 samba-doc - Samba documentation
 smbclient - a LanManager-like simple client for Unix
 smbfs - mount and umount commands for the smbfs (for kernels >= than 2.2.
 swat - Samba Web Administration Tool
 winbind - service to resolve user and group information from Windows NT ser
Closes: 269797
Changes:
 samba (3.0.6-4) unstable; urgency=low
 .
   * Update LDAP schema (cl...

Read more...

Revision history for this message
Daniel Stone (daniels) wrote :

Fixed in 3.0.6-1ubuntu2.

Changed in samba:
status: Unknown → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.