examples/LDAP/samba.schema.gz provided by samba-doc package has duplicate attributeType
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
samba (Debian) |
Fix Released
|
Unknown
|
|||
samba (Ubuntu) |
Fix Released
|
Low
|
Daniel Stone |
Bug Description
Automatically imported from Debian bug report #269797 http://
In Debian Bug tracker #269797, Steve Langasek (vorlon) wrote : Re: libcapi20: capidivert 0.0.2 generates coredump in libcapi / capi_get_cmsg | #1 |
In Debian Bug tracker #269797, Bastian Blank (waldi) wrote : examples/LDAP/samba.schema.gz - duplicate attributeType | #2 |
severity 269797 grave
thanks
Samba 3.0.6 needs this new defined attribute type sambaPasswordHi
for password changes and refuses to change passwords if not available.
The schema file which contains this type is broken.
Not being able to change passwords is a large security problem.
Bastian
--
Conquest is easy. Control is not.
-- Kirk, "Mirror, Mirror", stardate unknown
In Debian Bug tracker #269797, Bastian Blank (waldi) wrote : updated schema file | #3 |
According to http://
fixed schema file is available via
http://
Bastian
--
It would seem that evil retreats when forcibly confronted.
-- Yarnek of Excalbia, "The Savage Curtain", stardate 5906.5
Debian Bug Importer (debzilla) wrote : | #4 |
Automatically imported from Debian bug report #269797 http://
Debian Bug Importer (debzilla) wrote : | #5 |
Message-Id: <email address hidden>
Date: Fri, 03 Sep 2004 19:08:00 +0400
From: "Nikita V. Youshchenko" <email address hidden>
To: Debian Bug Tracking System <email address hidden>
Subject: examples/
attributeType
Package: samba-doc
Version: 3.0.6-3
Severity: normal
While setting up samba to use LDAP, I found that samba.schema provided
by the package has a bug, giving same attributeType to 2 attributes
(sambaPasswordH
The result is that if the file is included into slapd configuration,
slapd fails to start.
I've searched the net, and found
http://
that advises to change sambaPasswordHi
1.3.6.1.
-- System Information:
Debian Release: 3.0
APT prefers testing
APT policy: (620, 'testing'), (600, 'unstable'), (550, 'experimental')
Architecture: i386 (i686)
Kernel: Linux 2.6.7-1-k7-smp
Locale: LANG=ru_RU.KOI8-R, LC_CTYPE=
-- no debconf information
Debian Bug Importer (debzilla) wrote : | #6 |
Message-ID: <email address hidden>
Date: Fri, 3 Sep 2004 18:01:08 -0700
From: Steve Langasek <email address hidden>
To: <email address hidden>
Subject: Re: libcapi20: capidivert 0.0.2 generates coredump in libcapi / capi_get_cmsg
--p7qwJlK53pWzbayA
Content-Type: text/plain; charset=us-ascii
Content-
Content-
# 1 definition found
#
# From WordNet (r) 2.0 [wn]:
#
# unrelated
# adj 1: not connected or associated [ant: {related}]
# 2: not connected by kinship [ant: {related}]
#
severity 269767 grave
clone 269797 -1
retitle -1 libcapi20-3: devel files in a library package
severity -1 serious
thanks
The libcapi20-3 package contains libcapi20.so.2, not libcapi20.so.3 as
its name suggests. This looks very much like there have been
incompatible ABI changes without an soname change -- but with a package
name change, which is quite peculiar!. While the package name change
ensures that other packaged software using this library will function
correctly, library maintainers are expected to provide at least minimal
support for local third-party software by not breaking the
one-soname-one-ABI rule.
This package also contains static libs, libtool .la files, and header
files, all of which belong in a -dev package per policy. You have added
a Conflicts: against older versions of the library to ensure that dpkg
doesn't complain about this state of affairs, but it's nevertheless
contrary to the fundamental goals of providing shared library packages.
Since the packages depending on libcapi20-2 in testing also appear to be
in rather sorry shape right now, including one must-go package that
depends on libtiff3g, I'm planning to remove all of these packages from
testing pending resolution of the isdnutils bugs.
Thanks,
--=20
Steve Langasek
postmodern programmer
--p7qwJlK53pWzbayA
Content-Type: application/
Content-
Content-
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
iD8DBQFBORPRKN6
ca1Q0CHMJQ5Rozu
=XcsN
-----END PGP SIGNATURE-----
--p7qwJlK53pWzb
Debian Bug Importer (debzilla) wrote : | #7 |
Message-ID: <email address hidden>
Date: Tue, 7 Sep 2004 15:58:59 +0200
From: Bastian Blank <email address hidden>
To: <email address hidden>
Cc: <email address hidden>
Subject: examples/
--CE+1k2dSO48ffgeK
Content-Type: text/plain; charset=utf-8
Content-
Content-
severity 269797 grave
thanks
Samba 3.0.6 needs this new defined attribute type sambaPasswordHi
for password changes and refuses to change passwords if not available.
The schema file which contains this type is broken.
Not being able to change passwords is a large security problem.
Bastian
--=20
Conquest is easy. Control is not.
-- Kirk, "Mirror, Mirror", stardate unknown
--CE+1k2dSO48ffgeK
Content-Type: application/
Content-
Content-
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
iEYEARECAAYFAkE
69sAoI87LT1Bhj3
=HEGX
-----END PGP SIGNATURE-----
--CE+1k2dSO48ff
Debian Bug Importer (debzilla) wrote : | #8 |
Message-ID: <email address hidden>
Date: Tue, 7 Sep 2004 16:01:45 +0200
From: Bastian Blank <email address hidden>
To: <email address hidden>
Subject: updated schema file
--XF85m9dhOBO43t/C
Content-Type: text/plain; charset=utf-8
Content-
Content-
According to http://
fixed schema file is available via
http://
Bastian
--=20
It would seem that evil retreats when forcibly confronted.
-- Yarnek of Excalbia, "The Savage Curtain", stardate 5906.5
--XF85m9dhOBO43t/C
Content-Type: application/
Content-
Content-
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
iEYEARECAAYFAkE
X+8An1x/
=yZ4A
-----END PGP SIGNATURE-----
--XF85m9dhOBO43
In Debian Bug tracker #269797, Eloy Paris (peloy-chapus) wrote : Re: Bug#269797: examples/LDAP/samba.schema.gz - duplicate attributeType | #9 |
severity 269797 normal
thanks
I am sorry, but I disagree with the change in severity. The schema is
shipped as an example (in the samba-doc package) and therefore is not
installed in /etc automatically. It takes the same effort to fetch a
fresh copy from samba.org than to use the one included in the samba-doc
package.
Having said this, I am preparing a new upload which should be installed
in tomorrow's dinstall run.
Eloy.-
On Tue, Sep 07, 2004 at 03:58:59PM +0200, Bastian Blank wrote:
> severity 269797 grave
> thanks
>
> Samba 3.0.6 needs this new defined attribute type sambaPasswordHi
> for password changes and refuses to change passwords if not available.
> The schema file which contains this type is broken.
>
> Not being able to change passwords is a large security problem.
>
> Bastian
>
> --
> Conquest is easy. Control is not.
> -- Kirk, "Mirror, Mirror", stardate unknown
In Debian Bug tracker #269797, Eloy A. Paris (peloy) wrote : Bug#269797: fixed in samba 3.0.6-4 | #10 |
Source: samba
Source-Version: 3.0.6-4
We believe that the bug you reported is fixed in the latest version of
samba, which is due to be installed in the Debian FTP archive:
libpam-
to pool/main/
libsmbclient-
to pool/main/
libsmbclient_
to pool/main/
python2.
to pool/main/
samba-common_
to pool/main/
samba-doc_
to pool/main/
samba_3.
to pool/main/
samba_3.0.6-4.dsc
to pool/main/
samba_3.
to pool/main/
smbclient_
to pool/main/
smbfs_3.
to pool/main/
swat_3.
to pool/main/
winbind_
to pool/main/
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to <email address hidden>,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Eloy A. Paris <email address hidden> (supplier of updated samba package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing <email address hidden>)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Tue, 7 Sep 2004 15:28:42 -0400
Source: samba
Binary: samba-doc libsmbclient libpam-smbpass swat winbind smbclient samba samba-common libsmbclient-dev python2.3-samba smbfs
Architecture: source i386 all
Version: 3.0.6-4
Distribution: unstable
Urgency: low
Maintainer: Eloy A. Paris <email address hidden>
Changed-By: Eloy A. Paris <email address hidden>
Description:
libpam-smbpass - pluggable authentication module for SMB password database
libsmbclient - shared library that allows applications to talk to SMB servers
libsmbclient-dev - libsmbclient static libraries and headers
python2.3-samba - Python bindings that allow access to various aspects of Samba
samba - a LanManager-like file and printer server for Unix
samba-common - Samba common files used by both the server and the client
samba-doc - Samba documentation
smbclient - a LanManager-like simple client for Unix
smbfs - mount and umount commands for the smbfs (for kernels >= than 2.2.
swat - Samba Web Administration Tool
winbind - service to resolve user and group information from Windows NT ser
Closes: 269797
Changes:
samba (3.0.6-4) unstable; urgency=low
.
* Update LDAP schema (closes: #269797).
* Applied a couple of upstream fixes that will be present in Samba 3.0.7.
Files:
aa3fe3dba007ff
c09b6df5ef2e94
Debian Bug Importer (debzilla) wrote : | #11 |
Message-ID: <email address hidden>
Date: Tue, 7 Sep 2004 15:34:28 -0400
From: "Eloy A. Paris" <email address hidden>
To: Bastian Blank <email address hidden>, <email address hidden>
Cc: <email address hidden>
Subject: Re: Bug#269797: examples/
severity 269797 normal
thanks
I am sorry, but I disagree with the change in severity. The schema is
shipped as an example (in the samba-doc package) and therefore is not
installed in /etc automatically. It takes the same effort to fetch a
fresh copy from samba.org than to use the one included in the samba-doc
package.
Having said this, I am preparing a new upload which should be installed
in tomorrow's dinstall run.
Eloy.-
On Tue, Sep 07, 2004 at 03:58:59PM +0200, Bastian Blank wrote:
> severity 269797 grave
> thanks
>
> Samba 3.0.6 needs this new defined attribute type sambaPasswordHi
> for password changes and refuses to change passwords if not available.
> The schema file which contains this type is broken.
>
> Not being able to change passwords is a large security problem.
>
> Bastian
>
> --
> Conquest is easy. Control is not.
> -- Kirk, "Mirror, Mirror", stardate unknown
Matt Zimmerman (mdz) wrote : | #12 |
Documentation/
Debian Bug Importer (debzilla) wrote : | #13 |
Message-Id: <email address hidden>
Date: Tue, 07 Sep 2004 16:17:36 -0400
From: <email address hidden> (Eloy A. Paris)
To: <email address hidden>
Subject: Bug#269797: fixed in samba 3.0.6-4
Source: samba
Source-Version: 3.0.6-4
We believe that the bug you reported is fixed in the latest version of
samba, which is due to be installed in the Debian FTP archive:
libpam-
to pool/main/
libsmbclient-
to pool/main/
libsmbclient_
to pool/main/
python2.
to pool/main/
samba-common_
to pool/main/
samba-doc_
to pool/main/
samba_3.
to pool/main/
samba_3.0.6-4.dsc
to pool/main/
samba_3.
to pool/main/
smbclient_
to pool/main/
smbfs_3.
to pool/main/
swat_3.
to pool/main/
winbind_
to pool/main/
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to <email address hidden>,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Eloy A. Paris <email address hidden> (supplier of updated samba package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing <email address hidden>)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.7
Date: Tue, 7 Sep 2004 15:28:42 -0400
Source: samba
Binary: samba-doc libsmbclient libpam-smbpass swat winbind smbclient samba samba-common libsmbclient-dev python2.3-samba smbfs
Architecture: source i386 all
Version: 3.0.6-4
Distribution: unstable
Urgency: low
Maintainer: Eloy A. Paris <email address hidden>
Changed-By: Eloy A. Paris <email address hidden>
Description:
libpam-smbpass - pluggable authentication module for SMB password database
libsmbclient - shared library that allows applications to talk to SMB servers
libsmbclient-dev - libsmbclient static libraries and headers
python2.3-samba - Python bindings that allow access to various aspects of Samba
samba - a LanManager-like file and printer server for Unix
samba-common - Samba common files used by both the server and the client
samba-doc - Samba documentation
smbclient - a LanManager-like simple client for Unix
smbfs - mount and umount commands for the smbfs (for kernels >= than 2.2.
swat - Samba Web Administration Tool
winbind - service to resolve user and group information from Windows NT ser
Closes: 269797
Changes:
samba (3.0.6-4) unstable; urgency=low
.
* Update LDAP schema (cl...
Daniel Stone (daniels) wrote : | #14 |
Fixed in 3.0.6-1ubuntu2.
Changed in samba: | |
status: | Unknown → Fix Released |
# 1 definition found
#
# From WordNet (r) 2.0 [wn]:
#
# unrelated
# adj 1: not connected or associated [ant: {related}]
# 2: not connected by kinship [ant: {related}]
#
severity 269767 grave
clone 269797 -1
retitle -1 libcapi20-3: devel files in a library package
severity -1 serious
thanks
The libcapi20-3 package contains libcapi20.so.2, not libcapi20.so.3 as
its name suggests. This looks very much like there have been
incompatible ABI changes without an soname change -- but with a package
name change, which is quite peculiar!. While the package name change
ensures that other packaged software using this library will function
correctly, library maintainers are expected to provide at least minimal
support for local third-party software by not breaking the
one-soname-one-ABI rule.
This package also contains static libs, libtool .la files, and header
files, all of which belong in a -dev package per policy. You have added
a Conflicts: against older versions of the library to ensure that dpkg
doesn't complain about this state of affairs, but it's nevertheless
contrary to the fundamental goals of providing shared library packages.
Since the packages depending on libcapi20-2 in testing also appear to be
in rather sorry shape right now, including one must-go package that
depends on libtiff3g, I'm planning to remove all of these packages from
testing pending resolution of the isdnutils bugs.
Thanks,
--
Steve Langasek
postmodern programmer