Go to file
2012-08-01 10:21:44 +02:00
.gitignore
ldap.conf
libexec-check-config.sh
libexec-convert-config.sh
libexec-create-certdb.sh
libexec-functions
libexec-generate-server-cert.sh
libexec-upgrade-db.sh
openldap-ai-addrconfig.patch fix: querying for IPv6 DNS records when IPv6 is disabled on the host 2012-07-19 11:00:43 +02:00
openldap-autoconf-pkgconfig-nss.patch clean the package build process 2012-07-18 19:02:28 +02:00
openldap-constraint-count.patch
openldap-cve-nss-cipher-suite-ignored.patch CVE-2012-2668: cipher suite selection by name can be ignored 2012-06-27 13:55:02 +02:00
openldap-dns-priority.patch
openldap-evolution-ntlm.patch
openldap-fedora-systemd.patch
openldap-ldaprc-currentdir.patch
openldap-man-sasl-nocanon.patch
openldap-manpages.patch
openldap-nss-allow-ca-dbdir-pemfile.patch
openldap-nss-clean-memory-for-token-pin.patch fix: reading pin from file can make all TLS connections hang 2012-06-27 13:48:40 +02:00
openldap-nss-default-cipher-suite-always-selected.patch fix: default cipher suite is always selected 2012-06-27 14:10:28 +02:00
openldap-nss-dont-overwrite-verify-cert-error.patch
openldap-nss-ignore-untrusted-issuer-server-cert.patch fix: slapd refuses to set up TLS with self-signed PEM certificate 2012-07-21 17:59:04 +02:00
openldap-nss-multiple-tls-contexts.patch fix: less influence between individual TLS contexts 2012-06-27 14:40:59 +02:00
openldap-reentrant-gethostby.patch
openldap-security-pie.patch
openldap-smbk5pwd-overlay.patch fix: smbk5pwd module computes invalid LM hashes 2012-07-19 14:27:10 +02:00
openldap-sql-linking.patch
openldap-syncrepl-unset-tls-options.patch
openldap-tls-unbind-shutdown-order.patch
openldap-userconfig-setgid.patch
openldap.spec use tabs consistently 2012-08-01 10:21:44 +02:00
README.evolution
slapd.ldif
slapd.service fix: slapd fails to start on reboot 2012-06-27 14:05:10 +02:00
slapd.sysconfig
slapd.tmpfiles
sources

These files are here specifically for use in building the evolution-connector
package, and should not be used for any other purpose.

In order to authenticate to older servers, an LDAP client must perform an
ntlm_bind operation instead of a simple or SASL bind.  The ntlm_bind is not the
same thing as performing SASL authentication using NTLM as the mechanism, which
wouldn't require any patching.  Newer servers properly support DIGEST-MD5, so
this requirement only applies to clients which want to authenticate to older
servers, and this requirement will hopefully go away at some point.

Because the changes involved both modify the libldap ABI and add
non-standardized messages to the protocol, changed libraries are built
statically and stashed in a directory where they will not be found by a
compiler using the default search paths.

The openldap-devel package provides "openldap-evolution-devel" if it includes a
patched version of these libraries in such a directory.  Packages which depend
on these libraries should BuildRequire this virtual provision so that they
don't fail to compile or get miscompiled if the libraries are not present.

If/when the evolution-connector package stops requiring these changes, the
changed libraries will simply disappear.