]> git.proxmox.com Git - pve-access-control.git/blame - debian/changelog
bump version to 7.1-7
[pve-access-control.git] / debian / changelog
CommitLineData
eed46286
TL
1libpve-access-control (7.1-7) bullseye; urgency=medium
2
3 * userid-group check: distinguish create and update
4
5 * api: get user: declare token schema
6
7 -- Proxmox Support Team <support@proxmox.com> Mon, 21 Mar 2022 16:15:23 +0100
8
cd78b295
FG
9libpve-access-control (7.1-6) bullseye; urgency=medium
10
11 * fix #3768: warn on bad u2f or webauthn settings
12
13 * tfa: when modifying others, verify the current user's password
14
15 * tfa list: account for admin permissions
16
17 * fix realm sync permissions
18
19 * fix token permission display bug
20
21 * include SDN permissions in permission tree
22
23 -- Proxmox Support Team <support@proxmox.com> Fri, 21 Jan 2022 14:20:42 +0100
24
118088d8
TL
25libpve-access-control (7.1-5) bullseye; urgency=medium
26
27 * openid: fix username-claim fallback
28
29 -- Proxmox Support Team <support@proxmox.com> Thu, 25 Nov 2021 07:57:38 +0100
30
ebb14277
WB
31libpve-access-control (7.1-4) bullseye; urgency=medium
32
33 * set current origin in the webauthn config if no fixed origin was
34 configured, to support webauthn via subdomains
35
36 -- Proxmox Support Team <support@proxmox.com> Mon, 22 Nov 2021 14:04:06 +0100
37
44a55ff7
TL
38libpve-access-control (7.1-3) bullseye; urgency=medium
39
40 * openid: allow arbitrary username-claims
41
42 * openid: support configuring the prompt, scopes and ACR values
43
44 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Nov 2021 08:11:52 +0100
45
6f643e79
TL
46libpve-access-control (7.1-2) bullseye; urgency=medium
47
48 * catch incompatible tfa entries with a nice error
49
50 -- Proxmox Support Team <support@proxmox.com> Wed, 17 Nov 2021 13:44:45 +0100
51
92bca71e
TL
52libpve-access-control (7.1-1) bullseye; urgency=medium
53
54 * tfa: map HTTP 404 error in get_tfa_entry correctly
55
56 -- Proxmox Support Team <support@proxmox.com> Mon, 15 Nov 2021 15:33:22 +0100
57
1c9b6501
TL
58libpve-access-control (7.0-7) bullseye; urgency=medium
59
60 * fix #3513: pass configured proxy to OpenID
61
62 * use rust based parser for TFA config
63
64 * use PBS-like auth api call flow,
65
66 * merge old user.cfg keys to tfa config when adding entries
67
68 * implement version checks for new tfa config writer to ensure all
69 cluster nodes are ready to avoid login issues
70
71 * tickets: add tunnel ticket
72
73 -- Proxmox Support Team <support@proxmox.com> Thu, 11 Nov 2021 18:17:49 +0100
74
cd46b379
TL
75libpve-access-control (7.0-6) bullseye; urgency=medium
76
77 * fix regression in user deletion when realm does not enforce TFA
78
79 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Oct 2021 12:28:52 +0200
80
52da88a8
TL
81libpve-access-control (7.0-5) bullseye; urgency=medium
82
83 * acl: check path: add /sdn/vnets/* path
84
85 * fix #2302: allow deletion of users when realm enforces TFA
86
87 * api: delete user: disable user first to avoid surprise on error during the
88 various cleanup action required for user deletion (e.g., TFA, ACL, group)
89
90 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Sep 2021 15:50:47 +0200
91
543d646c
TL
92libpve-access-control (7.0-4) bullseye; urgency=medium
93
94 * realm: add OpenID configuration
95
96 * api: implement OpenID related endpoints
97
98 * implement opt-in OpenID autocreate user feature
99
100 * api: user: add 'realm-type' to user list response
101
102 -- Proxmox Support Team <support@proxmox.com> Fri, 02 Jul 2021 13:45:46 +0200
103
7a4c4fd8
TL
104libpve-access-control (7.0-3) bullseye; urgency=medium
105
106 * api: acl: add missing `/access/realm/<realm>`, `/access/group/<group>` and
107 `/sdn/zones/<zone>` to allowed ACL paths
108
109 -- Proxmox Support Team <support@proxmox.com> Mon, 21 Jun 2021 10:31:19 +0200
110
0902a936
FG
111libpve-access-control (7.0-2) bullseye; urgency=medium
112
113 * fix #3402: add Pool.Audit privilege - custom roles containing
114 Pool.Allocate must be updated to include the new privilege.
115
116 -- Proxmox Support Team <support@proxmox.com> Tue, 1 Jun 2021 11:28:38 +0200
117
67febb69
TL
118libpve-access-control (7.0-1) bullseye; urgency=medium
119
120 * re-build for Debian 11 Bullseye based releases
121
122 -- Proxmox Support Team <support@proxmox.com> Sun, 09 May 2021 18:18:23 +0200
123
2942ba41
TL
124libpve-access-control (6.4-1) pve; urgency=medium
125
126 * fix #1670: change PAM service name to project specific name
127
128 * fix #1500: permission path syntax check for access control
129
130 * pveum: add resource pool CLI commands
131
132 -- Proxmox Support Team <support@proxmox.com> Sat, 24 Apr 2021 19:48:21 +0200
133
54d312f3
TL
134libpve-access-control (6.1-3) pve; urgency=medium
135
136 * partially fix #2825: authkey: rotate if it was generated in the
137 future
138
139 * fix #2947: add an option to LDAP or AD realm to switch user lookup to case
140 insensitive
141
142 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Sep 2020 08:54:13 +0200
143
6a9be12f
TL
144libpve-access-control (6.1-2) pve; urgency=medium
145
146 * also check SDN permission path when computing coarse permissions heuristic
147 for UIs
148
149 * add SDN Permissions.Modify
150
151 * add VM.Config.Cloudinit
152
153 -- Proxmox Support Team <support@proxmox.com> Tue, 30 Jun 2020 13:06:56 +0200
154
e6624f50
TL
155libpve-access-control (6.1-1) pve; urgency=medium
156
157 * pveum: add tfa delete subcommand for deleting user-TFA
158
159 * LDAP: don't complain about missing credentials on realm removal
160
161 * LDAP: skip anonymous bind when client certificate and key is configured
162
163 -- Proxmox Support Team <support@proxmox.com> Fri, 08 May 2020 17:47:41 +0200
164
8f4a522f
TL
165libpve-access-control (6.0-7) pve; urgency=medium
166
167 * fix #2575: die when trying to edit built-in roles
168
169 * add realm sub commands to pveum CLI tool
170
171 * api: domains: add user group sync API enpoint
172
173 * allow one to sync and import users and groups from LDAP/AD based realms
174
175 * realm: add default-sync-options to config for more convenient sync configuration
176
177 * api: token create: return also full token id for convenience
178
179 -- Proxmox Support Team <support@proxmox.com> Sat, 25 Apr 2020 19:35:17 +0200
180
23059f35
TL
181libpve-access-control (6.0-6) pve; urgency=medium
182
183 * API: add group members to group index
184
185 * implement API token support and management
186
187 * pveum: add 'pveum user token add/update/remove/list'
188
189 * pveum: add permissions sub-commands
190
191 * API: add 'permissions' API endpoint
192
193 * user.cfg: skip inexisting roles when parsing ACLs
194
195 -- Proxmox Support Team <support@proxmox.com> Wed, 29 Jan 2020 10:17:27 +0100
196
3dd692e9
TL
197libpve-access-control (6.0-5) pve; urgency=medium
198
199 * pveum: add list command for users, groups, ACLs and roles
200
201 * add initial permissions for experimental SDN integration
202
203 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Nov 2019 17:56:37 +0100
204
4ef92d0d
FG
205libpve-access-control (6.0-4) pve; urgency=medium
206
207 * ticket: use clinfo to get cluster name
208
209 * ldaps: add sslversion configuration property to support TLS 1.1 to 1.3 as
210 SSL version
211
212 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2019 11:55:11 +0100
213
6e5bbca4
TL
214libpve-access-control (6.0-3) pve; urgency=medium
215
216 * fix #2433: increase possible TFA secret length
217
218 * parse user configuration: correctly parse group names in ACLs, for users
219 which begin their name with an @
220
221 * sort user.cfg entries alphabetically
222
223 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Oct 2019 08:52:23 +0100
224
e073493c
TL
225libpve-access-control (6.0-2) pve; urgency=medium
226
227 * improve CSRF verification compatibility with newer PVE
228
229 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Jun 2019 20:24:35 +0200
230
a237dc2e
TL
231libpve-access-control (6.0-1) pve; urgency=medium
232
233 * ticket: properly verify exactly 5 minute old tickets
234
235 * use hmac_sha256 instead of sha1 for CSRF token generation
236
237 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 18:14:45 +0200
238
f1531f22
TL
239libpve-access-control (6.0-0+1) pve; urgency=medium
240
241 * bump for Debian buster
242
243 * fix #2079: add periodic auth key rotation
244
245 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 21:31:15 +0200
246
ef761f51
TL
247libpve-access-control (5.1-10) unstable; urgency=medium
248
249 * add /access/user/{id}/tfa api call to get tfa types
250
251 -- Proxmox Support Team <support@proxmox.com> Wed, 15 May 2019 16:21:10 +0200
252
860ddcba
TL
253libpve-access-control (5.1-9) unstable; urgency=medium
254
255 * store the tfa type in user.cfg allowing to get it without proxying the call
256 to a higher priviledged daemon.
257
258 * tfa: realm required TFA should lock out users without TFA configured, as it
259 was done before Proxmox VE 5.4
260
261 -- Proxmox Support Team <support@proxmox.com> Tue, 30 Apr 2019 14:01:00 +0000
262
9fbad012
TL
263libpve-access-control (5.1-8) unstable; urgency=medium
264
265 * U2F: ensure we save correct public key on registration
266
267 -- Proxmox Support Team <support@proxmox.com> Tue, 09 Apr 2019 12:47:12 +0200
268
4473c96c
TL
269libpve-access-control (5.1-7) unstable; urgency=medium
270
271 * verify_ticket: allow general non-challenge tfa to be run as two step
272 call
273
274 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Apr 2019 16:56:14 +0200
275
a270d4e1
TL
276libpve-access-control (5.1-6) unstable; urgency=medium
277
278 * more general 2FA configuration via priv/tfa.cfg
279
280 * add u2f api endpoints
281
282 * delete TFA entries when deleting a user
283
284 * allow users to change their TOTP settings
285
286 -- Proxmox Support Team <support@proxmox.com> Wed, 03 Apr 2019 13:40:26 +0200
287
374647e8
TL
288libpve-access-control (5.1-5) unstable; urgency=medium
289
290 * fix vnc ticket verification without authkey lifetime
291
292 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Mar 2019 10:43:17 +0100
293
7fb70c94
TL
294libpve-access-control (5.1-4) unstable; urgency=medium
295
296 * fix #1891: Add zsh command completion for pveum
297
298 * ground work to fix #2079: add periodic auth key rotation. Not yet enabled
299 to avoid issues on upgrade, will be enabled with 6.0
300
301 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Mar 2019 09:12:05 +0100
302
6e010cde
TL
303libpve-access-control (5.1-3) unstable; urgency=medium
304
305 * api/ticket: move getting cluster name into an eval
306
307 -- Proxmox Support Team <support@proxmox.com> Thu, 29 Nov 2018 12:59:36 +0100
308
f5a9380a
TL
309libpve-access-control (5.1-2) unstable; urgency=medium
310
311 * fix #1998: correct return properties for read_role
312
313 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:22:40 +0100
314
b54b7474
TL
315libpve-access-control (5.1-1) unstable; urgency=medium
316
317 * pveum: introduce sub-commands
318
319 * register userid with completion
320
321 * fix #233: return cluster name on successful login
322
323 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Nov 2018 09:34:47 +0100
324
52192dd4
WB
325libpve-access-control (5.0-8) unstable; urgency=medium
326
327 * fix #1612: ldap: make 2nd server work with bind domains again
328
329 * fix an error message where passing a bad pool id to an API function would
330 make it complain about a wrong group name instead
331
332 * fix the API-returned permission list so that the GUI knows to show the
333 'Permissions' tab for a storage to an administrator apart from root@pam
334
335 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Jan 2018 13:34:50 +0100
336
3dadf8cf
FG
337libpve-access-control (5.0-7) unstable; urgency=medium
338
339 * VM.Snapshot.Rollback privilege added
340
341 * api: check for special roles before locking the usercfg
342
343 * fix #1501: pveum: die when deleting special role
344
345 * API/ticket: rework coarse grained permission computation
346
347 -- Proxmox Support Team <support@proxmox.com> Thu, 5 Oct 2017 11:27:48 +0200
348
ec4141f4
WB
349libpve-access-control (5.0-6) unstable; urgency=medium
350
351 * Close #1470: Add server ceritifcate verification for AD and LDAP via the
352 'verify' option. For compatibility reasons this defaults to off for now,
353 but that might change with future updates.
354
355 * AD, LDAP: Add ability to specify a CA path or file, and a client
356 certificate via the 'capath', 'cert' and 'certkey' options.
357
358 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Aug 2017 11:56:38 +0200
359
63134bd4
DM
360libpve-access-control (5.0-5) unstable; urgency=medium
361
362 * change from dpkg-deb to dpkg-buildpackage
363
364 -- Proxmox Support Team <support@proxmox.com> Thu, 22 Jun 2017 09:12:37 +0200
365
868fb1ea
DM
366libpve-access-control (5.0-4) unstable; urgency=medium
367
368 * PVE/CLI/pveum.pm: call setup_default_cli_env()
369
370 * PVE/Auth/PVE.pm: encode uft8 password before calling crypt
371
372 * check_api2_permissions: avoid warning about uninitialized value
373
374 -- Proxmox Support Team <support@proxmox.com> Tue, 02 May 2017 11:58:15 +0200
375
63358f40
DM
376libpve-access-control (5.0-3) unstable; urgency=medium
377
378 * use new PVE::OTP class from pve-common
379
380 * use new PVE::Tools::encrypt_pw from pve-common
381
382 -- Proxmox Support Team <support@proxmox.com> Thu, 30 Mar 2017 17:45:55 +0200
383
05fd50af
DM
384libpve-access-control (5.0-2) unstable; urgency=medium
385
386 * encrypt_pw: avoid '+' for crypt salt
387
388 -- Proxmox Support Team <support@proxmox.com> Thu, 30 Mar 2017 08:54:10 +0200
389
0835385b
FG
390libpve-access-control (5.0-1) unstable; urgency=medium
391
392 * rebuild for PVE 5.0
393
394 -- Proxmox Support Team <support@proxmox.com> Mon, 6 Mar 2017 13:42:01 +0100
395
730f8863
DM
396libpve-access-control (4.0-23) unstable; urgency=medium
397
398 * use new PVE::Ticket class
399
400 -- Proxmox Support Team <support@proxmox.com> Thu, 19 Jan 2017 13:42:06 +0100
401
1f1c4593
DM
402libpve-access-control (4.0-22) unstable; urgency=medium
403
404 * RPCEnvironment: removed check_volume_access() to avoid cyclic dependency
405 (moved to PVE::Storage)
406
407 * PVE::PCEnvironment: use new PVE::RESTEnvironment as base class
408
409 -- Proxmox Support Team <support@proxmox.com> Thu, 19 Jan 2017 09:12:04 +0100
410
f9105063
DM
411libpve-access-control (4.0-21) unstable; urgency=medium
412
413 * setup_default_cli_env: expect $class as first parameter
414
415 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jan 2017 13:54:27 +0100
416
9595066e
DM
417libpve-access-control (4.0-20) unstable; urgency=medium
418
419 * PVE/RPCEnvironment.pm: new function setup_default_cli_env
420
421 * PVE/API2/Domains.pm: fix property description
422
423 * use new repoman for upload target
424
425 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Jan 2017 12:13:26 +0100
426
2af5a793
DM
427libpve-access-control (4.0-19) unstable; urgency=medium
428
429 * Close #833: ldap: non-anonymous bind support
430
431 * don't import 'RFC' from MIME::Base32
432
433 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Aug 2016 13:09:08 +0200
434
5d87bb77
WB
435libpve-access-control (4.0-18) unstable; urgency=medium
436
437 * fix #1062: recognize base32 otp keys again
438
439 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Jul 2016 08:43:18 +0200
440
28ddf48b
WB
441libpve-access-control (4.0-17) unstable; urgency=medium
442
443 * drop oathtool and libdigest-hmac-perl dependencies
444
445 -- Proxmox Support Team <support@proxmox.com> Mon, 11 Jul 2016 12:03:22 +0200
446
15cebb28
DM
447libpve-access-control (4.0-16) unstable; urgency=medium
448
449 * use pve-doc-generator to generate man pages
450
451 -- Proxmox Support Team <support@proxmox.com> Fri, 08 Apr 2016 07:06:05 +0200
452
678df887
DM
453libpve-access-control (4.0-15) unstable; urgency=medium
454
455 * Fix uninitialized warning when shadow.cfg does not exist
456
457 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:10:57 +0200
458
cca9761a
DM
459libpve-access-control (4.0-14) unstable; urgency=medium
460
461 * Add is_worker to RPCEnvironment
462
463 -- Proxmox Support Team <support@proxmox.com> Tue, 15 Mar 2016 16:47:34 +0100
464
8643c99d
DM
465libpve-access-control (4.0-13) unstable; urgency=medium
466
467 * fix #916: allow HTTPS to access custom yubico url
468
469 -- Proxmox Support Team <support@proxmox.com> Mon, 14 Mar 2016 11:39:23 +0100
470
ae2a6bf9
DM
471libpve-access-control (4.0-12) unstable; urgency=medium
472
473 * Catch certificate errors instead of segfaulting
474
475 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Mar 2016 14:41:01 +0100
476
4836db5f
DM
477libpve-access-control (4.0-11) unstable; urgency=medium
478
479 * Fix #861: use safer sprintf formatting
480
481 -- Proxmox Support Team <support@proxmox.com> Fri, 08 Jan 2016 12:52:39 +0100
482
ccbe23dc
DM
483libpve-access-control (4.0-10) unstable; urgency=medium
484
485 * Auth::LDAP, Auth::AD: ipv6 support
486
487 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Dec 2015 12:09:32 +0100
488
90399ca4
DM
489libpve-access-control (4.0-9) unstable; urgency=medium
490
491 * pveum: implement bash completion
492
493 -- Proxmox Support Team <support@proxmox.com> Thu, 01 Oct 2015 17:22:52 +0200
494
364ffc13
DM
495libpve-access-control (4.0-8) unstable; urgency=medium
496
497 * remove_storage_access: cleanup of access permissions for removed storage
498
499 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:39:15 +0200
500
7c26cb4a
DM
501libpve-access-control (4.0-7) unstable; urgency=medium
502
503 * new helper to remove access permissions for removed VMs
504
505 -- Proxmox Support Team <support@proxmox.com> Fri, 14 Aug 2015 07:57:02 +0200
506
296afbd1
DM
507libpve-access-control (4.0-6) unstable; urgency=medium
508
509 * improve parse_user_config, parse_shadow_config
510
511 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:14:33 +0200
512
7d2df2ef
DM
513libpve-access-control (4.0-5) unstable; urgency=medium
514
515 * pveum: check for $cmd being defined
516
517 -- Proxmox Support Team <support@proxmox.com> Wed, 10 Jun 2015 10:40:15 +0200
518
98a34e3f
DM
519libpve-access-control (4.0-4) unstable; urgency=medium
520
521 * use activate-noawait triggers
522
523 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:25:31 +0200
524
15462727
DM
525libpve-access-control (4.0-3) unstable; urgency=medium
526
527 * IPv6 fixes
528
529 * non-root buildfix
530
531 -- Proxmox Support Team <support@proxmox.com> Wed, 27 May 2015 11:15:44 +0200
532
bbf4cc9a
DM
533libpve-access-control (4.0-2) unstable; urgency=medium
534
535 * trigger pve-api-updates event
536
537 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:06:38 +0200
538
dfbcf6d3
DM
539libpve-access-control (4.0-1) unstable; urgency=medium
540
541 * bump version for Debian Jessie
542
543 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Feb 2015 11:22:01 +0100
544
94971b3a
DM
545libpve-access-control (3.0-16) unstable; urgency=low
546
547 * root@pam can now be disabled in GUI.
548
549 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Jan 2015 06:20:22 +0100
550
7b17c7cb
DM
551libpve-access-control (3.0-15) unstable; urgency=low
552
553 * oath: add 'step' and 'digits' option
554
555 -- Proxmox Support Team <support@proxmox.com> Wed, 23 Jul 2014 06:59:52 +0200
556
1abc2c0a
DM
557libpve-access-control (3.0-14) unstable; urgency=low
558
559 * add oath two factor auth
560
561 * add oathkeygen binary to generate keys for oath
562
563 * add yubico two factor auth
564
565 * dedend on oathtool
566
567 * depend on libmime-base32-perl
30be0de9
DM
568
569 * allow to write builtin auth domains config (comment/tfa/default)
1abc2c0a
DM
570
571 -- Proxmox Support Team <support@proxmox.com> Thu, 17 Jul 2014 13:09:56 +0200
572
298450ab
DM
573libpve-access-control (3.0-13) unstable; urgency=low
574
575 * use correct connection string for AD auth
576
577 -- Proxmox Support Team <support@proxmox.com> Thu, 22 May 2014 07:16:09 +0200
578
396034e4
DM
579libpve-access-control (3.0-12) unstable; urgency=low
580
581 * add dummy API for GET /access/ticket (useful to generate login pages)
582
583 -- Proxmox Support Team <support@proxmox.com> Wed, 30 Apr 2014 14:47:56 +0200
584
26361123
DM
585libpve-access-control (3.0-11) unstable; urgency=low
586
587 * Sets common hot keys for spice client
588
589 -- Proxmox Support Team <support@proxmox.com> Fri, 31 Jan 2014 10:24:28 +0100
590
3643383d
DM
591libpve-access-control (3.0-10) unstable; urgency=low
592
593 * implement helper to generate SPICE remote-viewer configuration
594
595 * depend on libnet-ssleay-perl
596
597 -- Proxmox Support Team <support@proxmox.com> Tue, 10 Dec 2013 10:45:08 +0100
598
0baedcf7
DM
599libpve-access-control (3.0-9) unstable; urgency=low
600
601 * prevent user enumeration attacks
e4f8fc2e
DM
602
603 * allow dots in access paths
0baedcf7
DM
604
605 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2013 09:06:38 +0100
606
d4b63eae
DM
607libpve-access-control (3.0-8) unstable; urgency=low
608
609 * spice: use lowercase hostname in ticktet signature
610
611 -- Proxmox Support Team <support@proxmox.com> Mon, 28 Oct 2013 08:11:57 +0100
612
49594944
DM
613libpve-access-control (3.0-7) unstable; urgency=low
614
615 * check_volume_access : use parse_volname instead of path, and remove
616 path related code.
7c410d63
DM
617
618 * use warnings instead of global -w flag.
49594944
DM
619
620 -- Proxmox Support Team <support@proxmox.com> Tue, 01 Oct 2013 12:35:53 +0200
621
fe7de5d0
DM
622libpve-access-control (3.0-6) unstable; urgency=low
623
624 * use shorter spiceproxy tickets
625
626 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Jul 2013 12:39:09 +0200
627
4cdd9507
DM
628libpve-access-control (3.0-5) unstable; urgency=low
629
630 * add code to generate tickets for SPICE
631
632 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Jun 2013 13:08:32 +0200
633
677f9ab0
DM
634libpve-access-control (3.0-4) unstable; urgency=low
635
636 * moved add_vm_to_pool/remove_vm_from_pool from qemu-server
637
638 -- Proxmox Support Team <support@proxmox.com> Tue, 14 May 2013 11:56:54 +0200
639
139a8ecf
DM
640libpve-access-control (3.0-3) unstable; urgency=low
641
7b395f99 642 * Add new role PVETemplateUser (and VM.Clone priviledge)
139a8ecf
DM
643
644 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Apr 2013 11:42:15 +0200
645
b78ce7c2
DM
646libpve-access-control (3.0-2) unstable; urgency=low
647
648 * remove CGI.pm related code (pveproxy does not need that)
649
650 -- Proxmox Support Team <support@proxmox.com> Mon, 15 Apr 2013 12:34:23 +0200
651
786820f9
DM
652libpve-access-control (3.0-1) unstable; urgency=low
653
654 * bump version for wheezy release
655
656 -- Proxmox Support Team <support@proxmox.com> Fri, 15 Mar 2013 08:07:06 +0100
657
e5ae5487
DM
658libpve-access-control (1.0-26) unstable; urgency=low
659
660 * check_volume_access: fix access permissions for backup files
661
662 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Feb 2013 10:00:14 +0100
663
e3e6510c
DM
664libpve-access-control (1.0-25) unstable; urgency=low
665
666 * add VM.Snapshot permission
667
668 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Sep 2012 09:23:32 +0200
669
1e15ebe7
DM
670libpve-access-control (1.0-24) unstable; urgency=low
671
672 * untaint path (allow root to restore arbitrary paths)
673
674 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2012 13:06:34 +0200
675
437be042
DM
676libpve-access-control (1.0-23) unstable; urgency=low
677
678 * correctly compute GUI capabilities (consider pools)
679
680 -- Proxmox Support Team <support@proxmox.com> Wed, 30 May 2012 08:47:23 +0200
681
5bb4e06a
DM
682libpve-access-control (1.0-22) unstable; urgency=low
683
684 * new plugin architecture for Auth modules, minor API change for Auth
685 domains (new 'delete' parameter)
686
687 -- Proxmox Support Team <support@proxmox.com> Wed, 16 May 2012 07:21:44 +0200
688
3030a176
DM
689libpve-access-control (1.0-21) unstable; urgency=low
690
691 * do not allow user names including slash
692
693 -- Proxmox Support Team <support@proxmox.com> Tue, 24 Apr 2012 10:07:47 +0200
694
695libpve-access-control (1.0-20) unstable; urgency=low
696
697 * add ability to fork cli workers in background
698
699 -- Proxmox Support Team <support@proxmox.com> Wed, 18 Apr 2012 08:28:20 +0200
700
dd2cfee0
DM
701libpve-access-control (1.0-19) unstable; urgency=low
702
703 * return set of privileges on login - can be used to adopt GUI
704
705 -- Proxmox Support Team <support@proxmox.com> Tue, 17 Apr 2012 10:25:10 +0200
706
1cf154b7
DM
707libpve-access-control (1.0-18) unstable; urgency=low
708
533219a1
DM
709 * fix bug #151: corretly parse username inside ticket
710
711 * fix bug #152: allow user to change his own password
1cf154b7
DM
712
713 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2012 09:40:15 +0200
714
2de14407
DM
715libpve-access-control (1.0-17) unstable; urgency=low
716
717 * set propagate flag by default
718
719 -- Proxmox Support Team <support@proxmox.com> Thu, 01 Mar 2012 12:40:19 +0100
720
bdc61d7a
DM
721libpve-access-control (1.0-16) unstable; urgency=low
722
723 * add 'pveum passwd' method
724
725 -- Proxmox Support Team <support@proxmox.com> Thu, 23 Feb 2012 12:05:25 +0100
726
cc7bdf33
DM
727libpve-access-control (1.0-15) unstable; urgency=low
728
729 * Add VM.Config.CDROM privilege to PVEVMUser rule
730
731 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 11:44:23 +0100
732
a69bbe2e
DM
733libpve-access-control (1.0-14) unstable; urgency=low
734
735 * fix buf in userid-param permission check
736
737 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 10:52:35 +0100
738
d9483d94
DM
739libpve-access-control (1.0-13) unstable; urgency=low
740
741 * allow more characters in ldap base_dn attribute
742
743 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 06:17:02 +0100
744
84619607
DM
745libpve-access-control (1.0-12) unstable; urgency=low
746
747 * allow more characters with realm IDs
748
749 -- Proxmox Support Team <support@proxmox.com> Mon, 20 Feb 2012 08:50:33 +0100
750
09d27058
DM
751libpve-access-control (1.0-11) unstable; urgency=low
752
753 * fix bug in exec_api2_perm_check
754
755 -- Proxmox Support Team <support@proxmox.com> Wed, 15 Feb 2012 07:06:30 +0100
756
7a4c849e
DM
757libpve-access-control (1.0-10) unstable; urgency=low
758
759 * fix ACL group name parser
760
761 * changed 'pveum aclmod' command line arguments
762
763 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Feb 2012 12:08:02 +0100
764
3eac4e35
DM
765libpve-access-control (1.0-9) unstable; urgency=low
766
767 * fix bug in check_volume_access (fixes vzrestore)
768
769 -- Proxmox Support Team <support@proxmox.com> Mon, 13 Feb 2012 09:56:37 +0100
770
4384e19e
DM
771libpve-access-control (1.0-8) unstable; urgency=low
772
773 * fix return value for empty ACL list.
774
775 -- Proxmox Support Team <support@proxmox.com> Fri, 10 Feb 2012 11:25:04 +0100
776
d8a56966
DM
777libpve-access-control (1.0-7) unstable; urgency=low
778
779 * fix bug #85: allow root@pam to generate tickets for other users
780
781 -- Proxmox Support Team <support@proxmox.com> Tue, 17 Jan 2012 06:40:18 +0100
782
cb6f2f93
DM
783libpve-access-control (1.0-6) unstable; urgency=low
784
785 * API change: allow to filter enabled/disabled users.
786
787 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Jan 2012 12:30:37 +0100
788
272fe9ff
DM
789libpve-access-control (1.0-5) unstable; urgency=low
790
791 * add a way to return file changes (diffs): set_result_changes()
792
793 -- Proxmox Support Team <support@proxmox.com> Tue, 20 Dec 2011 11:18:48 +0100
794
e42eedbc
DM
795libpve-access-control (1.0-4) unstable; urgency=low
796
797 * new environment type for ha agents
798
799 -- Proxmox Support Team <support@proxmox.com> Tue, 13 Dec 2011 10:08:53 +0100
800
1fba27e0
DM
801libpve-access-control (1.0-3) unstable; urgency=low
802
803 * add support for delayed parameter parsing - We need that to disable
804 file upload for normal API request (avoid DOS attacs)
805
806 -- Proxmox Support Team <support@proxmox.com> Fri, 02 Dec 2011 09:56:10 +0100
807
5bf71a96
DM
808libpve-access-control (1.0-2) unstable; urgency=low
809
810 * fix bug in fork_worker
811
812 -- Proxmox Support Team <support@proxmox.com> Tue, 11 Oct 2011 08:37:05 +0200
813
2c3a6c0a
DM
814libpve-access-control (1.0-1) unstable; urgency=low
815
816 * allow '-' in permission paths
817
818 * bump version to 1.0
819
820 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jun 2011 13:51:48 +0200
821
822libpve-access-control (0.1) unstable; urgency=low
823
824 * first dummy package - no functionality
825
826 -- Proxmox Support Team <support@proxmox.com> Thu, 09 Jul 2009 16:03:00 +0200
827