]> git.proxmox.com Git - pve-access-control.git/blame - debian/changelog
bump version to 5.1-10
[pve-access-control.git] / debian / changelog
CommitLineData
ef761f51
TL
1libpve-access-control (5.1-10) unstable; urgency=medium
2
3 * add /access/user/{id}/tfa api call to get tfa types
4
5 -- Proxmox Support Team <support@proxmox.com> Wed, 15 May 2019 16:21:10 +0200
6
860ddcba
TL
7libpve-access-control (5.1-9) unstable; urgency=medium
8
9 * store the tfa type in user.cfg allowing to get it without proxying the call
10 to a higher priviledged daemon.
11
12 * tfa: realm required TFA should lock out users without TFA configured, as it
13 was done before Proxmox VE 5.4
14
15 -- Proxmox Support Team <support@proxmox.com> Tue, 30 Apr 2019 14:01:00 +0000
16
9fbad012
TL
17libpve-access-control (5.1-8) unstable; urgency=medium
18
19 * U2F: ensure we save correct public key on registration
20
21 -- Proxmox Support Team <support@proxmox.com> Tue, 09 Apr 2019 12:47:12 +0200
22
4473c96c
TL
23libpve-access-control (5.1-7) unstable; urgency=medium
24
25 * verify_ticket: allow general non-challenge tfa to be run as two step
26 call
27
28 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Apr 2019 16:56:14 +0200
29
a270d4e1
TL
30libpve-access-control (5.1-6) unstable; urgency=medium
31
32 * more general 2FA configuration via priv/tfa.cfg
33
34 * add u2f api endpoints
35
36 * delete TFA entries when deleting a user
37
38 * allow users to change their TOTP settings
39
40 -- Proxmox Support Team <support@proxmox.com> Wed, 03 Apr 2019 13:40:26 +0200
41
374647e8
TL
42libpve-access-control (5.1-5) unstable; urgency=medium
43
44 * fix vnc ticket verification without authkey lifetime
45
46 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Mar 2019 10:43:17 +0100
47
7fb70c94
TL
48libpve-access-control (5.1-4) unstable; urgency=medium
49
50 * fix #1891: Add zsh command completion for pveum
51
52 * ground work to fix #2079: add periodic auth key rotation. Not yet enabled
53 to avoid issues on upgrade, will be enabled with 6.0
54
55 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Mar 2019 09:12:05 +0100
56
6e010cde
TL
57libpve-access-control (5.1-3) unstable; urgency=medium
58
59 * api/ticket: move getting cluster name into an eval
60
61 -- Proxmox Support Team <support@proxmox.com> Thu, 29 Nov 2018 12:59:36 +0100
62
f5a9380a
TL
63libpve-access-control (5.1-2) unstable; urgency=medium
64
65 * fix #1998: correct return properties for read_role
66
67 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:22:40 +0100
68
b54b7474
TL
69libpve-access-control (5.1-1) unstable; urgency=medium
70
71 * pveum: introduce sub-commands
72
73 * register userid with completion
74
75 * fix #233: return cluster name on successful login
76
77 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Nov 2018 09:34:47 +0100
78
52192dd4
WB
79libpve-access-control (5.0-8) unstable; urgency=medium
80
81 * fix #1612: ldap: make 2nd server work with bind domains again
82
83 * fix an error message where passing a bad pool id to an API function would
84 make it complain about a wrong group name instead
85
86 * fix the API-returned permission list so that the GUI knows to show the
87 'Permissions' tab for a storage to an administrator apart from root@pam
88
89 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Jan 2018 13:34:50 +0100
90
3dadf8cf
FG
91libpve-access-control (5.0-7) unstable; urgency=medium
92
93 * VM.Snapshot.Rollback privilege added
94
95 * api: check for special roles before locking the usercfg
96
97 * fix #1501: pveum: die when deleting special role
98
99 * API/ticket: rework coarse grained permission computation
100
101 -- Proxmox Support Team <support@proxmox.com> Thu, 5 Oct 2017 11:27:48 +0200
102
ec4141f4
WB
103libpve-access-control (5.0-6) unstable; urgency=medium
104
105 * Close #1470: Add server ceritifcate verification for AD and LDAP via the
106 'verify' option. For compatibility reasons this defaults to off for now,
107 but that might change with future updates.
108
109 * AD, LDAP: Add ability to specify a CA path or file, and a client
110 certificate via the 'capath', 'cert' and 'certkey' options.
111
112 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Aug 2017 11:56:38 +0200
113
63134bd4
DM
114libpve-access-control (5.0-5) unstable; urgency=medium
115
116 * change from dpkg-deb to dpkg-buildpackage
117
118 -- Proxmox Support Team <support@proxmox.com> Thu, 22 Jun 2017 09:12:37 +0200
119
868fb1ea
DM
120libpve-access-control (5.0-4) unstable; urgency=medium
121
122 * PVE/CLI/pveum.pm: call setup_default_cli_env()
123
124 * PVE/Auth/PVE.pm: encode uft8 password before calling crypt
125
126 * check_api2_permissions: avoid warning about uninitialized value
127
128 -- Proxmox Support Team <support@proxmox.com> Tue, 02 May 2017 11:58:15 +0200
129
63358f40
DM
130libpve-access-control (5.0-3) unstable; urgency=medium
131
132 * use new PVE::OTP class from pve-common
133
134 * use new PVE::Tools::encrypt_pw from pve-common
135
136 -- Proxmox Support Team <support@proxmox.com> Thu, 30 Mar 2017 17:45:55 +0200
137
05fd50af
DM
138libpve-access-control (5.0-2) unstable; urgency=medium
139
140 * encrypt_pw: avoid '+' for crypt salt
141
142 -- Proxmox Support Team <support@proxmox.com> Thu, 30 Mar 2017 08:54:10 +0200
143
0835385b
FG
144libpve-access-control (5.0-1) unstable; urgency=medium
145
146 * rebuild for PVE 5.0
147
148 -- Proxmox Support Team <support@proxmox.com> Mon, 6 Mar 2017 13:42:01 +0100
149
730f8863
DM
150libpve-access-control (4.0-23) unstable; urgency=medium
151
152 * use new PVE::Ticket class
153
154 -- Proxmox Support Team <support@proxmox.com> Thu, 19 Jan 2017 13:42:06 +0100
155
1f1c4593
DM
156libpve-access-control (4.0-22) unstable; urgency=medium
157
158 * RPCEnvironment: removed check_volume_access() to avoid cyclic dependency
159 (moved to PVE::Storage)
160
161 * PVE::PCEnvironment: use new PVE::RESTEnvironment as base class
162
163 -- Proxmox Support Team <support@proxmox.com> Thu, 19 Jan 2017 09:12:04 +0100
164
f9105063
DM
165libpve-access-control (4.0-21) unstable; urgency=medium
166
167 * setup_default_cli_env: expect $class as first parameter
168
169 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jan 2017 13:54:27 +0100
170
9595066e
DM
171libpve-access-control (4.0-20) unstable; urgency=medium
172
173 * PVE/RPCEnvironment.pm: new function setup_default_cli_env
174
175 * PVE/API2/Domains.pm: fix property description
176
177 * use new repoman for upload target
178
179 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Jan 2017 12:13:26 +0100
180
2af5a793
DM
181libpve-access-control (4.0-19) unstable; urgency=medium
182
183 * Close #833: ldap: non-anonymous bind support
184
185 * don't import 'RFC' from MIME::Base32
186
187 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Aug 2016 13:09:08 +0200
188
5d87bb77
WB
189libpve-access-control (4.0-18) unstable; urgency=medium
190
191 * fix #1062: recognize base32 otp keys again
192
193 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Jul 2016 08:43:18 +0200
194
28ddf48b
WB
195libpve-access-control (4.0-17) unstable; urgency=medium
196
197 * drop oathtool and libdigest-hmac-perl dependencies
198
199 -- Proxmox Support Team <support@proxmox.com> Mon, 11 Jul 2016 12:03:22 +0200
200
15cebb28
DM
201libpve-access-control (4.0-16) unstable; urgency=medium
202
203 * use pve-doc-generator to generate man pages
204
205 -- Proxmox Support Team <support@proxmox.com> Fri, 08 Apr 2016 07:06:05 +0200
206
678df887
DM
207libpve-access-control (4.0-15) unstable; urgency=medium
208
209 * Fix uninitialized warning when shadow.cfg does not exist
210
211 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:10:57 +0200
212
cca9761a
DM
213libpve-access-control (4.0-14) unstable; urgency=medium
214
215 * Add is_worker to RPCEnvironment
216
217 -- Proxmox Support Team <support@proxmox.com> Tue, 15 Mar 2016 16:47:34 +0100
218
8643c99d
DM
219libpve-access-control (4.0-13) unstable; urgency=medium
220
221 * fix #916: allow HTTPS to access custom yubico url
222
223 -- Proxmox Support Team <support@proxmox.com> Mon, 14 Mar 2016 11:39:23 +0100
224
ae2a6bf9
DM
225libpve-access-control (4.0-12) unstable; urgency=medium
226
227 * Catch certificate errors instead of segfaulting
228
229 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Mar 2016 14:41:01 +0100
230
4836db5f
DM
231libpve-access-control (4.0-11) unstable; urgency=medium
232
233 * Fix #861: use safer sprintf formatting
234
235 -- Proxmox Support Team <support@proxmox.com> Fri, 08 Jan 2016 12:52:39 +0100
236
ccbe23dc
DM
237libpve-access-control (4.0-10) unstable; urgency=medium
238
239 * Auth::LDAP, Auth::AD: ipv6 support
240
241 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Dec 2015 12:09:32 +0100
242
90399ca4
DM
243libpve-access-control (4.0-9) unstable; urgency=medium
244
245 * pveum: implement bash completion
246
247 -- Proxmox Support Team <support@proxmox.com> Thu, 01 Oct 2015 17:22:52 +0200
248
364ffc13
DM
249libpve-access-control (4.0-8) unstable; urgency=medium
250
251 * remove_storage_access: cleanup of access permissions for removed storage
252
253 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:39:15 +0200
254
7c26cb4a
DM
255libpve-access-control (4.0-7) unstable; urgency=medium
256
257 * new helper to remove access permissions for removed VMs
258
259 -- Proxmox Support Team <support@proxmox.com> Fri, 14 Aug 2015 07:57:02 +0200
260
296afbd1
DM
261libpve-access-control (4.0-6) unstable; urgency=medium
262
263 * improve parse_user_config, parse_shadow_config
264
265 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:14:33 +0200
266
7d2df2ef
DM
267libpve-access-control (4.0-5) unstable; urgency=medium
268
269 * pveum: check for $cmd being defined
270
271 -- Proxmox Support Team <support@proxmox.com> Wed, 10 Jun 2015 10:40:15 +0200
272
98a34e3f
DM
273libpve-access-control (4.0-4) unstable; urgency=medium
274
275 * use activate-noawait triggers
276
277 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:25:31 +0200
278
15462727
DM
279libpve-access-control (4.0-3) unstable; urgency=medium
280
281 * IPv6 fixes
282
283 * non-root buildfix
284
285 -- Proxmox Support Team <support@proxmox.com> Wed, 27 May 2015 11:15:44 +0200
286
bbf4cc9a
DM
287libpve-access-control (4.0-2) unstable; urgency=medium
288
289 * trigger pve-api-updates event
290
291 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:06:38 +0200
292
dfbcf6d3
DM
293libpve-access-control (4.0-1) unstable; urgency=medium
294
295 * bump version for Debian Jessie
296
297 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Feb 2015 11:22:01 +0100
298
94971b3a
DM
299libpve-access-control (3.0-16) unstable; urgency=low
300
301 * root@pam can now be disabled in GUI.
302
303 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Jan 2015 06:20:22 +0100
304
7b17c7cb
DM
305libpve-access-control (3.0-15) unstable; urgency=low
306
307 * oath: add 'step' and 'digits' option
308
309 -- Proxmox Support Team <support@proxmox.com> Wed, 23 Jul 2014 06:59:52 +0200
310
1abc2c0a
DM
311libpve-access-control (3.0-14) unstable; urgency=low
312
313 * add oath two factor auth
314
315 * add oathkeygen binary to generate keys for oath
316
317 * add yubico two factor auth
318
319 * dedend on oathtool
320
321 * depend on libmime-base32-perl
30be0de9
DM
322
323 * allow to write builtin auth domains config (comment/tfa/default)
1abc2c0a
DM
324
325 -- Proxmox Support Team <support@proxmox.com> Thu, 17 Jul 2014 13:09:56 +0200
326
298450ab
DM
327libpve-access-control (3.0-13) unstable; urgency=low
328
329 * use correct connection string for AD auth
330
331 -- Proxmox Support Team <support@proxmox.com> Thu, 22 May 2014 07:16:09 +0200
332
396034e4
DM
333libpve-access-control (3.0-12) unstable; urgency=low
334
335 * add dummy API for GET /access/ticket (useful to generate login pages)
336
337 -- Proxmox Support Team <support@proxmox.com> Wed, 30 Apr 2014 14:47:56 +0200
338
26361123
DM
339libpve-access-control (3.0-11) unstable; urgency=low
340
341 * Sets common hot keys for spice client
342
343 -- Proxmox Support Team <support@proxmox.com> Fri, 31 Jan 2014 10:24:28 +0100
344
3643383d
DM
345libpve-access-control (3.0-10) unstable; urgency=low
346
347 * implement helper to generate SPICE remote-viewer configuration
348
349 * depend on libnet-ssleay-perl
350
351 -- Proxmox Support Team <support@proxmox.com> Tue, 10 Dec 2013 10:45:08 +0100
352
0baedcf7
DM
353libpve-access-control (3.0-9) unstable; urgency=low
354
355 * prevent user enumeration attacks
e4f8fc2e
DM
356
357 * allow dots in access paths
0baedcf7
DM
358
359 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2013 09:06:38 +0100
360
d4b63eae
DM
361libpve-access-control (3.0-8) unstable; urgency=low
362
363 * spice: use lowercase hostname in ticktet signature
364
365 -- Proxmox Support Team <support@proxmox.com> Mon, 28 Oct 2013 08:11:57 +0100
366
49594944
DM
367libpve-access-control (3.0-7) unstable; urgency=low
368
369 * check_volume_access : use parse_volname instead of path, and remove
370 path related code.
7c410d63
DM
371
372 * use warnings instead of global -w flag.
49594944
DM
373
374 -- Proxmox Support Team <support@proxmox.com> Tue, 01 Oct 2013 12:35:53 +0200
375
fe7de5d0
DM
376libpve-access-control (3.0-6) unstable; urgency=low
377
378 * use shorter spiceproxy tickets
379
380 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Jul 2013 12:39:09 +0200
381
4cdd9507
DM
382libpve-access-control (3.0-5) unstable; urgency=low
383
384 * add code to generate tickets for SPICE
385
386 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Jun 2013 13:08:32 +0200
387
677f9ab0
DM
388libpve-access-control (3.0-4) unstable; urgency=low
389
390 * moved add_vm_to_pool/remove_vm_from_pool from qemu-server
391
392 -- Proxmox Support Team <support@proxmox.com> Tue, 14 May 2013 11:56:54 +0200
393
139a8ecf
DM
394libpve-access-control (3.0-3) unstable; urgency=low
395
7b395f99 396 * Add new role PVETemplateUser (and VM.Clone priviledge)
139a8ecf
DM
397
398 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Apr 2013 11:42:15 +0200
399
b78ce7c2
DM
400libpve-access-control (3.0-2) unstable; urgency=low
401
402 * remove CGI.pm related code (pveproxy does not need that)
403
404 -- Proxmox Support Team <support@proxmox.com> Mon, 15 Apr 2013 12:34:23 +0200
405
786820f9
DM
406libpve-access-control (3.0-1) unstable; urgency=low
407
408 * bump version for wheezy release
409
410 -- Proxmox Support Team <support@proxmox.com> Fri, 15 Mar 2013 08:07:06 +0100
411
e5ae5487
DM
412libpve-access-control (1.0-26) unstable; urgency=low
413
414 * check_volume_access: fix access permissions for backup files
415
416 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Feb 2013 10:00:14 +0100
417
e3e6510c
DM
418libpve-access-control (1.0-25) unstable; urgency=low
419
420 * add VM.Snapshot permission
421
422 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Sep 2012 09:23:32 +0200
423
1e15ebe7
DM
424libpve-access-control (1.0-24) unstable; urgency=low
425
426 * untaint path (allow root to restore arbitrary paths)
427
428 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2012 13:06:34 +0200
429
437be042
DM
430libpve-access-control (1.0-23) unstable; urgency=low
431
432 * correctly compute GUI capabilities (consider pools)
433
434 -- Proxmox Support Team <support@proxmox.com> Wed, 30 May 2012 08:47:23 +0200
435
5bb4e06a
DM
436libpve-access-control (1.0-22) unstable; urgency=low
437
438 * new plugin architecture for Auth modules, minor API change for Auth
439 domains (new 'delete' parameter)
440
441 -- Proxmox Support Team <support@proxmox.com> Wed, 16 May 2012 07:21:44 +0200
442
3030a176
DM
443libpve-access-control (1.0-21) unstable; urgency=low
444
445 * do not allow user names including slash
446
447 -- Proxmox Support Team <support@proxmox.com> Tue, 24 Apr 2012 10:07:47 +0200
448
449libpve-access-control (1.0-20) unstable; urgency=low
450
451 * add ability to fork cli workers in background
452
453 -- Proxmox Support Team <support@proxmox.com> Wed, 18 Apr 2012 08:28:20 +0200
454
dd2cfee0
DM
455libpve-access-control (1.0-19) unstable; urgency=low
456
457 * return set of privileges on login - can be used to adopt GUI
458
459 -- Proxmox Support Team <support@proxmox.com> Tue, 17 Apr 2012 10:25:10 +0200
460
1cf154b7
DM
461libpve-access-control (1.0-18) unstable; urgency=low
462
533219a1
DM
463 * fix bug #151: corretly parse username inside ticket
464
465 * fix bug #152: allow user to change his own password
1cf154b7
DM
466
467 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2012 09:40:15 +0200
468
2de14407
DM
469libpve-access-control (1.0-17) unstable; urgency=low
470
471 * set propagate flag by default
472
473 -- Proxmox Support Team <support@proxmox.com> Thu, 01 Mar 2012 12:40:19 +0100
474
bdc61d7a
DM
475libpve-access-control (1.0-16) unstable; urgency=low
476
477 * add 'pveum passwd' method
478
479 -- Proxmox Support Team <support@proxmox.com> Thu, 23 Feb 2012 12:05:25 +0100
480
cc7bdf33
DM
481libpve-access-control (1.0-15) unstable; urgency=low
482
483 * Add VM.Config.CDROM privilege to PVEVMUser rule
484
485 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 11:44:23 +0100
486
a69bbe2e
DM
487libpve-access-control (1.0-14) unstable; urgency=low
488
489 * fix buf in userid-param permission check
490
491 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 10:52:35 +0100
492
d9483d94
DM
493libpve-access-control (1.0-13) unstable; urgency=low
494
495 * allow more characters in ldap base_dn attribute
496
497 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 06:17:02 +0100
498
84619607
DM
499libpve-access-control (1.0-12) unstable; urgency=low
500
501 * allow more characters with realm IDs
502
503 -- Proxmox Support Team <support@proxmox.com> Mon, 20 Feb 2012 08:50:33 +0100
504
09d27058
DM
505libpve-access-control (1.0-11) unstable; urgency=low
506
507 * fix bug in exec_api2_perm_check
508
509 -- Proxmox Support Team <support@proxmox.com> Wed, 15 Feb 2012 07:06:30 +0100
510
7a4c849e
DM
511libpve-access-control (1.0-10) unstable; urgency=low
512
513 * fix ACL group name parser
514
515 * changed 'pveum aclmod' command line arguments
516
517 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Feb 2012 12:08:02 +0100
518
3eac4e35
DM
519libpve-access-control (1.0-9) unstable; urgency=low
520
521 * fix bug in check_volume_access (fixes vzrestore)
522
523 -- Proxmox Support Team <support@proxmox.com> Mon, 13 Feb 2012 09:56:37 +0100
524
4384e19e
DM
525libpve-access-control (1.0-8) unstable; urgency=low
526
527 * fix return value for empty ACL list.
528
529 -- Proxmox Support Team <support@proxmox.com> Fri, 10 Feb 2012 11:25:04 +0100
530
d8a56966
DM
531libpve-access-control (1.0-7) unstable; urgency=low
532
533 * fix bug #85: allow root@pam to generate tickets for other users
534
535 -- Proxmox Support Team <support@proxmox.com> Tue, 17 Jan 2012 06:40:18 +0100
536
cb6f2f93
DM
537libpve-access-control (1.0-6) unstable; urgency=low
538
539 * API change: allow to filter enabled/disabled users.
540
541 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Jan 2012 12:30:37 +0100
542
272fe9ff
DM
543libpve-access-control (1.0-5) unstable; urgency=low
544
545 * add a way to return file changes (diffs): set_result_changes()
546
547 -- Proxmox Support Team <support@proxmox.com> Tue, 20 Dec 2011 11:18:48 +0100
548
e42eedbc
DM
549libpve-access-control (1.0-4) unstable; urgency=low
550
551 * new environment type for ha agents
552
553 -- Proxmox Support Team <support@proxmox.com> Tue, 13 Dec 2011 10:08:53 +0100
554
1fba27e0
DM
555libpve-access-control (1.0-3) unstable; urgency=low
556
557 * add support for delayed parameter parsing - We need that to disable
558 file upload for normal API request (avoid DOS attacs)
559
560 -- Proxmox Support Team <support@proxmox.com> Fri, 02 Dec 2011 09:56:10 +0100
561
5bf71a96
DM
562libpve-access-control (1.0-2) unstable; urgency=low
563
564 * fix bug in fork_worker
565
566 -- Proxmox Support Team <support@proxmox.com> Tue, 11 Oct 2011 08:37:05 +0200
567
2c3a6c0a
DM
568libpve-access-control (1.0-1) unstable; urgency=low
569
570 * allow '-' in permission paths
571
572 * bump version to 1.0
573
574 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jun 2011 13:51:48 +0200
575
576libpve-access-control (0.1) unstable; urgency=low
577
578 * first dummy package - no functionality
579
580 -- Proxmox Support Team <support@proxmox.com> Thu, 09 Jul 2009 16:03:00 +0200
581