]> git.proxmox.com Git - pve-access-control.git/blob - debian/changelog
6b13e3b0ffd643c4711eaf4d8380be9aff430b79
[pve-access-control.git] / debian / changelog
1 libpve-access-control (6.0-5) pve; urgency=medium
2
3 * pveum: add list command for users, groups, ACLs and roles
4
5 * add initial permissions for experimental SDN integration
6
7 -- Proxmox Support Team <support@proxmox.com> Tue, 26 Nov 2019 17:56:37 +0100
8
9 libpve-access-control (6.0-4) pve; urgency=medium
10
11 * ticket: use clinfo to get cluster name
12
13 * ldaps: add sslversion configuration property to support TLS 1.1 to 1.3 as
14 SSL version
15
16 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2019 11:55:11 +0100
17
18 libpve-access-control (6.0-3) pve; urgency=medium
19
20 * fix #2433: increase possible TFA secret length
21
22 * parse user configuration: correctly parse group names in ACLs, for users
23 which begin their name with an @
24
25 * sort user.cfg entries alphabetically
26
27 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Oct 2019 08:52:23 +0100
28
29 libpve-access-control (6.0-2) pve; urgency=medium
30
31 * improve CSRF verification compatibility with newer PVE
32
33 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Jun 2019 20:24:35 +0200
34
35 libpve-access-control (6.0-1) pve; urgency=medium
36
37 * ticket: properly verify exactly 5 minute old tickets
38
39 * use hmac_sha256 instead of sha1 for CSRF token generation
40
41 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 18:14:45 +0200
42
43 libpve-access-control (6.0-0+1) pve; urgency=medium
44
45 * bump for Debian buster
46
47 * fix #2079: add periodic auth key rotation
48
49 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 21:31:15 +0200
50
51 libpve-access-control (5.1-10) unstable; urgency=medium
52
53 * add /access/user/{id}/tfa api call to get tfa types
54
55 -- Proxmox Support Team <support@proxmox.com> Wed, 15 May 2019 16:21:10 +0200
56
57 libpve-access-control (5.1-9) unstable; urgency=medium
58
59 * store the tfa type in user.cfg allowing to get it without proxying the call
60 to a higher priviledged daemon.
61
62 * tfa: realm required TFA should lock out users without TFA configured, as it
63 was done before Proxmox VE 5.4
64
65 -- Proxmox Support Team <support@proxmox.com> Tue, 30 Apr 2019 14:01:00 +0000
66
67 libpve-access-control (5.1-8) unstable; urgency=medium
68
69 * U2F: ensure we save correct public key on registration
70
71 -- Proxmox Support Team <support@proxmox.com> Tue, 09 Apr 2019 12:47:12 +0200
72
73 libpve-access-control (5.1-7) unstable; urgency=medium
74
75 * verify_ticket: allow general non-challenge tfa to be run as two step
76 call
77
78 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Apr 2019 16:56:14 +0200
79
80 libpve-access-control (5.1-6) unstable; urgency=medium
81
82 * more general 2FA configuration via priv/tfa.cfg
83
84 * add u2f api endpoints
85
86 * delete TFA entries when deleting a user
87
88 * allow users to change their TOTP settings
89
90 -- Proxmox Support Team <support@proxmox.com> Wed, 03 Apr 2019 13:40:26 +0200
91
92 libpve-access-control (5.1-5) unstable; urgency=medium
93
94 * fix vnc ticket verification without authkey lifetime
95
96 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Mar 2019 10:43:17 +0100
97
98 libpve-access-control (5.1-4) unstable; urgency=medium
99
100 * fix #1891: Add zsh command completion for pveum
101
102 * ground work to fix #2079: add periodic auth key rotation. Not yet enabled
103 to avoid issues on upgrade, will be enabled with 6.0
104
105 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Mar 2019 09:12:05 +0100
106
107 libpve-access-control (5.1-3) unstable; urgency=medium
108
109 * api/ticket: move getting cluster name into an eval
110
111 -- Proxmox Support Team <support@proxmox.com> Thu, 29 Nov 2018 12:59:36 +0100
112
113 libpve-access-control (5.1-2) unstable; urgency=medium
114
115 * fix #1998: correct return properties for read_role
116
117 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:22:40 +0100
118
119 libpve-access-control (5.1-1) unstable; urgency=medium
120
121 * pveum: introduce sub-commands
122
123 * register userid with completion
124
125 * fix #233: return cluster name on successful login
126
127 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Nov 2018 09:34:47 +0100
128
129 libpve-access-control (5.0-8) unstable; urgency=medium
130
131 * fix #1612: ldap: make 2nd server work with bind domains again
132
133 * fix an error message where passing a bad pool id to an API function would
134 make it complain about a wrong group name instead
135
136 * fix the API-returned permission list so that the GUI knows to show the
137 'Permissions' tab for a storage to an administrator apart from root@pam
138
139 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Jan 2018 13:34:50 +0100
140
141 libpve-access-control (5.0-7) unstable; urgency=medium
142
143 * VM.Snapshot.Rollback privilege added
144
145 * api: check for special roles before locking the usercfg
146
147 * fix #1501: pveum: die when deleting special role
148
149 * API/ticket: rework coarse grained permission computation
150
151 -- Proxmox Support Team <support@proxmox.com> Thu, 5 Oct 2017 11:27:48 +0200
152
153 libpve-access-control (5.0-6) unstable; urgency=medium
154
155 * Close #1470: Add server ceritifcate verification for AD and LDAP via the
156 'verify' option. For compatibility reasons this defaults to off for now,
157 but that might change with future updates.
158
159 * AD, LDAP: Add ability to specify a CA path or file, and a client
160 certificate via the 'capath', 'cert' and 'certkey' options.
161
162 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Aug 2017 11:56:38 +0200
163
164 libpve-access-control (5.0-5) unstable; urgency=medium
165
166 * change from dpkg-deb to dpkg-buildpackage
167
168 -- Proxmox Support Team <support@proxmox.com> Thu, 22 Jun 2017 09:12:37 +0200
169
170 libpve-access-control (5.0-4) unstable; urgency=medium
171
172 * PVE/CLI/pveum.pm: call setup_default_cli_env()
173
174 * PVE/Auth/PVE.pm: encode uft8 password before calling crypt
175
176 * check_api2_permissions: avoid warning about uninitialized value
177
178 -- Proxmox Support Team <support@proxmox.com> Tue, 02 May 2017 11:58:15 +0200
179
180 libpve-access-control (5.0-3) unstable; urgency=medium
181
182 * use new PVE::OTP class from pve-common
183
184 * use new PVE::Tools::encrypt_pw from pve-common
185
186 -- Proxmox Support Team <support@proxmox.com> Thu, 30 Mar 2017 17:45:55 +0200
187
188 libpve-access-control (5.0-2) unstable; urgency=medium
189
190 * encrypt_pw: avoid '+' for crypt salt
191
192 -- Proxmox Support Team <support@proxmox.com> Thu, 30 Mar 2017 08:54:10 +0200
193
194 libpve-access-control (5.0-1) unstable; urgency=medium
195
196 * rebuild for PVE 5.0
197
198 -- Proxmox Support Team <support@proxmox.com> Mon, 6 Mar 2017 13:42:01 +0100
199
200 libpve-access-control (4.0-23) unstable; urgency=medium
201
202 * use new PVE::Ticket class
203
204 -- Proxmox Support Team <support@proxmox.com> Thu, 19 Jan 2017 13:42:06 +0100
205
206 libpve-access-control (4.0-22) unstable; urgency=medium
207
208 * RPCEnvironment: removed check_volume_access() to avoid cyclic dependency
209 (moved to PVE::Storage)
210
211 * PVE::PCEnvironment: use new PVE::RESTEnvironment as base class
212
213 -- Proxmox Support Team <support@proxmox.com> Thu, 19 Jan 2017 09:12:04 +0100
214
215 libpve-access-control (4.0-21) unstable; urgency=medium
216
217 * setup_default_cli_env: expect $class as first parameter
218
219 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jan 2017 13:54:27 +0100
220
221 libpve-access-control (4.0-20) unstable; urgency=medium
222
223 * PVE/RPCEnvironment.pm: new function setup_default_cli_env
224
225 * PVE/API2/Domains.pm: fix property description
226
227 * use new repoman for upload target
228
229 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Jan 2017 12:13:26 +0100
230
231 libpve-access-control (4.0-19) unstable; urgency=medium
232
233 * Close #833: ldap: non-anonymous bind support
234
235 * don't import 'RFC' from MIME::Base32
236
237 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Aug 2016 13:09:08 +0200
238
239 libpve-access-control (4.0-18) unstable; urgency=medium
240
241 * fix #1062: recognize base32 otp keys again
242
243 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Jul 2016 08:43:18 +0200
244
245 libpve-access-control (4.0-17) unstable; urgency=medium
246
247 * drop oathtool and libdigest-hmac-perl dependencies
248
249 -- Proxmox Support Team <support@proxmox.com> Mon, 11 Jul 2016 12:03:22 +0200
250
251 libpve-access-control (4.0-16) unstable; urgency=medium
252
253 * use pve-doc-generator to generate man pages
254
255 -- Proxmox Support Team <support@proxmox.com> Fri, 08 Apr 2016 07:06:05 +0200
256
257 libpve-access-control (4.0-15) unstable; urgency=medium
258
259 * Fix uninitialized warning when shadow.cfg does not exist
260
261 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:10:57 +0200
262
263 libpve-access-control (4.0-14) unstable; urgency=medium
264
265 * Add is_worker to RPCEnvironment
266
267 -- Proxmox Support Team <support@proxmox.com> Tue, 15 Mar 2016 16:47:34 +0100
268
269 libpve-access-control (4.0-13) unstable; urgency=medium
270
271 * fix #916: allow HTTPS to access custom yubico url
272
273 -- Proxmox Support Team <support@proxmox.com> Mon, 14 Mar 2016 11:39:23 +0100
274
275 libpve-access-control (4.0-12) unstable; urgency=medium
276
277 * Catch certificate errors instead of segfaulting
278
279 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Mar 2016 14:41:01 +0100
280
281 libpve-access-control (4.0-11) unstable; urgency=medium
282
283 * Fix #861: use safer sprintf formatting
284
285 -- Proxmox Support Team <support@proxmox.com> Fri, 08 Jan 2016 12:52:39 +0100
286
287 libpve-access-control (4.0-10) unstable; urgency=medium
288
289 * Auth::LDAP, Auth::AD: ipv6 support
290
291 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Dec 2015 12:09:32 +0100
292
293 libpve-access-control (4.0-9) unstable; urgency=medium
294
295 * pveum: implement bash completion
296
297 -- Proxmox Support Team <support@proxmox.com> Thu, 01 Oct 2015 17:22:52 +0200
298
299 libpve-access-control (4.0-8) unstable; urgency=medium
300
301 * remove_storage_access: cleanup of access permissions for removed storage
302
303 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:39:15 +0200
304
305 libpve-access-control (4.0-7) unstable; urgency=medium
306
307 * new helper to remove access permissions for removed VMs
308
309 -- Proxmox Support Team <support@proxmox.com> Fri, 14 Aug 2015 07:57:02 +0200
310
311 libpve-access-control (4.0-6) unstable; urgency=medium
312
313 * improve parse_user_config, parse_shadow_config
314
315 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:14:33 +0200
316
317 libpve-access-control (4.0-5) unstable; urgency=medium
318
319 * pveum: check for $cmd being defined
320
321 -- Proxmox Support Team <support@proxmox.com> Wed, 10 Jun 2015 10:40:15 +0200
322
323 libpve-access-control (4.0-4) unstable; urgency=medium
324
325 * use activate-noawait triggers
326
327 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:25:31 +0200
328
329 libpve-access-control (4.0-3) unstable; urgency=medium
330
331 * IPv6 fixes
332
333 * non-root buildfix
334
335 -- Proxmox Support Team <support@proxmox.com> Wed, 27 May 2015 11:15:44 +0200
336
337 libpve-access-control (4.0-2) unstable; urgency=medium
338
339 * trigger pve-api-updates event
340
341 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:06:38 +0200
342
343 libpve-access-control (4.0-1) unstable; urgency=medium
344
345 * bump version for Debian Jessie
346
347 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Feb 2015 11:22:01 +0100
348
349 libpve-access-control (3.0-16) unstable; urgency=low
350
351 * root@pam can now be disabled in GUI.
352
353 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Jan 2015 06:20:22 +0100
354
355 libpve-access-control (3.0-15) unstable; urgency=low
356
357 * oath: add 'step' and 'digits' option
358
359 -- Proxmox Support Team <support@proxmox.com> Wed, 23 Jul 2014 06:59:52 +0200
360
361 libpve-access-control (3.0-14) unstable; urgency=low
362
363 * add oath two factor auth
364
365 * add oathkeygen binary to generate keys for oath
366
367 * add yubico two factor auth
368
369 * dedend on oathtool
370
371 * depend on libmime-base32-perl
372
373 * allow to write builtin auth domains config (comment/tfa/default)
374
375 -- Proxmox Support Team <support@proxmox.com> Thu, 17 Jul 2014 13:09:56 +0200
376
377 libpve-access-control (3.0-13) unstable; urgency=low
378
379 * use correct connection string for AD auth
380
381 -- Proxmox Support Team <support@proxmox.com> Thu, 22 May 2014 07:16:09 +0200
382
383 libpve-access-control (3.0-12) unstable; urgency=low
384
385 * add dummy API for GET /access/ticket (useful to generate login pages)
386
387 -- Proxmox Support Team <support@proxmox.com> Wed, 30 Apr 2014 14:47:56 +0200
388
389 libpve-access-control (3.0-11) unstable; urgency=low
390
391 * Sets common hot keys for spice client
392
393 -- Proxmox Support Team <support@proxmox.com> Fri, 31 Jan 2014 10:24:28 +0100
394
395 libpve-access-control (3.0-10) unstable; urgency=low
396
397 * implement helper to generate SPICE remote-viewer configuration
398
399 * depend on libnet-ssleay-perl
400
401 -- Proxmox Support Team <support@proxmox.com> Tue, 10 Dec 2013 10:45:08 +0100
402
403 libpve-access-control (3.0-9) unstable; urgency=low
404
405 * prevent user enumeration attacks
406
407 * allow dots in access paths
408
409 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2013 09:06:38 +0100
410
411 libpve-access-control (3.0-8) unstable; urgency=low
412
413 * spice: use lowercase hostname in ticktet signature
414
415 -- Proxmox Support Team <support@proxmox.com> Mon, 28 Oct 2013 08:11:57 +0100
416
417 libpve-access-control (3.0-7) unstable; urgency=low
418
419 * check_volume_access : use parse_volname instead of path, and remove
420 path related code.
421
422 * use warnings instead of global -w flag.
423
424 -- Proxmox Support Team <support@proxmox.com> Tue, 01 Oct 2013 12:35:53 +0200
425
426 libpve-access-control (3.0-6) unstable; urgency=low
427
428 * use shorter spiceproxy tickets
429
430 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Jul 2013 12:39:09 +0200
431
432 libpve-access-control (3.0-5) unstable; urgency=low
433
434 * add code to generate tickets for SPICE
435
436 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Jun 2013 13:08:32 +0200
437
438 libpve-access-control (3.0-4) unstable; urgency=low
439
440 * moved add_vm_to_pool/remove_vm_from_pool from qemu-server
441
442 -- Proxmox Support Team <support@proxmox.com> Tue, 14 May 2013 11:56:54 +0200
443
444 libpve-access-control (3.0-3) unstable; urgency=low
445
446 * Add new role PVETemplateUser (and VM.Clone priviledge)
447
448 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Apr 2013 11:42:15 +0200
449
450 libpve-access-control (3.0-2) unstable; urgency=low
451
452 * remove CGI.pm related code (pveproxy does not need that)
453
454 -- Proxmox Support Team <support@proxmox.com> Mon, 15 Apr 2013 12:34:23 +0200
455
456 libpve-access-control (3.0-1) unstable; urgency=low
457
458 * bump version for wheezy release
459
460 -- Proxmox Support Team <support@proxmox.com> Fri, 15 Mar 2013 08:07:06 +0100
461
462 libpve-access-control (1.0-26) unstable; urgency=low
463
464 * check_volume_access: fix access permissions for backup files
465
466 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Feb 2013 10:00:14 +0100
467
468 libpve-access-control (1.0-25) unstable; urgency=low
469
470 * add VM.Snapshot permission
471
472 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Sep 2012 09:23:32 +0200
473
474 libpve-access-control (1.0-24) unstable; urgency=low
475
476 * untaint path (allow root to restore arbitrary paths)
477
478 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2012 13:06:34 +0200
479
480 libpve-access-control (1.0-23) unstable; urgency=low
481
482 * correctly compute GUI capabilities (consider pools)
483
484 -- Proxmox Support Team <support@proxmox.com> Wed, 30 May 2012 08:47:23 +0200
485
486 libpve-access-control (1.0-22) unstable; urgency=low
487
488 * new plugin architecture for Auth modules, minor API change for Auth
489 domains (new 'delete' parameter)
490
491 -- Proxmox Support Team <support@proxmox.com> Wed, 16 May 2012 07:21:44 +0200
492
493 libpve-access-control (1.0-21) unstable; urgency=low
494
495 * do not allow user names including slash
496
497 -- Proxmox Support Team <support@proxmox.com> Tue, 24 Apr 2012 10:07:47 +0200
498
499 libpve-access-control (1.0-20) unstable; urgency=low
500
501 * add ability to fork cli workers in background
502
503 -- Proxmox Support Team <support@proxmox.com> Wed, 18 Apr 2012 08:28:20 +0200
504
505 libpve-access-control (1.0-19) unstable; urgency=low
506
507 * return set of privileges on login - can be used to adopt GUI
508
509 -- Proxmox Support Team <support@proxmox.com> Tue, 17 Apr 2012 10:25:10 +0200
510
511 libpve-access-control (1.0-18) unstable; urgency=low
512
513 * fix bug #151: corretly parse username inside ticket
514
515 * fix bug #152: allow user to change his own password
516
517 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2012 09:40:15 +0200
518
519 libpve-access-control (1.0-17) unstable; urgency=low
520
521 * set propagate flag by default
522
523 -- Proxmox Support Team <support@proxmox.com> Thu, 01 Mar 2012 12:40:19 +0100
524
525 libpve-access-control (1.0-16) unstable; urgency=low
526
527 * add 'pveum passwd' method
528
529 -- Proxmox Support Team <support@proxmox.com> Thu, 23 Feb 2012 12:05:25 +0100
530
531 libpve-access-control (1.0-15) unstable; urgency=low
532
533 * Add VM.Config.CDROM privilege to PVEVMUser rule
534
535 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 11:44:23 +0100
536
537 libpve-access-control (1.0-14) unstable; urgency=low
538
539 * fix buf in userid-param permission check
540
541 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 10:52:35 +0100
542
543 libpve-access-control (1.0-13) unstable; urgency=low
544
545 * allow more characters in ldap base_dn attribute
546
547 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 06:17:02 +0100
548
549 libpve-access-control (1.0-12) unstable; urgency=low
550
551 * allow more characters with realm IDs
552
553 -- Proxmox Support Team <support@proxmox.com> Mon, 20 Feb 2012 08:50:33 +0100
554
555 libpve-access-control (1.0-11) unstable; urgency=low
556
557 * fix bug in exec_api2_perm_check
558
559 -- Proxmox Support Team <support@proxmox.com> Wed, 15 Feb 2012 07:06:30 +0100
560
561 libpve-access-control (1.0-10) unstable; urgency=low
562
563 * fix ACL group name parser
564
565 * changed 'pveum aclmod' command line arguments
566
567 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Feb 2012 12:08:02 +0100
568
569 libpve-access-control (1.0-9) unstable; urgency=low
570
571 * fix bug in check_volume_access (fixes vzrestore)
572
573 -- Proxmox Support Team <support@proxmox.com> Mon, 13 Feb 2012 09:56:37 +0100
574
575 libpve-access-control (1.0-8) unstable; urgency=low
576
577 * fix return value for empty ACL list.
578
579 -- Proxmox Support Team <support@proxmox.com> Fri, 10 Feb 2012 11:25:04 +0100
580
581 libpve-access-control (1.0-7) unstable; urgency=low
582
583 * fix bug #85: allow root@pam to generate tickets for other users
584
585 -- Proxmox Support Team <support@proxmox.com> Tue, 17 Jan 2012 06:40:18 +0100
586
587 libpve-access-control (1.0-6) unstable; urgency=low
588
589 * API change: allow to filter enabled/disabled users.
590
591 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Jan 2012 12:30:37 +0100
592
593 libpve-access-control (1.0-5) unstable; urgency=low
594
595 * add a way to return file changes (diffs): set_result_changes()
596
597 -- Proxmox Support Team <support@proxmox.com> Tue, 20 Dec 2011 11:18:48 +0100
598
599 libpve-access-control (1.0-4) unstable; urgency=low
600
601 * new environment type for ha agents
602
603 -- Proxmox Support Team <support@proxmox.com> Tue, 13 Dec 2011 10:08:53 +0100
604
605 libpve-access-control (1.0-3) unstable; urgency=low
606
607 * add support for delayed parameter parsing - We need that to disable
608 file upload for normal API request (avoid DOS attacs)
609
610 -- Proxmox Support Team <support@proxmox.com> Fri, 02 Dec 2011 09:56:10 +0100
611
612 libpve-access-control (1.0-2) unstable; urgency=low
613
614 * fix bug in fork_worker
615
616 -- Proxmox Support Team <support@proxmox.com> Tue, 11 Oct 2011 08:37:05 +0200
617
618 libpve-access-control (1.0-1) unstable; urgency=low
619
620 * allow '-' in permission paths
621
622 * bump version to 1.0
623
624 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jun 2011 13:51:48 +0200
625
626 libpve-access-control (0.1) unstable; urgency=low
627
628 * first dummy package - no functionality
629
630 -- Proxmox Support Team <support@proxmox.com> Thu, 09 Jul 2009 16:03:00 +0200
631