]> git.proxmox.com Git - pve-access-control.git/blob - debian/changelog
bump version to 6.0-4
[pve-access-control.git] / debian / changelog
1 libpve-access-control (6.0-4) pve; urgency=medium
2
3 * ticket: use clinfo to get cluster name
4
5 * ldaps: add sslversion configuration property to support TLS 1.1 to 1.3 as
6 SSL version
7
8 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2019 11:55:11 +0100
9
10 libpve-access-control (6.0-3) pve; urgency=medium
11
12 * fix #2433: increase possible TFA secret length
13
14 * parse user configuration: correctly parse group names in ACLs, for users
15 which begin their name with an @
16
17 * sort user.cfg entries alphabetically
18
19 -- Proxmox Support Team <support@proxmox.com> Tue, 29 Oct 2019 08:52:23 +0100
20
21 libpve-access-control (6.0-2) pve; urgency=medium
22
23 * improve CSRF verification compatibility with newer PVE
24
25 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Jun 2019 20:24:35 +0200
26
27 libpve-access-control (6.0-1) pve; urgency=medium
28
29 * ticket: properly verify exactly 5 minute old tickets
30
31 * use hmac_sha256 instead of sha1 for CSRF token generation
32
33 -- Proxmox Support Team <support@proxmox.com> Mon, 24 Jun 2019 18:14:45 +0200
34
35 libpve-access-control (6.0-0+1) pve; urgency=medium
36
37 * bump for Debian buster
38
39 * fix #2079: add periodic auth key rotation
40
41 -- Proxmox Support Team <support@proxmox.com> Tue, 21 May 2019 21:31:15 +0200
42
43 libpve-access-control (5.1-10) unstable; urgency=medium
44
45 * add /access/user/{id}/tfa api call to get tfa types
46
47 -- Proxmox Support Team <support@proxmox.com> Wed, 15 May 2019 16:21:10 +0200
48
49 libpve-access-control (5.1-9) unstable; urgency=medium
50
51 * store the tfa type in user.cfg allowing to get it without proxying the call
52 to a higher priviledged daemon.
53
54 * tfa: realm required TFA should lock out users without TFA configured, as it
55 was done before Proxmox VE 5.4
56
57 -- Proxmox Support Team <support@proxmox.com> Tue, 30 Apr 2019 14:01:00 +0000
58
59 libpve-access-control (5.1-8) unstable; urgency=medium
60
61 * U2F: ensure we save correct public key on registration
62
63 -- Proxmox Support Team <support@proxmox.com> Tue, 09 Apr 2019 12:47:12 +0200
64
65 libpve-access-control (5.1-7) unstable; urgency=medium
66
67 * verify_ticket: allow general non-challenge tfa to be run as two step
68 call
69
70 -- Proxmox Support Team <support@proxmox.com> Mon, 08 Apr 2019 16:56:14 +0200
71
72 libpve-access-control (5.1-6) unstable; urgency=medium
73
74 * more general 2FA configuration via priv/tfa.cfg
75
76 * add u2f api endpoints
77
78 * delete TFA entries when deleting a user
79
80 * allow users to change their TOTP settings
81
82 -- Proxmox Support Team <support@proxmox.com> Wed, 03 Apr 2019 13:40:26 +0200
83
84 libpve-access-control (5.1-5) unstable; urgency=medium
85
86 * fix vnc ticket verification without authkey lifetime
87
88 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Mar 2019 10:43:17 +0100
89
90 libpve-access-control (5.1-4) unstable; urgency=medium
91
92 * fix #1891: Add zsh command completion for pveum
93
94 * ground work to fix #2079: add periodic auth key rotation. Not yet enabled
95 to avoid issues on upgrade, will be enabled with 6.0
96
97 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Mar 2019 09:12:05 +0100
98
99 libpve-access-control (5.1-3) unstable; urgency=medium
100
101 * api/ticket: move getting cluster name into an eval
102
103 -- Proxmox Support Team <support@proxmox.com> Thu, 29 Nov 2018 12:59:36 +0100
104
105 libpve-access-control (5.1-2) unstable; urgency=medium
106
107 * fix #1998: correct return properties for read_role
108
109 -- Proxmox Support Team <support@proxmox.com> Fri, 23 Nov 2018 14:22:40 +0100
110
111 libpve-access-control (5.1-1) unstable; urgency=medium
112
113 * pveum: introduce sub-commands
114
115 * register userid with completion
116
117 * fix #233: return cluster name on successful login
118
119 -- Proxmox Support Team <support@proxmox.com> Thu, 15 Nov 2018 09:34:47 +0100
120
121 libpve-access-control (5.0-8) unstable; urgency=medium
122
123 * fix #1612: ldap: make 2nd server work with bind domains again
124
125 * fix an error message where passing a bad pool id to an API function would
126 make it complain about a wrong group name instead
127
128 * fix the API-returned permission list so that the GUI knows to show the
129 'Permissions' tab for a storage to an administrator apart from root@pam
130
131 -- Proxmox Support Team <support@proxmox.com> Thu, 18 Jan 2018 13:34:50 +0100
132
133 libpve-access-control (5.0-7) unstable; urgency=medium
134
135 * VM.Snapshot.Rollback privilege added
136
137 * api: check for special roles before locking the usercfg
138
139 * fix #1501: pveum: die when deleting special role
140
141 * API/ticket: rework coarse grained permission computation
142
143 -- Proxmox Support Team <support@proxmox.com> Thu, 5 Oct 2017 11:27:48 +0200
144
145 libpve-access-control (5.0-6) unstable; urgency=medium
146
147 * Close #1470: Add server ceritifcate verification for AD and LDAP via the
148 'verify' option. For compatibility reasons this defaults to off for now,
149 but that might change with future updates.
150
151 * AD, LDAP: Add ability to specify a CA path or file, and a client
152 certificate via the 'capath', 'cert' and 'certkey' options.
153
154 -- Proxmox Support Team <support@proxmox.com> Tue, 08 Aug 2017 11:56:38 +0200
155
156 libpve-access-control (5.0-5) unstable; urgency=medium
157
158 * change from dpkg-deb to dpkg-buildpackage
159
160 -- Proxmox Support Team <support@proxmox.com> Thu, 22 Jun 2017 09:12:37 +0200
161
162 libpve-access-control (5.0-4) unstable; urgency=medium
163
164 * PVE/CLI/pveum.pm: call setup_default_cli_env()
165
166 * PVE/Auth/PVE.pm: encode uft8 password before calling crypt
167
168 * check_api2_permissions: avoid warning about uninitialized value
169
170 -- Proxmox Support Team <support@proxmox.com> Tue, 02 May 2017 11:58:15 +0200
171
172 libpve-access-control (5.0-3) unstable; urgency=medium
173
174 * use new PVE::OTP class from pve-common
175
176 * use new PVE::Tools::encrypt_pw from pve-common
177
178 -- Proxmox Support Team <support@proxmox.com> Thu, 30 Mar 2017 17:45:55 +0200
179
180 libpve-access-control (5.0-2) unstable; urgency=medium
181
182 * encrypt_pw: avoid '+' for crypt salt
183
184 -- Proxmox Support Team <support@proxmox.com> Thu, 30 Mar 2017 08:54:10 +0200
185
186 libpve-access-control (5.0-1) unstable; urgency=medium
187
188 * rebuild for PVE 5.0
189
190 -- Proxmox Support Team <support@proxmox.com> Mon, 6 Mar 2017 13:42:01 +0100
191
192 libpve-access-control (4.0-23) unstable; urgency=medium
193
194 * use new PVE::Ticket class
195
196 -- Proxmox Support Team <support@proxmox.com> Thu, 19 Jan 2017 13:42:06 +0100
197
198 libpve-access-control (4.0-22) unstable; urgency=medium
199
200 * RPCEnvironment: removed check_volume_access() to avoid cyclic dependency
201 (moved to PVE::Storage)
202
203 * PVE::PCEnvironment: use new PVE::RESTEnvironment as base class
204
205 -- Proxmox Support Team <support@proxmox.com> Thu, 19 Jan 2017 09:12:04 +0100
206
207 libpve-access-control (4.0-21) unstable; urgency=medium
208
209 * setup_default_cli_env: expect $class as first parameter
210
211 -- Proxmox Support Team <support@proxmox.com> Thu, 12 Jan 2017 13:54:27 +0100
212
213 libpve-access-control (4.0-20) unstable; urgency=medium
214
215 * PVE/RPCEnvironment.pm: new function setup_default_cli_env
216
217 * PVE/API2/Domains.pm: fix property description
218
219 * use new repoman for upload target
220
221 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Jan 2017 12:13:26 +0100
222
223 libpve-access-control (4.0-19) unstable; urgency=medium
224
225 * Close #833: ldap: non-anonymous bind support
226
227 * don't import 'RFC' from MIME::Base32
228
229 -- Proxmox Support Team <support@proxmox.com> Fri, 05 Aug 2016 13:09:08 +0200
230
231 libpve-access-control (4.0-18) unstable; urgency=medium
232
233 * fix #1062: recognize base32 otp keys again
234
235 -- Proxmox Support Team <support@proxmox.com> Thu, 21 Jul 2016 08:43:18 +0200
236
237 libpve-access-control (4.0-17) unstable; urgency=medium
238
239 * drop oathtool and libdigest-hmac-perl dependencies
240
241 -- Proxmox Support Team <support@proxmox.com> Mon, 11 Jul 2016 12:03:22 +0200
242
243 libpve-access-control (4.0-16) unstable; urgency=medium
244
245 * use pve-doc-generator to generate man pages
246
247 -- Proxmox Support Team <support@proxmox.com> Fri, 08 Apr 2016 07:06:05 +0200
248
249 libpve-access-control (4.0-15) unstable; urgency=medium
250
251 * Fix uninitialized warning when shadow.cfg does not exist
252
253 -- Proxmox Support Team <support@proxmox.com> Fri, 01 Apr 2016 07:10:57 +0200
254
255 libpve-access-control (4.0-14) unstable; urgency=medium
256
257 * Add is_worker to RPCEnvironment
258
259 -- Proxmox Support Team <support@proxmox.com> Tue, 15 Mar 2016 16:47:34 +0100
260
261 libpve-access-control (4.0-13) unstable; urgency=medium
262
263 * fix #916: allow HTTPS to access custom yubico url
264
265 -- Proxmox Support Team <support@proxmox.com> Mon, 14 Mar 2016 11:39:23 +0100
266
267 libpve-access-control (4.0-12) unstable; urgency=medium
268
269 * Catch certificate errors instead of segfaulting
270
271 -- Proxmox Support Team <support@proxmox.com> Wed, 09 Mar 2016 14:41:01 +0100
272
273 libpve-access-control (4.0-11) unstable; urgency=medium
274
275 * Fix #861: use safer sprintf formatting
276
277 -- Proxmox Support Team <support@proxmox.com> Fri, 08 Jan 2016 12:52:39 +0100
278
279 libpve-access-control (4.0-10) unstable; urgency=medium
280
281 * Auth::LDAP, Auth::AD: ipv6 support
282
283 -- Proxmox Support Team <support@proxmox.com> Thu, 03 Dec 2015 12:09:32 +0100
284
285 libpve-access-control (4.0-9) unstable; urgency=medium
286
287 * pveum: implement bash completion
288
289 -- Proxmox Support Team <support@proxmox.com> Thu, 01 Oct 2015 17:22:52 +0200
290
291 libpve-access-control (4.0-8) unstable; urgency=medium
292
293 * remove_storage_access: cleanup of access permissions for removed storage
294
295 -- Proxmox Support Team <support@proxmox.com> Wed, 19 Aug 2015 15:39:15 +0200
296
297 libpve-access-control (4.0-7) unstable; urgency=medium
298
299 * new helper to remove access permissions for removed VMs
300
301 -- Proxmox Support Team <support@proxmox.com> Fri, 14 Aug 2015 07:57:02 +0200
302
303 libpve-access-control (4.0-6) unstable; urgency=medium
304
305 * improve parse_user_config, parse_shadow_config
306
307 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jul 2015 13:14:33 +0200
308
309 libpve-access-control (4.0-5) unstable; urgency=medium
310
311 * pveum: check for $cmd being defined
312
313 -- Proxmox Support Team <support@proxmox.com> Wed, 10 Jun 2015 10:40:15 +0200
314
315 libpve-access-control (4.0-4) unstable; urgency=medium
316
317 * use activate-noawait triggers
318
319 -- Proxmox Support Team <support@proxmox.com> Mon, 01 Jun 2015 12:25:31 +0200
320
321 libpve-access-control (4.0-3) unstable; urgency=medium
322
323 * IPv6 fixes
324
325 * non-root buildfix
326
327 -- Proxmox Support Team <support@proxmox.com> Wed, 27 May 2015 11:15:44 +0200
328
329 libpve-access-control (4.0-2) unstable; urgency=medium
330
331 * trigger pve-api-updates event
332
333 -- Proxmox Support Team <support@proxmox.com> Tue, 05 May 2015 15:06:38 +0200
334
335 libpve-access-control (4.0-1) unstable; urgency=medium
336
337 * bump version for Debian Jessie
338
339 -- Proxmox Support Team <support@proxmox.com> Thu, 26 Feb 2015 11:22:01 +0100
340
341 libpve-access-control (3.0-16) unstable; urgency=low
342
343 * root@pam can now be disabled in GUI.
344
345 -- Proxmox Support Team <support@proxmox.com> Fri, 30 Jan 2015 06:20:22 +0100
346
347 libpve-access-control (3.0-15) unstable; urgency=low
348
349 * oath: add 'step' and 'digits' option
350
351 -- Proxmox Support Team <support@proxmox.com> Wed, 23 Jul 2014 06:59:52 +0200
352
353 libpve-access-control (3.0-14) unstable; urgency=low
354
355 * add oath two factor auth
356
357 * add oathkeygen binary to generate keys for oath
358
359 * add yubico two factor auth
360
361 * dedend on oathtool
362
363 * depend on libmime-base32-perl
364
365 * allow to write builtin auth domains config (comment/tfa/default)
366
367 -- Proxmox Support Team <support@proxmox.com> Thu, 17 Jul 2014 13:09:56 +0200
368
369 libpve-access-control (3.0-13) unstable; urgency=low
370
371 * use correct connection string for AD auth
372
373 -- Proxmox Support Team <support@proxmox.com> Thu, 22 May 2014 07:16:09 +0200
374
375 libpve-access-control (3.0-12) unstable; urgency=low
376
377 * add dummy API for GET /access/ticket (useful to generate login pages)
378
379 -- Proxmox Support Team <support@proxmox.com> Wed, 30 Apr 2014 14:47:56 +0200
380
381 libpve-access-control (3.0-11) unstable; urgency=low
382
383 * Sets common hot keys for spice client
384
385 -- Proxmox Support Team <support@proxmox.com> Fri, 31 Jan 2014 10:24:28 +0100
386
387 libpve-access-control (3.0-10) unstable; urgency=low
388
389 * implement helper to generate SPICE remote-viewer configuration
390
391 * depend on libnet-ssleay-perl
392
393 -- Proxmox Support Team <support@proxmox.com> Tue, 10 Dec 2013 10:45:08 +0100
394
395 libpve-access-control (3.0-9) unstable; urgency=low
396
397 * prevent user enumeration attacks
398
399 * allow dots in access paths
400
401 -- Proxmox Support Team <support@proxmox.com> Mon, 18 Nov 2013 09:06:38 +0100
402
403 libpve-access-control (3.0-8) unstable; urgency=low
404
405 * spice: use lowercase hostname in ticktet signature
406
407 -- Proxmox Support Team <support@proxmox.com> Mon, 28 Oct 2013 08:11:57 +0100
408
409 libpve-access-control (3.0-7) unstable; urgency=low
410
411 * check_volume_access : use parse_volname instead of path, and remove
412 path related code.
413
414 * use warnings instead of global -w flag.
415
416 -- Proxmox Support Team <support@proxmox.com> Tue, 01 Oct 2013 12:35:53 +0200
417
418 libpve-access-control (3.0-6) unstable; urgency=low
419
420 * use shorter spiceproxy tickets
421
422 -- Proxmox Support Team <support@proxmox.com> Fri, 19 Jul 2013 12:39:09 +0200
423
424 libpve-access-control (3.0-5) unstable; urgency=low
425
426 * add code to generate tickets for SPICE
427
428 -- Proxmox Support Team <support@proxmox.com> Wed, 26 Jun 2013 13:08:32 +0200
429
430 libpve-access-control (3.0-4) unstable; urgency=low
431
432 * moved add_vm_to_pool/remove_vm_from_pool from qemu-server
433
434 -- Proxmox Support Team <support@proxmox.com> Tue, 14 May 2013 11:56:54 +0200
435
436 libpve-access-control (3.0-3) unstable; urgency=low
437
438 * Add new role PVETemplateUser (and VM.Clone priviledge)
439
440 -- Proxmox Support Team <support@proxmox.com> Mon, 29 Apr 2013 11:42:15 +0200
441
442 libpve-access-control (3.0-2) unstable; urgency=low
443
444 * remove CGI.pm related code (pveproxy does not need that)
445
446 -- Proxmox Support Team <support@proxmox.com> Mon, 15 Apr 2013 12:34:23 +0200
447
448 libpve-access-control (3.0-1) unstable; urgency=low
449
450 * bump version for wheezy release
451
452 -- Proxmox Support Team <support@proxmox.com> Fri, 15 Mar 2013 08:07:06 +0100
453
454 libpve-access-control (1.0-26) unstable; urgency=low
455
456 * check_volume_access: fix access permissions for backup files
457
458 -- Proxmox Support Team <support@proxmox.com> Thu, 28 Feb 2013 10:00:14 +0100
459
460 libpve-access-control (1.0-25) unstable; urgency=low
461
462 * add VM.Snapshot permission
463
464 -- Proxmox Support Team <support@proxmox.com> Mon, 10 Sep 2012 09:23:32 +0200
465
466 libpve-access-control (1.0-24) unstable; urgency=low
467
468 * untaint path (allow root to restore arbitrary paths)
469
470 -- Proxmox Support Team <support@proxmox.com> Wed, 06 Jun 2012 13:06:34 +0200
471
472 libpve-access-control (1.0-23) unstable; urgency=low
473
474 * correctly compute GUI capabilities (consider pools)
475
476 -- Proxmox Support Team <support@proxmox.com> Wed, 30 May 2012 08:47:23 +0200
477
478 libpve-access-control (1.0-22) unstable; urgency=low
479
480 * new plugin architecture for Auth modules, minor API change for Auth
481 domains (new 'delete' parameter)
482
483 -- Proxmox Support Team <support@proxmox.com> Wed, 16 May 2012 07:21:44 +0200
484
485 libpve-access-control (1.0-21) unstable; urgency=low
486
487 * do not allow user names including slash
488
489 -- Proxmox Support Team <support@proxmox.com> Tue, 24 Apr 2012 10:07:47 +0200
490
491 libpve-access-control (1.0-20) unstable; urgency=low
492
493 * add ability to fork cli workers in background
494
495 -- Proxmox Support Team <support@proxmox.com> Wed, 18 Apr 2012 08:28:20 +0200
496
497 libpve-access-control (1.0-19) unstable; urgency=low
498
499 * return set of privileges on login - can be used to adopt GUI
500
501 -- Proxmox Support Team <support@proxmox.com> Tue, 17 Apr 2012 10:25:10 +0200
502
503 libpve-access-control (1.0-18) unstable; urgency=low
504
505 * fix bug #151: corretly parse username inside ticket
506
507 * fix bug #152: allow user to change his own password
508
509 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Apr 2012 09:40:15 +0200
510
511 libpve-access-control (1.0-17) unstable; urgency=low
512
513 * set propagate flag by default
514
515 -- Proxmox Support Team <support@proxmox.com> Thu, 01 Mar 2012 12:40:19 +0100
516
517 libpve-access-control (1.0-16) unstable; urgency=low
518
519 * add 'pveum passwd' method
520
521 -- Proxmox Support Team <support@proxmox.com> Thu, 23 Feb 2012 12:05:25 +0100
522
523 libpve-access-control (1.0-15) unstable; urgency=low
524
525 * Add VM.Config.CDROM privilege to PVEVMUser rule
526
527 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 11:44:23 +0100
528
529 libpve-access-control (1.0-14) unstable; urgency=low
530
531 * fix buf in userid-param permission check
532
533 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 10:52:35 +0100
534
535 libpve-access-control (1.0-13) unstable; urgency=low
536
537 * allow more characters in ldap base_dn attribute
538
539 -- Proxmox Support Team <support@proxmox.com> Wed, 22 Feb 2012 06:17:02 +0100
540
541 libpve-access-control (1.0-12) unstable; urgency=low
542
543 * allow more characters with realm IDs
544
545 -- Proxmox Support Team <support@proxmox.com> Mon, 20 Feb 2012 08:50:33 +0100
546
547 libpve-access-control (1.0-11) unstable; urgency=low
548
549 * fix bug in exec_api2_perm_check
550
551 -- Proxmox Support Team <support@proxmox.com> Wed, 15 Feb 2012 07:06:30 +0100
552
553 libpve-access-control (1.0-10) unstable; urgency=low
554
555 * fix ACL group name parser
556
557 * changed 'pveum aclmod' command line arguments
558
559 -- Proxmox Support Team <support@proxmox.com> Tue, 14 Feb 2012 12:08:02 +0100
560
561 libpve-access-control (1.0-9) unstable; urgency=low
562
563 * fix bug in check_volume_access (fixes vzrestore)
564
565 -- Proxmox Support Team <support@proxmox.com> Mon, 13 Feb 2012 09:56:37 +0100
566
567 libpve-access-control (1.0-8) unstable; urgency=low
568
569 * fix return value for empty ACL list.
570
571 -- Proxmox Support Team <support@proxmox.com> Fri, 10 Feb 2012 11:25:04 +0100
572
573 libpve-access-control (1.0-7) unstable; urgency=low
574
575 * fix bug #85: allow root@pam to generate tickets for other users
576
577 -- Proxmox Support Team <support@proxmox.com> Tue, 17 Jan 2012 06:40:18 +0100
578
579 libpve-access-control (1.0-6) unstable; urgency=low
580
581 * API change: allow to filter enabled/disabled users.
582
583 -- Proxmox Support Team <support@proxmox.com> Wed, 11 Jan 2012 12:30:37 +0100
584
585 libpve-access-control (1.0-5) unstable; urgency=low
586
587 * add a way to return file changes (diffs): set_result_changes()
588
589 -- Proxmox Support Team <support@proxmox.com> Tue, 20 Dec 2011 11:18:48 +0100
590
591 libpve-access-control (1.0-4) unstable; urgency=low
592
593 * new environment type for ha agents
594
595 -- Proxmox Support Team <support@proxmox.com> Tue, 13 Dec 2011 10:08:53 +0100
596
597 libpve-access-control (1.0-3) unstable; urgency=low
598
599 * add support for delayed parameter parsing - We need that to disable
600 file upload for normal API request (avoid DOS attacs)
601
602 -- Proxmox Support Team <support@proxmox.com> Fri, 02 Dec 2011 09:56:10 +0100
603
604 libpve-access-control (1.0-2) unstable; urgency=low
605
606 * fix bug in fork_worker
607
608 -- Proxmox Support Team <support@proxmox.com> Tue, 11 Oct 2011 08:37:05 +0200
609
610 libpve-access-control (1.0-1) unstable; urgency=low
611
612 * allow '-' in permission paths
613
614 * bump version to 1.0
615
616 -- Proxmox Support Team <support@proxmox.com> Mon, 27 Jun 2011 13:51:48 +0200
617
618 libpve-access-control (0.1) unstable; urgency=low
619
620 * first dummy package - no functionality
621
622 -- Proxmox Support Team <support@proxmox.com> Thu, 09 Jul 2009 16:03:00 +0200
623