From: Russ Allbery Date: Mon, 22 Jul 2013 20:52:33 +0000 (-0700) Subject: Add changelog for upstream security patches X-Git-Tag: debian/1.6.1-3+deb7u1~5 X-Git-Url: https://git.michaelhowe.org/gitweb/?a=commitdiff_plain;h=0dca405c33d0bc9ae87aa59262edb4084834f8fd;p=packages%2Fo%2Fopenafs.git Add changelog for upstream security patches --- diff --git a/debian/changelog b/debian/changelog index 8cf567978..b060be72c 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,19 @@ +openafs (1.6.1-4) UNRELEASED; urgency=high + + * Apply upstream security patches: + - OPENAFS-SA-2013-003: New support for non-DES enctypes in the + long-lived AFS key. This requires deploying rxkad.keytab files on + each server containing all of the encryption types for the cell AFS + key. Once this is deployed on servers, DES will only be used for + the session key. Once deployed on all clients, a stronger security + mechanism will be used that allows the DES keys to be removed from + the AFS principal in the Kerberos KDC (but still uses DES for some + session encryption purposes). (CVE-2013-4134) + - OPENAFS-SA-2013-004: Properly support the -encrypt option in vos, + including with -localauth. (CVE-2013-4135) + + -- Russ Allbery Mon, 22 Jul 2013 13:52:11 -0700 + openafs (1.6.1-3) unstable; urgency=high * Apply upstream security patches: