From 0dca405c33d0bc9ae87aa59262edb4084834f8fd Mon Sep 17 00:00:00 2001 From: Russ Allbery Date: Mon, 22 Jul 2013 13:52:33 -0700 Subject: [PATCH] Add changelog for upstream security patches --- debian/changelog | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/debian/changelog b/debian/changelog index 8cf567978..b060be72c 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3 +1,19 @@ +openafs (1.6.1-4) UNRELEASED; urgency=high + + * Apply upstream security patches: + - OPENAFS-SA-2013-003: New support for non-DES enctypes in the + long-lived AFS key. This requires deploying rxkad.keytab files on + each server containing all of the encryption types for the cell AFS + key. Once this is deployed on servers, DES will only be used for + the session key. Once deployed on all clients, a stronger security + mechanism will be used that allows the DES keys to be removed from + the AFS principal in the Kerberos KDC (but still uses DES for some + session encryption purposes). (CVE-2013-4134) + - OPENAFS-SA-2013-004: Properly support the -encrypt option in vos, + including with -localauth. (CVE-2013-4135) + + -- Russ Allbery Mon, 22 Jul 2013 13:52:11 -0700 + openafs (1.6.1-3) unstable; urgency=high * Apply upstream security patches: -- 2.39.5