Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

krb5-pkinit-1.21.1-8.el9 RPM for x86_64

From CentOS Stream 9 BaseOS for x86_64

Name: krb5-pkinit Distribution: CentOS
Version: 1.21.1 Vendor: CentOS
Release: 8.el9 Build date: Mon May 5 18:28:01 2025
Group: Unspecified Build host: x86-04.stream.rdu2.redhat.com
Size: 127996 Source RPM: krb5-1.21.1-8.el9.src.rpm
Packager: builder@centos.org
Url: https://web.mit.edu/kerberos/www/
Summary: The PKINIT module for Kerberos 5
Kerberos is a network authentication system. The krb5-pkinit
package contains the PKINIT plugin, which allows clients
to obtain initial credentials from a KDC using a private key and a
certificate.

Provides

Requires

License

MIT

Changelog

* Fri Apr 18 2025 Julien Rische <jrische@redhat.com> - 1.21.1-9
  - Do not block HMAC-MD4/5 in FIPS mode
    Resolves: RHEL-88704
  - Don't issue RC4 session keys by default (CVE-2025-3576)
    Resolves: RHEL-88048
  - Add PKINIT paChecksum2 from MS-PKCA v20230920
    Resolves: RHEL-82647
* Tue Mar 25 2025 Julien Rische <jrische@redhat.com> - 1.21.1-7
  - Add dedicated tests sub-package
* Wed Jan 29 2025 Julien Rische <jrische@redhat.com> - 1.21.1-6
  - Prevent overflow when calculating ulog block size (CVE-2025-24528)
    Resolves: RHEL-76759
* Fri Jan 17 2025 Julien Rische <jrische@redhat.com> - 1.21.1-5
  - Support PKCS11 EC client certs in PKINIT
    Resolves: RHEL-74374
  - kdb5_util: fix DB entry flags on modification
    Resolves: RHEL-56059
  - Add ECDH support for PKINIT (RFC5349)
    Resolves: RHEL-4902
* Thu Oct 17 2024 Julien Rische <jrische@redhat.com> - 1.21.1-4
  - libkrad: implement support for Message-Authenticator (CVE-2024-3596)
    Resolves: RHEL-55423
  - Fix various issues detected by static analysis
    Resolves: RHEL-58216
  - Remove RSA protocol for PKINIT
    Resolves: RHEL-15323
* Fri Jul 05 2024 Julien Rische <jrische@redhat.com> - 1.21.1-3
  - CVE-2024-37370 CVE-2024-37371
    Fix vulnerabilities in GSS message token handling
    Resolves: RHEL-45402 RHEL-45392
* Wed Mar 20 2024 Julien Rische <jrische@redhat.com> - 1.21.1-2
  - Fix memory leak in GSSAPI interface
    Resolves: RHEL-27251
  - Fix memory leak in PMAP RPC interface
    Resolves: RHEL-27245
  - Fix memory leak in failing UTF-8 to UTF-16 re-encoding for PAC
    Resolves: RHEL-27253
  - Make TCP waiting time configurable
    Resolves: RHEL-17132
* Tue Aug 08 2023 Julien Rische <jrische@redhat.com> - 1.21.1-1
  - New upstream version (1.21.1)
  - Fix double-free in KDC TGS processing (CVE-2023-39975)
  - Add support for "pac_privsvr_enctype" KDB string attribute
    Resolves: rhbz#2060421
* Thu Jun 08 2023 Julien Rische <jrische@redhat.com> - 1.20.1-9
  - Do not disable PKINIT if some of the well-known DH groups are unavailable
    Resolves: rhbz#2187722
  - Make PKINIT CMS SHA-1 signature verification available in FIPS mode
    Resolves: rhbz#2155607
  - Allow to set PAC ticket signature as optional
    Resolves: rhbz#2178298

Files

/usr/lib/.build-id
/usr/lib/.build-id/fd
/usr/lib/.build-id/fd/b3a5eba24ced371db784ac7f9c4fdfed3ad222
/usr/lib64/krb5
/usr/lib64/krb5/plugins
/usr/lib64/krb5/plugins/preauth
/usr/lib64/krb5/plugins/preauth/pkinit.so


Generated by rpm2html 1.8.1

Fabrice Bellet, Thu Jun 19 01:53:52 2025