Commit graph

2897 commits

Author SHA1 Message Date
shannonjr
aa464f7c7b Applications for entering PINs or Passphrases. Used in conjunction with
gpg-agent that's part of gnupg-devel
2004-10-23 13:30:10 +00:00
shannonjr
097ee20b32 IPC library used by gnupg-devel. 2004-10-23 13:27:36 +00:00
shannonjr
4015fdc44e Re: pkg/27317 The header gcrypt.h references struct timeval without
including sys/time.h. Added the patch summitted with PR that adds
an include for sys/time.h. Bumped PKGREVISION.
2004-10-23 08:57:33 +00:00
jmmv
d8378b72e0 Sort USE_* variables. 2004-10-20 21:30:13 +00:00
jmmv
3294789b2b Update to 0.7.4:
* Key manager now uses new file chooser dialogs
* For detached signatures, prompt when missing plain text files
* Import/Export to clipboard implemented as copy/paste
* Dragging keys into the key manager import
* All file operations work with gnome-vfs remote URIs (ie: smb, ftp, http,
  etc...)
* Proper sort support for key listings
* Filter support on key manager and recipients windows
* Multiple file and folder support in nautilus
* Fixed MIME type integration with nautilus
* Rework the 'Key Properties' dialog
* Can now change primary user id, or delete user ids on a secret key
* Can sign individual user ids on a key
* Can now list signatures on a key
* Respects 'Encrypt to Self' option when encrypting files or text
* Gnome HIG (Human Interface Guidelines) compliancy fixes
* gedit plugin for encrypting/decrypting/signing/verifying text
* 'Seahorse Agent' for caching passwords on system
* Updated to a new version of GPGME (1.0)
* Fixed startup crashers
* New Key generation assistant (wizard/druid)
2004-10-20 20:45:55 +00:00
jmmv
a7e926f8f6 Update to 1.0.0:
* Version 1.0.0!  We are proud to present you with a thoroughly
  tested and stable version of the GPGME library.  A big Thank You!
  to all the people who made this possible.

  The development will be branched into a stable 1.x.y series and the
  head.

* The gpgme.m4 macro supports checking the API version.  Just prepend
  it to the required version string, separated by a colon.  For
  example, this release has the version "1:1.0.0".  The last release
  to which this version is (mostly) ABI compatible is "1:0.4.2",
  which is the default required version.
2004-10-20 19:09:11 +00:00
minskim
112b811bd0 This package never uses the gettext library directly. The dependency
on gettext-lib should be taken care of by libgpg-error.
2004-10-19 17:43:23 +00:00
minskim
c2d624c720 Include gettext-lib/buildlink3.mk so that libtoolized packages
depending on this package can link correctly with pkgsrc libintl.
2004-10-19 17:40:37 +00:00
adrianp
e7ec73d073 Note addition of msf-2.2
Fix entry for previous addition of InlineEgg
2004-10-19 16:42:03 +00:00
adrianp
887d7af91f The Metasploit Framework is an advanced open-source platform for developing,
testing, and using exploit code. This release includes 18 exploits and 27
payloads; many of these exploits are either the only ones publicly available
or just much more reliable than anything else out there. The Framework will
run on any modern system that has a working Perl interpreter, the Windows
installer includes a slimmed-down version of the Cygwin environment.
2004-10-19 16:38:22 +00:00
reed
e0d44887c9 Don't list the info/ files. This uses INFO_FILES so they
are automatically registered.
2004-10-19 04:03:05 +00:00
reed
02f75e7d15 This needs a yacc.
So used:
USE_GNU_TOOLS+=                yacc
(But it didn't necessarily need a GNU version.)
2004-10-19 04:01:13 +00:00
ben
23de6ec40d Add dependency on gettext-lib to provide libintl for platforms that do
not have it built in.  May address PR#27292.
2004-10-19 03:24:38 +00:00
adrianp
e447344c05 - Update nikto to 1.34
- No CHANGELOG available
2004-10-16 11:55:27 +00:00
minskim
ea70f07d61 This package requires GNU awk. 2004-10-15 20:54:02 +00:00
minskim
551bf9b517 Update libgpg-error to 1.0. Patch submitted by shannonjr@ and
slightly modified by me.

Changes since 0.6:
 * Ported to Solaris 2.8.

 * Added a new error source GPG_ERR_SOURCE_GSTI, and new error
   codes GPG_ERR_PROTOCOL_VIOLATION and GPG_ERR_INV_MAC for this
   source.

 * Interface changes relative to the 0.7 release:
   GPG_ERR_SOURCE_GSTI		NEW
   GPG_ERR_PROTOCOL_VIOLATION	NEW
   GPG_ERR_INV_MAC		NEW
   GPG_ERR_INV_REQUEST          NEW

 * libgpg-error can be built on systems where the errno macros do not
   evaluate to plain numbers, but expressions.  If you want to
   cross-compile, you might have to set CC_FOR_BUILD, though.

 * A new tool gpg-error to convert error numbers into symbols into
   strings is provided.

 * Interface changes relative to the 0.6 release:
   GPG_ERR_LOCALE_PROBLEM          NEW
   GPG_ERR_NOT_LOCKED              NEW
2004-10-15 18:21:56 +00:00
gavan
edd65d2726 Find OpenSSL in the correct location. 2004-10-14 16:43:15 +00:00
tv
7c79d95be1 You're going to install those .la files, and you're going to like it, Mister.
(Fixes build breakage because the .la files are needed by the new
libtoolize-plist logic.)
2004-10-14 15:21:25 +00:00
ben
bcd2b30a96 Uncomment erroneously commented out lines in Makefile. 2004-10-13 20:11:16 +00:00
ben
9867757bd4 Update fprot-workstation-bin to version 4.4.7, and add SunOS support.
Addresses PR#27254

Version 4.4.7 contains various bugfixes and improvements to the
documentation and software.
o       A critical bug fixed in scan-mail.pl.
o       Detection of JPG exploits has been added.
o       A file descriptor leak has been fixed in f-protd.
o       A minor bug in f-protd related to CPU hogging under certain
        conditions has been fixed.
o       A log level has been added (further information can be found in
        the man pages).
2004-10-13 20:07:55 +00:00
reed
62071c8b2f RCD_SCRIPTS_EXAMPLEDIR was just changed to be a relative directory
under ${PREFIX} instead of being an absolute path.

So fix the references using RCD_SCRIPTS_EXAMPLEDIR to be
${PREFIX}/${RCD_SCRIPTS_EXAMPLEDIR}.

This should have no changes to use before.

Please note that the MESSAGE files in most cases are wrong in the
first place. We have automated mechanisms and could have an automated
message for explaining rc.d script usage. (This is something to do!)
2004-10-11 22:14:51 +00:00
shannonjr
748155ca2e 1) Taking over maintainance of package on agreement with previous
maintainer Klaus Klein.
2) Update to version 0.9.7 to satisfy version requirements for, soon to
   be committed, gnupg2 (1.9.10) that provides SMIME support.
Libksba is a library to make the tasks of working with X.509 certificates,
CMS data and related objects more easy. It a highlevel interface to the
implemented protocols and presents the data in a consistent way.
2004-10-11 09:46:44 +00:00
tv
f86fc1d704 This is a libtool package. .la files go in the PLIST. 2004-10-07 16:27:13 +00:00
jlam
17c3aafac1 * Make PKGSRC_TOPDIR a private variable by renaming it to _PKGSRC_TOPDIR,
as it's only used internally by bsd.prefs.mk.

* Make _PKGSRCDIR a public variable by renaming it to PKGSRCDIR.
  Also, generate its value from ${_PKGSRC_TOPDIR} so it's less fragile
  than the old method of stripping off the last two components of
  ${.CURDIR}.  PKGSRCDIR may now be used after bsd.prefs.mk is defined.

* Change all references to _PKGSRCDIR to PKGSRCDIR.
2004-10-07 02:01:37 +00:00
gavan
9a103e8c28 Undefine open in ndbm_wrap.c. This fixes a build problem on Solaris. 2004-10-06 17:18:32 +00:00
wiz
0bb0bdc5bc Update to 20041004, closes PR 27161:
2004-10-03 22:04  nolan

      * src/: mypasswordsafe.ui.h, safedragobject.cpp,
        safedragobject.hpp, safelistview.cpp, safelistview.hpp: Did some
        work so MyPS wouldn't segfault when dragging onto another app

2004-10-03 22:03  nolan

      * MyPasswordSafe.pro: Removed spaces added by Designer
2004-10-06 14:23:00 +00:00
martti
a6618f7903 Moved corkscrew from security to net 2004-10-06 11:23:55 +00:00
grant
24dccf2ea5 rename cfg+ directory to libcfg+ so it matches the PKGNAME. 2004-10-06 10:17:06 +00:00
wiz
7bc8147566 Add and enable MyPasswordSafe. 2004-10-06 00:14:23 +00:00
wiz
c4db2c018c Initial import of MyPasswordSafe-20041001:
MyPasswordSafe is a straight-forward, easy-to-use password manager
that maintains compatibility with Password Safe files.  MyPasswordSafe
has the following features:
  * Safes are encrypted when they are stored to disk.
  * Passwords never have to be seen, because they are copied to
    the clipboard
  * Random passwords can be generated.
  * Window size, position, and column widths are remembered.
  * Passwords remain encrypted until they need to be decrypted at
    the dialog and file levels.
  * A safe can be made active so it will always be opened when
    MyPasswordSafe starts.
  * Supports Unicode in the safes
  * Languages supported: English and French
2004-10-06 00:13:19 +00:00
tron
ad52be7ad8 Fix dependences broken by package revision bump madness. Bump package
revision of this package, too.
2004-10-05 09:10:09 +00:00
adrianp
9fc77e69ef On certain OS'es (e.g. Darwin) CPP can be defined as "gcc -E -no-cpp-precomp".
So when it comes to do the building of the package this causes it to fail if
it is not enclosed in double-quotes.
2004-10-04 17:25:51 +00:00
tv
bbfaca0030 BUILDLINK_DEPENDS should, in nearly every case, be a dewey depends, not a
precise version.
2004-10-03 19:59:38 +00:00
tv
c487cb967a Libtool fix for PR pkg/26633, and other issues. Update libtool to 1.5.10
in the process.  (More information on tech-pkg.)

Bump PKGREVISION and BUILDLINK_DEPENDS of all packages using libtool and
installing .la files.

Bump PKGREVISION (only) of all packages depending directly on the above
via a buildlink3 include.
2004-10-03 00:12:51 +00:00
grant
eaa75b4082 there will not be a NetBSD-1.[7-9] but will be a NetBSD-[2-9].*
adjust patterns used in ONLY_FOR_PLATFORM/NOT_FOR_PLATFORM to reflect
this.
2004-10-01 10:37:32 +00:00
adrianp
bc374450b0 Update chkrootkit to 0.44
- Fix false positive on NetBSD for "login".  Thanks to Richard Ibbotson for
  helping sort this out.
- Install main shell script and documentation.

chkwtmp.c
	fix: del counter (Thanks to Dietrich Raisin)
chkproc.c
	fix: better support for Linux threads
chkrootkit;
	new rootkit detected: Madalin rootkit
	top and find tests improved for Suse Linux
	more ports added in the bindshell test
	fix: FreeBSD false positives
	fix: slammer detection
	lots of minor bug fixes
2004-09-28 10:41:59 +00:00
rh
2bbbc69209 Remove leftover patch that is no longer used. 2004-09-27 01:30:52 +00:00
rh
97534cc53f Update gnustep-ssl to 1.10.0. No major changes, this just syncs the
library changes for gnustep-base 1.10.0.
2004-09-24 01:58:53 +00:00
kim
03b17dde93 Pass ${MAKE_ENV} when calling ${MAKE}, so that rules in /etc/mk.conf
(and possibly elsewhere) behave as expected.  Without this, the build
framework thinks you are not building a package, but base.
2004-09-22 16:14:37 +00:00
adrianp
c201f7801a - Update to 2.0.5
- ok'ed wiz@, snj@
- Grab maintainership
- Remove DIST_SUBDIR directive

Verison 2.0.5:
--------------
  [BUG] OpenBSD compile fix.
  Support for 802.1Q.
  New signatures.
  Speel-chceked teh docuhmentation!
  Absolutely experimental support for open connection fingerprinting (-O).
  Synced manpage and documentation.
  Added several -O signatures.
2004-09-22 09:44:57 +00:00
jlam
1a280185e1 Mechanical changes to package PLISTs to make use of LIBTOOLIZE_PLIST.
All library names listed by *.la files no longer need to be listed
in the PLIST, e.g., instead of:

	lib/libfoo.a
	lib/libfoo.la
	lib/libfoo.so
	lib/libfoo.so.0
	lib/libfoo.so.0.1

one simply needs:

	lib/libfoo.la

and bsd.pkg.mk will automatically ensure that the additional library
names are listed in the installed package +CONTENTS file.

Also make LIBTOOLIZE_PLIST default to "yes".
2004-09-22 08:09:14 +00:00
martti
994f621439 Added corkscrew 2004-09-22 06:59:59 +00:00
martti
848d6afba1 Corkscrew is a tool for tunneling SSH through HTTP proxies. 2004-09-22 06:59:44 +00:00
jmmv
dfd6aacbb7 Update to 0.4.0. This version corresponds to GNOME 2.8.0.
Changes in version 0.4.0 are:
* Build fix on some systems
* Translation updates

Changes in version 0.3.3 are:
* Translation updates

Changes in version 0.3.2 are:
* New API functions for getting/setting ACL
* Implemented delete keyring operation

Changes in version 0.3.1 are:
* New and updated translations.
* New introduction document
* unlocking the NULL keyring unlocks the default keyring
2004-09-21 16:47:28 +00:00
agc
ab19a6524c Give a bit of leeway in the atime time calculation - the problem is
that, on a large SMP bulk build machine, and occasionally on smaller
less busy machines, we can get a false-postive message in the aide
output because the atime on a group of files can be one second later
than "cur_time", the current time as returned to aide. So allow for
one second's difference in the time calculation.

Bump package revision.
2004-09-21 14:14:27 +00:00
wiz
6a92a83960 Update to 0.1.4, provided by Sergio Jimenez in PR 26974.
Changes since 0.0.8:

* Changes in 0.1.4 (released 2004-08-08)

** Revamp of gnulib compatibility files.

** More translations.
German (by Roland Illig), Basque (by Mikel Olasagasti), French (by
Michel Robitaille), Irish (by Kevin Patrick Scannell), Dutch (by Elros
Cyriatan), Polish (by Jakub Bogusz), Romanian (by Laurentiu Buzdugan),
and Serbian (by Aleksandar Jelenak).

* Changes in 0.1.3 (released 2004-08-04)

** Command line tool support IPv6 (and other protocol families).
Requires that your system has `getaddrinfo'.

** Command line behaviour for gsasl tool improved.
The --client and --imap parameters are now the default.  The --connect
host and port can now be specified directly.  If --authentication-id
is not specified, the username of the user invoking gsasl is used
(i.e., getpwuid(getuid)->pw_name).  Alltogether, this allows simple
usage, as in `gsasl mail.example.com' to connect, via IMAP, to
mail.example.com.

* Changes in 0.1.2 (released 2004-07-16)

** The SMTP mode in `gsasl' should now work.

** Cross compile builds should work.
It should work for any sane cross compile target, but the only tested
platform is uClibc/uClinux on Motorola Coldfire.

** The GNU Readline library is used to read data, if available.

** Passwords read from stdin are not echoed to the terminal.

* Changes in 0.1.1 (released 2004-06-26)

** In the command line client, the default quality of protection is now none.

* Changes in 0.1.0 (released 2004-04-16)

** The library re-licensed to LGPL and distributed as a separate package.
This means a fork of this NEWS file, all the entries below relate to
the combined work of earlier versions.  New entries above does not
document user visible changes for the library ("libgsasl"), for that
see NEWS in the lib/ sub-directory, which is also distributed as a
stand-alone package.

* Changes in 0.0.14 (released 2004-01-22)

** Moved all mechanism specific code into sub-directories of lib/.
Each backend is built into its own library (e.g., libgsasl-plain.so),
to facilitate future possible use of dlopen to dynamically load
backends.

** Moved compatibility files (getopt*) to gl/, and added more (strdup*).

* Changes in 0.0.13 (released 2004-01-17)

** Nettle (the crypto functionality, crypto/) has been updated.
This fixes two portability issues, the new code should work on
platforms that doesn't have inttypes.h and alloca.

* Changes in 0.0.12 (released 2004-01-15)

** Protocol line parser in 'gsasl' tool more reliable.
Earlier it assumed two lines were sent in one packet in one place, and
sent as two packets in another place.

** Various bugfixes.

* Changes in 0.0.11 (released 2004-01-06)

** The client part of CRAM-MD5 now uses SASLprep instead of NFKC.
This aligns with draft-ietf-sasl-crammd5-01.

** The CRAM-MD5 challenge string now conform to the proper syntax.

** The string preparation (SASLprep and trace) functions now work correctly.

** DocBook manuals no longer included.
The reason is that recent DocBook tools from the distribution I use
(Debian) fails with an error.  DocBook manuals may be included in the
future, if I can get the tools to work.

** API and ABI modifications.
GSASL_SASLPREP_ERROR: ADD.

* Changes in 0.0.10 (released 2003-11-22)

** The CRAM-MD5 server now reject invalid passwords.
The logic flaw was introduced in 0.0.9, after blindly making code
changes to shut up valgrind just before the release.

** Various build improvements.
Pkg-config is no longer needed.  GTK-DOC is only used if present.

* Changes in 0.0.9 (released 2003-11-21)

** Command line client can talk to SMTP servers with --smtp.

** DocBook manuals in XML, PDF, PostScript, ASCII and HTML formats included.

** Token parser in DIGEST-MD5 fixed, improve interoperability of DIGEST-MD5.

** Libgcrypt >= 1.1.42 is used if available (for CRAM-MD5 and DIGEST-MD5).
The previous libgcrypt API is no longer supported.

** CRAM-MD5 and DIGEST-MD5 no longer require libgcrypt (but can still use it).
If libgcrypt 1.1.42 or later is not found, it uses a minimalistic
cryptographic library based on Nettle, from crypto/.  Currently only
MD5 and HMAC-MD5 is needed, making a dependence on libgcrypt overkill.

** Listing supported server mechanisms with gsasl_server_mechlist work.

** Autoconf 2.59, Automake 1.8 beta, Libtool CVS used.

** Source code for each SASL mechanism moved to its own sub-directory in lib/.

** The command line interface now uses getopt instead of argp.
The reason is portability, this also means we no longer use gnulib.

** API and ABI modifications.
gsasl_randomize: ADD.
gsasl_md5: ADD.
gsasl_hmac_md5: ADD.

gsasl_hexdump: REMOVED.  Never intended to be exported.

gsasl_step: ADD.
gsasl_step64: ADD.
gsasl_client_step: DEPRECATED: use gsasl_step instead.
gsasl_server_step: DEPRECATED: use gsasl_step instead.
gsasl_client_step_base64: DEPRECATED: use gsasl_step64 instead.
gsasl_server_step_base64: DEPRECATED: use gsasl_step64 instead.

gsasl_finish: ADD.
gsasl_client_finish: DEPRECATED: use gsasl_finish instead.
gsasl_server_finish: DEPRECATED: use gsasl_finish instead.

gsasl_ctx_get: ADD.
gsasl_client_ctx_get: DEPRECATED: use gsasl_ctx_get instead.
gsasl_server_ctx_get: DEPRECATED: use gsasl_ctx_get instead.

gsasl_appinfo_get: ADD.
gsasl_appinfo_set: ADD.
gsasl_client_application_data_get: DEPRECATED: use gsasl_appinfo_get instead.
gsasl_client_application_data_set: DEPRECATED: use gsasl_appinfo_set instead.
gsasl_server_application_data_get: DEPRECATED: use gsasl_appinfo_get instead.
gsasl_server_application_data_set: DEPRECATED: use gsasl_appinfo_set instead.

Gsasl: ADD.
Gsasl_ctx: DEPRECATED: use Gsasl instead.
Gsasl_session: ADD.
Gsasl_session_ctx: DEPRECATED: use Gsasl_session instead.

GSASL_CRYPTO_ERROR: ADD, replaces deprecated GSASL_LIBGCRYPT_ERROR.
GSASL_LIBGCRYPT_ERROR: DEPRECATED: use GSASL_CRYPTO_ERROR instead.

GSASL_KERBEROS_V5_INTERNAL_ERROR: ADD, replaces deprecated GSASL_SHISHI_ERROR.
GSASL_SHISHI_ERROR: DEPRECATED: use GSASL_KERBEROS_V5_INTERNAL_ERROR instead.

GSASL_INVALID_HANDLE: ADD.
2004-09-19 12:48:45 +00:00
wiz
f99d98e7ae Update to 0.0.13, provided by Sergio Jimenez in PR 26972:
* Changes in 0.0.13 (released 2004-08-08)

** Revamp of gnulib compatibility files.

** More translations.
French (by Michel Robitaille) and Romanian (by Laurentiu Buzdugan).

* Changes in 0.0.12 (released 2004-08-01)

** Added rudimentary self tests of Kerberos 5 context init/accept.
Tests client and server authentication, with and without mutual
authentication, and that various aspects of the API like ret_flags
work.

** Various fixes, discovered while writing the Kerberos 5 self test.

** Cross compile builds should work.
It should work for any sane cross compile target, but the only tested
platform is uClibc/uClinux on Motorola Coldfire.
2004-09-19 12:32:27 +00:00
agc
7847f8610c Use "pl" as the magic abbreviation for "pathlevel" in the package name. 2004-09-17 09:45:02 +00:00
cube
875ccd9356 Update to version 1.6.8p1. This is a security update, see advisory
at:

http://www.sudo.ws/sudo/alerts/sudoedit.html

Major changes since Sudo 1.6.8:

o Sudoedit now re-opens the temp file as the invoking user
  and will only open regular files.

o Better detection of unchanged files in sudoedit.

o The path to ldap.conf is now configurable.

o Added SSL tls_* certificate checking options when using LDAP.

o The sample pam config file has been updated.
2004-09-17 09:25:18 +00:00
he
6d056130e1 Add patches to work around compile problems for this package on
NetBSD-1.6.2_STABLE.  Gets rid of a parse error when only one
argument is given to HDN_WARN, which leaves us with "fprintf(fp, arg, )".
This may be a failure of the compiler on this platform to properly
do varargs macros, but the changes are noops and gets it building there.
2004-09-16 16:12:57 +00:00
jlam
d2601f50d9 Force using the BSD utmp interface on NetBSD until the configure
scripts can be taught how to properly detect our utmpx implementation.
This should fix the build on NetBSD-2.0 and -current.
2004-09-15 15:29:49 +00:00
jlam
b7ebacaf82 The configure script checks for some libraries the wrong order, since
-lreadline also needs either -ltermcap, -lcurses, -lncurses in the link
command to resolve all symbols used in the readline library.  Cause one
of these libraries to automatically be added whenever "-lreadline"
appears on the command line.  This is a generalization of the change in
revision 1.6 to work on more operating systems.
2004-09-15 04:53:21 +00:00
jlam
d19adcd53e Include buildlink3.mk files for packages needed to satisfy library
dependencies.  This fixes link failures when the Heimdal dependency
is satisfied by the package rather than the builtin Heimdal.  Pointed
out by Mark Davies in private email.

I've intentionally left out including readline/buildlink3.mk.  Although
it is used by libsl.* and libss.*, those libraries are not actually
critical or used by other packages that depend on Heimdal for Kerberos
functionality.
2004-09-15 04:11:11 +00:00
jlam
81d0dd7593 Teach builtin.mk about the latest releases of Heimdal and match them up
with NetBSD versions.
2004-09-14 15:10:09 +00:00
jlam
e34f12d5d3 Update security/heimdal to 0.6.3. Changes from version 0.6.1 include:
* fix vulnerabilities in ftpd
* support for linux AFS /proc "syscalls"
* support for RFC3244 (Windows 2000 Kerberos Change/Set Password) in kpasswdd
* fix possible KDC denial of service
* Fix possible buffer overrun in v4 kadmin (which now defaults to off)
2004-09-14 14:41:34 +00:00
jlam
e3b166145e Bump the PKGREVISION after fixing pkg/26678. 2004-09-12 05:10:09 +00:00
jlam
2af0a80597 List the other cy2-* packages that use cyrus-sasl2/Makefile.common. 2004-09-12 05:08:49 +00:00
jlam
32a5a6a6cf Fix build when using the built-in Heimdal on NetBSD. Analysis and fix
provided in PR pkg/26678 by Jukka Salmi.
2004-09-12 05:07:28 +00:00
wiz
d80b7341c4 According to the bulk build logs, this installs version 2.19
of the library, not 2.18; adapt PLIST.
2004-09-10 20:02:05 +00:00
markd
5c18b7d77d varargs -> stdarg
Don't try and use getutent() on NetBSD's that have utmpx
Fixes problems seen in bulkbuild.
2004-09-08 14:30:00 +00:00
adrianp
5cb8373a5d - Dont use the built-in libevent as it's too old. Fixes build on 2.0. 2004-09-07 08:13:30 +00:00
jlam
06f6c2e864 Apply the patches for security/mit-krb5 that fix MITKRB5-SA-2004-00{2,3}.
Bump the PKGREVISION for this security update.
2004-09-07 01:47:28 +00:00
danw
d096207c55 bump PKGREVISION for devel/cfg+ soname change 2004-09-06 20:39:13 +00:00
wiz
d5fbd67ecf Remove some obsolete comments, ok wennmach. 2004-09-05 18:44:56 +00:00
grant
bfa78b1cff fix PKGNAME. 2004-09-05 10:22:12 +00:00
grant
d73382a619 +pam-dbm 2004-09-05 10:01:32 +00:00
grant
367091f30f Initial import of pam-dbm-0.2 into the NetBSD packages collection.
pam_dbm is a PAM module for DBM authentication.
2004-09-05 10:01:19 +00:00
grant
1fb7f021f8 mis-import; remove 2004-09-05 10:00:25 +00:00
grant
b5c6e7db5a Initial import of pam_dbm-0.2 into the NetBSD packages collection.
pam_dbm is a PAM module for DBM authentication.
2004-09-05 09:58:43 +00:00
wiz
c85130d403 AUTOMAKE_REQD should only be set to 1.4 in the few cases where needed,
otherwise the default is better (and the variable doesn't need to be set).
Remove a few cases where it was set unnecessarily.
2004-09-04 23:40:43 +00:00
seb
06871c5037 Add & enable p5-Crypt-CipherSaber. 2004-09-04 14:13:11 +00:00
seb
15b8d483a4 Initial import of p5-Crypt-CipherSaber version 0.60 into the NetBSD Packages
Collection.

The CipherSaber Perl module provides an object oriented interface to
CipherSaber-1 and CipherSaber-2 encryption.
See http://ciphersaber.gurus.com for more information about CipherSaber.
2004-09-04 14:02:33 +00:00
wiz
9ac74e840c Update to 3.9p1:
* Added new "IdentitiesOnly" option to ssh(1), which specifies that it should
   use keys specified in ssh_config, rather than any keys in ssh-agent(1)

 * Make sshd(8) re-execute itself on accepting a new connection. This security
   measure ensures that all execute-time randomisations are reapplied for each
   connection rather than once, for the master process' lifetime. This includes
   mmap and malloc mappings, shared library addressing, shared library mapping
   order, ProPolice and StackGhost cookies on systems that support such things

 * Add strict permission and ownership checks to programs reading ~/.ssh/config
   NB ssh(1) will now exit instead of trying to process a config with poor
   ownership or permissions

 * Implemented the ability to pass selected environment variables between the
   client and the server. See "AcceptEnv" in sshd_config(5) and "SendEnv" in
   ssh_config(5) for details

 * Added a "MaxAuthTries" option to sshd(8), allowing control over the maximum
   number of authentication attempts permitted per connection

 * Added support for cancellation of active remote port forwarding sessions.
   This may be performed using the ~C escape character, see "Escape Characters"
   in ssh(1) for details

 * Many sftp(1) interface improvements, including greatly enhanced "ls" support
   and the ability to cancel active transfers using SIGINT (^C)

 * Implement session multiplexing: a single ssh(1) connection can now carry
   multiple login/command/file transfer sessions. Refer to the "ControlMaster"
   and "ControlPath" options in ssh_config(5) for more information

 * The sftp-server has improved support for non-POSIX filesystems (e.g. FAT)

 * Portable OpenSSH: Re-introduce support for PAM password authentication, in
   addition to the keyboard-interactive driver. PAM password authentication
   is less flexible, and doesn't support pre-authentication password expiry but
   runs in-process so Kerberos tokens, etc are retained

 * Improved and more extensive regression tests

 * Many bugfixes and small improvements
2004-08-31 11:27:11 +00:00
martti
34f8f2645b Updated dropbear to 0.43
- SECURITY: Don't try to free() uninitialised variables in DSS verification
  code. Thanks to Arne Bernin for pointing out this bug. This is possibly
  exploitable, all users with DSS and pubkey-auth compiled in are advised to
  upgrade.

- Clean up agent forwarding socket files correctly, patch from Gerrit Pape.

- Don't go into an infinite loop when portforwarding to servers which don't
  send any initial data/banner. Patch from Nikola Vladov

- Fix for network vs. host byte order in logging remote TCP ports, also
  from Gerrit Pape.

- Initialise many pointers to NULL, for general safety. Also checked cleanup
  code for mp_ints (related to security issues above).
2004-08-31 10:27:38 +00:00
jmmv
a8f0abc245 Fix paths to tclsh and wish, which were being found in the buildlink
directory.  Bump PKGREVISION to 4.  From Ryo HAYASAKA in PR pkg/26808.
2004-08-30 16:00:49 +00:00
jlam
7ad48acf7d Back out previous... unintended commit. 2004-08-28 20:38:18 +00:00
jlam
8d572feba3 Use the new BUILDLINK_TRANSFORM commands to more precisely state the
intended transformation: use "rm" to remove an option, "rmdir" to remove
all options containing a path starting with a given directory name, and
"rename" to rename options to something else.
2004-08-28 06:05:31 +00:00
drochner
c281f1bb2a +xmlsec1 2004-08-27 13:22:30 +00:00
drochner
a057543c69 import xmlsec1-1.2.6, an XML signature and encryption library 2004-08-27 13:19:57 +00:00
drochner
19e9d2911f update to 1.0.20
changes:
-bugfixes
-adds some limits to the verification functions to avoid denial of
 service attacks
-selftests added
2004-08-27 13:16:16 +00:00
drochner
28e05752a9 update to 0.5.5
changes:
Severeal cleanups and Libgcrypt 1.2.0 adjustments.
2004-08-27 13:01:35 +00:00
jlam
ca70938428 Replace RPATH_FLAG with LINKER_RPATH_FLAG and COMPILER_RPATH_FLAG,
which are the full option names used to set rpath directives for the
linker and the compiler, respectively.  In places were we are invoking
the linker, use "${LINKER_RPATH_FLAG} <path>", where the space is
inserted in case the flag is a word, e.g. -rpath.  The default values
of *_RPATH_FLAG are set by the compiler/*.mk files, depending on the
compiler that you use.  They may be overridden on a ${OPSYS}-specific
basis by setting _OPSYS_LINKER_RPATH_FLAG and _OPSYS_COMPILER_RPATH_FLAG,
respectively.  Garbage-collect _OPSYS_RPATH_NAME and _COMPILER_LD_FLAG.
2004-08-27 06:29:06 +00:00
lukem
9de8a5be02 add back idea.c.gz (from USE_IDEA=yes). (hi wiz!) 2004-08-26 13:39:05 +00:00
wiz
61bd72b91d Update to 1.2.6:
* Updated the included gettext.  This also fixes the installation
      problem from 1.2.5

    * Fixed a race condition possibly leading to deleted keys.
2004-08-26 13:19:32 +00:00
cube
536e0ddf84 Restore USE_LIBTOOL which was silently removed recently (hi xtraeme!).
Fix build with recent libtool.  Not bumping PKGREVISION, it's in the flow
of current PLIST fixes and such...
2004-08-24 17:31:48 +00:00
schmonz
6064f91bc1 visudo(8) is still in ${PREFIX}/sbin, at least on NetBSD 2.0_BETA. 2004-08-24 16:43:18 +00:00
xtraeme
748f9e643a Add missing files. 2004-08-24 09:19:16 +00:00
xtraeme
bb6feecffc Update security/sudo to 1.6.8 and convert to use bsd.options.mk, which
adds two new options, ldap and pam.

Changes:

 * Sudo now supports storing sudoers info in LDAP (optionally using TLS).
 * There is a new -e option to edit files the with uid of the invoking
   user. This makes it possible to give users to ability to safely edit
   files without the possibility of editing other files or running commands
   as the target user. If sudo is run as "sudoedit" the -e flag is implied.
 * A new tag, NOEXEC, will prevent a dynamically-linked program being run
   by sudo from executing another program (think shell escapes). Because
   this uses LD_PRELOAD it has no effect on static binaries.
 * A uid specified in sudoers now matches the user specified by the -u flag
   even if the -u flag specified a name, not a uid.
 * Added a -i option to simulate an initial login similar to "su -".
 * If sudo is used to run as root shell, further sudo commands will be logged
   as run by the user specified by the SUDO_USER environment variable. In -e
   mode (sudoedit), SUDO_USER is used to determine what user to run the editor
   when the real uid is 0.
 * The sudoers file is now parsed as the runas user in all cases instead of
   root. This fixes some issues with running NFS-mounted commands.
 * If the target user == invoking user a password is no longer required.
 * Sudo now produces a sensible error message when the targetpw Defaults option
   is set and a non-existent uid is specified via the -u option.
 * A negated user/uid in a runas list is now treated the same as a negated
   command and overrides a previously allowed entry.
 * PAM support now uses Use pam_acct_mgmt() to check for disabled accounts.
 * Added a check in visudo for runas_default being used before it was set.
 * Fixed several issues when closing all open descriptors. Sudo now uses
   closefrom() if it exists, otherwise it uses /proc/$$/fd if that exists
   with a fallback of closing all possible descriptors.
 * Quoting globbing characters with a backslash now works as documented.
 * Fixed a problem on FreeBSD (and perhaps others) when the user is only
   listed in NIS (not master.passwd) and netgroups are used in the
   master.passwd file.
 * The username in a log entry is no longer truncated at 8 characters.
 * Added a "sudo_lecture" option that can point to a file containing a
   custom lecture.
 * The timeout for password reading is now done via alarm(), not select().
 * /tmp/.odus is no longer used for timestamps by default.
 * Sudo now works on the nsr-tandem-nsk platform.
 * Fixed the --with-stow configure option.
 * TIS fwtk authentication now supports fwtk 2.0 and higher.
 * Added Stan Lee / Uncle Ben quote to the lecture from RedHat.
 * Added the --with-pc-insults configure to replace politically incorrect
   insults with other ones.
2004-08-23 21:15:17 +00:00
jlam
9d5426ff76 Change the way that legacy USE_* and FOO_USE_* options are converted
into the bsd.options.mk framework.  Instead of appending to
${PKG_OPTIONS_VAR}, it appends to PKG_DEFAULT_OPTIONS.  This causes
the default options to be the union of PKG_DEFAULT_OPTIONS and any
old USE_* and FOO_USE_* settings.

This fixes PR pkg/26590.
2004-08-22 19:32:51 +00:00
recht
380a09fb50 Bump PKGREVISION to 2 for the gpgme BUILDLINK_DEPENDS change. 2004-08-22 17:54:18 +00:00
recht
e453299c88 update to gpgme-0.9.0
Noteworthy changes in version 0.9.0 (unreleased)
------------------------------------------------

 * The type gpgme_key_t has now a new field keylist_mode that contains
   the keylist mode that was active at the time the key was retrieved.

 * The type gpgme_decrypt_result_t has a new field "wrong_key_usage"
   that contains a flag indicating that the key should not have been
   used for encryption.

 * Verifying a signature of a revoked key gives the correct result now
   (GPG_ERR_CERT_REVOKED error code).

 * Clarified that the error code GPG_ERR_NO_DATA from the decrypt &
   verify operations still allows you to look at the signature
   verification result.

 * Clarified that patterns in keylisting operations have an upper
   limit, and thus are not suited to list many keys at once by their
   fingerprint.  Also improve the error message if the pattern is too
   long for the CMS protocol to handle.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
gpgme_key_t			EXTENDED: New field keylist_mode.
gpgme_decrypt_result_t		EXTENDED: New field wrong_key_usage.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Set the 0.9.0 versions as BUILDLINK_DEPENDS in the buildlink3.mk for the
library major version changes.
2004-08-22 17:52:26 +00:00
markd
60aad77f97 Update to 0.4.7.
Noteworthy changes in version 0.4.7 (2004-04-29)
------------------------------------------------

 * Correctly initialize the fields expired, revoked, invalid, and
   disabled in the gpgme_key_t structures.

 * A bug fix: The flag wrong_key_usage of gpgme_signature_t was
   accidently of type int instead unsigned int.

Noteworthy changes in version 0.4.6 (2004-04-06)
------------------------------------------------

 * Bug fixes


Noteworthy changes in version 0.4.5 (2004-03-07)
------------------------------------------------

 * GPGME is now compiled with LFS (large file support) by default.

 * New key listing mode GPGME_KEYLIST_MODE_VALIDATE for validation of
   the listed keys.

 * New interface gpgme_cancel() that can be used to cancel
   asynchronous operations.

Noteworthy changes in version 0.4.4 (2004-01-12)
------------------------------------------------

 * The member "class" in gpgme_key_sig_t and gpgme_new_signature_t has
   been renamed to "sig_class", to avoid clash with C++ compilers.  In
   the C API, the old name "class" has been preserved for backwards
   compatibility, but is deprecated.
2004-08-21 10:54:47 +00:00
jlam
99aa413714 Whitespace nit. 2004-08-19 20:21:56 +00:00
adrianp
8488b0fc47 - Update to scanssh 2.0
- ok'ed snj@/wiz@

From the ChangeLog:
Supports open proxy detection.
High performance by using libevent.
2004-08-17 19:43:22 +00:00
adrianp
9842074d8a - Update to 2.0.4
- Replace SED with SUBST.*
- Improve DESCR
- ok'ed snj@/wiz@

From the Changelog:

Verison 2.0.4:
--------------
More signatures.
Improved documentation, mentions of p0f_db, etc.
[BUG] Fixed a minor problem with installation on systems w/o /usr/man/.
[BUG] Fixed a DLT_NULL problem, added a new loopback signature.
Multiple timestamp options, timestamps now read from pcap dumps.
Sync with new Windows port code.
[BUG] Fixed one-line reporting for masquerade detection.
2004-08-14 10:09:15 +00:00
jlam
dbb7938097 Add and enable the cy2-* plugins. 2004-08-13 18:46:11 +00:00
jlam
578aa09545 Initial import of security/cy2-plain, the SASL PLAIN AUTH plugin. 2004-08-13 18:14:32 +00:00
jlam
b40cc595d5 Initial import of security/cy2-otp, the SASL OTP AUTH plugin. 2004-08-13 18:14:19 +00:00
jlam
8956804fad Initial import of security/cy2-gssapi, the SASL GSSAPI AUTH plugin. 2004-08-13 18:14:04 +00:00
jlam
40bfd63ab1 Initial import of security/cy2-digestmd5, the SASL DIGEST-MD5 AUTH plugin. 2004-08-13 18:13:52 +00:00
jlam
65e3156ac8 Initial import of security/cy2-crammd5, the SASL CRAM-MD5 AUTH plugin. 2004-08-13 18:13:28 +00:00
jlam
8e3e379621 Initial import of security/cy2-anonymous, the SASL ANONYMOUS AUTH plugin. 2004-08-13 18:12:58 +00:00
jlam
73ce2d82db Split out the plugins into individual packages. This allows us to
explicitly add only those plugins for SASL support for servers that
won't let us exclude any found SASL plugins.  Also, don't bother
building the static library since the static library is useless until
the build mechanism is fixed by the Cyrus maintainers.

Bump the PKGREVISION.
2004-08-13 18:08:02 +00:00
adrianp
2e8018a550 - Include readline to fix Linux builds
- Add Python support
- Include an extra library on Linux to fix builds on some distros.

Last two issues submitted by Roland Illig in PR# 26620
2004-08-13 11:04:21 +00:00
agc
34c81a479f Add and enable hydan 2004-08-13 10:26:50 +00:00
agc
78eb53ddc6 Initial import of hydan-0.13 into the Packages Collection.
Hydan steganographically conceals a message into an application.  It
exploits redundancy in the i386 instruction set by defining sets of
functionally equivalent instructions.  It then encodes information in
machine code by using the appropriate instructions from each set.

Features:
       - Application filesize remains unchanged
       - Message is blowfish encrypted with a user-supplied
	 passphrase before being embedded
       - Encoding rate: 1/110

Primary uses for Hydan:
       - Covert Communication:  embedding data into binaries creates a
	 covert channel that can be used to exchange secret messages.
       - Signing:  a program's cryptographic signature can be embedded
	 into itself.  The recipient of the binary can then verify
	 that it has not been tampered with (virus or trojan), and is
	 really from who it claims to be from.  This check can be
	 built into the OS for user transparency.
       - Watermarking:  a watermark can be embedded to uniquely
	 identify binaries for copyright purposes, or as part of a DRM
	 scheme.  Note:  this usage is not recommended as Hydan
	 implements fragile watermarks.
2004-08-13 10:26:03 +00:00
jlam
defd97be15 Cosmetic changes. 2004-08-13 07:11:57 +00:00
jlam
453b0391f9 The name of this package is "cy2-sql". 2004-08-13 07:11:36 +00:00
jlam
bde3c2e8b4 First cut at supporting the built-in PAM on MacOS X. It's not the
same as Linux-PAM, but it's close enough for the purposes of compiling
programs.
2004-08-12 10:09:49 +00:00
tv
ec67d6f031 Fix PLIST. 2004-08-09 16:16:03 +00:00
taca
b6057b527a Update shared library version. 2004-08-08 04:04:53 +00:00
jdolecek
c539267d0e Update samba2 package to 2.2.10
Changes in 2.2.10:
A buffer overrun has been located in the code used to support
the 'mangling method = hash' smb.conf option.   Affected Samba
2.2 installations can avoid this possible security bug by using
the hash2 mangling method.  Server installations requiring
the hash mangling method are encouraged to upgrade to Samba v2.2.10
or v3.0.5.

Changes in 2.2.9:
This is a maintenance release of Samba 2.2.8a to address the
problem with user password changes after applying the Microsoft
hotfix described in KB828741 to Windows NT 4.0/200x/XP clients.

Also updated dependant packages pam-smbpass and winbind.
2004-08-07 08:18:37 +00:00
jdolecek
c889eeb7cb fix DEPENDS to use ../../net/samba2 (this is samba2-only pkg) 2004-08-07 07:55:56 +00:00
sketch
e479febb73 Append to CFLAGS on SunOS to avoid recursion. Fixes pkg/23475. 2004-08-06 16:51:39 +00:00
jlam
5828f0f1b9 Reorder conditions so that if make does short-circuit boolean evalutation,
then we avoid hitting the disk if we don't need to.
2004-08-06 15:43:09 +00:00
jlam
c4b3ae0830 Accidentally reversed meaning of test. 2004-08-06 15:41:46 +00:00
jlam
7ea57169b7 Redo previous to say what we really want: we don't care if ${LOCALBASE}
is "/usr", what we really want to check is if the pam_appl.h header found
is within the ${LOCALBASE} hierarchy, which implies that it's a
pkgsrc-controlled file, and hence not built-in.
2004-08-06 15:37:20 +00:00
jlam
a18c72be38 Add and enable amavisd-new. 2004-08-06 15:08:20 +00:00
jlam
1403a3a8be Reimport mail/amavisd-new as security/amavisd-new.
amavisd-new is an interface between message transfer agent (MTA) and
one or more content checkers, e.g. virus scanners, SpamAssassin, etc.
It is a performance-enhanced and feature-enriched version of amavisd
(which in turn is a daemonized version of AMaViS or amavis-perl).

amavisd-new is normally positioned at or near a central mailer, not
necessarily where user's mailboxes and final delivery takes place.  If
you are looking for fully per-user configurable and/or low-message-rate
solution to be placed at the final stage of mail delivery (e.g. called
from procmail), there may be other solutions more appropriate for your
needs.

Package created and maintained by Julian Dunn in pkgsrc-wip.
2004-08-06 15:05:53 +00:00
jlam
7fb711f0eb There is no way for libtool to generate a convenience library that
can be used to create shared libraries _and_ be linked into a statically
linked program.  Instead of trying to hack libtool to do this, just
accept the fact and do what you want another way!

Remove the ugly hack in sasldb/Makefile.am that regenerated the static
archive from the non-PIC object files.  While this was fine for linking
into programs, it breaks things when you link this into the sasldb
plugin.  Leaving it the other way, where the static archive from the
PIC object files, is also unacceptable because there are potential
problems on some platforms when linking an archive of of PIC objects
into an executable.  The solution: let the static archive contain PIC
objects and be used to link into the sasldb plugin, but for the programs
in the utils directory, explicitly add the non-PIC object files listed
in $(SASL_DB_BACKEND_STATIC) to the files used to generate the programs.
This is easy because SASL_DB_BACKEND_STATIC is already generated
properly by config/sasldb.m4, so make use if it.

This should fix problems with using Cyrus SASL on non-i386 platforms
noted in PR pkg/26492 by Matt Dainty.  Bump the PKGREVISION.
2004-08-06 06:36:18 +00:00
reed
f1d0bf8e92 In the rare case when LOCALBASE is /usr, don't let this think
that /usr/include/security/pam_appl.h means that PAM is builtin.
(This is so a dependency can be registered correctly.)
2004-08-06 03:14:22 +00:00
minskim
34ec2a4e09 Regen to make GNU patch happy. 2004-08-05 21:35:37 +00:00
jlam
870792f95d It's PKG_OPTIONS.heimdal, not PKG_OPTIONS.mit-krb5. 2004-08-05 16:28:45 +00:00
jlam
b4e8a59e09 Convert to use bsd.options.mk. 2004-08-05 04:20:28 +00:00
jlam
b32800e3ff Rename Makefile.options to options.mk in the packages that I maintain.
This follows the example of the mail/dovecot package, as suggested by
<schmonz>.
2004-08-05 03:04:33 +00:00
jlam
312137ee1c Document the "rsaref" build option. 2004-08-05 02:45:28 +00:00
jlam
86b87ebd21 Document libcrack build option. 2004-08-05 02:42:12 +00:00
jlam
4968d188f9 Add and enable cy2-sql. 2004-08-04 20:47:37 +00:00
jlam
e3523c699d Initial import of security/cy2-sql. This is the Cyrus SASLv2 SQL auxprop
plugin.
2004-08-04 20:47:10 +00:00
jlam
8e156b5599 Updated security/cyrus-sasl2 to 2.1.19. Changes from version 2.1.18
include:

* Fixes to saslauthd to allow better integration with realms (-r flag to
  saslauthd, %R token in LDAP module)
* A nontrivial number of small bugfixes.
2004-08-04 20:08:38 +00:00
jlam
e3ac987879 Updated security/cyrus-sasl2 to 2.1.19. Changes from version 2.1.18
include:

* Support for forwarding of GSSAPI credentials
* A nontrivial number of small bugfixes.
2004-08-04 19:41:06 +00:00
minskim
6c1e49d7f6 Make openssh build on Interix. Currently only the client (ssh) was
tested.  The server (sshd) still needs more patches especially because of
non-zero Administrator uid/gid issues.
2004-08-04 06:43:52 +00:00
jlam
1b1dbe02eb Become the maintainer for this package (approved by <chris>). 2004-08-03 23:40:23 +00:00
tv
a3a100fc65 Unfortunately, "mountd" REQUIREs "mountall", causing a circular dependency
here.  So it's not possible to mount cfs from "mountall" -- it will have to
be mounted by hand later in startup, e.g. rc.local.
2004-08-03 04:35:42 +00:00
tv
0fecdbf26d cfsd needs to be before "mountall" in order to be listed in /etc/fstab. 2004-08-02 17:09:35 +00:00
tv
75561db9a7 Make patch-ag apply correctly. 2004-08-02 17:09:06 +00:00
jlam
c095bbf9ce Note that this plugin supports NTLMv2. 2004-08-01 21:06:38 +00:00
jlam
c52152b5e2 Conform to doc/Makefile-example by moving inclusion of buildlink3.mk files
below the variable settings and above any make targets.
2004-08-01 21:02:13 +00:00
jlam
f74393acce Restore (and correct) the fix in revision 1.15 of Makefile. This causes
openssl/buildlink3.mk to be included unconditionally to provide the des.h
header and des* routines.
2004-08-01 19:43:45 +00:00
tv
1a48a554a7 Update to 0.32. Changes:
hashcash-0.32 - 09-Apr-2004 - Adam Back <adam@cypherspace.org>

	* documentation fixes

	* change multiple regexp behavior; previous algorithm only allowed
	  higher overrides; need to support both higher and lower
	  overrides.  This also required introducing -o option to join
	  regexps which are set intersections where otherwise risk of
	  uninteded override occuring and mail being rejected as spent or
	  insufficent bits.  Now revert to lexical order most specific
	  regexp first.

	* wrote test script test.sh

	* fix a few minor bugs uncovered by above test script

	* -c now means check date

	* allow -n etc with -X

	* introduced -b relative to default way of specifying bits

	* -b is no optional, if want token fully checked, but can give -b
	  default; or new relative to default -b +0.


hashcash-0.31 - 01-Apr-2004 - Adam Back <adam@cypherspace.org>

	* final 0.x version (v0 format) release before 1.x version (v1
	  format) (bug fixes / maintenance only afterwards on 0.x version)

	* remove -O3 from Makefile, use -O instead as fails on HPUX or
	  sun.

	* fix some out of date usage stuff in hashcash man page.

	* disable timing loop unless timing needed

	* fix multiple reciept bug in -cX/-cx reported by Junior Ang
	  <junior@chrysant.com>.  If you receive a mail multiple times
	  because you are on the receipt list multiple times, there will
	  be multiple hashcash headers for you.  In this case it is
	  necessary to examine the first matching, non-spent stamp.  The
	  bug was previous versions stopped on the first matching stamp
	  and then failed because it was spent.  Need to keep going and
	  check later also matching stamps until find one which is not
	  spent.

	* rationalize command line args further.  No implied -m , more
	  things that are awkward to implement but not that useful are
	  disallowed.

	* change purge operation to use read-write operations in the same
	  sdb file rather than creating a temporary file.  This makes
	  locking easier and is also aesthetically nicer.

	* add flock(2) database file write locking, and change creation
	  logic to use open(2) to avoid creation db race-condition also.

	* make resource string case insensitive by default to match email
	  semantics; add -C option to force case sensitivity if desired
	  (email addresses are converted to and stored in lower case, so
	  you have to both mint and verify with case sensitivity turned on
	  to make use of case sensitivity)

	* support minting multiple resources with multiple command line
	  args.  Also if no resources given on command line, read
	  resources from stdin.

	* support supplying multiple email addresses, for people who want
	  to accept as multiple addresses.

	* support multiple resources on purging also.

	* support multiple tokens with check mode as cmd line args, if
	  none given as args, read tokens from stdin; if -X/-x read from
	  cmd line args, then from stdin as email (matching stamp headers
	  skipping stamp headers)

	* rename default simple database to hashcash.sdb (.sdb extension),
	  to distinguish from planned support for better database.

	* fix bug in PPUTS didn't match PPRINTF

	* fixup -l, -w, -n so they support multiple tokens also

	* made use of -b optional (get the default on mint & check)

	* added "-b default" to specify default number of bits with -s
	  (otherwise no way to measure the default speed without
	  specifying the number of bits -- and when this can change over
	  time it would be inconvenient for scripting to have to
	  separately obtain this)

	* added support for wildcard email addresses with '*' wildcard
	  marker.  '*' before '@' does not match '@', '*' after '@' does
	  not match '.'.  And both email addresses must contain @ sign and
	  same number of '.' separated sub domains as wildcard address.
	  Wildcard matching is the new default.  Use -S to get plain
	  string match.  Can turn back on with -W.

	* increased size of random string to reduce chance of collisions
	  between users.  Now negligible chance of collision with typical
	  token sizes.

	* added support for regexps.  Can work from POSIX library or BSD
	  regexp library.  Use -E to get regexps.  Input is always in
	  POSIX syntax (specials are not quoted to have special action;
	  are quoted to have plain meaning).  If using BSD library still
	  give input in POSIX syntax, it's converted to BSD internally.

	* implement highest matching semantics.  Ensures that eg -c -b10
	  *@bar.invalid -b15 adam@bar.invalid will not accept a 10 bit
	  token for adam@bar.invalid.  (This is done by sorting resources
	  highest bits required first and accepting only the first highest
	  matching resource.)

	* change arg parsing so -b, -e, -g, -z, -E, -W, -S, apply to the
	  following resources and tokens, and can be changed for later
	  resources/tokens with tokens and args interspersed.  Means you
	  have to give these args before the resource/token or you will
	  get defaults.
2004-08-01 18:35:30 +00:00
seb
c965ed7bfd Revert previous: conflicts with openssh (and others) are already specified in
Makefile.common.
2004-07-31 12:52:42 +00:00
tv
87f76f2592 Detect builtin libdes. (NetBSD 2.0, for instance, has one.) 2004-07-31 05:31:57 +00:00
jlam
b460ce1ab5 Convert to use bsd.options.mk. The relevant options variable to set
for each package can be determined by invoking:

	make show-var VARNAME=PKG_OPTIONS_VAR

The old options are still supported unless the variable named in
PKG_OPTIONS_VAR is set within make(1) (usually via /etc/mk.conf).
2004-07-30 21:05:41 +00:00
wiz
7824c761d5 Update to 4.24.1:
Improve update_dat script with patch from Jason White in followup
to PR 26408.
. get updates from faster and more reliable http server
. dat file format has changed -- version info is now in a different file
. abort update if no write permissions in target dir
2004-07-29 22:19:57 +00:00
wiz
3090572bc4 Set USE_BUILDLINK3, since this package already includes a bl3 file.
While here, fix PLIST handling, so that multiple 'make install's work.
2004-07-29 00:59:53 +00:00
schmonz
3e9966eaa5 Enable pkgviews installation. 2004-07-28 15:55:45 +00:00
wiz
3b4cf0f45f Update to 1.2.5:
* New --ask-cert-level/--no-ask-cert-level option to turn on and
      off the prompt for signature level when signing a key.  Defaults
      to on.

    * New --min-cert-level option to disregard key signatures that are
      under a specified level.  Defaults to 1 (i.e. don't disregard
      anything).

    * New --max-output option to limit the amount of plaintext output
      generated by GnuPG.  This option can be used by programs which
      call GnuPG to process messages that may result in plaintext
      larger than the calling program is prepared to handle.  This is
      sometimes called a "Decompression Bomb".

    * New --list-config command for frontends and other programs that
      call GnuPG.  See doc/DETAILS for the specifics of this.

    * New --gpgconf-list command for internal use by the gpgconf
      utility from gnupg 1.9.x.

    * Some performance improvements with large keyrings.  See
      --enable-key-cache=SIZE in the README file for details.

    * Some portability fixes for the OpenBSD/i386, HPPA, and AIX
      platforms.

    * Simplified Chinese translation.
2004-07-28 15:17:42 +00:00
markd
69356e8ad6 USE_LANGUAGES=c c++ ; USE_LIBTOOL=yes 2004-07-28 13:18:11 +00:00
schmonz
995650e302 Update to 2.3.4. From the changelog:
* keychain 2.3.4 (24 Jul 2004)

  24 Jul 2004; Aron Griffis <agriffis@gentoo.org>;
  Fix bug 28599 reported by Bruno Pelaia; ignore defunct processes in
  ps output

* keychain 2.3.3 (30 Jun 2004)

  30 Jun 2004; Aron Griffis <agriffis@gentoo.org>;
  Fix bug reported by Matthew S. Moore in email; escape the backticks
  in --help output

  Fix bug reported by Herbie Ong in email; set pidf, cshpidf and lockf
  variables after parsing command-line to honor --dir setting

  Fix bug reported by Stephan Stahl in email; make spaces in filenames
  work throughout keychain, even in pure Bourne shell

  Fix operation on HP-UX with older OpenSSH by interpreting output of
  ssh-add as well as the error status

* keychain 2.3.2 (16 Jun 2004)

  16 Jun 2004; Aron Griffis <agriffis@gentoo.org>;
  Fix bug 53837 (keychain needs ssh-askpass) by unsetting SSH_ASKPASS
  when --nogui is specified

* keychain 2.3.1 (03 Jun 2004)

  03 Jun 2004; Aron Griffis <agriffis@gentoo.org>;
  Fix bug 52874: problems when the user is running csh

* keychain 2.3.0 (14 May 2004)

  14 May 2004; Aron Griffis <agriffis@gentoo.org>;
  Rewrite the locking code to avoid procmail

* keychain 2.2.2 (03 May 2004)

  03 May 2004; Aron Griffis <agriffis@gentoo.org>;
  Call loadagent prior to generating HOSTNAME-csh file so that
  variables are set.

* keychain 2.2.1 (27 Apr 2004)

  27 Apr 2004; Aron Griffis <agriffis@gentoo.org>;
  Find running ssh-agent processes by searching for /[s]sh-agen/
  instead of /[s]sh-agent/ for the sake of Solaris, which cuts off ps
  -u output at 8 characters.  Thanks to Clay England for reporting the
  problem and testing the fix.

* keychain 2.2.0 (21 Apr 2004)

  21 Apr 2004; Aron Griffis <agriffis@gentoo.org>;
  Rewrote most of the code, organized into functions, fixed speed
  issues involving ps, fixed compatibility issues for various UNIXes,
  hopefully didn't introduce too many bugs.  This version has a
  --quick option (for me) and a --timeout option (for carpaski).

  Also added a Makefile and converted the man-page to pod for easier
  editing.  See perlpod(1) for information on the format.  Note that
  the pod is sucked into keychain and colorized when you run make.
2004-07-26 19:02:10 +00:00
minskim
568b5f0a9f Add and enable crypto++. 2004-07-26 15:20:25 +00:00
minskim
9320d082ad Import crypto++ from pkgsrc-wip. Packaged by Sergio Jimenez and
slightly modified by me.

Crypto++ Library is a free C++ class library of cryptographic schemes.
One purpose of Crypto++ is to act as a repository of public domain
(not copyrighted) source code.  Although the library is copyrighted as
a compilation, the individual files in it (except for a few exceptions
listed in the license) are in the public domain.
2004-07-26 15:18:44 +00:00
grant
1e99c0fee7 add CONFLICT with ssh2-nox11. 2004-07-25 12:36:03 +00:00
grant
0b85776bd8 add CONFLICT with openssh. 2004-07-25 12:35:06 +00:00
grant
d4f7b767c4 "ln -s" does not overwrite existing targets on all platforms,
explicitly rm targets before trying to create symlinks.

fixes install on Solaris.
2004-07-25 12:29:19 +00:00
grant
6d3c089bb1 make this build on NetBSD >=2.0E with statvfs(). 2004-07-25 11:59:27 +00:00
grant
9a993c5df0 one of the Makefiles uses ${RM} but doesn't define it, so pass
RM=${RM} in MAKE_ENV.
2004-07-25 06:15:24 +00:00
grant
c379f4f3de this blindly calls "gcc", so use buildlink3 so it uses the wrappers. 2004-07-25 04:57:11 +00:00
grant
451309f5c1 call ${BSD_INSTALL} instead of "install". fixes install on Solaris. 2004-07-25 04:51:26 +00:00
grant
69b1c87899 be quiet in post-extract, too. 2004-07-25 04:47:15 +00:00
grant
4193bb5aa1 be quieter in post-patch and pre-build targets. 2004-07-25 04:46:10 +00:00
grant
ff39f3579e only pass -traditional if using gcc. 2004-07-25 04:45:41 +00:00
grant
72928b60b8 expose a hidden dependency on openssl (it is needed all the time, not
only when openldap support is enabled).
2004-07-25 04:35:14 +00:00
grant
6f7f00cf3e don't override pkgsrc set build variables, don't pass gcc specific
flags.

fixes install on Solaris.
2004-07-25 04:30:09 +00:00
grant
a8e47b5c8d use buildlink3, expose hidden dependency on openssl. 2004-07-25 04:19:59 +00:00
jlam
3b9a3e81f4 Honor VARBASE; bump PKGREVISION. 2004-07-24 14:01:20 +00:00
jlam
48fff8b8ad Bump PKGREVISION for last change. 2004-07-24 13:56:09 +00:00
jlam
dec6dfc605 Honor VARBASE. 2004-07-24 13:55:30 +00:00
wiz
b659bc0f1e Update to 0.0.11, provided by Sergio Jimenez in PR 26418.
* Changes in 0.0.11 (released 2004-04-18)

** Minor cleanups to the core header file.
Using xom.h is no longer supported (the file doesn't exist on modern
systems).

** Kerberos 5 sequence number handling fixed.
First, gss_init_sec_context set the sequence numbers correctly, before
the incorrect sequence numbers prevented gss_(un)wrap from working
correctly.  Secondly, gss_unwrap now check the sequence numbers
correctly.  This was prompted by the addition of randomized sequence
numbers by default in Shishi 0.0.15.

** The compatibility files in gl/ where synced with Gnulib.

** Various bugfixes and cleanups.

** Polish translation added, by Jakub Bogusz.
2004-07-24 08:33:19 +00:00
jlam
5fea00931a This homepage doesn't exist anymore. 2004-07-23 18:07:18 +00:00
adam
1383a1ac33 Changes 2.0.12:
* Fixed a bug in ./configure which would sometimes assume that GTK is not
  installed whereas it actually is
* Fixed a race condition in nessus-adduser for users who do not configure
  their TMPDIR variable (thanks to Cyrille Barthelemy)
* Fixed a bug in nessus-update-plugins which would not update the plugins
  properly on all systems (thanks to Keith Butler)
* Fixed the installer to compile Nessus with GTK support if gtk-config OR
  pkg-config is installed.
2004-07-22 14:59:53 +00:00
recht
4150812b27 add python as category
ok'd a while back at pkgsrcCon by agc and wiz
2004-07-22 09:15:59 +00:00
schmonz
b01de5d5ce Add CONFLICTS with qmail>=1.03nb7 and netqmail>=1.05 (to be committed
shortly). All three packages have a "bin/forward" and a corresponding
section 1 manual page.
2004-07-21 22:27:19 +00:00
salo
67c5db45ee USE_IMAKE implies USE_X11BASE, remove it. 2004-07-21 21:16:10 +00:00
snj
8b784bb73b Add steghide. 2004-07-21 03:09:44 +00:00
snj
6912515fb2 Initial import of steghide-0.5.1.
Steghide is a steganography program that can hide data in JPEG, BMP, WAV,
and AU files.

Taken from pkgsrc-wip and modified by me.
2004-07-21 03:08:08 +00:00
adam
18143cdd0b Changes 2.0.11:
* Solaris support fix
* HTML support fix
* Supports GTK+ 2.x
* Minor speed improvements in client-server communication
2004-07-20 11:47:41 +00:00
rh
512edec2f0 Fix a typo: use ldap.conf (not pam.conf) as the default LDAP config file.
Pointed out by Dick Davies < rasputnik at hellooperator dot net >.
2004-07-17 01:24:45 +00:00
recht
e50331f9b0 add and enable prngd 2004-07-15 23:11:40 +00:00
recht
116e819eba Initial import of prngd-0.9.29
from  othyro at freeshell dot org via pkgsrc-wip

PRNGD is a Pseudo Random Number Generator Daemon. It is intended
to replace EGD, and provides an EGD compatible interface to obtain
random data and as an entropy source.

PRNGD is never drained and can never block.  And it has a seed-save
file, so that it is immediately usable after system start.
2004-07-15 23:10:35 +00:00
grant
89cd919656 this needs -lnsl -lsocket on Solaris. 2004-07-11 00:48:42 +00:00
recht
43fcfda955 Use a better fix from ASG CVS the GSSAPI problems.
patch-ap now includes the updates between rev 1.84 and rev 1.90
modulo the support for passing of GSSAPI credentials.

Patch provided by Jukka Salmi in PR 26184

Bump PKGREVISION to 3 for the new fix.
2004-07-08 21:11:25 +00:00
jlam
b8db9b28ee Accept "yes" or "YES" for USE_LIBCRACK. 2004-07-06 22:49:29 +00:00
wiz
4237d54a34 Unused. 2004-07-06 22:41:15 +00:00
jlam
e9f1f50552 Refer to ${VARBASE} instead of /var for the location for local state
information.
2004-07-06 22:38:32 +00:00
jdolecek
e20e6ce14e Update php4 package to 4.3.7.
Change list from release notes:

* Synchronized bundled GD library with GD 2.0.23.
* Fixed a bug that prevented compilation of GD extensions against
  FreeType 2.1.0-2.1.2.
* Fixed thread safety issue with informix connection id.
* Fixed incorrect resolving of relative paths by glob() in windows.
* Fixed mapping of Greek letters to html entities.
* Fixed a bug that caused an on shutdown crash when using PHP with Apache
  2.0.49.
* Fixed a number of crashes inside pgsql, cpdf and gd extensions.

All in all this release fixes over 30 bugs that have been discovered
and resolved since the 4.3.6 release.
2004-07-06 19:52:01 +00:00
agc
14f1743611 Add and enable libfwbuilder 2004-07-06 18:05:44 +00:00
agc
005b3be3c6 Initial import of libfwbuilder-1.0.2 into the Packages Collection. This
was based a long time ago on the OpenBSD port, but the only thing that
remains form that is one of the patches, and I'm not sure that's necessary
any more.

	Firewall Builder is multi-platform firewall configuration and
	management tool.  It consists of a GUI and set of policy compilers for
	various firewall platforms.  Firewall Builder uses object-oriented
	approach, it helps administrator maintain a database of network
	objects and allows policy editing using simple drag-and-drop
	operations.  Firewall Builder currently supports

		iptables,
		ipfilter,
		OpenBSD PF, and
		Cisco PIX

	libfwbuilder provides the back-end functionality in a library.
2004-07-06 18:04:39 +00:00
jlam
569b488dc8 Re-add revision 1.3 of patch-ab as patch-ag. This resurrects a change to
use shlibtool to build the plugins to avoid generating and installing a
static archive for the plugin module.  This fixes PLIST breakage.  Bump the
PKGREVISION to 2.
2004-07-06 04:20:59 +00:00
recht
70a0a95356 Pull in a fix from ASG CVS: increase maxoutbuf buffer size
This allows uploading of SIEVE scripts larger than 4kb if GSSAPI
authentification is used for cyrus-imapd.

link to the patch provided by Jukka Salmi in PR 26165

bump PKGREVISION to 1
2004-07-05 16:49:18 +00:00
wiz
0f392f8b3a bl2 -> bl3 in a package that does not have USE_BUILDLINK* set. 2004-07-02 20:47:49 +00:00
jmmv
fcc4f184f1 When exec'ing child processes (netstat and vmstat), make sure the standard
file descriptors (0, 1, 2) are open.  This avoids multiple warnings issued
under NetBSD about running set[ug]id programs with those descriptors closed.

Fixes PR pkg/26079; although it talks about gaim, the problem is here, in
libgcrypt.  Bump PKGREVISION to 1.
2004-07-02 13:14:27 +00:00
wiz
6ef1244cbb Unused. 2004-07-01 13:45:08 +00:00
wiz
f28fe02579 Convert to bl3. 2004-07-01 13:44:11 +00:00
abs
1386ca7e03 Update to bl3. All test built with jdk or sun-jdk14.
jakarta-tomcat4 has other issues independant of this - will patch next
2004-06-28 17:28:56 +00:00
grant
5a154be6d4 use buildlink3 for compiler specific flag stripping. fixes build on
Solaris.
2004-06-27 13:42:46 +00:00
grant
7ea99394af tiny whitespace tweak 2004-06-27 13:26:22 +00:00
grant
46af0a9282 this needs flex and bison to build. fixes build on Solaris.
XXX this could be handled better by the tools stuff.
2004-06-27 13:23:40 +00:00
grant
e14ffac7c8 this needs -lnsl on Linux and -lnsl -lsocket on Solaris. 2004-06-27 13:16:36 +00:00
grant
65a1836873 this blindly calls "gcc" so use buildlink3 so it uses the wrapper. 2004-06-27 13:13:23 +00:00
grant
5e484408f2 don't call a static function from an inline function, not all
compilers allow it.
2004-06-27 12:53:55 +00:00
grant
e4dde7ff5f don't inline a function in one source file and expect to be able to
use it in other source files - not all compilers allow this.
2004-06-27 12:21:21 +00:00
grant
84fa22a676 use buildlink3 and include libpcap/buildlink3.mk to remove the hidden
dependency on libpcap.

no PKGREVISION bump required as this would not build without libpcap,
anyway.
2004-06-27 11:42:43 +00:00
grant
ec99b37c2b this uses a c and c++ compiler. 2004-06-27 11:41:09 +00:00
grant
4fe60be368 this blindly calls "gcc" so use buildlink3 so it uses the compiler
wrappers.
2004-06-27 11:40:07 +00:00
grant
da83d1c44d this uses zlib, so use buildlink3 and include zlib/buildlink3.mk. 2004-06-26 19:30:58 +00:00
grant
9616d4f229 don't override CC, don't pass gcc specific flags. 2004-06-26 19:25:12 +00:00
grant
6022149b49 be quiet in do-build 2004-06-26 19:24:54 +00:00
grant
1379931ff3 use the specially provided targets for solaris sparc and i386
optimisations.

this doesn't have a configure script.
2004-06-26 19:17:33 +00:00
grant
a26a5b7e73 nuke trailing slashes 2004-06-26 19:07:25 +00:00
grant
286b9d2abf oops, back out a line that shouldn't have been committed. 2004-06-26 19:06:31 +00:00
grant
5d1455f21f don't override CC, LD, etc. 2004-06-26 19:06:04 +00:00
jlam
bba20f1510 Cede maintainership to the hard-working people on tech-pkg@NetBSD.org. 2004-06-25 15:44:30 +00:00
jlam
c963f6ffa4 Whitespace nits. 2004-06-25 15:42:52 +00:00
jlam
bd19bb9398 Set BUILDLINK_RECOMMMENDED to mit-krb5>=1.3.4 due to the security advisory:
http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-001-an_to_ln.txt
2004-06-24 15:13:24 +00:00
jlam
c7e6c1022f Update to security/mit-krb5 to 1.3.4. Major changes from version 1.3.3
include a fix for security advisory [MITKRB-SA-2004-001]:

http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2004-001-an_to_ln.txt

Please read the security advisory to see if you are affected and should
update your MIT krb5 installation.
2004-06-24 14:43:29 +00:00
snj
24d928e694 Update flawfinder to 1.26. Don't set PY_PATCHPLIST, as it is useless.
Don't include python/extension.mk, as it is also useless.  Don't set
NO_CONFIGURE, because it makes PYTHON_PATCH_SCRIPTS useless.  Don't set
MAKEFILE, as we don't actually use the included makefile for anything.

Changes since 1.24:
* Added more support for Microsoft's approach to internationalization.
* Added two new rules for GLib functions, "g_get_home_dir" and
  g_get_tmp_dir".
* Added curl_getenv().
* Added several rules for input functions (for -I) -
  recv, recvfrom, recvmsg, fread, and readv.
* Tightened the false positive test slightly; if a name is
  followed by = or - or + it's unlikely to be a function call,
  so it'll be quietly discarded.
* Modified the summary report format slightly.
* Modified the getpass text to remove an extraneous character.
* Added rules for cuserid, getlogin, getpass, mkstemp, getpw, memalign,
  as well as the obsolete functions gsignal, ssignal, ulimit, usleep.
* Modified text for strncat to clarify it.
* Fixed error in --columns format, so that the output is simply
  "filename:linenumber:columnnumber" when --columns (-C) is used.
* Eliminated "Number of" phrase in the footer report
* Added more statistical information to the footer report.
* Added shortcut single-letter commands (-D for --dataonly,
  -Q for --quiet, -C for --columns), so that invoking from
  editors is easier.
* Tries to autoremove some false positives.  In particular, a function
  name followed immediately by "=" (ignoring whitespace)
  is automatically considered to be a variable and NOT a function,
  and thus doesn't register as a hit.  There are exotic cases
  where this won't be correct, but they're pretty unlikely in
  real code.
* Added a "--falsepositive" (-F) option, which tries to remove
  many more likely false positives.
2004-06-23 16:19:41 +00:00
drochner
b8ae38c3a0 update to 0.42
Many fixes and feature additions since 0.38. Too many to list here.
2004-06-21 18:27:47 +00:00
jmmv
fccea2f44b Update to 0.4.4:
This is mainly a bugfix release.  Sometimes EOF was not properly detected
while reading the password file.  This would result in an 'Line too long'
error message (and some wierd behavour).  Also, the current password file
is now backed up before each write.
2004-06-21 07:29:13 +00:00
itojun
c4a3b55800 upgrade to 20040617a. includes important certificate mangement change. 2004-06-17 03:36:18 +00:00
kristerw
b4e5dc1e43 Add and enable openssh+gssapi. 2004-06-15 18:46:27 +00:00
kristerw
e33e13d60b Resurrect openssh+gssapi per request of jwise@. 2004-06-15 18:44:57 +00:00
uebayasi
208c6f1b98 Update priv to 1.0beta2nb1.
* Make sure ${PKG_SYSCONFDIR} is passed to configure.
* Care ${PRIV_CONF_DIR} as an obsoleted variable.

Pointed out by Matt Green.
2004-06-14 03:16:42 +00:00
jmmv
fec33c7153 Convert to subst.mk. 2004-06-10 21:16:35 +00:00
jmmv
05c93204df Fix build (SSL not found during configuration, causing missing includes).
Problem probably introduced during the conversion to buildlink3.
Exposed by latest kristerw@'s bulk build in NetBSD 2.0_BETA/i386.
2004-06-10 21:11:08 +00:00
cjep
f6887a97b1 Add USE_INET6 to BUILD_DEFS as these packages use it. Part of PR#25743 from
Georg Schwarz.
2004-06-08 12:23:59 +00:00
schmonz
15ce0d6eda Add simple rc.d script. Bump PKGREVISION. 2004-06-06 14:19:04 +00:00
agc
defa9a1be3 Update audit-packages to 1.32, with fixes for the problems mentioned
in PR 25654 from Hauke Fath.

Take any non-standard values from audit-packages.conf file in
audit-packages as well as download-vulnerability-list.

Fix the pre-formatted documentation so that filenames to be
substituted are not formatted with the bold or underline "overstrikes"
on ttys, so that the correct sed substitutions take place at package
install time.
2004-06-06 08:28:54 +00:00
kristerw
1b0ace13d4 Remove obsolete packages, per discussion on tech-pkg. 2004-06-01 21:50:37 +00:00
jschauma
b8981cbdfa Since we set ALL_TARGET to irix6 (under, IRIX 6.x), we don't need to patch
the irix6.5 target into the Makefile.
2004-06-01 15:34:16 +00:00
kristerw
7510202d93 Depend on security/openssh instead of security/ssh for machines that
do not have /usr/bin/ssh.
2004-05-31 22:13:16 +00:00
kivinen
bf01247c07 Fixed bug, which only appeared in the NetBSD 2.0 systems where the
write can return 0 even when the select has indicated that socket
is writable. Do not consider this error, but call select again.
2004-05-28 12:00:10 +00:00
wiz
c0859358d8 Use versioned distfile. 2004-05-27 01:22:55 +00:00
reed
5cdf9aa4fd The libopencdk.so.8.0 used libgcrypt.so.11.
libgcrypt was recently upgraded. So when using binary packages
it is possible for new libgcrypt (libgcrypt.so.12.1) to be installed
with old opencdk-0.5.4 package.

So bump PKGREVISION and BUILDLINK_DEPENDS (to force a new package
to be required).
2004-05-27 00:51:39 +00:00
wiz
d2c65848f0 Make chklastlog useful on NetBSD; from Makoto Fujiwara in PR 25701.
Bump PKGREVISION.
2004-05-26 15:04:32 +00:00
wiz
19b27aaa2b PKGREVISION bump because of libidn shlib major bump. 2004-05-26 14:55:46 +00:00
sekiya
5cb9931c01 Add tacshell. 2004-05-26 12:05:10 +00:00
sekiya
435c70f240 tacshell-0.91: RSA ACE/Server sdshell workalike, using TACACS+ 2004-05-26 12:04:27 +00:00
adam
59fee122d5 buildlink3 now requires libgcrypt 1.2.0 or higher 2004-05-26 07:44:58 +00:00
tron
f869e3de69 Remove me as maintainer of this package. 2004-05-26 05:42:28 +00:00
uebayasi
988501a185 ${PKG_SYSCONFDIR} is created by INSTALL scripts via OWN_DIRS. No need to
run @exec mkdir/rmdir here.
2004-05-24 11:27:22 +00:00
kristerw
b075252528 Make this package compile when using gcc 3.3. 2004-05-23 23:03:40 +00:00
snj
784ea8c189 Fix MASTER_SITES. From Robert Elz in PR pkg/25681. 2004-05-23 04:07:41 +00:00
adam
616c770a63 Shared library major version change, so buildlink3.mk has to be updated, right? 2004-05-22 10:17:47 +00:00
adam
177071660e Changes 1.0.13:
- Some complilation fixes.
- Added the --xml parameter to the certtool utility.

Changes 1.0.12:
- Corrected bug in OpenPGP key loading using a callback.
- Renamed gnutls-srpcrypt to srptool
- Allow handshake requests by the client.
* Things backported from the development branch:
- Added support for authority key identifier and the extended key usage
  X.509 extension fields. The certtoool was updated to support them.
- Added batch support to certtool. Now it can use templates.
- The RC2 cipher is no more included. The one in libgcrypt is now used.

Changes 1.0.11:
- Added gnutls_sign_algorithm_get_name() and gnutls_pk_algorithm_get_name()
- Corrected bug in TLS renegotiation.

Changes 1.0.10:
- Corrected bug in RSA parameters handling which could cause
  unexpected crashes.
- Corrected bug in SSL 3.0 authentication.
2004-05-22 10:09:53 +00:00
adam
5fcb1873eb Changes 1.2.0
* First stable release.

Changes 1.1.94
 * The support for multi-threaded users goes into its third
   incarnation.  We removed compile time support for thread libraries.
   To support the thread library of your choice, you have to set up
   callback handlers at initialization time.  New data structures, a
   new control command, and default initializers are provided for this
   purpose.

 * Interface changes relative to the 1.1.93 release:
libgcrypt-config --thread       OBSOLETE
libgcrypt-pth.la                REMOVED
libgcrypt-pthread.la            REMOVED
GCRYCTL_SET_THREAD_CBS          NEW
struct gcrypt_thread_cbs        NEW
enum gcry_thread_option         NEW
GCRY_THREAD_OPTION_PTH_IMPL     NEW
GCRY_THREAD_OPTION_PTHREAD_IMPL NEW

Changes 1.1.93
 * The automatic thread library detection has finally been removed.
   From now on, only linking explicitely to libgcrypt, libgcrypt-pth
   or libgcrypt-pthread is supported.
2004-05-22 10:07:48 +00:00
adam
b50fe994c1 Changes 0.2.10
- Added scripts to assist in libtasn1 version detection
  from configure scripts.
- Corrected a DER decoding bug which was reported
  by Max Vozeler <max@hinterhof.net>.

Changes 0.2.9
- Accept negative numbers as range in INTEGER declarations

Changes 0.2.8
- Add asn1_delete_element function
2004-05-22 07:30:03 +00:00
reed
a6877657cc Only use the NetBSD-specific MESSAGE.urandom for NetBSD.
It says to use "pseudo-device   rnd" kernel configuration.

TODO: if the above instructions are fine for other
operating systems with /dev/urandom then add.
2004-05-21 23:00:23 +00:00
reed
ec087dd4e3 The makefile had a comment saying PAM authentication causes memory
faults, and haven't tracked down why yet.

No allow PAM authentication if Linux (and USE_PAM is defined).

This will close my 20846 PR from March 2003.

Also, install the contrib/sshd.pam.generic file as the example
sshd.pam instead of the FreeBSD version, but this okay since
it was commented out in the first place.

TODO: test the PAM support on other platforms and allow
if USE_PAM is defined.
2004-05-21 22:54:43 +00:00
tron
f9bf086fdc Require at least version 2.0.10 of the "nessus-libraries" package because
"nessus-core" won't build otherwise.
2004-05-20 12:49:09 +00:00
kim
aecc988438 Use -lcrypto with Heimdahl if it exists.
Fixes PR pkg/25623
2004-05-19 19:26:38 +00:00