Dear Heimdal Community,
A team consisting of staff from Two Sigma Open Source and AuriStor are
pleased to announce the release of Heimdal 7.1.
The release download page is:
https://github.com/heimdal/heimdal/releases/tag/heimdal-7.1.0
The source tarball can be downloaded from:
https://github.com/heimdal/heimdal/releases/download/heimdal-7.1.0/heimdal-7.1.0.tar.gz
https://github.com/heimdal/heimdal/releases/download/heimdal-7.1.0/heimdal-7.1.0.tar.gz.sig
SHA256(heimdal-7.1.0.tar.gz)= cee58ab3a4ce79f243a3e73f465dac19fe2b93ef1c5ff244d6f1d689fedbde2d
SHA1(heimdal-7.1.0.tar.gz)= 72d79c7c6953047f3949a5f7d03c20237ff69c69
The signature key fingerprint is: E659 41B7 1CF3 C459 A34F A89C 45E7 572A 28CD 8CC8
Why 7?
We are adopting a new versioning scheme.
o Each feature release will have a new major number.
o The minor will be a patch level. A value of 0 is
reserved for release candidates. A value of 99 is
reserved for development.
o Stable releases will not have a micro number (always 0).
o Micro numbers will be incremented in release candidates
and development as needed.
For example, the release candidates for 7.1 were 7.0.1, 7.0.2 and
All bug fixes will then be 7.2, 7.3, etc.
New development for Heimdal 8 will be 7.99.1, 7.99.2, 7.99.3, etc.
When the next feature release is issued its version number will
start with 8.0.1 as the first release candidate and the first
release will be 8.1.
Major changes in Heimdal 7:
We have a lot of major improvements since our last official
release, including:
o hcrypto is now thread safe on all platforms and
as much as possible hcrypto now uses the operating
system's preferred crypto implementation ensuring
that optimized hardware assisted implementations of
AES-NI are used.
o RFC 6113 Generalized Framework for Kerberos
Pre-Authentication (FAST).
o Hierarchical capath support
o iprop has been revamped to fix a number of race
conditions that could lead to inconsistent replication.
o The KDC process now uses a multi-process model improving
resiliency and performance.
o AES Encryption with HMAC-SHA2 for Kerberos 5
draft-ietf-kitten-aes-cts-hmac-sha2-11
o Moved kadmin and ktutil to /usr/bin
o Stricter fcache checks (see fcache_strict_checking krb5.conf setting)
o Removed legacy applications: ftp, kx, login, popper, push, rcp, rsh,
telnet, xnlock
For a more detailed list of changes please see:
https://github.com/heimdal/heimdal/blob/master/NEWS
which contains a bullet point summary of the major security,
feature and bug fix changes that have been applied to the Heimdal
source tree over the last four years since the release of 1.5.3.
We expect that the ABI for libgssapi and libkrb5 is unchanged from
the prior release (1.5.3).
Credits:
At least the following individuals have contributed to Heimdal 7,
(please pardon any omissions):
Abhinav Upadhyay Heath Kehoe Nico Williams
Andreas Schneider Henry Jacques Patrik Lundin
Andrew Bartlett Howard Chu Philip Boulain
Andrew Tridgell Igor Sobrado Ragnar Sundblad
Antoine Jacoutot Ingo Schwarze Remi Ferrand
Arran Cudbard-Bell Jakub Čajka Rod Widdowson
Arvid Requate James Le Cuirot Rok Papež
Asanka Herath James Lee Roland C. Dowdeswell
Ben Kaduk Jeffrey Altman Ross L Richardson
Benjamin Kaduk Jeffrey Clark Russ Allbery
Bernard Spil Jeffrey Hutzelman Samuel Cabrero
Brian May Jelmer Vernooij Samuel Thibault
Chas Williams Ken Dreyer Santosh Kumar Pradhan
Chaskiel Grundman Kiran S J Sean Davis
Dana Koch Kumar Thangavelu Sergio Gelato
Daniel Schepler Landon Fuller Simon Wilkinson
David Mulder Linus Nordberg Stef Walter
Douglas Bagnall Love Hörnquist Åstrand Stefan Metzmacher
Ed Maste Luke Howard Steffen Jaeckel
Eray Aslan Magnus Ahltorp Timothy Pearson
Florian Best Marc Balmer Tollef Fog Heen
Fredrik Pettai Marcin Cieślak Tony Acero
Greg Hudson Marco Molteni Uri Simchoni
Gustavo Zacarias Matthieu Hautreux Viktor Dukhovni
Günther Deschner Michael Meffie Volker Lendecke
Harald Barth Moritz Lenz
--
The Heimdal Release Team.
_______________________________________________
Heimdal-announce mailing list
[email protected]
https://www.h5l.org/mailman/listinfo/heimdal-announce
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.