sudo 1.8.24b2 released

"Todd C. Miller" <[email protected]> Mon, 30 Jul 2018 16:40:31 -0600
Newsgroups gmane.comp.tools.sudo.devel
Message-ID <[email protected]>
The second beta version of sudo 1.8.24 is now available.  Sudo
1.8.24 builds on the changes in 1.8.23 to merge the LDAP/SSSD and
file-based lookup code.  This has allowed the removal almost 1,500
lines of code from the LDAP and SSSD backends.

If you rely on the LDAP or SSSD backends, please do give the 1.8.24
beta a try if you are able to.

Source:
    https://www.sudo.ws/dist/beta/sudo-1.8.24b2.tar.gz
    ftp://ftp.sudo.ws/pub/sudo/beta/sudo-1.8.24b2.tar.gz

SHA256 checksum:
    0e5cdc2a4af8d09c795db1cb37d0199d3faf7ebd3ed078dde506c78640a16546
MD5 checksum:
    e5ae996ac01eae070bb8cce9be800a2c

Binary packages:
    https://www.sudo.ws/dist/beta/packages/index.html#binary

For a list of download mirror sites, see:
    https://www.sudo.ws/download_mirrors.html

Sudo web site:
    https://www.sudo.ws/

Sudo web site mirrors:
    https://www.sudo.ws/mirrors.html

Major changes between sudo 1.8.24b2 and 1.8.24b1:

 * Fixed a race condition when building with parallel make.
   Bug #842

 * Fixed a duplicate free when netgroup_base in ldap.conf is set
   to an invalid value.

 * Fixed a group lookup bug on Linux introduced in sudo 1.8.24b1.

 * Fixed a bug introduced in sudo 1.8.23 on AIX that could prevent
   local users and groups from being resolved properly on systems
   that have users stored in NIS, LDAP or AD.

 * Added a workaround for an AIX bug exposed by a change in sudo
   1.8.23 that prevents the terminal mode from being restored when
   I/O logging is enabled.

 * On systems using PAM, sudo now ignores the PAM_NEW_AUTHTOK_REQD
   and PAM_AUTHTOK_EXPIRED errors from PAM account management if
   authentication is disabled for the user.  This fixes a regression
   introduced in sudo 1.8.23.  Bug #843

Major changes between sudo 1.8.24b1 and 1.8.23:

 * The LDAP and SSS back-ends now use the same rule evaluation code
   as the sudoers file backend.  This builds on the work in sudo
   1.8.23 where the formatting functions for "sudo -l" output were
   shared.  The handling of negated commands in SSS and LDAP is
   unchanged.

 * Fixed a regression introduced in 1.8.23 where "sudo -i" could
   not be used in conjunction with --preserve-env=VARIABLE.  Bug #835

 * cvtsudoers can now parse base64-encoded attributes in LDIF files.

 * Random insults are now more random.

 * Fixed the noexec wordexp(3) test on FreeBSD.

 * Added SUDO_CONV_PREFER_TTY flag for conversation function to
   tell sudo to try writing to /dev/tty first. Can be used in
   conjunction with SUDO_CONV_INFO_MSG and SUDO_CONV_ERROR_MSG.

 * Sudo now supports an arbitrary number of groups per user on
   Solaris.  Previously, only the first 64 groups were found.
   This should remove the need to set "max_groups" in sudo.conf.

 * Fixed typos in the OpenLDAP sudo schema.  Bugs #839 and #840.

____________________________________________________________
sudo-workers mailing list <[email protected]>
For list information, options, or to unsubscribe, visit:
https://www.sudo.ws/mailman/listinfo/sudo-workers
signature.asc (application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCAAGBQJbX5PYAAoJEKn0wCHOpHD7MpYP/11JI+5vIcMRJkeOKdCaxOrr
zZF7DEParOOi43QBJNLV96riSwK+686uhENGMj3/pRyQ9s0WO6vQhJx+DcTu3Pth
xOsbpa7JAuWezln/NXouXooLSz0LwkBGDU10BGQAZWwKT2SjdR4xWGh1O/qxJUus
JMKCzNG0l6XhZMlKu+Xbii0hhJ0ZCUSJ6Tb8QQnN3xoN3HiirkHw6Q4rwxQlUuGS
aKaC0cVB6oOEET5FWLWZYQsWK4Nf2sGbs6VJiBltrNe4DQk6fqK4ETAH/0Plo/Rp
L2I80yf/CDGcQa3hpxggQMKcdehOVZDA256rnaZpbwGsizfTULc6Dna9moHYytHH
WUXJtALlmOKa+wWEcEtssWn98IEUOCxeVl/9onQuRWNg758iHtd88XCUVjf8j9mM
0PiVUcypeS0+uIsKvXGkk1jl1BsIOLJiZk/8xR4FrQaENVijRKQDTNemRioWnISj
wtPSnU52acaYjtoy1cv5lMeVcModQpQps85BBHs5QB1L+t9qXQ3SRc4B9jEjktz2
tUTfliQARhXaDyxSPSnYutPHQ1+V/DKwx6ovZORrCTf7laBuWSeHtdf2b1e5VaOT
xneReLmDulqQaG36cxetbKIoH9bJWtEM9kUYQAULoXgUsIarRrDFQxSCezAQJ36J
v4Qzsw3gns91xVH6xSJF
=Rgmd
-----END PGP SIGNATURE-----