From rmeggins at redhat.com Thu Dec 1 13:37:55 2005 From: rmeggins at redhat.com (Richard Megginson) Date: Thu, 01 Dec 2005 06:37:55 -0700 Subject: [Fedora-directory-announce] Announcing Fedora Directory Server 1.0 Message-ID: <438EFCB3.70606@redhat.com> We are proud to announce the release of Fedora Directory Server 1.0. This release marks a significant milestone for the open source community, who now have access to the code for the console and administration engine as well as the previously open sourced LDAP engine. This release uses the Apache httpd engine as its administration server, and includes mod_nss - a rewrite of mod_ssl which uses the Mozilla NSS crypto engine. The 1.0 release, in addition to its many other features such as LDAPv3, Multi-Master Replication, and Windows Synchronization, includes support for MD5, SHA-256, SHA-384, and SHA-512 password hashing, as well as many bug fixes. Fedora Directory Server 1.0 furthers the evolution and democratization of open source software in making this powerful, enterprise proven technology available to all. It is a boon for developers who are now able to port the full package - LDAP engine, console, and admin engine - to many different platforms. If you have used the previous version of Fedora Directory Server, we invite you to try our new version. If you are using another LDAP server, we invite you to try ours and let us know how it compares - we're always looking for ways to improve. Our community is already active and growing, and you are welcome and encouraged to join. There are many ways: joining the mailing lists, reporting bugs, editing documentation, writing scripts/patches/plug-ins, and many more. Try it out! - http://directory.fedora.redhat.com/wiki/Download Our home page - http://directory.fedora.redhat.com/ Join our community! - http://directory.fedora.redhat.com/wiki/Ways_to_contribute mod_nss - http://directory.fedora.redhat.com/wiki/Mod_nss Drop us a line! - fedora-directory-users at redhat.com and http://directory.fedora.redhat.com/wiki/Mailing_Lists -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3312 bytes Desc: S/MIME Cryptographic Signature URL: From rmeggins at redhat.com Wed Dec 7 16:07:20 2005 From: rmeggins at redhat.com (Richard Megginson) Date: Wed, 07 Dec 2005 09:07:20 -0700 Subject: [Fedora-directory-announce] SECURITY] Fedora Directory Server 1.0 Update: Admin Server Message-ID: <439708B8.9010305@redhat.com> --------------------------------------------------------------------- Fedora Directory Server Update Notification 2005-12-07 --------------------------------------------------------------------- Product : Fedora Directory Server Name : Admin Server Version : 1.0 Release : 1 Summary : The Admin Server httpd administrative engine. Description : The Admin Server component of Fedora Directory Server is an httpd server which uses Apache 2 to serve up web pages and execute CGIs used to administer the Fedora Directory Server. This package is included with Fedora Directory Server. --------------------------------------------------------------------- Update Information: Fixed bug #174837 (CVE-2005-3630) https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174837 Frank Reppin discovered a flaw in the default Apache configuration for Fedora DS. By default clients are allowed to read everything under the document root, which can reveal sensitive information to a remote user. This update modifies this behavior, only allowing read access to specific files and directories under the document root. --------------------------------------------------------------------- This update is a patch file available for download from: http://directory.fedora.redhat.com/download/adminserver10to101.patch 2d7553a300551ef2a19b1b89a017e5ff adminserver20051205.patch To install the patch: cd /opt/fedora-ds patch -p0 < adminserver10to101.patch ./restart-admin -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3178 bytes Desc: S/MIME Cryptographic Signature URL: From rmeggins at redhat.com Wed Dec 7 16:47:47 2005 From: rmeggins at redhat.com (Richard Megginson) Date: Wed, 07 Dec 2005 09:47:47 -0700 Subject: [Fedora-directory-announce] Correction: [SECURITY] Fedora Directory Server 1.0 Update: Admin Server Message-ID: <43971233.1030209@redhat.com> Correction to the below notice. The link is broken. It should be http://directory.fedora.redhat.com/sources/adminserver10to101.patch And the md5sum is not correct. It should be 1a18195b3bf057139e04852f6f3c0be9 adminserver10to101.patch I apologize for any inconvenience or confusion. --------------------------------------------------------------------- Fedora Directory Server Update Notification 2005-12-07 --------------------------------------------------------------------- Product : Fedora Directory Server Name : Admin Server Version : 1.0 Release : 1 Summary : The Admin Server httpd administrative engine. Description : The Admin Server component of Fedora Directory Server is an httpd server which uses Apache 2 to serve up web pages and execute CGIs used to administer the Fedora Directory Server. This package is included with Fedora Directory Server. --------------------------------------------------------------------- Update Information: Fixed bug #174837 (CVE-2005-3630) https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=174837 Frank Reppin discovered a flaw in the default Apache configuration for Fedora DS. By default clients are allowed to read everything under the document root, which can reveal sensitive information to a remote user. This update modifies this behavior, only allowing read access to specific files and directories under the document root. --------------------------------------------------------------------- This update is a patch file available for download from: http://directory.fedora.redhat.com/download/adminserver10to101.patch 2d7553a300551ef2a19b1b89a017e5ff adminserver20051205.patch To install the patch: cd /opt/fedora-ds patch -p0 < adminserver10to101.patch ./restart-admin -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3178 bytes Desc: S/MIME Cryptographic Signature URL: From rmeggins at redhat.com Fri Dec 9 04:51:25 2005 From: rmeggins at redhat.com (Richard Megginson) Date: Thu, 08 Dec 2005 21:51:25 -0700 Subject: [Fedora-directory-announce] Announcing Fedora Directory Server 1.0.1 Message-ID: <43990D4D.7040200@redhat.com> Fedora Directory Server 1.0.1 is released! This release is primarily a patch release to address some issues with the 1.0 release. If you are using 1.0, you are strongly encouraged to upgrade to 1.0.1 as soon as possible. If you have not installed 1.0 yet, use 1.0.1 instead. Release Notes: http://directory.fedora.redhat.com/wiki/Release_Notes Download: http://directory.fedora.redhat.com/wiki/Download Home Page: http://directory.fedora.redhat.com/wiki/Main_Page -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3178 bytes Desc: S/MIME Cryptographic Signature URL: