<feed xmlns='http://www.w3.org/2005/Atom'>
<title>samba.git/testprogs, branch v3-5-test</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.</subtitle>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/'/>
<entry>
<title>Revert "blackbox:test_kinit - Remove the "-H" (hive) parameter"</title>
<updated>2009-09-21T09:33:13+00:00</updated>
<author>
<name>Matthias Dieter Wallnöfer</name>
<email>mwallnoefer@yahoo.de</email>
</author>
<published>2009-09-21T09:33:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=0af3b06824825ee42ba0fe7414d774ace72292d0'/>
<id>0af3b06824825ee42ba0fe7414d774ace72292d0</id>
<content type='text'>
This reverts commit d4389a230b6aea5a0b2a98e255b14a59c8248b0b.

This revert changed the behaviour which I didn't expect. Thanks abartlet to
point this out!
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This reverts commit d4389a230b6aea5a0b2a98e255b14a59c8248b0b.

This revert changed the behaviour which I didn't expect. Thanks abartlet to
point this out!
</pre>
</div>
</content>
</entry>
<entry>
<title>blackbox:test_kinit - Remove the "-H" (hive) parameter</title>
<updated>2009-09-20T21:07:22+00:00</updated>
<author>
<name>Matthias Dieter Wallnöfer</name>
<email>mwallnoefer@yahoo.de</email>
</author>
<published>2009-09-20T21:07:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=d4389a230b6aea5a0b2a98e255b14a59c8248b0b'/>
<id>d4389a230b6aea5a0b2a98e255b14a59c8248b0b</id>
<content type='text'>
The "enableaccount" script works only on local LDB anymore - therefore remove
this parameter.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The "enableaccount" script works only on local LDB anymore - therefore remove
this parameter.
</pre>
</div>
</content>
</entry>
<entry>
<title>blackbox/test_ldb.sh: test searching using OIDs instead of names for attributes and classes</title>
<updated>2009-09-20T04:44:19+00:00</updated>
<author>
<name>Stefan Metzmacher</name>
<email>metze@samba.org</email>
</author>
<published>2009-09-20T04:05:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=c5d38fd45abb037ff03dfb196c7fd0e2f59b1f28'/>
<id>c5d38fd45abb037ff03dfb196c7fd0e2f59b1f28</id>
<content type='text'>
metze
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
metze
</pre>
</div>
</content>
</entry>
<entry>
<title>s4:pwsettings: Added blackbox tests.</title>
<updated>2009-09-09T23:09:56+00:00</updated>
<author>
<name>Andrew Kroeger</name>
<email>andrew@id10ts.net</email>
</author>
<published>2009-09-08T11:01:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=e3a2a22451b3f2b7294da0e6d1f1f6e6d4a33368'/>
<id>e3a2a22451b3f2b7294da0e6d1f1f6e6d4a33368</id>
<content type='text'>
The added tests include basic validation that the script runs and accepts all
custom arguments.  The tests also verify changes to the password complexity,
minimum password length, and minimum password length settings.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The added tests include basic validation that the script runs and accepts all
custom arguments.  The tests also verify changes to the password complexity,
minimum password length, and minimum password length settings.
</pre>
</div>
</content>
</entry>
<entry>
<title>testprogs:subunit.sh: Add function for expected failures.</title>
<updated>2009-09-09T23:09:56+00:00</updated>
<author>
<name>Andrew Kroeger</name>
<email>andrew@id10ts.net</email>
</author>
<published>2009-09-08T21:01:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=67a8a8c9e652d0f1aa5a1c593177bd75bc4af284'/>
<id>67a8a8c9e652d0f1aa5a1c593177bd75bc4af284</id>
<content type='text'>
The testit_expect_failure() function is like the testit() function, with
reversed error detection logic.  This reversal only affects the pass/fail logic
and logging - the original return code from the command is still returned to the
calling script.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The testit_expect_failure() function is like the testit() function, with
reversed error detection logic.  This reversal only affects the pass/fail logic
and logging - the original return code from the command is still returned to the
calling script.
</pre>
</div>
</content>
</entry>
<entry>
<title>s4:kerberos Add support for user principal names in certificates</title>
<updated>2009-07-28T04:10:47+00:00</updated>
<author>
<name>Andrew Bartlett</name>
<email>abartlet@samba.org</email>
</author>
<published>2009-07-28T04:05:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=8ff1f50b0c47f7ff92d557ef4caf64a44b387ab4'/>
<id>8ff1f50b0c47f7ff92d557ef4caf64a44b387ab4</id>
<content type='text'>
This extends the PKINIT code in Heimdal to ask the HDB layer if the
User Principal Name name in the certificate is an alias (perhaps just
by case change) of the name given in the AS-REQ.  (This was a TODO in
the Heimdal KDC)

The testsuite is extended to test this behaviour, and the other PKINIT
certficate (using the standard method to specify a principal name in a
certificate) is updated to use a Administrator (not administrator).
(This fixes the kinit test).

Andrew Bartlett
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This extends the PKINIT code in Heimdal to ask the HDB layer if the
User Principal Name name in the certificate is an alias (perhaps just
by case change) of the name given in the AS-REQ.  (This was a TODO in
the Heimdal KDC)

The testsuite is extended to test this behaviour, and the other PKINIT
certficate (using the standard method to specify a principal name in a
certificate) is updated to use a Administrator (not administrator).
(This fixes the kinit test).

Andrew Bartlett
</pre>
</div>
</content>
</entry>
<entry>
<title>s4:kerberos Add test to show that we actually export the keytab</title>
<updated>2009-07-27T12:41:43+00:00</updated>
<author>
<name>Andrew Bartlett</name>
<email>abartlet@samba.org</email>
</author>
<published>2009-07-27T12:39:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=cdd7a5208fbcb65e4a75ee08f8f015530f418c15'/>
<id>cdd7a5208fbcb65e4a75ee08f8f015530f418c15</id>
<content type='text'>
While it is hard to prove it is correct, at least the new
'nettestuser' principal and the Administrator principal are correct.

We had to fix the case of 'Administrator' in the selftest code to
match the DB, as the keytab lookup is case sensitive.

Andrew Bartlett
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
While it is hard to prove it is correct, at least the new
'nettestuser' principal and the Administrator principal are correct.

We had to fix the case of 'Administrator' in the selftest code to
match the DB, as the keytab lookup is case sensitive.

Andrew Bartlett
</pre>
</div>
</content>
</entry>
<entry>
<title>s4:heimdal Allow KRB5_NT_ENTERPRISE names in all DB lookups</title>
<updated>2009-06-30T02:11:14+00:00</updated>
<author>
<name>Andrew Bartlett</name>
<email>abartlet@samba.org</email>
</author>
<published>2009-06-30T02:11:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=89a074b784295204aa8d7dd585bf3533ac7971a7'/>
<id>89a074b784295204aa8d7dd585bf3533ac7971a7</id>
<content type='text'>
The previous code only allowed an KRB5_NT_ENTERPRISE name (an e-mail
list user principal name) in an AS-REQ.  Evidence from the wild
(Win2k8 reportadely) indicates that this is instead valid for all
types of requests.

While this is now handled in heimdal/kdc/misc.c, a flag is now defined
in Heimdal's hdb so that we can take over this handling in future (once we start
using a system Heimdal, and if we find out there is more to be done
here).

Andrew Bartlett
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The previous code only allowed an KRB5_NT_ENTERPRISE name (an e-mail
list user principal name) in an AS-REQ.  Evidence from the wild
(Win2k8 reportadely) indicates that this is instead valid for all
types of requests.

While this is now handled in heimdal/kdc/misc.c, a flag is now defined
in Heimdal's hdb so that we can take over this handling in future (once we start
using a system Heimdal, and if we find out there is more to be done
here).

Andrew Bartlett
</pre>
</div>
</content>
</entry>
<entry>
<title>s4: Add tests and 'must change password' flags in setpassword and newuser</title>
<updated>2009-06-18T03:49:30+00:00</updated>
<author>
<name>Andrew Bartlett</name>
<email>abartlet@samba.org</email>
</author>
<published>2009-06-18T02:38:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=1e6fb7d7306ee64ac649afe235e452ac116de394'/>
<id>1e6fb7d7306ee64ac649afe235e452ac116de394</id>
<content type='text'>
In particular, ensure that we can acutally change the password under
these circumstances.

Andrew Bartlett
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
In particular, ensure that we can acutally change the password under
these circumstances.

Andrew Bartlett
</pre>
</div>
</content>
</entry>
<entry>
<title>s4:testprogs Don't specify a username/password when checking the ccache</title>
<updated>2009-06-18T03:49:30+00:00</updated>
<author>
<name>Andrew Bartlett</name>
<email>abartlet@samba.org</email>
</author>
<published>2009-06-18T02:36:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.exis.tech/samba.git/commit/?id=033e25fdcea93763e1e8fe295fb6d2c3d261bcc4'/>
<id>033e25fdcea93763e1e8fe295fb6d2c3d261bcc4</id>
<content type='text'>
The purpose of this test is to ensure that the Kerberos credentials
cache is valid.  If the username and password is specified, this
overrides the very thing we are trying to test.

Andrew Bartlett
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The purpose of this test is to ensure that the Kerberos credentials
cache is valid.  If the username and password is specified, this
overrides the very thing we are trying to test.

Andrew Bartlett
</pre>
</div>
</content>
</entry>
</feed>
