Bug Fix Advisory Updated nss_ldap package

Advisory: RHBA-2004:533-03
Type: Bug Fix Advisory
Severity: N/A
Issued on: 2004-12-13
Last updated on: 2004-12-13
Affected Products: Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux WS (v. 2.1)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A

Details

An updated nss_ldap package that fixes a bug in pam_ldap is now available.

The nss_ldap module is a set of C library extensions that allow
applications to consult X.500 and LDAP directory servers for information
that would conventionally be stored in local files or distributed using NIS.

The pam_ldap module allows PAM-enabled applications to authenticate users
using a directory server.

When the pam_ldap module attempts to change a user's password by connecting
to a replica server, the replica server returns a referral record. This in
turn directs the client to make the change on a server which contains a
writable copy of an entry which corresponds to the user. If the entry is a
shadowAccount object, pam_ldap will attempt to modify the entry's
shadowLastChanged attribute to hold the current date. Previously, when the
module attempted to authenticate to the server to make this change, it
would attempt to authenticate using the user's previous password, so the
change would fail to be made.

All users of nss_ldap should upgrade to this updated package, which
resolves these issues.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
nss_ldap-189-12.src.rpm     08919c4ee78818c5e0a8ff1aa232a3e3
 
IA-32:
nss_ldap-189-12.i386.rpm
File outdated by:  RHSA-2005:751
    21fedb0bc56aa6e16657d78a96a68d01
 
IA-64:
nss_ldap-189-12.ia64.rpm
File outdated by:  RHSA-2005:751
    e04cc9a43cec6b8d56b2f04acbf8b88f
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
nss_ldap-189-12.src.rpm     08919c4ee78818c5e0a8ff1aa232a3e3
 
IA-32:
nss_ldap-189-12.i386.rpm
File outdated by:  RHSA-2005:751
    21fedb0bc56aa6e16657d78a96a68d01
 
Red Hat Enterprise Linux WS (v. 2.1)

SRPMS:
nss_ldap-189-12.src.rpm     08919c4ee78818c5e0a8ff1aa232a3e3
 
IA-32:
nss_ldap-189-12.i386.rpm
File outdated by:  RHSA-2005:751
    21fedb0bc56aa6e16657d78a96a68d01
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
nss_ldap-189-12.src.rpm     08919c4ee78818c5e0a8ff1aa232a3e3
 
IA-64:
nss_ldap-189-12.ia64.rpm
File outdated by:  RHSA-2005:751
    e04cc9a43cec6b8d56b2f04acbf8b88f
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

120523 - [patch] updateref not updating shadowLastChange from slave to master


Keywords

pam_ldap, referral, shadowLastChange


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/