+userdir-ldap (0.3.80) UNRELEASED; urgency=low
+
+ [ Peter Palfrader ]
+ * some ud-echelon fixes,
+ * userdir_gpg.py: GetClearSig: add lax_multipart to deal
+ with random multipart mails.
+ * naming your variable like a module is unsmart.
+ * ud-generate:
+ - filter on shadowAccount.
+ - fix breaking old ud-generate locks.
+ * ud-mailgate: only run ldapmodfiy if we actually have attributes to modify.
+ * ud-replicate:
+ - do not hard-code 'debian.org' in the 'write-zonefile debian.org' call,
+ but instead re-use the domain from email-append.
+ - now preserve server side modifcation times when rsyncing data.
+ * userdir_ldap.py: read auth password from environment if set.
+ * Introduce BaseBaseDN which is the real base dn. BaseDN itself
+ has historically been used as the root of the user tree.
+ * Allow a set of users to be ignored for picking UIDs.
+ * When picking uid/gid numbers try to pick the same number for both.
+ * Merge from torproject.org:
+ - Allow sshRSAAuthKey for role accounts.
+ - Support ssh key attributes for gitolite export.
+ - Add ssh-gitolite support.
+ * debianGroups may have cn attribute (helpful when putting samba stuff into
+ ldap).
+ * ud-mailgate: Do not try to do an ldap modify with no changes - now show
+ command to changes@ should work again.
+ * ud-generate: No longer expand $ in dnsZoneEntry data to a \n\t.
+ * ud-generate: Move code into getLastBuildTime() and getLastLDAPChangeTime()
+ functions.
+ * ud-generate: Add -f option to build even if cache is current.
+ * ud-generate: Move main code into a ud_generate()
+ * ud-generate: speed improvements:
+ - cut down on calls to IsInGroup by doing it once in generate_host()
+ and not having the individual generators run it.
+ o side effect: Up until now we exported empty groups to a host, if
+ that group had a user with that group as their primary group - even
+ if that particular user was not exported to this this. No we no
+ longer export empty groups.
+ - speed up ssh tarball generation: No longer write indidividual user's ssh
+ authorized_keys to disk, only to read them later. Directly create a
+ TarInfo object without referring to any on-disk files.
+ - get rid of global state variable CurrentHost. This will enable upcoming
+ changes.
+ - UDLdap.py: make a cache for __getitem__() decisions.
+ - wrap cdbmake calls in eatmydata. Nothing else does any fsync stuff,
+ so doing it here just costs a lot.
+ * ud-generate: Use a flock() lock instead of python's lockfile class.
+ * ud-generate: The ssh authorized_keys file for the sshdist user now wraps
+ the rsync call in an flock wrapper that acquires a shared lock on
+ ud-generate's lock. This prevents syncing while ud-generate runs.
+
+ [ Stephen Gran ]
+ * Fix deprecation warnings for sha module by using hashlib module instead
+ * ud-fingerserv: update Net::LDAP import
+ * Implement audit logging for ldap
+ * stop running ud-generate if nothing has changed, based on audit logs
+
+ [ Martin Zobel-Helas ]
+ * ud-generate: generate webPasswords
+ * ud-replicate: set correct permissions for web-passwords
+ * add freecdb to depends
+ * userdir-ldap.schema
+ - add webPasswords
+ - add mailPreserveSuffixSeperator
+
+ -- Martin Zobel-Helas <zobel@debian.org> Fri, 23 Mar 2012 19:19:16 +0100
+
+userdir-ldap (0.3.79) unstable; urgency=low
+
+ * Add ud-sync-accounts-to-afs, a script to sync accounts to an
+ AFS protection database.
+ * ud-generate:
+ - support host ACLs that expire.
+ - lock output directory when generating.
+ - support sync keyring dirs now too.
+ * ud-useradd: A new -g switch for adding guest accounts, with
+ proper setting hostacls and shadowexpire and picking the
+ right keyring.
+ * Remove .pgp (v3 pgp key) keyrings from config.
+ * Update guest welcome template.
+ * ud-gpgimport: handle guest keyrings.
+ * ud-mailgate:
+ - Make updating of gender actually work.
+ - Do not mess with sudo passwords if nothing changed.
+ * templates/change-reply: say a word about subjects in mail to admin@db.
+ * move gpgwrapper to unmaintained/ - it is now using obsolete interfaces.
+ * try to properly handle some more mime stuff.
+ - use email module instead of deprecated mimetools and multifile modules
+ - changes: sigcheck ud-echelon ud-mailgate userdir_gpg.py
+ * move ud-echelon and sigcheck to GPGCheckSig2 interface.
+
+ -- Peter Palfrader <weasel@debian.org> Sat, 21 May 2011 14:53:18 +0200
+
+userdir-ldap (0.3.78) unstable; urgency=low
+
+ * Start refactoring ud-generate:
+ - If environment variables UD_CREDENTIALS, UD_GENERATEDIR, UD_HMAC_KEY
+ are set, use their respective value instead of the default. This
+ makes it possible to run ud-generate as a non-privileged user for
+ testing purposes.
+ - Start wrapping ldap search results in classes. For now we have done
+ this with just an ldap account.
+ - Also got rid of the global PasswdAttrs variable. Now functions
+ get the account list (now a list of Account classes instead of
+ ldap result array of tuples of hashes) passed to them like well-behaved
+ functions.
+ * userdir-ldap-slapd.conf: Fix ACL rule for keyring maintainers
+ (we want group=..., not dn=...).
+ * Add ud-krb-reset, and make ud-mailgate call it when
+ receiving a mail at chpasswd@ saying
+ 'Please change my Kerberos password'.
+ * ud-generate: Add an extra output file called all-users.json that
+ can be used on one of the AFS hosts to create afs users.
+
+ -- Peter Palfrader <weasel@debian.org> Mon, 13 Sep 2010 19:08:34 +0200
+
+userdir-ldap (0.3.77) unstable; urgency=low
+
+ [ Peter Palfrader ]
+ * ud-mailgate: Remove a global declaration after a variable has
+ already been assigned globally.
+ * ud-mailgate: We use the result of the pgp check for quite a long
+ time in the main program. Give it its own variable instead of
+ using Res which was overwritten a bit later. Also make a new
+ gpgcheck2 class that allows us to access the values of the gpg
+ signature check in a saner way.
+ * ud-gpgimport: Get rid of "0x" when printing keyids/fingerprints.
+ * Add ud-lock.
+ * Fix a typo in welcome-message-800 noticed by Tommi Vainikainen.
+ * Refactor the LDAP acls to be easier to manage.
+ Effective changes:
+ - Keyring Maintainers ldap group gets to write to the keyFingerPrint
+ attribute.
+ - sshrsaauthkey is no longer compareable by *.
+ * ud-generate: refuse to run as root.
+
+ [ Stephen Gran ]
+ * Add txt record support to ud-mailgate
+ * Clean up addition of identifying txt records to debian.net slightly
+
+ -- Peter Palfrader <weasel@debian.org> Fri, 30 Jul 2010 19:46:48 +0200
+
+userdir-ldap (0.3.76) unstable; urgency=low
+
+ [ Peter Palfrader ]
+ * ud-generate: Export groups even if nobody has that group as a
+ supplementary group, as long as there are users that have it as a primary
+ group.
+ * ud-useradd: If we do not have a template for a specific group, use the
+ general purpose template file (welcome-message).
+ * ud-useradd: Fix usergroup support:
+ - Move ldap call to actually add the user to the right place,
+ - Properly compare strings and numbers.
+ * ud-useradd: Only ask for private subscription if this installation
+ has a debian-private like mailinglist whose membership is configured
+ by ud-ldap. (defaults to true.)
+ * Fix welcome-message to be like welcome-message-800 and 60000 wrt
+ email headers
+ * ud-useradd: Properly encode realname in subjects and to header lines
+ regardless of which template is being used.
+ * ud-generate: move the regex that determines whether or not to include
+ a host in the dns-sshfp zone snippet (for SSHFP and A, AAAA and MX
+ records) to the config file.
+ * Include a host in DNS even if we do not have both ssh keys and an
+ arch for that host configured.
+
+ [ Stephen Gran ]
+ * Add patches from Helmut Grohne <helmut@subdivi.de>:
+ Allow ssh keys to be exported only to specific hosts by prefixing them
+ with allowed_hosts=[host1[,host2 ...]]] when adding them using
+ ud-mailgate.
+
+ -- Stephen Gran <sgran@debian.org> Sat, 30 Jan 2010 13:33:40 +0000
+
+userdir-ldap (0.3.75) unstable; urgency=low
+
+ * Enable support for mailDefaultOptions
+ * Make a stab at really not exporting empty groups.
+
+ -- Stephen Gran <sgran@debian.org> Mon, 16 Nov 2009 21:36:53 +0000
+
+userdir-ldap (0.3.74) unstable; urgency=low
+
+ [ Peter Palfrader ]
+ * ud-generate: Make sure we only add people in gid 800 to debian-private.
+ (DebianUsers was just a copy of PasswdAttrs. So use PasswdAttrs in
+ all the places that currently use DebianUsers. Make a filtered list
+ DebianDDUsers (accounts in gid 800), and use that for building the
+ debian-private subscription list.)
+ * welcome-message-60000: improve wording of a sentence. Sometimes less
+ is more.
+
+ [ Stephen Gran ]
+ * Initial support for BATV token storage.
+ * generate a new file for mail forwards for users present on this machine
+
+ -- Stephen Gran <sgran@debian.org> Sun, 15 Nov 2009 11:54:41 +0000
+
+userdir-ldap (0.3.73) unstable; urgency=low
+
+ * Add dnsTTL host attribute to override the zone default TTL
+ for A and AAAA records. Also for MX, HINFO and SSHFP.
+
+ -- Peter Palfrader <weasel@debian.org> Sun, 18 Oct 2009 12:38:51 +0200
+
+userdir-ldap (0.3.72) unstable; urgency=low
+
+ [ Peter Palfrader ]
+ * ud-useradd: Allow unsetting of middle names by entering a space.
+ * userdir-ldap.conf: Add debian-maintainers.gpg to keyrings and
+ sync_keyrings.
+ * ud-useradd: force gidNumber to be an int when we open the welcome
+ template (it can be different when we read it from input using -n).
+ * Tweak templates/welcome-message-60000.
+ * ud-generate: don't blow up when a host does not have IP-addresses.
+ * We autogenerate the authorized_keys files for sshdist on db-master.
+ It limits the hosts' ssh key to coming from their respective addresses.
+ Now we can add additional source addresses to accept for this since
+ not all hosts appear to come from their published address (or have
+ a published address for that matter).
+
+ [ Stephen Gran ]
+ * Make zone reloads work when ud-generate updates zone files
+
+ -- Stephen Gran <sgran@debian.org> Mon, 05 Oct 2009 00:54:43 +0100
+
+userdir-ldap (0.3.71) unstable; urgency=low
+
+ * Enable autogeneration of DNS records for .d.o hosts
+
+ -- Stephen Gran <sgran@debian.org> Sun, 23 Aug 2009 12:50:01 +0000
+
+userdir-ldap (0.3.70) unstable; urgency=low
+
+ * Enable autogeneration of sshdist's authorized_keys file
+
+ -- Stephen Gran <sgran@debian.org> Sun, 09 Aug 2009 16:10:35 +0000
+
+userdir-ldap (0.3.69) unstable; urgency=low
+
+ * Make ud-host do allowedGroups, exportOptions.
+
+ -- Peter Palfrader <weasel@debian.org> Thu, 23 Jul 2009 22:52:08 +0200
+
+userdir-ldap (0.3.68) unstable; urgency=low