-userdir-ldap (0.3.76xXx) unstable; urgency=low
+userdir-ldap (0.3.XXX) UNRELEASED; urgency=low
+ [ Peter Palfrader ]
+ * some ud-echelon fixes,
+ * userdir_gpg.py: GetClearSig: add lax_multipart to deal
+ with random multipart mails.
+ * naming your variable like a module is unsmart.
+ * ud-generate: filter on shadowAccount.
+
+ [ Stephen Gran ]
+ * Fix deprecation warnings for sha module by using hashlib module instead
+
+ -- Stephen Gran <sgran@debian.org> Thu, 09 Jun 2011 17:51:52 +0000
+
+userdir-ldap (0.3.79) unstable; urgency=low
+
+ * Add ud-sync-accounts-to-afs, a script to sync accounts to an
+ AFS protection database.
+ * ud-generate:
+ - support host ACLs that expire.
+ - lock output directory when generating.
+ - support sync keyring dirs now too.
+ * ud-useradd: A new -g switch for adding guest accounts, with
+ proper setting hostacls and shadowexpire and picking the
+ right keyring.
+ * Remove .pgp (v3 pgp key) keyrings from config.
+ * Update guest welcome template.
+ * ud-gpgimport: handle guest keyrings.
+ * ud-mailgate:
+ - Make updating of gender actually work.
+ - Do not mess with sudo passwords if nothing changed.
+ * templates/change-reply: say a word about subjects in mail to admin@db.
+ * move gpgwrapper to unmaintained/ - it is now using obsolete interfaces.
+ * try to properly handle some more mime stuff.
+ - use email module instead of deprecated mimetools and multifile modules
+ - changes: sigcheck ud-echelon ud-mailgate userdir_gpg.py
+ * move ud-echelon and sigcheck to GPGCheckSig2 interface.
+
+ -- Peter Palfrader <weasel@debian.org> Sat, 21 May 2011 14:53:18 +0200
+
+userdir-ldap (0.3.78) unstable; urgency=low
+
+ * Start refactoring ud-generate:
+ - If environment variables UD_CREDENTIALS, UD_GENERATEDIR, UD_HMAC_KEY
+ are set, use their respective value instead of the default. This
+ makes it possible to run ud-generate as a non-privileged user for
+ testing purposes.
+ - Start wrapping ldap search results in classes. For now we have done
+ this with just an ldap account.
+ - Also got rid of the global PasswdAttrs variable. Now functions
+ get the account list (now a list of Account classes instead of
+ ldap result array of tuples of hashes) passed to them like well-behaved
+ functions.
+ * userdir-ldap-slapd.conf: Fix ACL rule for keyring maintainers
+ (we want group=..., not dn=...).
+ * Add ud-krb-reset, and make ud-mailgate call it when
+ receiving a mail at chpasswd@ saying
+ 'Please change my Kerberos password'.
+ * ud-generate: Add an extra output file called all-users.json that
+ can be used on one of the AFS hosts to create afs users.
+
+ -- Peter Palfrader <weasel@debian.org> Mon, 13 Sep 2010 19:08:34 +0200
+
+userdir-ldap (0.3.77) unstable; urgency=low
+
+ [ Peter Palfrader ]
+ * ud-mailgate: Remove a global declaration after a variable has
+ already been assigned globally.
+ * ud-mailgate: We use the result of the pgp check for quite a long
+ time in the main program. Give it its own variable instead of
+ using Res which was overwritten a bit later. Also make a new
+ gpgcheck2 class that allows us to access the values of the gpg
+ signature check in a saner way.
+ * ud-gpgimport: Get rid of "0x" when printing keyids/fingerprints.
+ * Add ud-lock.
+ * Fix a typo in welcome-message-800 noticed by Tommi Vainikainen.
+ * Refactor the LDAP acls to be easier to manage.
+ Effective changes:
+ - Keyring Maintainers ldap group gets to write to the keyFingerPrint
+ attribute.
+ - sshrsaauthkey is no longer compareable by *.
+ * ud-generate: refuse to run as root.
+
+ [ Stephen Gran ]
+ * Add txt record support to ud-mailgate
+ * Clean up addition of identifying txt records to debian.net slightly
+
+ -- Peter Palfrader <weasel@debian.org> Fri, 30 Jul 2010 19:46:48 +0200
+
+userdir-ldap (0.3.76) unstable; urgency=low
+
+ [ Peter Palfrader ]
* ud-generate: Export groups even if nobody has that group as a
supplementary group, as long as there are users that have it as a primary
group.
* ud-useradd: Fix usergroup support:
- Move ldap call to actually add the user to the right place,
- Properly compare strings and numbers.
+ * ud-useradd: Only ask for private subscription if this installation
+ has a debian-private like mailinglist whose membership is configured
+ by ud-ldap. (defaults to true.)
+ * Fix welcome-message to be like welcome-message-800 and 60000 wrt
+ email headers
+ * ud-useradd: Properly encode realname in subjects and to header lines
+ regardless of which template is being used.
+ * ud-generate: move the regex that determines whether or not to include
+ a host in the dns-sshfp zone snippet (for SSHFP and A, AAAA and MX
+ records) to the config file.
+ * Include a host in DNS even if we do not have both ssh keys and an
+ arch for that host configured.
+
+ [ Stephen Gran ]
+ * Add patches from Helmut Grohne <helmut@subdivi.de>:
+ Allow ssh keys to be exported only to specific hosts by prefixing them
+ with allowed_hosts=[host1[,host2 ...]]] when adding them using
+ ud-mailgate.
- -- Peter Palfrader <weasel@debian.org> Sat, 09 Jan 2010 00:19:44 +0100
+ -- Stephen Gran <sgran@debian.org> Sat, 30 Jan 2010 13:33:40 +0000
userdir-ldap (0.3.75) unstable; urgency=low