RHBA-2009:1358: bug fix and enhancement update
197
has been changed so that it does not attempt to resolve the origins of entries in access.conf which
do not contain an IP address or an IP addresses and a netmask value. (
BZ#459057
1385
)
• the pam_keyinit module did not save the UserID (UID) of the process during session close, which
made it unable to switch back to that original UID. An error message was output to the system log in
that case. The UID is now correctly saved with these updated packages, which makes the spurious
log message disappear. (
BZ#466411
1386
)
• the pam_filter module was not able to open a new pseudoterminal, which prevented the module
from functioning properly. With this update, pam_filter is able to open new pseudoterminals.
(
BZ#473970
1387
)
• when the "open_tty" module was used in combination with the "pam_tty_audit" module in the
system-auth pam configuration file, pam_tty_audit could segmentation fault if the "open_only"
option was set and the open_tty module was called by the "su" command or another utility.
(
BZ#476833
1388
)
• the "smbpasswd" utility allows a user to change their encrypted SMB password, which is stored
in the smbpasswd file. However, it was not possible for non-root users to change their password
with "smbpasswd" due to overly strict checking in the helper of the pam_unix module. This has
been corrected so that users can once again change their SMB passwords using "smbpasswd".
(
BZ#476904
1389
)
• the coreutils package was listed incorrectly as a prerequisite requirement for the pam packages
instead of a post-install requirement. This dependency statement has been corrected in these
updated packages. (
BZ#497570
1390
)
In addition, these updated packages provide the following enhancements:
• Gnome Display Manager's (GDM's) accessibility features did not function correctly when an audio
device was not properly configured. The configuration file for console device modes now sets
audio devices as owned by the "audio" group if there is no console user. This provides support for
accessible login with GDM. (
BZ#244688
1391
)
• the pam_tally2 module now supports a new option that allows serialized access to the /var/
log/tallylog file. Enabling this option prevents possible failed authentication when two separate
processes attempt to authenticate nearly simultaneously when the lock_time option ("always deny
for n seconds after a failed attempt") is set to a value of one or greater. (
BZ#455217
1392
)
• these updated pam packages provide a new PAM module, pam_faildelay, which can read the
"FAIL_DELAY" value from the /etc/login.defs configuration file and set the amount of delay between
login prompts following a failed login attempt to that value. (
BZ#476217
1393
)
• these updated pam packages provide a new PAM module, pam_pwhistory, which saves the
last passwords for each user in order to force password change history and keep the user from
alternating between the same password too frequently. (
BZ#451085
1394
)
Users are advised to upgrade to these updated pam packages, which resolve these issues and add
these enhancements.
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...