Debian release 1.1-1

Format: 1.8
Date: Wed, 16 Jul 2014 17:08:35 -0700
Source: wallet
Binary: keytab-backend wallet-client wallet-server
Architecture: source all i386
Version: 1.1-1
Distribution: unstable
Urgency: medium
Maintainer: Russ Allbery <>
Changed-By: Russ Allbery <>
 keytab-backend - Provide existing MIT Kerberos keytabs via remctl
 wallet-client - Kerberos-authenticated secure data management client
 wallet-server - Kerberos-authenticated secure data management server
 wallet (1.1-1) unstable; urgency=medium
   * New upstream release.
     - New object type, duo, which creates a UNIX integration with the Duo
       Security cloud multifactor authentication service.
     - The owner and getacl commands now return the name of the ACL.
     - The date passed to expires can be any date format understood by
     - wallet-rekey now works properly with keytabs containing multiple
       principals and does not store new principals in a separate file
     - Fix setting enctype restrictions on keytab objects and populate the
       reference table for valid enctypes on database creation.
     - Fix Wallet::Config documentation of ldap_map_principal.
     - Generate a long, random password when creating new principals in the
       Heimdal KDC to avoid problems with password quality checks.
     - Remove erroneous foreign key constraints between the object history
       and objects table, an incorrect linkage in the ACL history table,
       and add indices for object type, name, and ACL.
     - Use DateTime objects uniformly in the database layer.
     - ACL renames are now recorded in the ACL history.
     - Fix wallet-backend parsing of the expires command to expect only one
     - Fix ordering of table drops during wallet-admin destroy to honor
       foreign key reference constraints.
     - The initial ADMIN ACL creation is no longer documented in history.
   * Document in the wallet-server package description that a DBD::* module
     and corresponding DateTime::Format::* module are required.  (There
     isn't a way to fully represent the required dependency.)
   * Rebuild Autoconf and Automake files during the build.
   * Define AUTOMATED_TESTING to enable some additional Perl tests.
   * Adjust debian/rules for the new Module::Build Perl build system.
   * Drop now-unneeded dh_builddeb override for xz compression.
   * Enable uscan verification of the GnuPG signatures on upstream
     releases in debian/watch.
   * Update standards version to 3.9.5 (no changes required).
