notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine

Bot filter coming soon

To deter bots pegging the database CPU to 100%, a bot testing filter to be added to the website. This should not affect newsfeeds etc. Anubis seems light-weight - it''''''''s already in use within the FreeBSD Project. This notice is just a heads up in case you see something odd. This notice will be updated after Anubis is installed.

Port details on branch 2022Q4
krb5-120 MIT implementation of RFC 4120 network authentication service
1.20.1 security on this many watch lists=0 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 1.20.1Version of this port present on the latest quarterly branch.
Maintainer: cy@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2022-11-15 16:39:06
Last Update: 2022-11-15 17:19:38
Commit Hash: e95bb48
License: MIT
WWW:
https://web.mit.edu/kerberos/
Description:
Kerberos V5 is an authentication system developed at MIT. Abridged from the User Guide: Under Kerberos, a client sends a request for a ticket to the Key Distribution Center (KDC). The KDC creates a ticket-granting ticket (TGT) for the client, encrypts it using the client's password as the key, and sends the encrypted TGT back to the client. The client then attempts to decrypt the TGT, using its password. If the client successfully decrypts the TGT, it keeps the decrypted TGT, which indicates proof of the client's identity. The TGT permits the client to obtain additional tickets, which give permission for specific services. Since Kerberos negotiates authenticated, and optionally encrypted, communications between two points anywhere on the internet, it provides a layer of security that is not dependent on which side of a firewall either client is on. The Kerberos V5 package is designed to be easy to use. Most of the commands are nearly identical to UNIX network programs you are already used to. Kerberos V5 is a single-sign-on system, which means that you have to type your password only once per session, and Kerberos does the authenticating and encrypting transparently. Jacques Vidrine <n@nectar.com>
Homepage    cgit ¦ Codeberg ¦ GitHub ¦ GitLab ¦ SVNWeb - no subversion history for this port

Manual pages:
pkg-plist: as obtained via: make generate-plist
Expand this list (184 items)
Collapse this list.
  1. @ldconfig
  2. /usr/local/share/licenses/krb5-120-1.20.1/catalog.mk
  3. /usr/local/share/licenses/krb5-120-1.20.1/LICENSE
  4. /usr/local/share/licenses/krb5-120-1.20.1/MIT
  5. bin/compile_et
  6. bin/gss-client
  7. bin/k5srvutil
  8. bin/kadmin
  9. bin/kdestroy
  10. bin/kinit
  11. bin/klist
  12. bin/kpasswd
  13. bin/krb5-config
  14. @mode 04755
  15. @owner root
  16. @group wheel
  17. bin/ksu
  18. @mode
  19. @owner root
  20. @group wheel
  21. bin/kswitch
  22. bin/ktutil
  23. bin/kvno
  24. bin/sclient
  25. bin/sim_client
  26. bin/uuclient
  27. include/com_err.h
  28. include/gssapi.h
  29. include/gssapi/gssapi.h
  30. include/gssapi/gssapi_alloc.h
  31. include/gssapi/gssapi_ext.h
  32. include/gssapi/gssapi_generic.h
  33. include/gssapi/gssapi_krb5.h
  34. include/gssapi/mechglue.h
  35. include/gssrpc/auth.h
  36. include/gssrpc/auth_gss.h
  37. include/gssrpc/auth_gssapi.h
  38. include/gssrpc/auth_unix.h
  39. include/gssrpc/clnt.h
  40. include/gssrpc/netdb.h
  41. include/gssrpc/pmap_clnt.h
  42. include/gssrpc/pmap_prot.h
  43. include/gssrpc/pmap_rmt.h
  44. include/gssrpc/rename.h
  45. include/gssrpc/rpc.h
  46. include/gssrpc/rpc_msg.h
  47. include/gssrpc/svc.h
  48. include/gssrpc/svc_auth.h
  49. include/gssrpc/types.h
  50. include/gssrpc/xdr.h
  51. include/krad.h
  52. include/krb5.h
  53. include/krb5/ccselect_plugin.h
  54. include/krb5/clpreauth_plugin.h
  55. include/krb5/hostrealm_plugin.h
  56. include/krb5/kadm5_hook_plugin.h
  57. include/krb5/kdcpolicy_plugin.h
  58. include/krb5/kdcpreauth_plugin.h
  59. include/krb5/localauth_plugin.h
  60. include/krb5/krb5.h
  61. include/krb5/locate_plugin.h
  62. include/krb5/plugin.h
  63. include/krb5/pwqual_plugin.h
  64. include/kadm5/admin.h
  65. include/kadm5/chpass_util_strings.h
  66. include/krb5/kadm5_auth_plugin.h
  67. include/kadm5/kadm_err.h
  68. include/kdb.h
  69. include/krb5/certauth_plugin.h
  70. include/krb5/preauth_plugin.h
  71. include/profile.h
  72. include/verto-module.h
  73. include/verto.h
  74. lib/libcom_err.so
  75. lib/libcom_err.so.3
  76. lib/libcom_err.so.3.0
  77. lib/libgssapi_krb5.so
  78. lib/libgssapi_krb5.so.2
  79. lib/libgssapi_krb5.so.2.2
  80. lib/libgssrpc.so
  81. lib/libgssrpc.so.4
  82. lib/libgssrpc.so.4.2
  83. lib/libk5crypto.so
  84. lib/libk5crypto.so.3
  85. lib/libk5crypto.so.3.1
  86. lib/libkadm5clnt.so
  87. lib/libkadm5clnt_mit.so
  88. lib/libkadm5clnt_mit.so.12
  89. lib/libkadm5clnt_mit.so.12.0
  90. lib/libkadm5srv.so
  91. lib/libkadm5srv_mit.so
  92. lib/libkadm5srv_mit.so.12
  93. lib/libkadm5srv_mit.so.12.0
  94. lib/libkdb5.so
  95. lib/libkdb5.so.10
  96. lib/libkdb5.so.10.0
  97. lib/libkrb5.so
  98. lib/libkrb5.so.3
  99. lib/libkrb5.so.3.3
  100. lib/libkrb5support.so
  101. lib/libkrb5support.so.0
  102. lib/libkrb5support.so.0.1
  103. lib/krb5/plugins/kdb/db2.so
  104. @comment lib/krb5/plugins/kdb/klmdb.so
  105. lib/krb5/plugins/tls/k5tls.so
  106. @comment lib/krb5/plugins/kdb/kldap.so
  107. lib/krb5/plugins/preauth/otp.so
  108. lib/krb5/plugins/preauth/pkinit.so
  109. lib/krb5/plugins/preauth/spake.so
  110. lib/krb5/plugins/preauth/test.so
  111. @comment lib/libkdb_ldap.so
  112. @comment lib/libkdb_ldap.so.1
  113. @comment lib/libkdb_ldap.so.1.0
  114. lib/libkrad.so
  115. lib/libkrad.so.0
  116. lib/libkrad.so.0.0
  117. lib/libverto.so
  118. lib/libverto.so.0
  119. lib/libverto.so.0.0
  120. libdata/pkgconfig/gssrpc.pc
  121. libdata/pkgconfig/kadm-client.pc
  122. libdata/pkgconfig/kadm-server.pc
  123. libdata/pkgconfig/kdb.pc
  124. libdata/pkgconfig/krb5-gssapi.pc
  125. libdata/pkgconfig/krb5.pc
  126. libdata/pkgconfig/mit-krb5-gssapi.pc
  127. libdata/pkgconfig/mit-krb5.pc
  128. man/man1/compile_et.1.gz
  129. man/man1/k5srvutil.1.gz
  130. man/man1/kadmin.1.gz
  131. man/man1/kdestroy.1.gz
  132. man/man1/kinit.1.gz
  133. man/man1/klist.1.gz
  134. man/man1/kpasswd.1.gz
  135. man/man1/krb5-config.1.gz
  136. man/man1/ksu.1.gz
  137. man/man1/kswitch.1.gz
  138. man/man1/ktutil.1.gz
  139. man/man1/kvno.1.gz
  140. man/man1/sclient.1.gz
  141. man/man5/.k5identity.5.gz
  142. man/man5/.k5login.5.gz
  143. man/man5/k5identity.5.gz
  144. man/man5/k5login.5.gz
  145. man/man5/kadm5.acl.5.gz
  146. man/man5/kdc.conf.5.gz
  147. man/man5/krb5.conf.5.gz
  148. man/man7/kerberos.7.gz
  149. man/man8/kadmin.local.8.gz
  150. man/man8/kadmind.8.gz
  151. man/man8/kdb5_ldap_util.8.gz
  152. man/man8/kdb5_util.8.gz
  153. man/man8/kprop.8.gz
  154. man/man8/kpropd.8.gz
  155. man/man8/kproplog.8.gz
  156. man/man8/krb5kdc.8.gz
  157. man/man8/sserver.8.gz
  158. sbin/gss-server
  159. sbin/kadmin.local
  160. sbin/kadmind
  161. @comment sbin/kdb5_ldap_util
  162. sbin/kdc
  163. sbin/kdb5_util
  164. sbin/kprop
  165. sbin/kpropd
  166. sbin/kproplog
  167. sbin/krb5-send-pr
  168. sbin/krb5kdc
  169. sbin/sim_server
  170. sbin/sserver
  171. sbin/uuserver
  172. share/et/et_c.awk
  173. share/et/et_h.awk
  174. share/locale/de/LC_MESSAGES/mit-krb5.mo
  175. share/locale/en_US/LC_MESSAGES/mit-krb5.mo
  176. @comment share/krb5/kerberos.schema
  177. @comment share/krb5/kerberos.ldif
  178. @dir lib/krb5/plugins/authdata
  179. @dir lib/krb5/plugins/libkrb5
  180. @dir var/run/krb5kdc
  181. @dir var/krb5kdc
  182. @owner
  183. @group
  184. @mode
Collapse this list.
Dependency lines:
  • krb5-120>0:security/krb5-120
Conflicts:
CONFLICTS:
  • heimdal
  • krb5
  • krb5-11*
CONFLICTS_BUILD:
  • boringssl
To install the port:
cd /usr/ports/security/krb5-120/ && make install clean
To add the package, run one of these commands:
  • pkg install security/krb5-120
  • pkg install krb5-120
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.
PKGNAME: krb5-120
Flavors: there is no flavor information for this port.
distinfo:
TIMESTAMP = 1668532397 SHA256 (krb5-1.20.1.tar.gz) = 704aed49b19eb5a7178b34b2873620ec299db08752d6a8574f95d41879ab8851 SIZE (krb5-1.20.1.tar.gz) = 8661660

No package information for this port in our database
Sometimes this happens. Not all ports have packages. Perhaps there is a build error. Check the fallout link: pkg-fallout
Dependencies
NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
Build dependencies:
  1. gmake>=4.3 : devel/gmake
  2. libtool : devel/libtool
  3. pkgconf>=1.3.0_1 : devel/pkgconf
  4. msgfmt : devel/gettext-tools
  5. perl5>=5.32.r0<5.33 : lang/perl5.32
Library dependencies:
  1. libintl.so : devel/gettext-runtime
  2. libreadline.so.8 : devel/readline
There are no ports dependent upon this port

Configuration Options:
===> The following configuration options are available for krb5-120-1.20.1: DNS_FOR_REALM=off: Enable DNS lookups for Kerberos realm names EXAMPLES=on: Build and/or install examples KRB5_HTML=on: Install krb5 HTML documentation KRB5_PDF=on: Install krb5 PDF documentation LDAP=off: LDAP protocol support LMDB=off: OpenLDAP Lightning Memory-Mapped Database support NLS=on: Native Language Support ====> Command line editing for kadmin and ktutil: you can only select none or one of them READLINE=on: Command line editing via libreadline LIBEDIT=off: Command line editing via libedit ===> Use 'make config' to modify these settings
Options name:
security_krb5-120
USES:
compiler:c++11-lang cpe gmake gettext-runtime gssapi:bootstrap,mit libtool:build localbase perl5 pkgconfig ssl gettext readline
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (1 items)
Collapse this list.
  1. http://web.mit.edu/kerberos/dist/krb5/1.20/
Collapse this list.

Number of commits found: 2

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
1.20.1
15 Nov 2022 17:19:38
commit hash: e95bb48de1cc0e2e2514695e0875cf9fe7728523commit hash: e95bb48de1cc0e2e2514695e0875cf9fe7728523commit hash: e95bb48de1cc0e2e2514695e0875cf9fe7728523commit hash: e95bb48de1cc0e2e2514695e0875cf9fe7728523 files touched by this commit
Cy Schubert (cy) search for other commits by this committer
security/krb5-120: Update to 1.20.1

Security:	CVE-2022-42898
(cherry picked from commit abcf942f2ba44a1f333ce3daa2b8961202351a09)
1.20_1
15 Nov 2022 16:37:57
commit hash: a718d88e077255f3c6b124b1be30cfc9e9d2e58ecommit hash: a718d88e077255f3c6b124b1be30cfc9e9d2e58ecommit hash: a718d88e077255f3c6b124b1be30cfc9e9d2e58ecommit hash: a718d88e077255f3c6b124b1be30cfc9e9d2e58e files touched by this commit
Cy Schubert (cy) search for other commits by this committer
security/krb5-*: Address CVE-2022-42898

Topic: Vulnerabilities in PAC parsing

CVE-2022-42898: integer overflow vulnerabilities in PAC parsing

SUMMARY
=======

Three integer overflow vulnerabilities have been discovered in the MIT
krb5 library function krb5_parse_pac().

IMPACT
======
(Only the first 15 lines of the commit message are shown above View all of this commit message)

Number of commits found: 2