summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--debian/.git-dpm8
-rw-r--r--debian/NEWS48
-rw-r--r--debian/README.Debian78
-rw-r--r--debian/README.KDC51
-rw-r--r--debian/README.source47
-rw-r--r--debian/changelog2595
-rw-r--r--debian/clean6
-rw-r--r--debian/compat1
-rw-r--r--debian/control466
-rw-r--r--debian/copyright1338
-rw-r--r--debian/gbp.conf2
-rw-r--r--debian/kdc.conf16
-rw-r--r--debian/krb5-admin-server.config10
-rwxr-xr-xdebian/krb5-admin-server.init124
-rw-r--r--debian/krb5-admin-server.install7
-rw-r--r--debian/krb5-admin-server.links1
-rw-r--r--debian/krb5-admin-server.lintian-overrides2
-rw-r--r--debian/krb5-admin-server.postinst15
-rw-r--r--debian/krb5-admin-server.postrm11
-rw-r--r--debian/krb5-admin-server.service16
-rw-r--r--debian/krb5-admin-server.templates22
-rw-r--r--debian/krb5-doc.doc-base.admin12
-rw-r--r--debian/krb5-doc.doc-base.appdev12
-rw-r--r--debian/krb5-doc.doc-base.basic12
-rw-r--r--debian/krb5-doc.doc-base.build12
-rw-r--r--debian/krb5-doc.doc-base.plugindev12
-rw-r--r--debian/krb5-doc.doc-base.user12
-rw-r--r--debian/krb5-doc.docs12
-rw-r--r--debian/krb5-doc.install6
-rw-r--r--debian/krb5-gss-samples.docs1
-rw-r--r--debian/krb5-gss-samples.install3
-rw-r--r--debian/krb5-gss-samples.lintian-overrides2
-rw-r--r--debian/krb5-k5tls.install1
-rw-r--r--debian/krb5-kdc-ldap.docs3
-rw-r--r--debian/krb5-kdc-ldap.insserv-override10
-rw-r--r--debian/krb5-kdc-ldap.install7
-rw-r--r--debian/krb5-kdc.NEWS8
-rw-r--r--debian/krb5-kdc.config19
-rw-r--r--debian/krb5-kdc.dirs.in5
-rw-r--r--debian/krb5-kdc.docs2
-rwxr-xr-xdebian/krb5-kdc.init128
-rw-r--r--debian/krb5-kdc.install8
-rw-r--r--debian/krb5-kdc.lintian-overrides1
-rw-r--r--debian/krb5-kdc.news15
-rw-r--r--debian/krb5-kdc.postinst51
-rw-r--r--debian/krb5-kdc.postrm26
-rw-r--r--debian/krb5-kdc.prerm18
-rw-r--r--debian/krb5-kdc.service19
-rw-r--r--debian/krb5-kdc.templates33
-rwxr-xr-xdebian/krb5-kpropd.init127
-rw-r--r--debian/krb5-kpropd.install2
-rw-r--r--debian/krb5-kpropd.postinst19
-rw-r--r--debian/krb5-kpropd.prerm13
-rw-r--r--debian/krb5-kpropd.service15
-rw-r--r--debian/krb5-locales.install1
-rw-r--r--debian/krb5-multidev.dirs.in3
-rw-r--r--debian/krb5-multidev.install.in12
-rw-r--r--debian/krb5-multidev.links.in2
-rw-r--r--debian/krb5-otp.NEWS7
-rw-r--r--debian/krb5-otp.install2
-rw-r--r--debian/krb5-otp.tmpfile1
-rw-r--r--debian/krb5-pkinit.install2
-rw-r--r--debian/krb5-user.docs1
-rw-r--r--debian/krb5-user.install20
-rw-r--r--debian/krb5-user.lintian-overrides1
-rwxr-xr-xdebian/krb5_newrealm41
-rw-r--r--debian/krb5_newrealm.sgml32
-rw-r--r--debian/libgssapi-krb5-2.dirs1
-rw-r--r--debian/libgssapi-krb5-2.install1
-rw-r--r--debian/libgssapi-krb5-2.lintian-overrides1
-rw-r--r--debian/libgssapi-krb5-2.postinst14
-rw-r--r--debian/libgssapi-krb5-2.postrm9
-rw-r--r--debian/libgssapi-krb5-2.symbols168
-rw-r--r--debian/libgssrpc4.install1
-rw-r--r--debian/libgssrpc4.symbols147
-rw-r--r--debian/libk5crypto3.install1
-rw-r--r--debian/libk5crypto3.symbols114
-rw-r--r--debian/libkadm5clnt-mit11.install1
-rw-r--r--debian/libkadm5clnt-mit11.symbols122
-rw-r--r--debian/libkadm5srv-mit11.install1
-rw-r--r--debian/libkadm5srv-mit11.symbols142
-rw-r--r--debian/libkdb-ldap1.install1
-rw-r--r--debian/libkdb5-9.install1
-rw-r--r--debian/libkrad-dev.install2
-rw-r--r--debian/libkrad0.install1
-rw-r--r--debian/libkrad0.symbols26
-rw-r--r--debian/libkrb5-3.dirs.in1
-rw-r--r--debian/libkrb5-3.docs2
-rw-r--r--debian/libkrb5-3.install2
-rw-r--r--debian/libkrb5-3.lintian-overrides1
-rw-r--r--debian/libkrb5-3.symbols682
-rw-r--r--debian/libkrb5-dev.dirs.in4
-rw-r--r--debian/libkrb5-dev.links2
-rw-r--r--debian/libkrb5support0.install1
-rw-r--r--debian/libkrb5support0.symbols103
-rw-r--r--debian/news7
-rw-r--r--debian/patches/debian-local/0001-Debian-HURD-compatibility.patch135
-rw-r--r--debian/patches/debian-local/0002-debian-Handle-multi-arch-paths-in-krb5-config.patch66
-rw-r--r--debian/patches/debian-local/0003-debian-osconf.hin-path-changes.patch36
-rw-r--r--debian/patches/debian-local/0004-debian-install-ldap-library-in-subdirectory.patch41
-rw-r--r--debian/patches/debian-local/0005-gssapi-never-unload-mechanisms.patch34
-rw-r--r--debian/patches/debian-local/0006-Add-substpdf-target.patch40
-rw-r--r--debian/patches/debian-local/0007-Fix-pkg-config-library-include-paths.patch102
-rw-r--r--debian/patches/debian-local/0008-Use-isystem-for-include-paths.patch109
-rw-r--r--debian/patches/series11
-rw-r--r--debian/patches/upstream/0009-Remove-erroneous-text-from-kinit-man-page.patch63
-rw-r--r--debian/patches/upstream/0010-Fix-memory-leak-in-none-replay-cache-type.patch33
-rw-r--r--debian/patches/upstream/0011-Document-the-double-colon-behavior-of-DIR-ccaches.patch33
-rw-r--r--debian/po/POTFILES.in2
-rw-r--r--debian/po/ca.po140
-rw-r--r--debian/po/cs.po225
-rw-r--r--debian/po/da.po137
-rw-r--r--debian/po/de.po277
-rw-r--r--debian/po/es.po216
-rw-r--r--debian/po/eu.po183
-rw-r--r--debian/po/fi.po132
-rw-r--r--debian/po/fr.po197
-rw-r--r--debian/po/gl.po272
-rw-r--r--debian/po/it.po137
-rw-r--r--debian/po/ja.po135
-rw-r--r--debian/po/nl.po138
-rw-r--r--debian/po/pl.po137
-rw-r--r--debian/po/pt.po271
-rw-r--r--debian/po/pt_BR.po139
-rw-r--r--debian/po/ro.po264
-rw-r--r--debian/po/ru.po205
-rw-r--r--debian/po/sv.po201
-rw-r--r--debian/po/templates.pot101
-rw-r--r--debian/po/tr.po136
-rw-r--r--debian/po/vi.po141
-rwxr-xr-xdebian/rules226
-rw-r--r--debian/slapd-before-kdc.conf2
-rw-r--r--debian/source/format1
-rw-r--r--debian/source/include-binaries1
-rw-r--r--debian/source/lintian-overrides7
-rw-r--r--debian/tests/control7
-rw-r--r--debian/tests/kinit27
-rw-r--r--debian/tests/slapd-gssapi52
-rw-r--r--debian/tests/util68
-rw-r--r--debian/upstream/signing-key.pgpbin0 -> 3449 bytes
-rw-r--r--debian/watch5
141 files changed, 12059 insertions, 0 deletions
diff --git a/debian/.git-dpm b/debian/.git-dpm
new file mode 100644
index 000000000..6e32aafc2
--- /dev/null
+++ b/debian/.git-dpm
@@ -0,0 +1,8 @@
+# see git-dpm(1) from git-dpm package
+a243df875ff905d1c676bd726b19bafea07b628c
+a243df875ff905d1c676bd726b19bafea07b628c
+a75eb54fd955cbf7a8ac44e527fd0e400e87844a
+a75eb54fd955cbf7a8ac44e527fd0e400e87844a
+krb5_1.17.orig.tar.gz
+0c404b081db9c996c581f636ce450ee28778f338
+8761763
diff --git a/debian/NEWS b/debian/NEWS
new file mode 100644
index 000000000..ff20c4cec
--- /dev/null
+++ b/debian/NEWS
@@ -0,0 +1,48 @@
+krb5 (1.8+dfsg~alpha1-1) unstable; urgency=low
+
+ This version of MIT Kerberos disables DES and 56-bit RC4 by default.
+ These encryption types are generally regarded as weak; defeating them
+ is well within the expected resources of some attackers. However,
+ some applications, such as OpenAFS or Kerberized NFS, still rely on
+ DES. To re-enable DES support add allow_weak_crypto=true to the
+ libdefaults section of /etc/krb5.conf
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 08 Jan 2010 22:41:14 -0500
+
+krb5 (1.6.dfsg.4~beta1-7) unstable; urgency=low
+
+ * In response to MIT's 2006 announcement that Kerberos 4 is at end of
+ life and no longer under development, this version of the krb5 package
+ removes most support for krb4. In particular, krb4 headers are no
+ longer included; applications with krb4 support cannot be built using
+ libkrb5-dev. In addition, krb4 support has been removed from the KDC
+ and user utilities. If you do not use Kerberos 4 and do not have
+ krb4-config installed, you should notice no changes. However, if you
+ do use Kerberos 4, you must transition away from Kerberos 4 before
+ upgrading to this version.
+ * Downgrading from this version to a previous version can be
+ difficult because of library name changes. Please follow these
+ instructions:
+ - Get the libkrb53 and libkadm55 debs you want to downgrade to
+ -dpkg --force-depends --remove libkrb5-3 libkrb5support0 libdes425-3
+ libgssapi-krb5-2 libgssrpc4 libkadm5clnt5 libkadm5srv5 libkdb5-4
+ libk5crypto3
+ - At this point your system has broken Kerberos libraries
+ - dpkg -i libkrb53*deb libkadm55*deb (using the debs you got above)
+ - aptitude -f install to fix any other packages that may be broken
+
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 26 Feb 2009 21:12:41 -0500
+
+krb5 (1.6.1-1) unstable; urgency=low
+
+ * Note that in this version, the behavior for finding what realm a
+ server lives in has changed. In particular, if there is no
+ domain_realm entry in krb5.conf, a server will assume that its key
+ lives in the default realm set in krb5.conf. Previous versions would
+ strip the hostname from the domain of the server. So, if the server's
+ key is not in the default realm, add a domain_realm mapping. Clients
+ still use DNS as a heuristic in some cases.
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 25 Apr 2007 23:40:13 -0400
+
diff --git a/debian/README.Debian b/debian/README.Debian
new file mode 100644
index 000000000..561899d9b
--- /dev/null
+++ b/debian/README.Debian
@@ -0,0 +1,78 @@
+ MIT Kerberos for Debian
+
+Kerberos Package Roadmap
+
+ Most systems using Kerberos should install at least krb5-user, which
+ contains the basic kinit, klist, and kdestroy binaries to manage user
+ Kerberos credentials, as well as other basic utilities. In order to
+ use Kerberos passwords for local authentication and obtain Kerberos
+ credentials automatically when logging in, install and configure
+ libpam-krb5.
+
+ To log on to other systems using Kerberos authentication, most sites
+ will find a Kerberos-enabled sshd the most convenient. See the ssh documentation for information on enabling GSSAPI
+ authentication (which is how Kerberos authentication is done over the
+ ssh protocol).
+
+ Some sites will instead prefer to use Kerberos-enabled versions of the
+ standard Unix login utilities (rsh, rlogin, telnet, ftp). The clients
+ are available in the krb5-clients package and the servers are available
+ in the krb5-rsh-server, krb5-telnetd, and krb5-ftpd packages. Please
+ note that the telnetd and ftpd included in those packages do not use PAM
+ (this is not supported upstream and may or may not ever be supported);
+ they only support Kerberos and will not run other PAM modules. For more
+ flexible login support, use Kerberos-enabled ssh instead.
+
+ The krb5-kdc and krb5-admin-server packages are only needed and used on
+ Kerberos KDCs, only one set of which is needed for each independently
+ managed Kerberos realm. For more information on how to set up a
+ Kerberos realm using the Debian packages, install krb5-kdc and then read
+ /usr/share/doc/krb5-kdc/README.KDC.
+
+Documentation
+
+ All Kerberos binaries and most configuration files have manual pages.
+ For the info pages and reference manual, install krb5-doc. If you need
+ additional information, see <http://web.mit.edu/kerberos/>.
+
+Debian-Specific Information
+
+ MIT distributes the Kerberos sources as a tarball and a PGP signature,
+ tarred up into a single .tar file. In order to create the Debian
+ original upstream source (.orig.tar.gz), I untarred the parent tarball,
+ checked the PGP signature, and used the contained tarball as the
+ upstream source. Since krb5-1.7, a separate "krb5-appl" tarball contains
+ the kerberized client utilities (rlogin, rsh, etc.) with a similar
+ nested-tarball scheme.
+
+ MIT Kerberos is built against the libcom_err and libss provided by the
+ e2fsprogs source package. It is built against the version of db
+ included in src/util/db2 in the Kerberos sources. In the future,
+ krb5-kdc may change to use db4, although doing so will make upgrades
+ somewhat difficult.
+
+ None of the sample clients and servers are installed. As a general
+ rule, these are not useful unless you are doing development, and in such
+ a situation you probably want to build them from source.
+
+ Note that by default, no unencrypted services are enabled. That means,
+ if you are using krb5-clients and the supporting server packages, you
+ need to use rlogin -x to connect to a Debian system and if you use rsh
+ or rcp without the -x option you will get an error that encryption is
+ required. In this day and age, not encrypting network traffic is a good
+ way to get attacked.
+
+ If installed, krb5-rsh-server by default allows any user in the local
+ realm whose principal matches a local account name to log on to that
+ account. See the klogind and kshd man pages. If this isn't the
+ behavior you want, one option is to create an empty .k5login file in the
+ home directory of every user and then add principals to those files
+ where it's appropriate. One way to do this for all newly created users
+ is:
+
+ touch /etc/skel/.k5login
+
+ This will cause an empty .k5login file to be put in the home directory
+ of newly created users.
+
+ -- Sam Hartman <hartmans@debian.org>, Wed, 2 Nov 2016 23:18:47 -0400
diff --git a/debian/README.KDC b/debian/README.KDC
new file mode 100644
index 000000000..c07a04192
--- /dev/null
+++ b/debian/README.KDC
@@ -0,0 +1,51 @@
+ Running a Debian Kerberos Realm
+
+You will want to install the krb5-kdc and krb5-admin-server on your master
+KDC and at least krb5-kdc on any slave KDCs you have. You may wish to
+install krb5-admin-server on slaves in case you need them to become the
+master KDC in a hurry, but in this case you may want to configure
+krb5-admin-server to not start unless started manually. Otherwise,
+clients may change their password on a slave server, a change that will
+then be overwritten silently later and may cause user confusion. (This
+can only happen if the client is misconfigured to use a slave server as
+the admin server, but sometimes this happens.)
+
+If you want to use the LDAP backend, also install the krb5-kdc-ldap
+package, which contains the kldap plugin.
+
+krb5-kdc adds a commented-out line for kpropd to /etc/inetd.conf. You
+will want to uncomment this on slave KDCs so that they can receive updates
+from the master, but leave it commented out on the master.
+
+You should look at the KDC configuration file (/etc/krb5kdc/kdc.conf) and
+adjust the parameters appropriately. If you expect to be using a lot of
+Kerberos4 services, you should either remove +preauth from the default
+principal flags or select full krb4 support when prompted by debconf.
+(You can run dpkg-reconfigure on krb5-kdc to see this prompt again.) If
+you remove +preauth from the flags, principals will by default not require
+preauthentication. This is less secure since it opens you to offline
+dictionary attacks, but this level of security is what people have been
+suffering with throughout the lifetime of Kerberos4. You can turn on
+requires_preauth for specific high-security principals in kadmin. If you
+simply select full krb4 support, then Kerberos5 clients will require
+preauthentication, but all principals will be accepted for Kerberos4.
+This has a similar vulnerability to dictionary attacks and cannot be
+overridden by setting requires_preauth selectively.
+
+By default principals are created with most supported keys, including AES
+and 3DES keys. This means that if you ever decide at some point in the
+future that you no longer have any services using older weaker enctypes,
+you can get the full security benefits of stronger encryption types by
+dropping the weaker ones from supported_enctypes in /etc/krb5kdc/kdc.conf.
+Note however, that for some services, like AFS, you may need to only create
+single DES keys. You might do this by for example:
+
+ kadmin.local -e des-cbc-crc:normal -q "ktadd afs/ATHENA.MIT.EDU"
+
+Similarly, for old Java applications, you may need to create keys without
+AES enctypes, particularly if Java is using a ticket cache created by a
+different program.
+
+You will probably want to create /etc/krb5kdc/kadm5.acl to include a list
+of users who are authorized to run kadmin in your realm. The kadmind
+documentation provides examples.
diff --git a/debian/README.source b/debian/README.source
new file mode 100644
index 000000000..14ad18e44
--- /dev/null
+++ b/debian/README.source
@@ -0,0 +1,47 @@
+This package is managed with git-dpm.
+If you are not familiar with git-dpm, then treat it as a standard quilt package stored in git with patches applied; it will become obvious the next time that git-dpm is used that cleanup is required and the appropriate cherry-picks can be made.
+
+
+Submitting Patch to the Maintainer:
+
+It's best to clone the git repository mentioned in debian/control and
+use the git format-patch command to generate patches. Attach these
+patches to bugs on the krb5 source package.
+
+
+Preparing a new Upstream version:
+
+You'll need two things to do this correctly. First, you'll need the
+upstream tarball. Secondly, you'll need a clone of the upstream git repository
+git://github.com/krb5/krb5.git . Upstream has removed the files with
+non-DFSG-compliant licenses, so we no longer need a special workflow
+to generate a DFSG-compliant orig tarball.
+From within a git repository containing both the upstream tag for the release and the debian packaging:
+
+1) Make sure there is a local upstream branch that descends from origin/upstream
+2) Rename upstream's tarfile to the expected .orig.tar.gz name.
+2) git-dpm import-new-upstream -p tag_from_upstream orig_tarball
+3) git tag upstream/version_number upstream
+
+This will update the upstream branch and create an upstream tag.
+
+4) git dpm checkout-patched&&git rebase upstream_tag
+
+5) git dpm update-patches
+
+Old repository: The packaging for krb-1.11 and later is in the repository
+pointed to by the VCS fields in the control file. The previous repository
+(based off upstream's testing git export, prior to their conversion to git)
+is at git.debian.org/git/pkg-k5-afs/debian-krb5.git .
+
+Old old repository: There's an old old repository at
+git://git.debian.org/git/pkg-k5-afs/krb5-debian-2011.git containing
+old packaging. If you want to merge or otherwise work across the
+boundary with that old repository then you may want to copy
+debian/source/grafts.old_repository to .git/info/grafts
+
+Do not commit anything based on the old repositories to the new one.
+Ideally the commit hooks should stop you.
+
+ -- Sam Hartman <hartmans@debian.org>, Tue, 27 Dec 2011 06:11:15 -0500
+ -- Benjamin Kaduk <kaduk@mit.edu>, Fri 28 Oct 2013 15:55:54 -0400
diff --git a/debian/changelog b/debian/changelog
new file mode 100644
index 000000000..c50efd547
--- /dev/null
+++ b/debian/changelog
@@ -0,0 +1,2595 @@
+krb5 (1.17-2) unstable; urgency=medium
+
+ * Finish removing the run kadmind debconf template which was obsoleted
+ when the systemd units were installed, LP: #1817376
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 25 Feb 2019 13:55:57 -0500
+
+krb5 (1.17-1) unstable; urgency=low
+
+ * New Upstream release
+ * Don't include all memory ccaches in ccache collection, avoids invalid
+ mutex, Closes: #918088
+ * The default path for the KDC database even without a config file is
+ /var/lib/krb5kdc/principal, Closes: #777579
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 13 Jan 2019 15:59:40 -0500
+
+krb5 (1.16.2-1) unstable; urgency=medium
+
+ [ Ondřej Nový ]
+ * d/changelog: Remove trailing whitespaces
+ * d/control: Remove trailing whitespaces
+ * d/rules: Remove trailing whitespaces
+
+
+ [ Sam Hartman ]
+ * New Upstream version, Closes: #915780
+ * CVE-2018-20217: Incorrect KDC assertion leading to denial of service,
+ Closes: #917387
+ * Fix typo in tests
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 31 Dec 2018 15:25:16 -0500
+
+krb5 (1.16.1-1) unstable; urgency=medium
+
+ [ Sam Hartman ]
+ * New upstream release
+ - Fix flaws in LDAP DN checking, including a null dereference KDC
+ crash which could be triggered by kadmin clients with administrative
+ privileges [CVE-2018-5729, CVE-2018-5730], Closes: #891869
+ * Install kerberos.openldap.ldif, which is probably more useful than
+ kerberos.ldif if you're hoping to use the Kerberos schema on Debian.
+ Also, the bugs in kerberos.ldif have been corrected; Closes: #660767
+ * Suggest krb5-k5tls from krb5-user, Closes: #887937
+ * Merge dep8 tests, thanks Canonical and Andreas Hasenack (LP:
+ #1677881)
+
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 16 Jul 2018 20:09:54 -0400
+
+krb5 (1.16-2) unstable; urgency=medium
+
+ * Update location of packaging GIT repository
+ * krb5-config was incorrectly changed to include the multiarch tripple
+ in include paths. However, our include files are not architecture
+ specific; fix krb5-config to not include a multiarch tripple in
+ include paths, Closes: #887810
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 20 Jan 2018 11:02:57 -0500
+
+krb5 (1.16-1) unstable; urgency=medium
+
+ * New Upstream Version, Closes: #884490
+ - libkdb5 soname is now 9
+ * Note that we break moonshot-gss-eap less than 1.0.1. In particular
+ because /etc/gss/mech.d/README is no longer installed,
+ moonshot-gss-eap will drop a stray file in /usr/etc.
+ * make krb5-config identical on all architectures and make
+ krb5-multidev and libkrb5-dev multiarch installable; solution based on
+ discussion with Hugh McMaster, Closes: #881597
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 04 Jan 2018 10:29:06 -0500
+
+krb5 (1.15.2-2) unstable; urgency=medium
+
+ * Apply upstream patch removing a fixed-size buffer in PKINIT client code,
+ Closes: #871698
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Sat, 28 Oct 2017 18:09:28 -0500
+
+krb5 (1.15.2-1) unstable; urgency=medium
+
+ [ Sam Hartman ]
+ * Fix plugins directory, thanks Andreas Hasenack, Closes: #872140
+ * Move kpropd to krb5-kpropd since stretch is released
+ * Mark krb5-kdc and krb5-addmin-server as multi-arch foreign
+
+ [ Benjamin Kaduk ]
+ * New Upstream Version
+ - Ignore files starting with '.' in profile include directories
+ - Use longer timeout for HTTPS (KKDCP) transport before switching to UDP
+ - Fix kadm5 setkey operations wit LDAP KDB
+ - Fix CVE-2017-11462: preserve GSS context on init/accept failure,
+ Closes: #873563
+ - Prevent NULL dereference with keyboard master key
+ * Update to policy 4.1.1:
+ - Refer to service(8) instead of /etc/init.d/foo
+ - Support the 'nodoc' DEB_BUILD_OPTIONS entry
+ - Make all packages Priority: optional
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Tue, 24 Oct 2017 17:12:31 -0500
+
+krb5 (1.15.1-2) unstable; urgency=high
+
+ * Depend on libsasl2-dev for LDAP SASL authentication, Thanks Hideki
+ Yamane, Closes: #868035
+ * Remove /etc/gss/mech.d/README on libgssapi-krb5-2 purge, Closes: #868121
+ * CVE-2017-11368: Remote authenticated attackers can crash the KDC,
+ Closes: #869260
+ * Set Restart=on-abnormal in krb5-kdc.service and krb5-admind.service to
+ minimize the impact of future DOS bugs.
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 23 Jul 2017 14:16:38 -0400
+
+krb5 (1.15.1-1) unstable; urgency=medium
+
+ * New Upstream Version
+ - Samba wants this, Closes: #861651
+ * Include krb5-otp tmpfile for freeipa, Closes: #859243
+ * Move doxygen to build-indep, Closes: #754139
+ * For stage1 builds, skip LDAP, based on patch by Johannes Schauer and
+ Peter Pentchev, Closes: #752407
+ * Annotate control file for stage1 without ldap, Closes: #752409
+ * Remove /etc/gss/mech.d/README, Closes: #861218
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 09 Jul 2017 14:38:55 -0400
+
+krb5 (1.15-2) experimental; urgency=medium
+
+
+ * Upstream patches to fix startup if getaddrinfo() returns a wildcard v6
+ address, and to fix handling of explicitly specified v4 wildcard
+ address; regression over previous versions, Closes: #860767
+ * Fix SRV lookups to respect udp_preference_limit, regression over
+ previous versions with OTP, Closes: #856307
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 19 Apr 2017 16:50:01 -0400
+
+krb5 (1.15-1) unstable; urgency=medium
+
+ [ Benjamin Kaduk ]
+ * New upstream version
+ - Make zap() more reliable and use it more consistently; the
+ previous version could be optimized out by gcc 5.1 or later
+ - Update license statement in ccapi/common/win/OldCC/autolock.hxx,
+ Closes: #846088
+ * Update Debian-HURD-compatibility.patch, Closes: #845381
+ * Bump debhelper compat level to 9
+
+ [ Sam Hartman ]
+ * Actually build and ship German translations, Closes: #842497
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Sun, 04 Dec 2016 15:37:57 -0500
+
+krb5 (1.15~beta1-1) unstable; urgency=low
+
+ [ Benjamin Kaduk ]
+ * New upstream version
+ - Upstream's tarball is now DFSG-free
+ - Builds against openssl 1.1.0, Closes: #828369
+ - Add support for the AES-SHA2 enctypes
+ - Add support to kadmin for remote extraction of current keys
+ and principal attributes to prevent such extraction
+ - Add DNS auto-discovery using URI records in addition to SRV records
+ - Improve LDAP backend to contain some features previously only
+ present in the BDB backend
+ - Use the getrandom system call on supported Linux kernels
+ - Use SHA256 instead of MD5 for hashing authenticators in the replay cache
+ * The symbol gssrpc_svcauth_gss_creds was removed upstream from
+ libgssrpc; no soname bump because this is an internal API never in a
+ public header
+ [ Sam Hartman ]
+ * Update standards version to 3.9.8
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Wed, 02 Nov 2016 00:12:46 -0400
+
+krb5 (1.14.3+dfsg-2) unstable; urgency=medium
+
+ * Fix gcc -O3, thanks Ben Kaduk/Steve Langasek, Closes: #833798
+ * Fix kdb5_util create on 32-bit platforms, thanks Greg Hudson, Closes:
+ #834035
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 05 Sep 2016 21:03:14 -0400
+
+krb5 (1.14.3+dfsg-1) unstable; urgency=medium
+
+ * New upstream version
+ - includes fix for CVE-2016-3120, Closes: #832572
+ * build-dep-indep on texlive-generic-extra to pick up iftex.sty after
+ a reshuffle, Closes: #828946
+ * Comment out supported_enctypes in kdc.conf to avoid including
+ single-DES enctypes, Closes: #806928
+ * Spell Build-Depends-Indep properly, Closes: #829196
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Sat, 30 Jul 2016 22:42:39 -0400
+
+krb5 (1.14.2+dfsg-1) unstable; urgency=low
+
+ * New upstream version
+ - Includes fix for CVE-2016-3119: remote DOS with ldap for
+ authenticated attackers, Closes: #819468
+ * Fix short descriptions capitalization, Thanks Laura Arjona Reina,
+ Closes: #821021
+ * New German translation, Thanks Chris Leick, Closes: #816548
+
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 30 May 2016 13:12:02 -0400
+
+krb5 (1.14+dfsg-1) experimental; urgency=medium
+
+ * New upstream version, Closes: #812131
+ * Apply upstream patches:
+ - upstream/0010-Fix-mechglue-gss_acquire_cred_impersonate_name.patch
+ - 0011-Correctly-use-k5_wrapmsg-in-ldap_principal2.c.patch
+ - upstream/0012-Set-TL_DATA-mask-flag-for-master-key-operations.patch
+ - upstream/0013-Check-context-handle-in-gss_export_sec_context.patch
+ - upstream/0014-Check-internal-context-on-init-context-errors.patch
+ - upstream/0015-Fix-interposed-gss_accept_sec_context.patch
+ - upstream/0016-Work-around-uninitialized-warning-in-cc_kcm.c.patch
+ - upstream/0017-Increase-hostname-length-in-ipropd_svc.c.patch
+ - upstream/0018-Make-ksu-work-with-prompting-clpreauth-modules.patch
+ - upstream/0019-Fix-memory-leak-in-SPNEGO-gss_init_sec_context.patch
+ - upstream/0020-Fix-EOF-check-in-kadm5.acl-line-processing.patch
+ - upstream/0021-Fix-iprop-server-stub-error-management.patch
+ - upstream/0022-Verify-decoded-kadmin-C-strings-CVE-2015-8629.patch
+ - upstream/0023-Check-for-null-kadm5-policy-name-CVE-2015-8630.patch
+ -upstream/0024-Fix-leaks-in-kadmin-server-stubs-CVE-2015-8631.patch
+ - Use blocking lock for db promote, Closes: #815677
+ * Verify decoded kadmin C strings [CVE-2015-8629]
+ CVE-2015-8629: An authenticated attacker can cause kadmind to read
+ beyond the end of allocated memory by sending a string without a
+ terminating zero byte. Information leakage may be possible for an
+ attacker with permission to modify the database. (Closes: #813296)
+ * Check for null kadm5 policy name [CVE-2015-8630]
+ CVE-2015-8630: An authenticated attacker with permission to modify a
+ principal entry can cause kadmind to dereference a null pointer by
+ supplying a null policy value but including KADM5_POLICY in the mask.
+ (Closes: #813127)
+ * Fix leaks in kadmin server stubs [CVE-2015-8631]
+ CVE-2015-8631: An authenticated attacker can cause kadmind to leak
+ memory by supplying a null principal name in a request which uses one.
+ Repeating these requests will eventually cause kadmind to exhaust all
+ available memory. (Closes: #813126)
+
+ * Remove all references to libkrb53, Closes: #708175
+ * Merge patch for kpropd service, introducing a new stub package for now
+ that will contain the binaries in stretch+1. We don't want to move
+ the binaries now because we'd either break existing installations or
+ we'd need krb5-kdc to depend on the new package, which would cause
+ kpropd to start in cases where we don't want it, thanks Mark Proehl
+ and Michael Weiser, Closes: #775277
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 15 Feb 2016 15:49:06 -0500
+
+krb5 (1.13.2+dfsg-4) unstable; urgency=high
+
+ * Import upstream patches fixing regressions in the previous upload:
+ - CVE-2015-2698: the patch for CVE-2015-2696 caused memory corruption
+ for applications calling gss_export_sec_context() on contexts
+ established using the IAKERB mechanism.
+ - Supply gss_import_sec_context implementations for SPNEGO and IAKERB,
+ which were not implemented due to the erroneous belief that the
+ exported context tokens would be tagged with the underlying
+ context's mechanism.
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Wed, 04 Nov 2015 22:47:22 -0500
+
+krb5 (1.13.2+dfsg-3) unstable; urgency=high
+
+ * Import upstream patches for three CVEs:
+ - CVE-2015-2695: SPNEGO context aliasing during establishment
+ - CVE-2015-2696: IAKERB context aliasing during establishment
+ - CVE-2015-2697: unsafe string handling in TGS processing
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Mon, 26 Oct 2015 14:03:52 -0400
+
+krb5 (1.13.2+dfsg-2) unstable; urgency=medium
+
+ * No-change rebuild to target unstable
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Thu, 25 Jun 2015 17:10:03 -0400
+
+krb5 (1.13.2+dfsg-1) experimental; urgency=medium
+
+ * New upstream release:
+ - Fix importing GSS composite export names
+ - Fix kadm5.acl wildcard matching when early lines have partial matches
+ - Disable principal renames for LDAP; they do not work properly and are
+ hard to fix
+ - Fix LDAP ticket policies on big-endian LP64 systems
+ - Fix memory leak in DB2 iteration
+ - Prevent requires_preauth bypass (CVE-2015-2694), Closes: #783557
+ * Add python to build-depends-indep, since we call it manually during
+ the documentation build, Closes: #746395
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Thu, 14 May 2015 13:38:58 -0400
+
+krb5 (1.13.1+dfsg-1) experimental; urgency=low
+
+ * New upstream release:
+ - Make the KDC default to listening on TCP (as well as UDP)
+ - Bump DAL major version for krb5_db_iterate() API change; KDB modules
+ will need to be rebuilt
+ - Let ksu use any keytab entry to verify the obtained TGT
+ - Improve kadm5_randkey_principal interop with Solaris KDCs
+ - Export symbols for some public gss interfaces
+ - Allow the logger to work with redirected stderr
+ - Remove length limit on PKINIT PKCS#12 prompts
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Mon, 16 Mar 2015 14:23:06 -0400
+
+krb5 (1.12.1+dfsg-20) unstable; urgency=high
+
+ * Import upstream patch for CVE-2015-2694, Closes: #783557
+ * Bump Standards-Version to 3.9.6 (no changes needed)
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Wed, 13 May 2015 14:40:36 -0400
+
+krb5 (1.12.1+dfsg-19) unstable; urgency=medium
+
+ * mark systemd unit directories as optional, Closes: #780831
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 20 Mar 2015 16:22:33 -0400
+
+krb5 (1.12.1+dfsg-18) unstable; urgency=high
+
+ * Import upstream patch for CVE-2014-5355, Closes: #778647
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Wed, 18 Feb 2015 12:52:14 -0500
+
+krb5 (1.12.1+dfsg-17) unstable; urgency=high
+
+ * MITKRB5-SA-2015-001
+ - CVE-2014-5352: gss_process_context_token() incorrectly frees context
+ - CVE-2014-9421: kadmind doubly frees partial deserialization results
+ - CVE-2014-9422: kadmind incorrectly validates server principal name
+ - CVE-2014-9423: libgssrpc server applications leak uninitialized bytes
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 03 Feb 2015 10:29:35 -0500
+
+krb5 (1.12.1+dfsg-16) unstable; urgency=medium
+
+ * Import upstream patches for CVE-2014-5353 and CVE-2014-5354,
+ Closes: #773226, Closes: #773228
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Mon, 15 Dec 2014 16:18:26 -0500
+
+krb5 (1.12.1+dfsg-15) unstable; urgency=medium
+
+ * Also apply slapd-before-kdc.conf to krb5-admin-server.service.d,
+ Closes: #769710
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Fri, 21 Nov 2014 12:36:08 -0500
+
+krb5 (1.12.1+dfsg-14) unstable; urgency=medium
+
+ * The upstream patch in 1.12.1+dfsg-13 was incomplete; pull in
+ another upstream patch upon which it depended, to fix the
+ kfreebsd build, Closes: #768379
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Fri, 07 Nov 2014 13:17:36 -0500
+
+krb5 (1.12.1+dfsg-13) unstable; urgency=medium
+
+ * Remove the ExecReload line added in 1.12.1+dfsg-12; it is not
+ a regression from the SysV init script and therefore not suitable
+ for jessie post-freeze
+ * Apply upstream patch to fix build on FreeBSD 10.1, Closes: #768379
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Thu, 06 Nov 2014 18:08:26 -0500
+
+krb5 (1.12.1+dfsg-12) unstable; urgency=medium
+
+ * Fix typo in krb5-kdc EnvironmentFile name, Closes: #768344
+ * Add an ExecReload line to krb5-kdc.service to help with log rotation
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Thu, 06 Nov 2014 15:30:44 -0500
+
+krb5 (1.12.1+dfsg-11) unstable; urgency=medium
+
+ * Provide systemd service units for krb5-kdc, Partially affects: #734161
+ * Provide systemd overrides to start slapd first when krb5-kdc-ldap is
+ installed, Thanks Michael Biebl, Closes: #758992
+ * Provide kadmind service unit, Closes: #734161
+ * Drop support for RUN_KADMIND in favor of update-rc.d disable
+ * In krb5_newrealm, use service rather than calling init scripts directly
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 20 Oct 2014 16:51:09 -0400
+
+krb5 (1.12.1+dfsg-10) unstable; urgency=medium
+
+ * Import upstream's patch for CVE-2014-5351, Closes: #762479
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Mon, 22 Sep 2014 14:53:33 -0400
+
+krb5 (1.13~alpha1+dfsg-1) experimental; urgency=low
+
+ [ Jelmer Vernooij ]
+ * Reintroduce changes to move krb5-config into krb5-multidev:
+ + Provide -L and -I flags from krb5-config. Closes: #730837
+ + Ship krb5-config.mit binary in krb5-multidev., Closes: #745322
+ + Provide -L and -I flags from pkg-config files. Closes: #750041
+ * Use -isystem for include paths, to prevent the compiler from warning
+ about problems in them. Closes: #751760
+
+ [ Sam Hartman ]
+ * Reintroduce patches and accept proposed patches
+ * Update lintian source overrides because some of the BCP 78 hits are
+ false positives. We need to investigate cmac.c.
+
+ [ Benjamin Kaduk ]
+ * New upstream prerelease:
+ - Add support for accessing KDCs via an https proxy using the MS-KKDCP
+ protocol, using a plugin provided by the new krb5-k5tls package, which
+ uses openssl for the TLS implementation. The openssl-using code is
+ confined to a separate, runtime-loadable, plugin module, in a separate
+ package, to ameliorate concerns about GPL code that links libkrb5 running
+ into issues with the openssl license. The Kerberos license is both
+ GPL and OpenSSL compatible. There might be an issue if an application
+ was GPL licensed and someone used the OpenSSL plugin with that
+ application. Even that is probably fine provided that no one
+ distributes a combination that tends to encourage such usage. There's
+ an existing krb5-pkinit plugin that also links to OpenSSL, but at time
+ of integration into Debian no GPLed applications in the archive called
+ APIs that would cause that plugin to be loaded.
+ - Add support for hierarchical incremental propagation.
+ - Add support to the LDAP KDB module for binding to the LDAP server
+ using SASL.
+ - Add client support for the Kerberos Cache Manager protocol, allowing
+ caches served by a Heimdal kcm daemon to be accessed using the KCM:
+ cache type.
+ - Add support for performing unlocked database dumps to the DB2 KDC
+ back end, allowing the KDC and kadmind to continue accessing the
+ database during lengthy database dumps.
+ - The default location of the socket used by the OTP plugin has moved
+ from /etc/krb5kdc to /run/krb5kdc/.
+ * Break old versions of libraries that consume libkrb5support0, which
+ had its export symbol list change in 1.12 without the dependencies
+ changing to reflect that. Closes: #758288, Closes: #760149
+ * Fix the documentation build by explicitly mapping krb5.hin as a C file.
+ Closes: #759954
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 11 Sep 2014 18:00:35 -0400
+
+krb5 (1.12.1+dfsg-9) unstable; urgency=high
+
+ [ Jelmer Vernooij ]
+ * Reintroduce changes to move krb5-config into krb5-multidev:
+ + Provide -L and -I flags from krb5-config. Closes: #730837
+ + Ship krb5-config.mit binary in krb5-multidev., Closes: #745322
+ + Provide -L and -I flags from pkg-config files. Closes: #750041
+ * Use -isystem for include paths, to prevent the compiler from warning
+ about problems in them. Closes: #751760
+
+ [ Sam Hartman ]
+ * Reintroduce patches and accept proposed patches
+ * Update lintian source overrides because some of the BCP 78 hits are
+ false positives. We need to investigate cmac.c.
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 03 Sep 2014 23:14:34 -0400
+
+krb5 (1.12.1+dfsg-7) unstable; urgency=high
+
+ * Apply upstream's patch for CVE-2014-4345 (MITKRB5-SA-2014-001), buffer
+ overrun in kadmind with LDAP backend, Closes: #757416
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Thu, 07 Aug 2014 18:33:37 -0400
+
+krb5 (1.12.1+dfsg-6) unstable; urgency=medium
+
+ [ Benjamin Kaduk ]
+ * Apply upstream's patch to switch to TAILQ macros instead of CIRCLEQ macros,
+ to work around an issue with certain gcc versions. This is expected to
+ resolve Ubuntu bug (LP: #1347147).
+
+ [ Sam Hartman ]
+ * Include a quick and dirty patch so we build cleanly with -O3 fixing
+ incorrect may be uninitialized warnings.
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Tue, 29 Jul 2014 17:05:37 -0400
+
+krb5 (1.12.1+dfsg-5) unstable; urgency=high
+
+ * Apply upstream patches for CVE-2014-4343, CVE-2014-4344, Closes: #755520,
+ Closes: #755521
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Mon, 21 Jul 2014 17:27:10 -0400
+
+krb5 (1.12.1+dfsg-4) unstable; urgency=high
+
+ * Apply upstream patch for CVE-2014-4341, CVE-2014-4342, Closes: #753624,
+ Closes: #753625
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Fri, 11 Jul 2014 13:43:19 -0400
+
+krb5 (1.12.1+dfsg-3) unstable; urgency=high
+
+ * High urgency to revert some changes in the previous version that got
+ into testing. Unfortunately moving krb5-config into krb5-multidev
+ breaks some -Werror builds, so we'll revert until we can work out what
+ to do, Closes: #751760
+ * Revert krb5-config to krb5-multidev, reintroduces: #745322
+ * Remove -I and -L from krb5-config, Reintroduces: #730837
+ * Remove pkgconfig paths that include mit-kerberos, Reintroduces: #750041
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 16 Jun 2014 08:28:33 -0400
+
+krb5 (1.12.1+dfsg-2) unstable; urgency=low
+
+ [ Jelmer Vernooij ]
+ * Provide -L and -I flags from krb5-config. Closes: #730837
+ * Ship krb5-config.mit binary in krb5-multidev., Closes: #745322
+ * Provide -L and -I flags from pkg-config files. Closes: #750041
+
+ [ Sam Hartman ]
+ * Include upstream patch to load gss mechanisms from /etc/gss/mech.d,
+ Closes: #673680
+ * Sysconfdir explicitly set to /etc
+ * Include ubuntu change to permit libverto-libevent1 (not currently
+ built in Debian) as an alternative for the KDC. For now just
+ reduces diff with Ubuntu. Next libverto upload will probably start
+ building that for Debian too.
+ * Do not cause endless loop when a mechanism fails to include
+ gss_add_cred_from or other new methods (upstream #7926)
+ * Include /etc/gss/mech.d/README
+ * Low urgency to give extra time in unstable
+ * Update symbols for gss_indicate_mechs
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 04 Jun 2014 12:09:56 -0400
+
+krb5 (1.12.1+dfsg-1) unstable; urgency=low
+
+ [ Sam Hartman ]
+ * New upstream version
+ * Move gbp.conf to debian
+
+ [ Benjamin Kaduk ]
+ * Pull in upstream patch to put OTP sockets in /run by default
+ * Pull in upstream patch to avoid duplicate "/etc/krb5.conf" in profile
+ path, so we can safely set sysconfdir to /etc
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 20 Feb 2014 20:54:53 -0500
+
+krb5 (1.12+dfsg-2) unstable; urgency=low
+
+ * Split out libkrad-dev into its own package, Closes: #735323
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 27 Jan 2014 09:29:42 -0500
+
+krb5 (1.12+dfsg-1) experimental; urgency=low
+
+ [ Benjamin Kaduk ]
+ * New upstream release (closes: #730085, #728845, #637662, #729291).
+ * Update HURD compatibility patch (closes: #729191).
+ * Move pkgconfig files to krb5-multidev and avoid conflicts with
+ heimdal (closes: #730267).
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Mon, 02 Dec 2013 12:25:43 -0500
+
+krb5 (1.12~alpha1+dfsg-1) experimental; urgency=low
+
+ [ Benjamin Kaduk ]
+ * New upstream release, Closes: #694988, #697954
+ * Build-depend on python-lxml, Closes: #725596
+ * Remove Debian versions from symbols
+ * Add myself to uploaders
+
+ [ Sam Hartman ]
+ * Build-depend on libverto-dev 0.2.4 to get verto_set_flags
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Mon, 28 Oct 2013 16:12:52 -0400
+
+krb5 (1.11.3+dfsg-3+nmu1) unstable; urgency=high
+
+ * Non-maintainer upload by the Security Team.
+ * Add python-lxml build dependency (closes: #725596).
+ * Fix cve-2013-1417: KDC daemon crash condition (closes: #730085).
+ * Fix cve-2013-1418: null pointer dereference issue (closes: #728845).
+
+ -- Michael Gilbert <mgilbert@debian.org> Sat, 16 Nov 2013 23:40:00 +0000
+
+krb5 (1.11.3+dfsg-3) unstable; urgency=low
+
+
+ [ Benjamin Kaduk ]
+ * Update config.sub and config.guess, patch from upstream, Closes: #717840
+ * Update Brazillian Portugese Translation, thanks Fernando Ike,
+ Closes: #719726
+ * Bump the version of the gssrpc_clnt_create symbol. The routine itself
+ was changed in a backwards-compatible way, but callers from the kadm5
+ libraries were changed to rely on the new behavior, Closes: #718275
+ * Add symbols files for the kadm5 libraries. The KADM5 API version number
+ was increased for the 1.11 release but the corresponding library sonames
+ were not, so we must indicate the behavior change ourself, Closes: #716772
+
+ [ Sam Hartman ]
+ * krb5-kdc depends on libverto-libev1, work around for #652699
+ * Remove krb5-kdc conflict since it's more than one release cycle old
+ * Add Benjamin Kaduk to uploaders
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 25 Aug 2013 16:48:53 -0400
+
+krb5 (1.11.3+dfsg-2) experimental; urgency=low
+
+ * Run autoreconf to update configure based on aclocal patch
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 08 Jun 2013 22:00:50 -0400
+
+krb5 (1.11.3+dfsg-1) experimental; urgency=low
+
+ * New upstream version
+ - Turns out 1.11.2+dfsg didn't include the pingpong fix, but this
+ does , Closes: #
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 07 Jun 2013 21:31:03 -0400
+
+krb5 (1.11.2+dfsg-2) experimental; urgency=low
+
+ * Import upstream's patch to not warn or error on variadic macros,
+ Closes: #709824
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Sat, 25 May 2013 16:06:48 -0400
+
+krb5 (1.11.2+dfsg-1) experimental; urgency=low
+
+ * New upstream version, Closes: #697662
+ - By not depending on texinfo, we avoid FTBFSing from its changes,
+ Closes: #708711
+ * Fix "usage of keytabs gives "Generic preauthentication failure while
+ getting initial credentials"" via upstream change to prefer keys in
+ the keytab
+ (Closes: #698534)
+ * Fixed upstream "kerberos password policy attributes missing from
+ kerberos.schema" (Closes:
+ #655381)
+ * Remove arch-dep and arch-indep dependency in rules (Closes: #708973)
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 23 May 2013 21:56:23 -0400
+
+krb5 (1.10.1+dfsg-5) unstable; urgency=low
+
+ * Import workaround for getaddrinfo bug from upstream. Described in
+ upstream's RT 7124, addresses the main concern of #697662
+ * Correct CVE number for CVE-2012-1016 in changelog and patches, Closes:
+ #703457
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Mon, 25 Mar 2013 11:50:07 -0400
+
+krb5 (1.10.1+dfsg-4+nmu1) unstable; urgency=high
+
+ * Non-maintainer upload by the Security Team.
+ * Fix cve-2012-1016: null pointer derefence when handling a draft9 request
+ (closes: #702633).
+
+ -- Michael Gilbert <mgilbert@debian.org> Fri, 15 Mar 2013 04:15:27 +0000
+
+krb5 (1.10.1+dfsg-4) unstable; urgency=high
+
+ * KDC null pointer dereference with PKINIT, CVE-2013-1415
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Fri, 15 Feb 2013 16:07:53 -0500
+
+krb5 (1.10.1+dfsg-3) unstable; urgency=low
+
+ * Kadmind crash only triggered by admin users, cve-2012-1013, Closes:
+ #687647
+ * Don't unload GSS-API plugins to avoid crashing applications that use
+ GSS-API on systems with plugins installed, Closes: #693741
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 19 Nov 2012 17:35:04 -0500
+
+krb5 (1.10.1+dfsg-2) unstable; urgency=high
+
+ * MITKRB5-SA-2012-001 [CVE-2012-1014 CVE-2012-1015] KDC frees
+ uninitialized pointers
+ * Break libgssglue1 << 0.2-2 for multiarch, Closes: #680612
+ * Don't free caller's principal in verify_init_creds, Closes: #512410
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 31 Jul 2012 08:20:09 -0400
+
+krb5 (1.10.1+dfsg-1) unstable; urgency=low
+
+ * New Upstream Version
+ - Set display_name in gss_get_name_attribute, Closes: #658514
+ * Fix use counts on preauthentication, Closes: #670457
+ * Fix kadmin access controls, Closes: #670918
+ * Accept NMU with longer hostname, Closes: #657027
+ * Fix history from old databases, Closes: #660869
+ * Fix gcc 4.6.2 may be used uninitialized warnings/errors, Closes: #672075
+ * Check all keys in keytab for verifying credentials, Possibly fixes:
+ #669127
+ * Avoid multi-arch libpath in krb5-config, Closes: #642229
+ * Debconf translations:
+ - Turkish debconf Translation, Thanks Atila KOC, Closes: #659072
+ - Polish, thanks Michal/ Kul/ach, Closes: #658437
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 10 May 2012 16:32:13 -0400
+
+krb5 (1.10+dfsg~beta1-2.1) unstable; urgency=low
+
+ * Non-maintainer upload.
+ * Apply patch from Svante Signell to fix FTBFS on hurd-i386, Closes: #657027.
+
+ -- Samuel Thibault <sthibault@debian.org> Thu, 26 Apr 2012 00:52:37 +0200
+
+krb5 (1.10+dfsg~beta1-2) unstable; urgency=low
+
+ * Oops, actually fix build flags, Closes: #655248
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 13 Jan 2012 17:39:34 -0500
+
+krb5 (1.10+dfsg~beta1-1) unstable; urgency=low
+
+ * New Upstream version
+ * Fix hardening flags and pre-dpkg-buildflags support, Closes: #655248
+ * Update some symbols files for enhanced functions in 1.10
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 13 Jan 2012 17:11:39 -0500
+
+krb5 (1.10+dfsg~alpha2-1) unstable; urgency=low
+
+ * New upstream Version
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 27 Dec 2011 06:02:35 -0500
+
+krb5 (1.10+dfsg~alpha1-7) unstable; urgency=high
+
+ * Merge in github/krb5-1-10 branch up through 12/16/2010: many new
+ upstream changes
+ * Includes fix for MITKRB5-SA-2011-007 KDC null pointer
+ dereference in TGS handling [CVE-2011-1530]
+ , Closes: #651226
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 16 Dec 2011 15:30:18 -0500
+
+krb5 (1.10+dfsg~alpha1-6) unstable; urgency=low
+
+ * Fix segfault with unknown hostnames in krb5_sname_to_principal,
+ Closes: #650671
+ * Indicate that this library breaks libsmbclient versions that depend on
+ krb5_locate_kdc, Closes: #650603, #650611
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 01 Dec 2011 19:34:41 -0500
+
+krb5 (1.10+dfsg~alpha1-5) unstable; urgency=low
+
+ * Add texinfo back to build depends: policy has been subverted by the
+ evil forces of wishful thinking and forward progress
+ * Conflict: with libkrb53 again. The transition is over and we no longer
+ need that package.
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 30 Nov 2011 09:09:55 -0500
+
+krb5 (1.10+dfsg~alpha1-4) unstable; urgency=low
+
+ * Add kadmind and krb5kdc pidfiles, Closes: #550781
+ * Respect locale in time display, Closes: #138430
+ * Status action for init scripts, Thanks Yukio Shiiya, Closes: #645363,
+ #645364
+ * Fix dependencies for krb5-kdc
+ * Add dpkg-buildflags support
+ * Initial build-arch and build-indep support: currently build-indep
+ depends on build-arch but that's OK as a starting point
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 29 Nov 2011 20:34:03 -0500
+
+krb5 (1.10+dfsg~alpha1-3) unstable; urgency=low
+
+ * Build depend on pkg-config
+
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 29 Nov 2011 17:35:48 -0500
+
+krb5 (1.10+dfsg~alpha1-2) unstable; urgency=low
+
+ * LDAP plugin depends on ldap library for parallel builds
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 29 Nov 2011 17:35:30 -0500
+
+krb5 (1.10+dfsg~alpha1-1) unstable; urgency=low
+
+ * New upstream release
+
+ - mit-krb5-sa-2011-006, Closes: #646367
+ - Install k5login.5 not just .k5login.5, Closes: #623068
+ - Fixes LDAP file descriptor leak, Closes: #561176
+ * Updated translations:
+ - French, Thanks Christian Perrier, Closes: #630827
+ - Catalan, Thanks Innocent De Marchi, Closes: #632208
+ * Update to krb5-1-10 branch of 2011-11-28
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 29 Nov 2011 13:05:17 -0500
+
+krb5 (1.9.1+dfsg-3) unstable; urgency=low
+
+ * New function gss_localname from trunk
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 21 Sep 2011 16:53:47 -0400
+
+krb5 (1.9.1+dfsg-2) unstable; urgency=low
+
+ * Revert incorrect Danish translations
+ * Multiarch support, Thanks Steve Langasek, Closes: #634121
+ * Use linux-any in debian/control instead of explicit exclusions,
+ Closes: #634311
+ * Apply upstream r24977 in order to fix problems where a name exists
+ for v6 but not v4, Closes: #532536
+ * Apply upstream tickets 6916 and 6917 to fi x referrals behavior with
+ old KDCs, Closes: #631106
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 09 Aug 2011 11:52:04 -0400
+
+krb5 (1.9.1+dfsg-1) unstable; urgency=low
+
+ * New upstream version
+ * Fix g_make_token_header when no token type is passed
+ * Support absolute paths for GSS-API mechanisms
+ * Add gss_authorize_localname, gss_userok, gss_pname_to_uid
+ * Fix gss_acquire_cred handling with empty mech set; fix
+ accept_sec_context handling in this case too
+ * Permit importing anonymous name with empty buffer
+ * New Translations:
+ - Dutch: Thanks Vincent Zweije, Closes: #624173
+ - Danish, Thanks Joe Dalton, Closes: #626530
+ * Fix kadmin free of null pointer on change password, Closes: #622681
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 02 Jun 2011 10:57:10 -0400
+
+krb5 (1.9+dfsg-2) unstable; urgency=low
+
+ * In the interest of testing other GSS-API mechanisms it is desirable to
+ install the gss-server and gss-client application. These are useful to
+ people developing new GSS-API mechanisms within Debian.
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 04 May 2011 16:07:42 -0400
+
+krb5 (1.9+dfsg-1) unstable; urgency=low
+
+ * New upstream version
+ * Pull in krb5 1.9 branch as of 03/16/2011
+ - Include updates in 1.8.3+dfsg-4, 1.8.3+dfsg-5, 1.8.3+dfsg-6
+ - Include fixes for trace logging
+ * Since Debian does not and will not ever build with edirectory
+ support, remove documentation of edirectory commands from the man
+ page. Closes: #580502
+ * Includes IPv6 support for kadmind, Closes: #595796
+ * Upstream 1.9 supports hooks for password change and synchronization,
+ Closes: #588968
+ * LDAP now supports stash creation after db cretaion, Closes: #484808
+ * Krb5 1.9 supports including files from krb5.conf, Closes: #429692
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 17 Mar 2011 20:54:04 -0400
+
+krb5 (1.9+dfsg~beta2-1) experimental; urgency=low
+
+ * New upstream release
+ * Fix default location of kpropd.acl in kpropd.M (LP: #688464)
+ * Ignore PACs without a server signature generated by OS X Open
+ Directory rather than failing authentication, Closes: #604925
+ * New exported API: krb5_tkt_creds_get
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 10 Dec 2010 14:30:35 -0500
+
+krb5 (1.9+dfsg~beta1-1) experimental; urgency=low
+
+ * New upstream release
+ * No longer use symbols files for libkadm5 ad libkdb5: these libraries
+ change very rapidly and tend to change soname each major release.
+ Symbols files will be introduced if they make sense again.
+ * Update symbols for libkrb5-3: note that several internal functions
+ have disappeared. These functions were not part of the public ABI
+ which remains stable
+ * Update library package names based on soname changes
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 21 Nov 2010 17:31:55 -0500
+krb5 (1.8.3+dfsg-6) unstable; urgency=low
+
+ * Fix double free with pkinit on KDC, CVE-2011-0284, Closes: #618517
+ * Updated Danish debconf translations, thanks Joe Dalton, Closes:
+ #584282
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 16 Mar 2011 10:10:55 -0400
+
+krb5 (1.8.3+dfsg-5) unstable; urgency=low
+
+ * KDC/LDAP DOS (CVE-2010-4022, CVE-2011-0281, and CVE-2011-0282,
+ Closes: #613487
+ * Fix delegation of credentials against Windows servers; significant
+ interoperability issue, Closes: #611906
+ * Set nt-srv-inst on TGS names to work against W2K8R2 KDCs, Closes:
+ #616429
+ * Don't fail authentication when PAC verification fails; support hmac-
+ md5 checksums even for non-RC4 keys, Closes: #616728
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 06 Mar 2011 18:08:35 -0500
+
+krb5 (1.8.3+dfsg-4) unstable; urgency=medium
+
+ * Ignore PACs without a server signature generated by OS X Open
+ Directory rather than failing authentication, Closes: #604925
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 14 Dec 2010 11:53:26 -0500
+
+krb5 (1.8.3+dfsg-3) unstable; urgency=emergency
+
+ * MITKRB5-SA-2010-007
+ * CVE-2010-1324: An unauthenticated attacker can inject arbitrary
+ content into an existing GSS connection that appears to be integrity
+ protected from the legitimate peer under some circumstances
+ * GSS applications may accept a PAC produced by an attacker as if it
+ were signed by a KDC
+ * CVE-2010-1323: attackers have a 1/256 chance of being able to
+ produce krb_safe messages that appear to be from legitimate remote
+ sources. Other than use in KDC database copies this may not be a
+ huge issue only because no one actually uses krb_safe
+ messages. Similarly, an attacker can force clients to display
+ challenge/response values of the attacker's choice.
+ * CVE-2010-4020: An attacker may be able to generate what is
+ accepted as a ad-signedpath or ad-kdc-issued checksum with 1/256
+ probability
+ * New Vietnamese debconf translations, Thanks Clytie Siddall,
+ Closes: #601533
+ * Update standards version to 3.9.1 (no changes required
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 20 Nov 2010 14:50:54 -0500
+
+krb5 (1.8.3+dfsg-2) unstable; urgency=high
+
+ * MITKRB5-SA-2010-006 [CVE-2010-1322]: null pointer dereference in
+ kdc_authdata.c leading to KDC crash, Closes: #599237
+ * Fix two memory leaks in krb5_get_init_creds path; one of these memory
+ leaks is quite common for any application such as PAM or kinit that
+ gets initial credentials, thanks Bastian Blank, Closes: #598032
+ * Install doc/CHANGES only in krb5-doc, not in all packages, saves
+ several megabytes on most Debian systems, Closes: #599562
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 13 Oct 2010 10:41:19 -0400
+
+krb5 (1.8.3+dfsg-1) unstable; urgency=low
+
+ * New Upstream release; only change is version bump from beta1 to final
+ * Bring back a libkrb53 oldlibs package. Note that this is technically a
+ policy violation because it doesn't provide libdes425.so.3 or
+ libkrb4.so.2 and thus provides a different ABI. However, some
+ packages, such as postgres8.4 require the lenny version to be present
+ for the squeeze transition, so we cannot force the removal of
+ libkrb53's reverse dependencies. We can conflict or break with lenny
+ packages that will not work with this libkrb53, but we may break
+ out-of-archive packages without notice. Absent someone coming up with
+ a patch to the modern libk5crypto-3 that allows it to work with the
+ lenny libkrb53 (a weekend's worth of work proved this would be quite
+ difficult), this is the best solution we've come up with, Closes: #596678
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 19 Sep 2010 14:59:46 -0400
+
+krb5 (1.8.3+dfsg~beta1-2) unstable; urgency=low
+
+ * Remove documentation that has moved to the krb5-appl package and is
+ not shipped upstream from Debian diff
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 10 Aug 2010 15:33:15 -0400
+
+krb5 (1.8.3+dfsg~beta1-1) unstable; urgency=low
+
+ * New Upstream version
+ * Add breaks with libkrb53 because libdes425 cannot work with new
+ libk5crypto3 (Closes: #557929)
+ * You want this version: it fixes an incompatibility with how PACs are
+ verified with Windows 2008
+ * As a result of libkrb53 breaks, we no longer get into problems with
+ krb5int_hmac, Closes: #566988
+ * Note that libkdb5-4 breaks rather than conflicts libkadm5srv6, Closes:
+ #565429
+ * Start kdc before x display managers, Closes: #588536
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 05 Aug 2010 12:15:50 -0400
+
+krb5 (1.8.1+dfsg-5) unstable; urgency=low
+
+ * Ignore duplicate token sent in mechListMIC from Windows 2000 SPNEGO
+ (LP: #551901)
+ * krb5-admin-server starts after krb5-kdc, Closes: #583494
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 04 Aug 2010 16:10:02 -0400
+
+krb5 (1.8.1+dfsg-4) unstable; urgency=low
+
+ * fix prerm script (Closes: #577389), thanks Harald Dunkel
+
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 20 May 2010 12:33:43 -0400
+
+krb5 (1.8.1+dfsg-3) unstable; urgency=high
+
+ * CVE-2010-1321 GSS-API accept sec context null pointer deref, Closes:
+ #582261
+ * Force use of bash for build, Closes: #581473
+ * Start slapd before krb5 when krb5-kdc-ldap installed, Closes:
+ #582122
+
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 19 May 2010 16:37:36 -0400
+
+krb5 (1.8.1+dfsg-2) unstable; urgency=high
+
+ * Fix crash in renewal and validation, Thanks Joel Johnson for such a
+ prompt bug report, Closes: #577490
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 12 Apr 2010 13:08:35 -0400
+
+krb5 (1.8.1+dfsg-1) unstable; urgency=high
+
+ * New upstream release
+ * Fixes significant ABI incompatibility between Heimdal and MIT in the
+ init_creds_step API; backward incompatible change in the meaning of
+ the flags API. Since this was introduced in 1.8 and since no better
+ solution was found, it's felt that getting 1.8.1 out everywhere that
+ had 1.8 very promptly is the right approach. Otherwise software build
+ against 1.8 will be broken in the future.
+ * Testing of Kerberos 1.8 showed an incompatibility between Heimdal/MIT
+ Kerberos and Microsoft Kerberos; resolve this incompatibility. As a
+ result, mixing KDCs between 1.8 and 1.8.1 in the same realm may
+ produce undesirable results for constrained delegation. Again,
+ another reason to replace 1.8 with 1.8.1 as soon as possible.
+ * Acknowledge security team upload, thanks for picking up the slack and
+ sorry it was necessary
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 11 Apr 2010 10:12:59 -0400
+
+krb5 (1.8+dfsg-1.1) unstable; urgency=high
+
+ * Non-maintainer upload by the Security Team.
+ * Fixed CVE-2010-0628: denial of service (assertion failure and daemon crash)
+ via an invalid packet that triggers incorrect preparation of an error
+ token. (Closes: 575740)
+ * Makes src/slave/kpropd.c ISO C90 compliant (Closes: #574703)
+
+ -- Giuseppe Iuculano <iuculano@debian.org> Fri, 09 Apr 2010 19:11:50 +0200
+
+krb5 (1.8+dfsg-1) unstable; urgency=low
+
+ * New upstream version
+ * Include new upstream notice file in docs
+ * Update symbols files
+ * Include upstream ticket 6676: fix handling of cross-realm tickets
+ issued by W2K8R2
+ * Add ipv6 support to kprop, Michael Stapelberg, Closes: #549476
+ * New Brazilian Portuguese translations, Thanks Eder L. Marques,
+ Closes: #574149
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 17 Mar 2010 15:51:54 -0400
+
+krb5 (1.8+dfsg~alpha1-7) unstable; urgency=high
+
+ * MITKRB5-SA-2010-001: Avoid an assertion failure leading to a denial of
+ service in the KDC by doing better input validation. (CVE-2010-0283)
+ * Update standards version to 3.8.4 (no changes required).
+
+ -- Russ Allbery <rra@debian.org> Tue, 16 Feb 2010 12:20:51 -0800
+
+krb5 (1.8+dfsg~alpha1-6) unstable; urgency=medium
+
+ * Import upstream fixes including:
+ - A non-conformance with RFC 4120 that causes enc_padata to be
+ included when the client may not support it
+ - Weak crypto acts as a filter and does not reject if DES is
+ included in krb5.conf, fixes Samba net ads join, Closes: #566977
+ * Medium urgency because of the samba bug fix. If the samba maintainers
+ request the release team to bump to high I'd support that.
+ * Update libkdb5 symbols for new upstream internal interface
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 12 Feb 2010 12:24:26 -0500
+
+krb5 (1.8+dfsg~alpha1-5) unstable; urgency=high
+
+ [ Sam Hartman ]
+ * New API to allow an application to enable weak crypto
+ * Rename libkadm5clnt and libkadm5srv to libkadm5clnt_mit and
+ libkadm5srv_mit in order to avoid conflicts with Heimdal packages.
+ Sorry for the second trip through new, but we needed to coordinate
+ with upstream on the ABI issues involved with this change.
+ * Medium urgency in order to get a fix for openafs-krb5 weak crypto into
+ testing sooner
+ * Include fix for pam-krb5 segfault with wrong password; bump urgency to
+ high.
+
+ [ Russ Allbery ]
+ * Change libkrb5-dbg to only depend on libkrb5-3, libk5crypto3, or
+ libkrb5support0. All of the other packages for which it provides
+ debugging symbols also depend on one of those packages and always
+ will, so listing the disjunction of every library package is
+ overkill. Remove from the Depends several obsolete library packages
+ no longer included.
+ * Drop obsolete Replaces for libkadm5srv-mit7 and libkadm5clnt-mit7.
+ * Wrap krb5-multidev dependencies and description and shorten the short
+ description.
+ * Reformat NEWS.Debian to avoid using a bulleted list per devref.
+
+ [ Sam Hartman ]
+ * Link libkadm5{clnt,srv}.so specially so that the links work without
+ libkrb5-dev installed
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 22 Jan 2010 23:35:09 -0500
+
+krb5 (1.8+dfsg~alpha1-4) unstable; urgency=high
+
+ * Add replaces to deal with moving files from krb5-multidev to
+ libkrb5-dev, Closes: #565217
+ * This is definitely the getting all the conflicts combinations right is
+ tricky series of releases. Sorry about the wasted cycles.
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 13 Jan 2010 19:00:37 -0500
+
+krb5 (1.8+dfsg~alpha1-3) unstable; urgency=high
+
+ * Move files to avoid overlap between heimdal-dev and krb5-multidev,
+ Closes: #565132
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 13 Jan 2010 04:18:32 -0500
+
+krb5 (1.8+dfsg~alpha1-2) unstable; urgency=high
+
+ * While Kerberos 1.8 is not vulnerable to CVE-2009-4212 (the vulnerable
+ code was removed during the 1.8 release process for code
+ simplification and code size reasons), this is urgency high to get a
+ version of Kerberos that fixes that integer underflow in the AES and
+ RC4 code into testing.
+ * For now, heimdal and MIT shared libraries for kadm5 will conflict;
+ discussions of how to fix this are ongoing upstream, Closes: #564666
+ * New translations; sorry about missing them in the last upload
+ - Vietnamese, Thanks Clytie Siddall, Closes: #548204
+ - Basque, Thanks Piarres Beobide, Closes: #534284
+ * Update standards version (no changes required)
+ * Pull upstream changes made since alpha1 into the package. In
+ particular this includes a fix to a bug where unkeyed checksums are
+ accepted by the FAST KDC backend. That bug was introduced between 1.7
+ and 1.8 alpha1 so is only present in prior Debian packages of 1.8. See
+ upstream tickets 6632 and 6633.
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 12 Jan 2010 19:26:09 -0500
+
+krb5 (1.8+dfsg~alpha1-1) unstable; urgency=low
+
+ * Include symlinks in libkrb5-dev too
+ * New upstream release
+ * Fix .so symlinks in krb5-multidev
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 08 Jan 2010 22:41:23 -0500
+
+krb5 (1.8+dfsg~aa+r23527-1) experimental; urgency=low
+
+ * MIT krb5 trunk prior to 1.8 branch
+ * Remove krb5-telnet, krb5-ftpd, krb5-clients, krb5-rsh-server, no
+ longer provided upstream. These are provided now in a separate source
+ distribution.
+ * Bring back functions needed by Samba, Closes: #531635
+ * I know that the symbols revisions are generating lintian warnings;
+ that will be cleaned up when upstream actually makes an alpha release
+ * Implement krb5-multidev similar to heimdal-multidev so that packages
+ can be built against both MIT Kerberos and Heimdal
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 03 Jan 2010 17:54:04 -0500
+
+krb5 (1.7+dfsg-4) unstable; urgency=high
+
+
+ * cve-2009-3295, MIT-KRB5-SA-2009-003: KDC crash when failing to find
+ the realm of a host., Thanks 2Jakob Haufe for the report to Debian
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 28 Dec 2009 10:42:32 -0500
+
+krb5 (1.7+dfsg-3) unstable; urgency=low
+
+ * Fix typo in control file
+ * Exclude usr/lib/krb5/plugins from dh_makeshlibs call to deal with
+ behavior change in dh_makeshlibs, Closes: #558719
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 29 Nov 2009 23:24:01 -0500
+
+krb5 (1.7+dfsg-2) unstable; urgency=low
+
+ * Only picked up part of the upstream fix to #557979; upstream fully
+ reverted to 1.6.
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 29 Nov 2009 19:34:44 -0500
+
+krb5 (1.7+dfsg-1) unstable; urgency=low
+
+ * New upstream version, Closes: #554225
+ * Several fixes applied after the 1.7 release:
+ - 6506: correctly handle keytab vs stash file
+ - 6508: kadmind ACL parsing could reference uninitialized memory
+ - 6509: kadmind can reference null pointer on ACL error
+ - 6511: uninitialized memory passed to krb5_free_error in change
+ password client path
+ - 6514: none replay cache memory leak
+ - 6515: profile library mutex performance improvements
+ - 6541: memory leak in PAC verify code
+ - 6542: Check for null characters in pkinit certs
+ - 6543: login vs user order in ftpd sometimes wrong
+ - 6551: Memory leak in spnego accept_sec_context error path
+ * libkrb5-dev depends on libkadm5clnt6 (LP: #472080)
+ * Avoid locking out accounts on PREAUTH_FAILED, Closes: #557979, (LP:
+ #489418)
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 29 Nov 2009 17:29:26 -0500
+
+krb5 (1.7dfsg~beta3-2) UNRELEASED; urgency=low
+
+ * Update to policy 3.8.2 (no changes)
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 20 Jun 2009 06:32:22 -0400
+
+krb5 (1.7dfsg~beta3-1) unstable; urgency=low
+
+ * New upstream release
+ * Revert relaxation of Debian symbol versions introduced in
+ 1.7dfsg~beta1-3
+ * Fix kproplog's manpage (LP: #374819)
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 27 May 2009 21:15:41 -0400
+
+krb5 (1.7dfsg~beta2-4) unstable; urgency=low
+
+ * Upstream fixes to RT #6490, Closes: #528729
+ - Use MS usage 9 not 8 for tgs-rep encrypted in subkey
+ - Do not use keyed checksum with RC4; WS2003 expects it to be
+ encrypted in the subsession key, everyone else expects the session
+ key. Note that a keyed checksum for RC4 would work against WS2008.
+ * Patch from Marc Dequ?nes (Duck) for HURD portability, Closes:
+ #528828
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 20 May 2009 08:57:53 -0400
+
+krb5 (1.7dfsg~beta2-3) unstable; urgency=low
+
+ * Use correct enctype identifier in lucid security context export,
+ Closes: #528514
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 18 May 2009 14:59:46 -0400
+
+krb5 (1.7dfsg~beta2-2) unstable; urgency=low
+
+ * Apply upstream patch from ticket 6488 intended to fix
+ gss_krb5_export_lucid_sec_context and thus NFS; hopefully fixes
+ #528514
+ * Apply patch from ticket 6489 to fix UCS2 handling in RC4 string to
+ key and PAC routines
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 14 May 2009 16:21:48 -0400
+
+krb5 (1.7dfsg~beta2-1) unstable; urgency=low
+
+ * New Upstream release including FAST support for DES and 3DES.
+ * Remove non-free content accidentally reintroduced in beta1, Closes: #528555
+ * Add strict dependency from libgssapi-krb5-2 to libkrb5-3 as discussed
+ in #528514
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 13 May 2009 14:09:31 -0400
+
+krb5 (1.7dfsg~beta1-4) unstable; urgency=low
+
+ * When decrypting the TGS response fails with the subkey, try with the
+ session key to work around Heimdal bug, Closes: #527353
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 07 May 2009 16:16:34 -0400
+
+krb5 (1.7dfsg~beta1-3) unstable; urgency=low
+
+ * Relax symbol versions of symbols that exist in krb5 1.6.dfsg.2 to
+ 1.6.dfsg.2. No software currently in Debian uses the new
+ functionality, and this will ease the transition because it allows
+ krb5 to move independently of packages that are being rebuilt. This
+ change will be reverted before the end of May, 2009.
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 05 May 2009 09:01:17 -0400
+
+krb5 (1.7dfsg~beta1-2) unstable; urgency=low
+
+ * Upload to unstable with permission of release team; note that this
+ upload will make anything that depends on libkrb53 uninstallable in
+ unstable. The release team will make binary only NMUs to rebuild any
+ such packages and they will depend on the new libraries. Packages
+ built since 1.6.dfsg.4~beta1-9 entered unstable should not be affected.
+ * Upstream change: return PREAUTH_REQUIRED not PREAUTH_FAILED on unknown
+ preauth type in the KDC.
+ * Remove a bunch of patches applied ustream from debian/patches
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 04 May 2009 16:19:09 -0400
+
+krb5 (1.7dfsg~beta1-1) experimental; urgency=low
+
+ * New upstream release
+ - kadmin and related commands moved to /usr/bin, Closes: #477296
+ - Kadmin headers are Public: Closes: #191616
+ - KDC supports loopback address, Closes: #478425
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 22 Apr 2009 09:53:15 -0400
+
+krb5 (1.7dfsg~alpha1-1) experimental; urgency=low
+
+ * New upstream version
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 05 Apr 2009 20:46:14 -0400
+
+krb5 (1.6.dfsg.4~beta1-13) unstable; urgency=high
+
+ * MITKRB5-SA-2009-001: Fix read-beyond-end-of-buffer DOS in SPNEGO, an
+ SPNEGO null pointer dereference, and incorrect length validation in
+ an ASN.1 decoder. (CVE-2009-0844, CVE-2009-0845, CVE-2009-0847)
+ * MITKRB5-SA-2009-002: ASN.1 general time decoder can free uninitialized
+ pointer. (CVE-2009-0846)
+ * Add dependency on libkrb53 from libkrb5-dev. This should make it
+ significantly more difficult for buildds to get out of sync. I don't
+ think we can do better within the constraints of this transition,
+ Closes: #522469
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 07 Apr 2009 14:58:31 -0400
+
+krb5 (1.6.dfsg.4~beta1-12) unstable; urgency=low
+
+ * Translation updates:
+ - Romanian, thanks Eddy Petrișor. (Closes: #519660)
+ - Finnish, thanks Esko Arajärvi. (Closes: #519741)
+ - Russian, thanks Sergey Alyoshin. (Closes: #519744)
+ - Spanish, thanks Francisco Javier Cuadrado. (Closes: #519808)
+
+ -- Russ Allbery <rra@debian.org> Fri, 27 Mar 2009 11:24:28 -0700
+
+krb5 (1.6.dfsg.4~beta1-11) unstable; urgency=low
+
+ * Upload from the partial-krb4 branch not the master branch so we don't
+ break unstable.
+ - Restore libkrb53 and libkadm55
+ * Resync the aes test files from upstream to fix a line ending problem
+ and significantly shrink the debian diff
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 13 Mar 2009 10:19:42 -0400
+
+krb5 (1.6.dfsg.4~beta1-10) unstable; urgency=low
+
+ * Add Homepage control field.
+ * Add ${misc:Depends} to dependencies for all packages.
+ * Expand the packages that satisfy the libkrb5-dbg dependency.
+ * Include a few more details about the differences between the various
+ library packages in their long descriptions and fix some whitespace
+ inconsistencies. Thanks, Gerfried Fuchs. (Closes: #519403)
+ * Remove empty usr/include/kerberosIV directory in libkrb5-dev.
+ * Use set -e instead of #!/bin/sh -e for all maintainer scripts.
+ * Use which without a path to check for update-inetd.
+ * Improve the leading comment in /etc/default/krb5-kdc.
+ * Remove unnecessary section override for krb5-pkinit.
+ * Update to debhelper compatibility level V7.
+ - Use dh_lintian to install Lintian overrides.
+ - Use dh_prep instead of dh_clean -k.
+ * Update standards version to 3.8.1 (no changes required).
+ * Fix superfluous space in the krb5-kdc debconf templates and unfuzzy
+ translations. Thanks, Helge Kreutzmann. (Closes: #518403)
+ * Translation updates:
+ - French, thanks Christian Perrier. (Closes: #518221)
+ - Japanese, thanks TANAKA Atushi. (Closes: #518345)
+ - Swedish, thanks Martin Bagge. (Closes: #518347)
+ - German, thanks Helge Kreutzmann. (Closes: #518402)
+ - Czech, thanks Miroslav Kure. (Closes: #518993)
+ - Portuguese, thanks Miguel Figueiredo. (Closes: #519000)
+ - Italian, thanks Luca Monducci. (Closes: #519178)
+ - Galician, thanks Marce Villarino. (Closes: #519481)
+
+ -- Russ Allbery <rra@debian.org> Thu, 12 Mar 2009 18:00:31 -0700
+krb5 (1.6.dfsg.4~beta1-9) unstable; urgency=medium
+
+ * Fix typo in downgrade instructions in NEWS file.
+ * Fix override for libkadm55
+ * Upload to unstable.
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 01 Mar 2009 15:33:58 -0500
+
+krb5 (1.6.dfsg.4~beta1-8) experimental; urgency=low
+
+ * Re-introduce libkrb53 and libkadm55 based on discussion on
+ debian-devel; in this version, libkrb53 contains only libkrb4. Both
+ libkrb53 and libkadm55 depend on the split library packages. These
+ dependencies are unversioned; that means that before any symbols are
+ added the shlibs files need to be repointed away from libkrb53 and
+ libkadm55. Any version of the split library packages can satisfy the
+ symbols needed by the libraries previously shipped in libkrb53.
+ * Perform two builds; one without krb4 and one with krb4 for the only
+ warnings; they will go away when the shlibs files are repointed.
+ * Remove krb4 support from debconf and init scripts.
+ * Remove the krb4 migration guide from doc-base
+ * Fix up replaces in control file so that libraries that used to be in
+ libkadm55 claim to replace libkadm55
+ * Only use parallel builds on the krb5 build; it breaks krb4 enabled
+ builds.
+ * Used versioned replaces; this seems to make it harder to get a system
+ into a broken state if you remove the new packages, Closes: #517483
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 28 Feb 2009 00:42:51 -0500
+
+krb5 (1.6.dfsg.4~beta1-7) experimental; urgency=low
+
+ * Do not build krb4 support; this is being removed upstream with 1.7 and
+ it is strongly desirable to examine the debian implications.
+ * As a result, the libraries which were previously all in libkrb53 need
+ to change package names as we are dropping some libraries. So, split
+ out the libraries into lib<libraryname>-<soname> per policy. The old
+ format was consistent with policy when it was written 8 years ago, and
+ has lasted well. As a result, a significant number of new library
+ packages are introduced.
+ * Use dpkg-gensymbols support for .symbols files for better version tracking
+ * Update to policy 3.8.0
+ - Support parallel=
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 20 Feb 2009 16:57:43 -0500
+
+krb5 (1.6.dfsg.4~beta1-6) unstable; urgency=low
+
+ * In the krb5-install info pages, document the need to create an empty
+ database on new slaves before the first database propagation to work
+ around a bug in kdb5_util. This is a workaround for Bug#512670, which
+ won't be fixed in time for the lenny release.
+
+ -- Russ Allbery <rra@debian.org> Sun, 01 Feb 2009 10:07:37 -0800
+
+krb5 (1.6.dfsg.4~beta1-5) unstable; urgency=low
+
+ * Correct the actions of krb5_newrealm in its man page. It doesn't
+ create a keytab for kadmind since kadmind no longer needs one.
+ Mention that it does create a stash file and that it starts the KDC
+ and kadmind daemons. Thanks, David Medberry. (Closes: #504126)
+ * Translation updates:
+ - Spanish, thanks Ignacio Mondino. (Closes: #504766)
+
+ -- Russ Allbery <rra@debian.org> Mon, 29 Dec 2008 22:21:21 -0800
+
+krb5 (1.6.dfsg.4~beta1-4) unstable; urgency=low
+
+ [ Russ Allbery ]
+ * Translation updates:
+ - Swedish, thanks Martin Bagge. (Closes: #487669, #491774)
+ - Italian, thanks Luca Monducci. (Closes: #493962)
+
+ [ Sam Hartman ]
+ * Translation Updates:
+ - Dutch, Thanks Vincent Zweije, Closes: #495733
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 21 Aug 2008 10:41:41 -0400
+
+krb5 (1.6.dfsg.4~beta1-3) unstable; urgency=low
+
+ * Set length to 0 on no-salt ldap keys so they do not crash; uupstream
+ ticket 5545, Closes: #480523
+ * Swedish translations, thanks Martin Bagge, Closes: #487563
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 22 Jun 2008 23:00:37 -0400
+
+krb5 (1.6.dfsg.4~beta1-2) unstable; urgency=low
+
+ [ Russ Allbery ]
+ * Translation updates:
+ - Japanese, thanks TANAKA, Atushi.
+ - Russian, thanks Sergey Alyoshin. (Closes: #485473)
+ - Brazilian Portuguese, thanks Eder L. Marques. (Closes: #485613)
+ - Romanian, thanks Eddy Petrișor. (Closes: #484996)
+
+ [ Sam Hartman ]
+ * Upload 1.6.4 beta 1 to unstable. As best I can tell evaluating the
+ changes this is a strict improvement over 1.6.3 even though it is
+ still a beta version. There is not an ABI change ; backing out would
+ be relatively easy.
+ * Patch from Bryan Kadzban to look inside spnego union_creds when
+ looking for a specific mechanism cred. This allows spnego creds to be
+ used when copying out to a ccache after delegation, Closes: #480434
+ * Ksu now calls krb5_verify_init_creds rather than using its own custom
+ logic because that is correct and so it can take advantage of the
+ following change.
+ * krb5_verify_init_creds uses the default realm if it gets a referral
+ realm as input for server, Closes: #435427
+ * Add -D_FORTIFY_SOURCE=2 and -fstack-protector on ia32 and x86_64 at
+ the request of Moritz Muehlenhoff ; he was unsure that adding these
+ flags on other platforms would be a good idea. I'd be happy to expand
+ the list at the request of port maintainers, Closes: #484371
+ * Fix KDC purge code introduced in previous revision.
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 16 Jun 2008 09:29:00 -0400
+
+krb5 (1.6.dfsg.4~beta1-1) experimental; urgency=low
+
+ [ Russ Allbery ]
+ * Do not translate the Kerberos v4 modes. They are literal strings
+ passed to the Kerberos KDC as arguments to the -4 option. Comment
+ mentions of those strings in the debconf template so that
+ translators know this.
+ * Rather than prompting at installation time for whether the KDC
+ database should be deleted on purge, prompt in prerm when the package
+ is being removed for whether the database should be deleted.
+ * Translation updates:
+ - Galician, thanks Jacobo Tarrio. (Closes: #482324)
+ - French, thanks Christian Perrier. (Closes: #482326)
+ - Vietnamese, thanks Clytie Siddall. (Closes: #482362)
+ - Basque, thanks Piarres Beobide. (Closes: #482376)
+ - Czech, thanks Miroslav Kure. (Closes: #482428)
+ - German, thanks Helge Kreutzmann. (Closes: #482366)
+ - Spanish, thanks Diego D'Onofrio.
+ - Finnish, thanks Esko Arajärvi. (Closes: #482682)
+ - Portuguese, thanks Miguel Figueiredo. (Closes: #483049)
+
+ [ Sam Hartman ]
+ * Remove extra space in debian/rules so upstream configure scripts can
+ work.
+ * Upgrade to 1.6.4 beta 1.
+ * Upstream includes several fixes to bugs that were assigned CVE
+ numbers; upstream does not actually consider these security issues and
+ no advisory was issued, but they are included here for the benefit of
+ the security team in case anyone asks. Closes: #454974
+ - fix CVE-2007-5972: double fclose() in krb5_def_store_mkey()
+ - fix CVE-2007-5971: double-free in gss_krb5int_make_seal_token_v3()
+ - fix CVE-2007-5902: integer overflow in svcauth_gss_get_principal()
+ - fix CVE-2007-5971: free of non-heap pointer in gss_indicate_mechs()
+ - fix CVE-2007-5894: apparent uninit length in ftpd.c:reply()
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 31 May 2008 10:53:21 -0400
+
+krb5 (1.6.dfsg.3-2) unstable; urgency=low
+
+ * kdc.conf was previously in krb5-doc, not uninstalled. Properly
+ handle moving it to the krb5-kdc package. (Closes: #480452)
+ * Include libkdb-ldap1 in krb5-kdc-pkinit, install it into a private
+ directory (/usr/lib/krb5) rather than directly in /usr/lib, and use an
+ RPATH in kdb5_ldap_util and the plugin to find the library. Drop the
+ libkdb-ldap1 library package. This library isn't intended to be used
+ by any software outside of the KDC plugin and utility. Thanks,
+ Bastian Blank. (Closes: #479384)
+ * Load defaults for debconf configuration of krb5-admin-server and
+ krb5-kdc from the /etc/default files if they exist. Thanks, Bastian
+ Blank. (Closes: #479404)
+ * Preserve DAEMON_ARGS settings in /etc/default/krb5-admin-server and
+ /etc/default/krb5-kdc even if debconf configuration is enabled.
+ * Don't require that a stash file be created in /etc/init.d/krb5-kdc.
+ Stash files are optional. (Closes: #479457)
+ * Error out instead of silently existing if debconf's confmodule cannot
+ be loaded. Given that we depend on debconf, if this fails, something
+ serious went wrong and we shouldn't ignore it.
+ * Use /bin/which instead of command -v to check for update-inetd.
+ * Unconditionally remove kpropd's inetd.conf entry in the postrm of
+ krb5-kdc rather than special-casing remove and deconfigure.
+ * Add 256-bit AES and RC4 keys to the default kdc.conf, the first
+ because it's the strongest enctype currently supported and the second
+ for Windows compatibility. Improve the README.KDC enctype
+ documentation.
+ * Install kerberos.ldif and kerberos.schema in krb5-kdc-ldap as
+ documentation. Thanks, Bastian Blank. (Closes: #479239)
+
+ -- Russ Allbery <rra@debian.org> Fri, 09 May 2008 20:27:16 -0700
+
+krb5 (1.6.dfsg.3-1) unstable; urgency=low
+
+ * Final upstream 1.6.3 release.
+ * Package the LDAP plugin for the KDC, which allows one to use an LDAP
+ server to store the KDC database. Install the krb5-kdc-ldap package
+ for the plugin. (Closes: #453113)
+ * If krb5-config/default_realm isn't set, use EXAMPLE.COM as the realm
+ so that the kdc.conf will at least be syntactically valid (but will
+ still require editing). (Closes: #474741)
+ * krb5-kdc explicitly depends on krb5-config since it relies on debconf
+ variables set by that package.
+ * Always stop krb524d on /etc/init.d/krb5-kdc stop even if the
+ configuration has been changed to no longer run it. Thanks, Bastian
+ Blank. (Closes: #477294)
+ * Install the kdc.conf man page. (Closes: #477307)
+ * krb5-kdc no longer depends on update-inetd and inet-superserver and
+ instead just suggests openbsd-inetd | inet-superserver and
+ conditionally adds the commented-out kpropd example if update-inetd is
+ available. krb5-admin-server doesn't need inet-superserver at all.
+ Thanks, Bastian Blank. (Closes: #477301)
+ * Change the doc-base sections to System/Security.
+ * Correctly mangle the version in the watch file.
+ * Remove conflicts with packages already not present in oldstable.
+ * Remove versioned build-dependencies satisfied by oldstable.
+ * Remove versioned Replaces for versions older than oldstable.
+
+ -- Russ Allbery <rra@debian.org> Sun, 27 Apr 2008 20:39:36 -0700
+
+krb5 (1.6.dfsg.3~beta1-4) unstable; urgency=emergency
+
+ * MITKRB5-SA-2008-001: When Kerberos v4 support is enabled in the KDC,
+ malformed messages may result in NULL pointer use, double-frees, or
+ exposure of information. (CVE-2008-0062, CVE-2008-0063)
+ * MITKRB5-SA-2008-002: If the file descriptor limit is larger than
+ FD_SETSIZE and kadmind has more open connections than FD_SETSIZE, an
+ array overrun and memory corruption may result. (CVE-2008-0947)
+
+ -- Russ Allbery <rra@debian.org> Fri, 07 Mar 2008 18:53:59 -0800
+
+krb5 (1.6.dfsg.3~beta1-3) unstable; urgency=low
+
+ * Apply cross-build patch from Neil Williams. (Closes: #465294)
+ * Document in comments that configuration management via debconf should
+ be disabled before making manual changes to /etc/default/krb5-kdc and
+ /etc/default/krb5-admin-server. (Closes: #443326)
+ * Support DAEMON_ARGS in /etc/default/krb5-admin-server for kadmind.
+ Thanks, Dwayne Litzenberger. (Closes: #443331)
+ * Don't stop the servers in runlevel S. This isn't a real runlevel and
+ cannot be switched to, so the links are extraneous.
+ * Use binary:Version instead of Source-Version in debian/control.
+ * Depend on openbsd-inetd | inet-superserver instead of on update-inetd,
+ since inetd implementations may provide their own update-inetd.
+ * Improve quoting and formatting in the postinsts for krb5-kdc and
+ krb5-admin-server. Error on failure to load debconf, since we do
+ depend on it. Support reconfigure.
+ * Fix file locations in the krb524 doc-base control file.
+ * Add the info documentation to all doc-base control files.
+ * Fix a variety of man page errors uncovered by man --warnings.
+ * Wrap Depends and Conflicts fields in debian/control.
+ * dpkg-dev now compresses duplicate relations, so no need for lintian
+ overrides.
+ * Add an override for the empty plugin directory in libkrb53.
+ * Update standards version to 3.7.3 (no changes required).
+ * Translation updates:
+ - Finnish, thanks Esko Arajärvi. (Closes: #451146)
+ - Dutch, thanks Vincent Zweije. (Closes: #460589)
+
+ -- Russ Allbery <rra@debian.org> Mon, 18 Feb 2008 20:53:08 -0800
+
+krb5 (1.6.dfsg.3~beta1-2) unstable; urgency=low
+
+ * Move pkinit into a new package krb5-pkinit. We don't want pkinit to
+ always be installed because this pulls in an openssl dependency and
+ most people don't need it. However we want the plugin available when
+ needed, Closes: #444938
+ * I had hoped to wait for the upstream release, but that is being a bit slow.
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 18 Oct 2007 17:03:27 -0400
+
+krb5 (1.6.dfsg.3~beta1-1) unstable; urgency=low
+
+ * New Upstream release
+ - Fix krb5_set_default_tgs_enctypes, Closes: #413838
+
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 01 Oct 2007 21:21:59 -0400
+
+krb5 (1.6.dfsg.1-7) unstable; urgency=emergency
+
+ * mit-sa-2007-6:
+ - CVE 2007-3999 rpc library buffer overflow
+ - CVE 2007-uninitialized kadmin pointer
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 04 Sep 2007 15:06:51 -0400
+
+krb5 (1.6.dfsg.1-6) unstable; urgency=low
+
+ * Don't depend on libkeyutils-dev on non-Linux architectures. Thanks,
+ Petr Salinger. (Closes: #430215)
+ * Restore support for the RUN_KADMIND setting as written by debconf.
+ Thanks, Christoph Neerfeld. (Closes: #429535)
+ * Wrap the build-depends line now that dpkg in oldstable supports this.
+ * Update debconf templates and debian/control long package descriptions
+ as suggested by the debian-l10n-english team as part of the Smith
+ review project. Thanks to Christian Perrier for the coordination
+ work. (Closes: #428195)
+ * Debconf translation updates:
+ - Galician, thanks Jacobo Tarrio. (Closes: #429511)
+ - Portuguese, thanks Miguel Figueiredo. (Closes: #429592)
+ - Basque, thanks Piarres Beobide. (Closes: #429637)
+ - Japanese, thanks TANAKA, Atushi. (Closes: #429844)
+ - Vietnamese, thanks Clytie Siddall. (Closes: #429907)
+ - German, thanks Helge Kreutzmann. (Closes: #430561)
+ - Czech, thanks Miroslav Kure. (Closes: #431203)
+ - Russian, thanks Yuri Kozlov. (Closes: #431247)
+ - French, thanks Christian Perrier.
+
+ -- Russ Allbery <rra@debian.org> Sun, 15 Jul 2007 20:58:07 -0700
+
+krb5 (1.6.dfsg.1-5) unstable; urgency=emergency
+
+ * MIT-SA-2007-4: The kadmin RPC library can free an uninitialized
+ pointer or write past the end of a stack buffer. This may lead to
+ execution of arbitrary code. (CVE-2007-2442, CVE-2007-2443)
+ * MIT-SA-2007-5: kadmind is vulnerable to a stack buffer overflow that
+ may lead to execution of arbitrary code. (CVE-2007-2798)
+
+ -- Russ Allbery <rra@debian.org> Wed, 13 Jun 2007 13:07:44 -0700
+
+krb5 (1.6.dfsg.1-4) unstable; urgency=low
+
+ * Make --deps switch to krb5-config include dependent libraries; otherwise do not, Closes: #422985
+ * Include copyright statement for remaining IETF draft, Closes: #393380
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 13 May 2007 16:28:56 -0400
+
+krb5 (1.6.dfsg.1-3) unstable; urgency=low
+
+ * Upstream bug #5552: krb5_get_init_creds needs to not dereference
+ gic_opts if it is null. Instead, assume that it is default options,
+ Closes: #422687
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 8 May 2007 14:46:55 -0400
+
+krb5 (1.6.dfsg.1-2) unstable; urgency=low
+
+ * Fix shlibdeps to reflect 1.6.dfsg.1 instead of 1.6.1
+ * Upload 1.6 to unstable
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 3 May 2007 20:23:47 -0400
+
+krb5 (1.6.dfsg.1-1) experimental; urgency=low
+
+ * Oops, I failed to understand how the version numbers work. Since 1.6.1 is less than 1.6.dfsg, the version numbering is going to be a bit screwy for the 1.6 series. We will use 1.6.dfsg.1 for 1.6.1.
+ * Update to update-inetd dependency, Closes: #420748
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 29 Apr 2007 08:59:28 -0400
+
+krb5 (1.6.1.dfsg-1) experimental; urgency=low
+
+ * Depend on keyutils-lib-dev so we consistently get keyring cache support
+ * New Portuguese translation, thanks Miguel Figueiredo , Closes: #409318
+ * New Upstream release
+ - Update shlibs for new API
+ * Fix handling of null realm in krb5_rd_req_decoded; now we treat a null realm as a default realm there.
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 28 Apr 2007 16:21:03 -0400
+
+krb5 (1.6.dfsg-1) experimental; urgency=low
+
+ * New 1.6 release from upstream.
+ * Update copyright
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 1 Feb 2007 22:26:08 -0500
+
+krb5 (1.6.dfsg~alpha1-1) experimental; urgency=low
+
+ * New upstream release
+ * Remove IETF RFCs, Closes: #393380
+ * Update copyright file based on new copyrights upstearm
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 22 Nov 2006 10:28:13 -0500
+
+krb5 (1.4.4-8) unstable; urgency=emergency
+
+ * MIT-SA-2007-1: telnet allows login as an arbitrary user when
+ presented with a specially crafted username; CVE-2007-0956
+ * krb5_klog_syslog has a trivial buffer overflow that can be exploited
+ by network data; CVE-2007-0957. The upstream patch is very intrusive
+ because it fixes each call to syslog to have proper length checking as
+ well as the actual krb5_klog_syslog internals to use vsnprintf rather
+ than vsprintf. I have chosen to only include the change to
+ krb5_klog_syslog for sarge. This is sufficient to fix the problem but
+ is much smaller and less intrusive. (MIT-SA-2007-2)
+ * MIT-SA-2007-3: The GSS-API library can cause a double free if
+ applications treat certain errors decoding a message as errors that
+ require freeing the output buffer. At least the gssapi rpc library
+ does this, so kadmind is vulnerable. Fix the gssapi library because
+ the spec allows applications to treat errors this way. CVE-2007-1216
+ * New Japanese translation, thanks TANAKA Atushi, Closes: #414382
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 11 Mar 2007 19:08:52 -0400
+
+krb5 (1.4.4-7) unstable; urgency=low
+
+ * Translation updates:
+ - New Portuguese translation, thanks Rui Branco. (Closes: #409318)
+
+ -- Russ Allbery <rra@debian.org> Wed, 21 Feb 2007 15:23:08 -0800
+
+
+krb5 (1.4.4-6) unstable; urgency=emergency
+
+ * MIT-SA-2006-2: kadmind and rpc library call through function pointer
+ to freed memory (CVE-2006-6143). Null out xp_auth unless it is
+ associated with an rpcsec_gss connection.
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 4 Jan 2007 16:07:02 -0500
+
+krb5 (1.4.4-5) unstable; urgency=low
+
+ * Translation updates:
+ - New Spanish translation, thanks Fernando Cerezal. (Closes: #402986)
+
+ -- Russ Allbery <rra@debian.org> Sun, 17 Dec 2006 17:18:05 -0800
+
+krb5 (1.4.4-4) unstable; urgency=low
+
+ * Remove the check for pthread_mutexattr_setrobust_np in the thread
+ initialization code. This was only needed on Solaris 9 and has been
+ removed upstream, and was causing FTBFS with glibc 2.5. Thanks,
+ Martin Pitt. (Closes: #396166)
+ * Translation updates:
+ - New Romanian translation, thanks stan ioan-eugen. (Closes: #395347)
+
+ -- Russ Allbery <rra@debian.org> Sun, 5 Nov 2006 21:32:17 -0800
+
+krb5 (1.4.4-3) unstable; urgency=low
+
+ * Don't require the presence of debconf during the postrm. Thanks to
+ Bill Allombert for the report. (Closes: #388784)
+ * Fix uses of hyphens instead of minus signs in the man pages.
+
+ -- Russ Allbery <rra@debian.org> Fri, 22 Sep 2006 14:57:34 -0700
+
+krb5 (1.4.4-2) unstable; urgency=low
+
+ * Patch from Alejandro R. Sedeno to allow 32-bit and 64-bit krb4 ticket
+ files to be used on the same system. Similar to a patch included in
+ MIT Kerberos 1.5 but backported because of missing byte order macros.
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 20 Sep 2006 22:51:59 -0400
+
+krb5 (1.4.4-1) unstable; urgency=low
+
+ * New upstream release.
+ * Stop using --exec to start and stop services since then services will
+ not be stopped properly during an upgrade. (Closes: #385039)
+ * Rewrite the init scripts to include LSB information and to use the LSB
+ logging functions. krb5-kdc and krb5-admin-server now depend on
+ lsb-base (>= 3.0-6) for the LSB functions.
+
+ -- Russ Allbery <rra@debian.org> Fri, 1 Sep 2006 20:45:59 -0700
+
+krb5 (1.4.4~beta1-1) unstable; urgency=low
+
+ * New upstream version including several memory leak fixes
+ * Install upstream changelog
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 16 Aug 2006 16:45:56 -0400
+
+krb5 (1.4.3-9) unstable; urgency=high
+
+ * Add error checking to setuid, setreuid to avoid local privilege
+ escalation ; fixes krb5-sa-2006-1, CVE-2006-3084, CVE-2006-3083
+ * Update standards version to 3.7.2 (no changes required).
+ * Translation updates.
+ - Russian, thanks Yuri Kozlov. (Closes: #380303)
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 6 Aug 2006 17:12:40 -0400
+
+krb5 (1.4.3-8) unstable; urgency=low
+
+ * Defer seeding of the random number generator in kadmind until after
+ forking and backgrounding, since otherwise blocking on /dev/random may
+ block system startup. (Closes: #364308)
+ * Update config.{guess,sub}. (Closes: #373727)
+ * Better fix for error handling of a zero-length keytab. Thanks,
+ Rainer Weikusat.
+
+ -- Russ Allbery <rra@debian.org> Sun, 16 Jul 2006 08:59:20 -0700
+
+krb5 (1.4.3-7) unstable; urgency=low
+
+ * Fix double free caused by a zero-length keytab. Thanks, Steve
+ Langasek. (Closes: #344295)
+ * Fix segfault in krb5_kuserok if the local name doesn't correspond to a
+ local account. (Discovered in bug #354133.)
+ * Build a separate libkrb5-dbg package containing the detached debugging
+ information for libkrb53 and libkadm55.
+ * Update debhelper compatibility level to V5 since the dh_strip behavior
+ around debug packages changes in V5 and we should use the current
+ interface from the beginning.
+ * Translation updates.
+ - Dutch, thanks Vincent Zweije. (Closes: #360444)
+ - Galician, thanks Jacobo Tarrio. (Closes: #361809)
+
+ -- Russ Allbery <rra@debian.org> Sat, 15 Apr 2006 16:22:01 -0700
+
+krb5 (1.4.3-6) unstable; urgency=low
+
+ * Assume krb5 in krb5_gss_canonicalize_name if the null mechanism is
+ passed in. Fixes a segfault in racoon from ipsec-tools. Thanks,
+ Daniel Kahn Gillmor. (Closes: #351877)
+ * v5passwdd is gone, so remove the debconf template, the prompts, and
+ the code to start and stop it from the init script. Thanks, Greg
+ Folkert.
+ * Fix incorrect option names in krb5.conf(5). Thanks, Martin v.
+ Loewis. (Closes: #347643)
+ * Translation updates.
+ - Danish, thanks Claus Hindsgaul. (Closes: #350041)
+
+ -- Russ Allbery <rra@debian.org> Tue, 21 Feb 2006 23:25:34 -0800
+
+krb5 (1.4.3-5) unstable; urgency=medium
+
+ * Configure with --enable-shared --enable-static so that libkrb5-dev
+ gets static libraries.
+ * Fix double free in getting credentials, Closes: #344543
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 25 Dec 2005 21:59:47 -0500
+
+krb5 (1.4.3-4) unstable; urgency=high
+
+ * Fix problem when libpthreads is dynamically loaded into a program
+ causing mutexes to sometimes be used and sometimes not be used. If
+ the library starts out without threads support it will never start
+ using threads support; doing anything else causes hangs.
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 16 Dec 2005 18:16:53 -0500
+
+krb5 (1.4.3-3) unstable; urgency=low
+
+ * Additional internal pthread symbols have to be declared weak on Hurd.
+ Thanks, Michael Banck. (Closes: #341608)
+ * Build on GNU/kFreeBSD. Thanks, Petr Salinger. (Closes: #261712)
+ * Change the default KDC enctype to 3DES to match upstream (the
+ difference was probably a mismerge).
+ * Remove /etc/default/krb5-admin-server on purge. (Closes: #333161)
+ * Document the behavior of klogind and kshd if the user has no .k5login
+ file. Remove vestigial .rhosts references. (Closes: #250966)
+ * Document krb5-rsh-server authorization defaults in README.Debian.
+ * Enable kinit -a to match the man page. (Closes: #232431)
+ * Remove the patch to tightly bind libkrb4 to libdes425. This should no
+ longer be necessary with symbol versioning.
+ * Upstream has removed the file with questionable licensing, so the
+ upstream tarball is no longer repacked. Remove the get-orig-source
+ target in debian/rules and the notes in copyright and README.Debian.
+ * Add a watch file.
+ * Translation updates.
+ - German, thanks jens. (Closes: #330925)
+
+ -- Russ Allbery <rra@debian.org> Sun, 4 Dec 2005 11:37:40 -0800
+
+krb5 (1.4.3-2) unstable; urgency=low
+
+ * Conflict with libauthen-krb5-perl (<< 1.4-5) because of krb5_init_ets.
+ * Update uploader address.
+ * Conflict with libapache-mod-auth-kerb because it accesses library
+ internals in a way that breaks.
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 30 Nov 2005 22:33:47 -0500
+
+krb5 (1.4.3-1) experimental; urgency=low
+
+ * New upstream release.
+ * Install ac_check_krb5 for use by aclocal.
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 19 Nov 2005 16:20:56 -0500
+
+krb5 (1.4.2-1) UNRELEASED; urgency=low
+
+ * New upstream version. (Closes: #293077)
+ - kadmind4, v5passwdd, and v5passwd are no longer included.
+ - Increase the libkrb53 shlibs version dependency. Programs linked
+ against this version will not work with an older libkrb53.
+ - Rebuild should fix link problems on powerpc. (Closes: #329709)
+ * Re-enable optimization on m68k to stop hiding the toolchain problem.
+ * Don't build crypto code -O3. It uncovers too many gcc bugs.
+ * Fix compilation on Hurd. Thanks, Michael Banck. (Closes: #324305)
+ * Always initialize the output token in gss_init_sec_context, even with
+ an unknown mechanism. (Closes: #311977)
+ * rcp should fall back to /usr/bin/netkit-rcp, not /usr/bin/rpc.
+ * Add the missing shared library depends for libkadm55.
+ * Use dh_install rather than dh_movefiles and enable --fail-missing to
+ be sure to pick up any new upstream files.
+ * Avoid test -a in maintainer scripts.
+ * Expand and reformat the documentation and sample kdc.conf file.
+ * Add a doc-base file for the krb425 migration guide.
+ * Ignore lintian warnings about the library package names. We'll fix
+ them the next time upstream changes SONAMEs.
+ * Conflict with packages that used internal symbols not part of the
+ public ABI
+ * Use "MIT Kerberos" rather than krb5 in the krb5-doc short description.
+ * Remove the saved patches that have been applied upstream or are no
+ longer applied to the package, update the remaining patches, and move
+ them into debian/patches.
+ * Break out the other patches of interest for ease submitting them
+ upstream.
+ * Translation updates.
+ - Vietnamese, thanks Clytie Siddall. (Closes: #319704)
+
+ -- Russ Allbery <rra@stanford.edu> Thu, 22 Sep 2005 17:08:58 -0700
+
+krb5 (1.3.6-5) unstable; urgency=high
+
+ * Disable optimization on m68k to attempt to work around a gcc 4.0 bug.
+
+ -- Russ Allbery <rra@stanford.edu> Sun, 14 Aug 2005 22:26:00 -0700
+
+krb5 (1.3.6-4) unstable; urgency=high
+
+ [ Russ Allbery ]
+ * Fix a mistake in variable names that caused the package to be built
+ without optimization.
+ * Allow whitespace before comments in krb5.conf. Thanks, Jeremie
+ Koenig. (Closes: #314609)
+ * GCC 4.0 compile fixes, thanks Daniel Schepler. (Closes: #315618)
+ * Avoid "say yes" in debconf templates. (Closes: #306883)
+ * Update Czech translation, thanks Miroslav Kure.
+ * Update French translation, thanks Christian Perrier. (Closes: #307748)
+ * Update Portuguese (Brazil) translation, thanks André Luís Lopes.
+ * New Vietnamese translation, thanks Clytie Siddall. (Closes: #312172)
+ * Update standards version to 3.6.2 (no changes required).
+ * DAK can now handle not repeating maintainers in uploaders.
+
+ [ Sam Hartman ]
+ * Fix double free in krb5_recvauth; critical because it is in the code
+ path for kpropd and may allow arbitrary code execution.
+ (CAN-2005-1689)
+ * krb5_unparse_name overflows allocated storage by one byte on 0 element
+ principal name. (CAN-2005-1175, VU#885830)
+ * Do not free unallocated storage in the KDC's TCP request handling
+ path. (CAN-2005-1174, VU#259798)
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 12 Jul 2005 15:45:14 -0400
+
+krb5 (1.3.6-3) unstable; urgency=low
+
+ * krb5-kdc: Install a commented-out line for kpropd with update-inetd.
+ Add dependency on netbase for update-inetd. (Closes: #293182)
+ * krb5-kdc: Ask with debconf whether the user wishes to delete the KDC
+ database on purge, modelled after how postgresql handles the same
+ situation. (Closes: #289358)
+ * Close leak in the arcfour crypto support. Thanks, fumihiko kakuma.
+ (Closes: #244595)
+ * krb5-config should never return -I/usr/include. (Closes: #165521)
+ * Write manual pages for fakeka, krb524init, kadmind4, and v5passwdd.
+ Backport from upstream the manual pages for krb5-config and krb524d.
+ (Closes: #78953, #96437)
+ * Fix paths in manual pages to match the Debian defaults. Fix service
+ in the inetd.conf example in the kpropd man page to work with Debian
+ /etc/services. (Closes: #157736)
+ * Fix references to kerberos(1) in the rlogin and kinit man pages and
+ include kerberos.1 in krb5-doc. (Closes: #154381, #154384)
+ * Add more detailed information about each package to the extended
+ descriptions. (Closes: #135517)
+ * krb5-doc: Include info pages. (Closes: #292512)
+ * krb5-doc: Fix two minor variable name problems in the texinfo docs.
+ * Let dh_installdebconf set the debconf dependency.
+ * Update standards version to 3.6.1.
+ - Support noopt in DEB_BUILD_OPTIONS.
+ - Let debhelper take care of calling ldconfig appropriately.
+ - Remove calls to dh_undocumented.
+ - Remove lintian overrides for links to the undocumented man page.
+ - Install kdc.conf template in /usr/share/krb5-kdc rather than
+ /usr/share/krb5 (policy 10.7.3 states the directory should be named
+ after the package).
+ - Symlink the kdc.conf template to /usr/share/doc/krb5-kdc/examples
+ per policy 10.7.3 since it's also a useful example.
+ * Update debhelper compatibility level to V4.
+ - Remove all *.conffiles control files. They're no longer needed.
+ * rules generally cleaned up. Commented out and unused debhelper programs
+ removed as the set being run wasn't comprehensive anyway. Invocation
+ order now matches the debhelper examples.
+ * Removed (s) from copyright to make lintian happier.
+ * Removed unnecessary lintian override for libkrb53.
+ * Add lintian overrides for the duplicate dependencies on krb5 libraries.
+
+ -- Russ Allbery <rra@stanford.edu> Sat, 16 Apr 2005 14:12:08 -0700
+
+krb5 (1.3.6-2) unstable; urgency=high
+
+ * Package priority to standard
+ * Fix buffer overflow in slc_add_reply in telnet.c (CAN-2005-0469)
+ * Fix telnet.c env_opt_add buffer overflow (CAN-2005-0468)
+ * Note that both of these vulnerabilities are client-side
+ vulnerabilities that can be exploited only by a server.
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 3 Apr 2005 23:49:08 -0400
+
+krb5 (1.3.6-1) unstable; urgency=medium
+
+ * New upstream version
+ * Changing a password afwter the size of password history has been
+ reduced may double free or write past end of an arry; fix
+ (CAN-2004-1189 / CERT VU#948033)
+ * Conflict between krb5-kdc and kerberos4kth-kdc; also deals with
+ krb5-admin-server conflict indirectly, Closes: #274763
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 2 Jan 2005 15:55:25 -0500
+
+krb5 (1.3.5-1) unstable; urgency=low
+
+ * New pt_br debconf translation, Cluses: #278734
+ * New upstream version
+ * Part of the fix to #261712: allow ftpd to build on gnu/bsd
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 26 Nov 2004 18:44:02 -0500
+
+krb5 (1.3.4-4) unstable; urgency=high
+
+ * Fix what is hopefully the last remnant of the patch to gettextize the
+ debconf without making the code consistent, thanks Thimo Neubauer,
+ Closes: #271456
+ * Fix krb5_newrealm man page to better describe dependencies, thanks
+ Rachel Elizabeth Dillon , Closes: #269685
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 13 Sep 2004 11:36:38 -0400
+
+krb5 (1.3.4-3) unstable; urgency=high
+
+ * Initial Czech translations thanks to Miroslav Kure, Closes: #264366
+ * Updated French debconf translation, thanks Martin Quinson, Closes: #264941
+ * KDC and clients double-free on error conditions (CAN-2004-0642 VU#795632)
+ *krb5_rd_cred() double-frees on error conditions(CAN-2004-0643 , CERT
+ VU#866472 )
+ * ASN.1 decoder in MIT Kerberos 5 releases krb5-1.3.4 and
+ earlier allows unauthenticated remote attackers to induce
+ infinite loop, causing denial of service, including in KDC
+ code (CAN-2004-0644 , CERT VU#550464)
+ * Fix double free in krb524d handling of encrypted ticket contents
+ (CAN-2004-0772)
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 31 Aug 2004 13:04:51 -0400
+
+krb5 (1.3.4-2) unstable; urgency=low
+
+ * Fix doc-base files, Closes: #262916
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 4 Aug 2004 13:08:53 -0400
+
+krb5 (1.3.4-1) unstable; urgency=low
+
+ * New upstream version
+ * Update krb5-doc to include pointers to the right html documents,
+ Closes: #203321
+ * Patches to find res_search on amd64 and to include new Debian ports in
+ shared library building, Closes: #261712
+ * Install default file for krb5-admin-server, Closes: #262428
+ * Patch from Russ Allbery to only prompt for a password once in krb4
+ when null is passed in to krb_get_in_pw_tkt, Closes: #262192
+ * New pt_br translation, thanks Andre Luis Lopes, Closes: #254115
+ * New French translation, thanks Christian Perrier, closes: #253685
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 31 Jul 2004 12:12:44 -0400
+
+krb5 (1.3.3-2) unstable; urgency=high
+
+ * Fix buffer overflow in krb5_aname_to_localname; potential remote root
+ exploit in some fairly limited circumstances. You are not vulnerable
+ unless you have enabled aname_to_lname rules in krb5.conf (CAN-2004-0523)
+ * Fix kadmind template formatting, thanks Christian Perrier
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 5 Jun 2004 16:57:44 -0400
+
+krb5 (1.3.3-1) unstable; urgency=low
+
+ * New upstream version
+ * Gettextize my debconf templates, thanks Martin Quinson , Closes:
+ #236176
+ * Don't remove /etc/krb5.conf on libkrb53 purge
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 13 Apr 2004 20:04:37 -0400
+
+krb5 (1.3.2-2) unstable; urgency=low
+
+ * Don't check for /etc/krb5kdc/kadm5.keytab, Closes: #235966
+ * Fix dangling symlink, Closes: #203622
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 14 Mar 2004 20:46:27 -0500
+
+krb5 (1.3.2-1) unstable; urgency=low
+
+ * New Upstream Release, Closes: #223485
+ * Includes upstream patch to ignore unknown address families, Closes: #206851
+ * Include note that encrypted services are not enabled, Closes: #232115
+ * Up shlib deps because of new features in auth context
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 29 Feb 2004 09:36:27 -0500
+
+krb5 (1.3-3) unstable; urgency=low
+
+ * Don't clear the key schedule so krb4 callers can use it, Closes: #203566
+ * Use alternatives system for rcp, Closes: #218392
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 3 Feb 2004 14:07:12 -0500
+
+krb5 (1.3-2) unstable; urgency=low
+
+ * Include patch to MIT Bug #1681, an incompatible change to etype_info2.
+ This change will break clients between 1.3 beta1 and 1.3-1 talking to
+ 1.3-2 KDCs, but is necessary because of a protocol bug.
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 24 Jul 2003 13:32:33 -0400
+
+krb5 (1.3-1) unstable; urgency=medium
+
+ * New upstream version--finally 1.3 is released, Closes: #199573
+ * Don't depend on com_err in libcrypto, Closes: #201005
+ * Urgency is medium because the only code change is removing a single
+ call to com_err and this package not being in testing is blocking
+ other packages. The beta has been in unstable more than 10 days.
+ * Update shlibs again to avoid long-term references to a beta in the archive
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 19 Jul 2003 15:19:38 -0400
+
+krb5 (1.2.99-1.3.beta5-1) unstable; urgency=low
+
+ * New upstream version
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 5 Jul 2003 21:29:44 -0400
+
+krb5 (1.2.99-1.3.beta4-1) unstable; urgency=low
+
+ * Fix rpath on generated binaries and in krb5-config, Closes: #198124
+ * Fix build-depends to require comerr-dev with correct shlibs,
+ Closes: #197650
+ * New upstream version
+ * Don't generate /etc/krb5kdc/kadm5.keytab as 1.3 does not require it
+ except for kadmind4
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 20 Jun 2003 17:37:15 -0400
+
+krb5 (1.2.99-1.3.beta3-4) unstable; urgency=low
+
+ * Add replaces for libkadm55 on libkrb53
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 11 Jun 2003 16:41:16 -0400
+
+krb5 (1.2.99-1.3.beta3-3) unstable; urgency=low
+
+ * One more try at avoiding autoconf dependency
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 11 Jun 2003 03:04:56 -0400
+
+krb5 (1.2.99-1.3.beta3-2) unstable; urgency=low
+
+ * Touch some more files to defeat autoheader
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 10 Jun 2003 23:55:08 -0400
+
+krb5 (1.2.99-1.3.beta3-1) unstable; urgency=low
+
+ * Fix dh_makeshlibs call so dependencies are correct
+ * New upstream version
+ * Patch from Steve Langasek for versioned symbols; adapted to
+ better fit the build system and to work for all libraries
+ * This version builds with GCC 3.3, Closes: #195571
+ * Move the rest of the administration libraries into libkadm55 to reduce
+ space required by libkrb53.
+ * libkrb53 conflicts with current openafs-krb5 because of ABI changes in
+ krb524
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 10 Jun 2003 20:56:33 -0400
+
+krb5 (1.2.99-1.3.beta2-1) experimental; urgency=low
+
+ * New upstream version
+ * Include a patch from upstream CVS (post beta2) to fix renewable tickets.
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 1 Jun 2003 00:30:35 -0400
+
+krb5 (1.2.99-1.3.beta1-1) experimental; urgency=low
+
+ * New upstream pre-release
+ * Update copyright
+ * Add db_stop calls to krb5-kdc.postinst and krb5-admin-server.postinst
+ * Install a fakeka binary
+ * Install libkrb524.a even though upstream does not
+ * kdc defaults to no v4 support per upstream change.
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 15 May 2003 11:37:10 -0400
+
+krb5 (1.2.99-1.3.alpha3-1) experimental; urgency=low
+
+ * New upstream pre-release
+ - ftp no longer segfaults on wildcards, Closes: #175495
+ - Clock skew is returned on clock skew with preauth, Closes: #98855
+ - Preauthentication has been reworked to improve interoperability with
+ older implementations and to comply with Kerberos Clarifications,
+ Closes: #169014
+ - Typo in man page fixed, Closes: #127302
+ * Remove dangling symlink, Closes: #133244
+ * Depend on sufficiently new com_err and libss
+ * Build the crypto library -O9 as it seems to help performance a lot.
+ * Bump up shared library versions; all the public libraries have new
+ functions
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 12 May 2003 02:22:37 -0400
+
+krb5 (1.2.7-3) unstable; urgency=high
+
+ * Patch for CERT VU#623217 and VU#442569: Cryptographic weaknesses in
+ Kerberos 4
+ - Add -X option to krb5kdc and krb524d. By default cross-realm is
+ no longer supported for krb4 as it is a security hole.
+ - Add protection to isolate krb5 keys from krb4 especially for the
+ TGS key
+ - Remove support for the MIT extension to krb4 to use 3DES keys as it
+ is insecure.
+ * Patch to various DOS issues where the KDC assumes principal names have
+ certain components. Fixes CAN-2003-0072
+ * VU#516825: Additional errors in XDR that may lead to denial of
+ service.
+ * Fix template bug in v5passwd template, Closes: #172565
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 25 Mar 2003 08:03:00 -0500
+
+krb5 (1.2.7-2) unstable; urgency=low
+
+ * Remove declaration of errno from krb.h
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 6 Jan 2003 15:38:20 -0500
+
+krb5 (1.2.7-1) unstable; urgency=high
+
+ * New upstream version
+ * Still urgency high until the kadmin4 fix gets into testing
+ * Don't declare errno so glibc will be happy; applying upstream as well,
+ Closes :#168528
+ * Remove pidfile argument from start-stop-daemon call for restarting
+ krb5kdc so it actually works, Closes: #174881
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 5 Jan 2003 18:00:55 -0500
+
+krb5 (1.2.6-2) unstable; urgency=high
+
+ * Security fix for buffer overflow in kadmind4 (mitsa-2002-2)
+ * If bison is too good for yacc compatibility then we're to good for
+ bison, Closes: #165655
+ * Include readme.debian if we're going to reference it, Closes: #166399
+ * Fix readme.debian comments to be correct
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 26 Oct 2002 17:18:41 -0400
+
+krb5 (1.2.6-1) unstable; urgency=low
+
+ * New upstream version
+ * Important: upstream has introduced a new way of handling AFS tickets
+ within krb524d; long-term this may allow the use of ticket keys other
+ than DES with AFS, but short-term this will break AFS because OpenAFS
+ has not yet released servers that support the new mechanism. If you
+ run AFS servers and don't want them to break, please look at README.debian
+ * This includes a fix for 162794 as that is now in the upstream
+ * For now, libkrb5-dev is going to be priority extra. If anyone
+ complains I'll attempt to fight the comerr-dev dependency battle;
+ honestly I think comerr-dev is common enough and on enough systems
+ that it rates optional but the maintainer does not, Closes: #145165
+ * Fix restart to restart krb524d, Closes: #162477
+
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 6 Oct 2002 16:40:44 -0400
+
+krb5 (1.2.5-3) unstable; urgency=high
+
+ * Try to fix diversion handling for real this time, Closes: #155514
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 5 Aug 2002 13:40:53 -0400
+
+krb5 (1.2.5-2) unstable; urgency=high
+
+ * We are still installing a krb5.conf.template; don't as that is
+ kerberos-configs's job.
+ * The MIT KDC was not sending etype info padata; this couldcreate a
+ problem if you require preauth and have unusual salts; patch from
+ upstream CVS
+ * Add readme to krb5-user, Closes: #152670
+ * Fix typo in alternatives handling so man page symlinks are handled
+ correctely, Closes: #152707
+ * Include XDR encoding patch for krb5-sa-2002-01; same patch as the
+ woody security update
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 3 Aug 2002 17:51:50 -0400
+
+krb5 (1.2.5-1) unstable; urgency=low
+
+ * New upstream version; not really any patches that will actually
+ affect Debian at all, as we pulled them into 1.2.4 packages from
+ upstream CVS
+ * Stop shipping patches that upstream has accepted and released
+ * Update included upstream PGP signature
+ * Fix diversion handling; it was fairly broken in 1.2.4. All we divert
+ now is rcp
+ * Ftp should not be diverted, closes: #146171
+ * Fix overly small fixed length buffer in kuserok, closes: #145106
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 2 Jun 2002 19:22:39 -0400
+
+krb5 (1.2.4-5) unstable; urgency=low
+
+ * Pull up bugfix from 1.2.5 beta1 to src/lib/krb5/asn.1/asn1_get.c
+ * This should be the last thing we need from 1.2.5; Debian has all the
+ 1.2.5 changes besides the API reorg. I'm not checking an API reorg
+ this close to woody release.
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 12 Apr 2002 12:16:49 -0400
+
+krb5 (1.2.4-4) unstable; urgency=low
+
+ * Suggest rather than recommend krb5-user from libkrb53, closes: #140116
+ * Fix null pointer dereference in krb5 library; pull patch from 1.2.5 beta1
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 10 Apr 2002 14:19:49 -0400
+
+krb5 (1.2.4-3) unstable; urgency=medium
+
+ * Move from non-us to main
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 16 Mar 2002 15:04:44 -0500
+
+krb5 (1.2.4-2) unstable; urgency=low
+
+ * Don't respect umask when writing out srvtabs; you always want them
+ 0600 and if you don't you can chmod later, closes: #135988
+ * To work with Heimdal, accept encrypted creds in
+ gss_accept_sec_context, closes: #135962
+ * Fix kadmin ACL bug. Targets (a cool but undocumented ACL feature)
+ didn't work quite right. They do now.
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 3 Mar 2002 18:53:40 -0500
+
+krb5 (1.2.4-1) unstable; urgency=low
+
+ * Don't check address in krb5_rd_cred; upstream patch also applied to
+ their CVS, closes: #132226
+ * Patch from Ken Raeburn to improve over-the-wire errors from KDC,
+ included because I happened to be testing it and it seemed to work
+ * New upstream release
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 1 Mar 2002 00:44:26 -0500
+
+krb5 (1.2.3-2) unstable; urgency=low
+
+ * We want to be able to use krb4 and libssl's libcrypto in the same
+ program. To do this, we make libkrb4 bind libdes425 -Bsymbolic and we
+ allow krb_mk_priv and krb_rd_priv to take null schedule arguments.
+
+ -- Sam Hartman <hartmans@debian.org> Tue, 15 Jan 2002 12:17:40 -0500
+
+krb5 (1.2.3-1) unstable; urgency=low
+
+ * New upstream version, closes: #110932
+ * Use alternatives for rsh, closes: #122710
+ * Major version of libkadm5 bumped; we no longer conflict with heimdal there
+
+ -- Sam hartman <hartmans@debian.org> Thu, 10 Jan 2002 06:59:13 -0500
+
+krb5 (1.2.2-8) unstable; urgency=low
+
+ * Oops, call htons around port numbers in kprop patch
+ * Register with doc-base, closes: #100463
+ * Move krb5.conf and kdc.conf manpages into krb5-doc; krb5-doc now
+ conflicts with heimdal-docs, closes: #121141
+
+ -- Sam Hartman <hartmans@debian.org> Sun, 25 Nov 2001 23:47:35 -0500
+
+krb5 (1.2.2-7) unstable; urgency=low
+
+ * Forward only tickets we believe the remote side knows the enctype
+ of, closes: #99320
+ * Start krb5-kdc and krb5-admin-server before RPC services, thanks Hein
+ Roehrig, closes: #88604
+ * Install krb5.conf and kdc.conf man pages in krb5-user. This is not
+ ideal but installing them in krb5-config won't work as they are
+ implementation dependent, closes: #109522
+ * Install kprop manpage, thanks Steve Langasek, closes: #120040
+ * Fix FHS paths with kprop; store files in /var/lib/krb5kdc, thanks
+ again Steve, closes: #120050
+ * Telnet help should open a connection to the host help not give you a
+ usage message, thanks Graeme Mathieson <graeme@mathie.cx> for a patch
+ which will be sent upstream, closes: #118730
+ * Fix kprop handling of service name. If we can't find what we are
+ looking for in /etc/services default to the obvious correct answer;
+ thanks Steve, will commit upstream, closes: #120010
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 24 Nov 2001 22:10:16 -0500
+
+krb5 (1.2.2-6) unstable; urgency=high
+
+ * Include telnetd security patch for ring buffer issue from upstream
+ * Conflict with the right Heimdal libs, closes: #103872
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 1 Aug 2001 15:19:43 -0400
+
+krb5 (1.2.2-5) unstable; urgency=low
+
+ * Use krb5-config; remove our own krb5.conf handling.. Note this is the
+ krb5-config package for /etc/krb5.conf, not the krb5-config library
+ helper command.
+ *
+ * Conflict with kerberos4kth-services, closes: #93303
+ * Update config.guess and config.sub, closes: #97585
+ * Have telnetd depend on krb5-rsh-server. I suspect this will make
+ people grumpy and we need a better fix. Really, Kerberized rlogin is
+ better than telnetd from a security standpoint, so I'm OK with it for
+ now. Closes: #96695
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 16 May 2001 17:44:47 -0400
+
+krb5 (1.2.2-4) unstable; urgency=low
+
+ * Fix shared libraries to build with gcc not ld to properly include
+ -lgcc symbols, closes: #94407
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 20 Apr 2001 02:47:21 -0400
+
+krb5 (1.2.2-3) unstable; urgency=high
+
+ * Fix vulnerability with glob call. CERT claims that Linux is not
+ vulnerable, but I believe the krb5 implementation is. The result of
+ glob was copied into a fixed-sized buffer. This fixes that
+ closes: #93689
+ * Provide ftp-server not ftpd, closes: #93531
+ * Do not link kadm5clnt against kdb5.
+
+ -- Sam Hartman <hartmans@debian.org> Wed, 11 Apr 2001 19:50:17 -0400
+
+krb5 (1.2.2-2) unstable; urgency=low
+
+ * Work to provide an alternative for telnet and to be a telnet-client,
+ closes: 87914
+ * libkrb5-dev depends on comerr-dev, closes: #87489
+ * Make clean target remove configure-stamp
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 5 Mar 2001 08:25:17 -0500
+
+krb5 (1.2.2-1) unstable; urgency=low
+
+ * New Upstream version, Closes: #82546
+ * Depend on debconf, closes: #87490
+ * Fix debconf formatting issue, closes: #84447
+ * Create sample ACL file, closes: #84448
+ * Fix lintian warnings and override as appropriate
+ * Upgrade to policy 3.5 moving stuff out of examples.
+
+ -- Sam Hartman <hartmans@debian.org> Fri, 2 Mar 2001 11:32:06 -0500
+
+krb5 (1.2.1-9) unstable; urgency=low
+
+ * Do not use TIOCGLTC anywhere
+ * Build without TCL, closes: #81977
+ * Fix krb5-admin-server restart, closes: #81070
+ * With the new dpkg-source, files get diffed in the wrong order for us
+ to prevent autoconf from getting run just by mangling things and
+ making sure we change every configure script. So, touch every
+ configure script in debian/rules.
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 13 Jan 2001 19:27:37 -0500
+
+krb5 (1.2.1-8) unstable; urgency=low
+
+ * Use separate build directory because the source tree supports it and
+ it works around failures in the upstream clean target, closes: #78954
+ * Make sure we modify all the configure scripts since we modify
+ aclocal.m4 so that time stamps don't cause autoconf to be run.
+ * Add bison and debhelper as build-depends, closes: #79643
+ * New maintainer address
+
+ -- Sam Hartman <hartmans@debian.org> Sat, 23 Dec 2000 16:20:24 -0500
+
+krb5 (1.2.1-7) unstable; urgency=low
+
+ * Do not conflict with libss.a
+ * Upload to Debian(Closes: BUG#78499)
+
+ -- Sam Hartman <hartmans@mit.edu> Mon, 4 Dec 2000 04:15:50 -0500
+
+krb5 (1.2.1-6) unstable; urgency=low
+
+ * Fix kpasswd manpage.
+ * Split out libkadm5 to avoid Heimdal conflict
+
+ * Conflict with kerberos4kth.
+ * Remove runpaths from libs and executables.
+
+ -- Sam Hartman <hartmans@mit.edu> Wed, 29 Nov 2000 12:18:22 -0500
+
+krb5 (1.2.1-5) unstable; urgency=low
+
+ * If libkrb53 was preconfigured, then krb5.conf could overide explicit
+ user input.
+
+ -- Sam Hartman <hartmans@mit.edu> Sat, 25 Nov 2000 17:01:26 -0500
+
+krb5 (1.2.1-4) unstable; urgency=low
+
+ * Write init.d scripts for kdc and admin server.
+ * Ask what admin programs to run and what krb4 mode to use.
+ * Populate initial kdc.conf if needed.
+ * New script (krb5_newrealm) to set up a Kerberos realm
+ * Document KDC issues.
+ * Make libkrb53.config work again so libkrb53 installs
+
+ -- Sam Hartman <hartmans@mit.edu> Sat, 18 Nov 2000 17:22:16 -0500
+
+krb5 (1.2.1-3) unstable; urgency=low
+
+ * Add KDC packages
+ * Install login.krb5 Sadly, it is needed to make forwarded credentials
+ work. This is unfortunate; it is not a good login program.
+
+ -- Sam Hartman <hartmans@mit.edu> Wed, 8 Nov 2000 16:10:13 -0500
+
+krb5 (1.2.1-2) unstable; urgency=low
+
+ * Add copyright and README.debian
+ * Ship kadmin in krb5-user.
+ * Add services to inetd.conf
+ * Add support for generating krb5.conf
+
+ -- Sam Hartman <hartmans@mit.edu> Thu, 2 Nov 2000 17:29:59 -0500
+
+krb5 (1.2.1-1) unstable; urgency=low
+
+ * Initial Release.
+
+ -- Sam Hartman <hartmans@permabit.com> Thu, 19 Oct 2000 16:05:06 -0400
+
+
diff --git a/debian/clean b/debian/clean
new file mode 100644
index 000000000..ae6164249
--- /dev/null
+++ b/debian/clean
@@ -0,0 +1,6 @@
+debian/krb5-kdc.dirs
+debian/krb5-multidev.dirs
+debian/krb5-multidev.links
+debian/krb5-multidev.install
+debian/libkrb5-3.dirs
+debian/libkrb5-dev.dirs
diff --git a/debian/compat b/debian/compat
new file mode 100644
index 000000000..ec635144f
--- /dev/null
+++ b/debian/compat
@@ -0,0 +1 @@
+9
diff --git a/debian/control b/debian/control
new file mode 100644
index 000000000..5ed0886be
--- /dev/null
+++ b/debian/control
@@ -0,0 +1,466 @@
+Source: krb5
+Section: net
+Priority: optional
+Build-Depends: debhelper (>= 10), byacc | bison,
+ comerr-dev, docbook-to-man,
+ libkeyutils-dev [linux-any], libldap2-dev <!stage1>, libsasl2-dev <!stage1>,
+ libncurses5-dev, libssl-dev, ss-dev,
+ libverto-dev (>= 0.2.4), pkg-config
+Build-Depends-Indep: python, python-cheetah, python-lxml, python-sphinx, doxygen, doxygen-latex, texlive-generic-extra
+Standards-Version: 4.1.1
+Maintainer: Sam Hartman <hartmans@debian.org>
+Uploaders: Russ Allbery <rra@debian.org>, Benjamin Kaduk <kaduk@mit.edu>
+Homepage: http://web.mit.edu/kerberos/
+VCS-Git: https://salsa.debian.org/debian/krb5
+VCS-Browser: https://salsa.debian.org/debian/krb5
+
+Package: krb5-user
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}, libkrb5-3 (= ${binary:Version}),
+ krb5-config
+Multi-Arch: foreign
+Conflicts: heimdal-clients
+Suggests: krb5-k5tls
+Description: basic programs to authenticate using MIT Kerberos
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the basic programs to authenticate to MIT Kerberos,
+ change passwords, and talk to the admin server (to create and delete
+ principals, list principals, etc.).
+
+Package: krb5-kdc
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}, libkrb5-3 (= ${binary:Version}),
+ libkadm5srv-mit11,
+ krb5-config, krb5-user, lsb-base (>= 3.0-6), libverto-libev1 | libverto-libevent1,
+ libkdb5-9 (>= 1.13.1+dfsg-1)
+Suggests: krb5-kpropd, krb5-admin-server,
+ krb5-kdc-ldap (= ${binary:Version})
+Multi-Arch: foreign
+Description: MIT Kerberos key server (KDC)
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the Kerberos key server (KDC). The KDC manages all
+ authentication credentials for a Kerberos realm, holds the master keys
+ for the realm, and responds to authentication requests. This package
+ should be installed on both master and slave KDCs.
+
+Package: krb5-kdc-ldap
+Architecture: any
+Build-Profiles: <!stage1>
+Depends: ${misc:Depends}, ${shlibs:Depends}, krb5-kdc (= ${binary:Version})
+Description: MIT Kerberos key server (KDC) LDAP plugin
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the LDAP plugin for the Kerberos key server (KDC)
+ and supporting utilities. This plugin allows the KDC data to be stored
+ in an LDAP server rather than the default local database. It should be
+ installed on both master and slave KDCs that use LDAP as a storage
+ backend.
+
+Package: krb5-admin-server
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}, libkrb5-3 (= ${binary:Version}),
+ krb5-kdc (>= 1.10+dfsg~), lsb-base (>= 3.0-6)
+Multi-Arch: foreign
+Description: MIT Kerberos master server (kadmind)
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the Kerberos master server (kadmind), which handles
+ account creations and deletions, password changes, and other
+ administrative commands via the Kerberos admin protocol. It also
+ contains the command used by the master KDC to propagate its database to
+ slave KDCs. This package is generally only used on the master KDC for a
+ Kerberos realm.
+
+Package: krb5-kpropd
+Architecture: any
+Multi-Arch: foreign
+Depends: ${misc:Depends}, ${shlibs:Depends},
+ krb5-kdc (= ${binary:Version}),
+ lsb-base
+Replaces: krb5-kdc (<< 1.15.1-3~)
+Suggests: openbsd-inetd | inet-superserver
+Description: MIT Kerberos key server (Slave KDC Support)
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the Kerberos slave KDC update server (kpropd). The
+ kpropd command runs on the slave KDC server. It listens for update requests
+ made by the kprop program, and periodically requests incremental updates from
+ the master KDC. This package should be installed on slave KDCs.
+
+Package: krb5-multidev
+Section: libdevel
+Architecture: any
+Depends: ${misc:Depends}, libkrb5-3 (= ${binary:Version}),
+ libk5crypto3 (= ${binary:Version}), libgssapi-krb5-2 (= ${binary:Version}),
+ libgssrpc4 (= ${binary:Version}),
+ libkadm5srv-mit11 (= ${binary:Version}),
+ libkadm5clnt-mit11 (= ${binary:Version}),
+ comerr-dev
+Pre-Depends: ${misc:Pre-Depends}
+Multi-Arch: same
+Suggests: krb5-doc
+Description: development files for MIT Kerberos without Heimdal conflict
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ Most users wishing to build applications against MIT Kerberos should
+ install libkrb5-dev. However, that package conflicts with heimdal-dev.
+ This package installs libraries and headers in /usr/include/mit-krb5 and
+ /usr/lib/mit-krb5 and can be installed along side heimdal-multidev, which
+ provides the same facilities for Heimdal.
+
+Package: libkrb5-dev
+Section: libdevel
+Architecture: any
+Pre-Depends: ${misc:Pre-Depends}
+Depends: ${misc:Depends}, krb5-multidev (= ${binary:Version})
+Replaces: krb5-multidev (<< 1.8+dfsg~alpha1-3)
+Conflicts: heimdal-dev
+Multi-Arch: same
+Suggests: krb5-doc
+Description: headers and development libraries for MIT Kerberos
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the symlinks, headers, and development libraries
+ needed to compile and link programs that use the Kerberos libraries.
+
+Package: libkrb5-dbg
+Architecture: any
+Depends: ${misc:Depends}, libkrb5-3 (= ${binary:Version})
+ | libk5crypto3 (= ${binary:Version})
+ | libkrb5support0 (= ${binary:Version})
+Section: debug
+Multi-Arch: same
+Description: debugging files for MIT Kerberos
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the debugging information for the MIT Kerberos
+ libraries. Install this package if you need to trace problems inside the
+ MIT Kerberos libraries with a debugger.
+
+Package: krb5-pkinit
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}, libkrb5-3 (= ${binary:Version})
+Breaks: krb5-kdc (<< 1.14+dfsg)
+Suggests: opensc
+Multi-Arch: same
+Description: PKINIT plugin for MIT Kerberos
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains a plugin for the PKINIT protocol, which allows
+ Kerberos tickets to be obtained using public-key credentials such as
+ X.509 certificates or a smart card. This plugin can be used by the
+ client libraries and the KDC.
+
+Package: krb5-otp
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}, libkrad0 (= ${binary:Version}),
+ libkrb5-3 (>= 1.12~alpha1+dfsg-1~)
+Multi-Arch: same
+Description: OTP plugin for MIT Kerberos
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains a plugin for the OTP preauthentication method
+ (RFC 6560), which allows Kerberos tickets to be obtained using
+ One-Time Password authentication. This plugin is for use on the KDC; the
+ client support is built in to libkrb5.
+
+Package: krb5-k5tls
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}, libkrb5-3 (>= 1.13~alpha1+dfsg~)
+Multi-Arch: same
+Description: TLS plugin for MIT Kerberos
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains a plugin for the TLS functionality used by optional
+ functionality in MIT Kerberos. The only current consumer is client support
+ for the MS-KKDCP protocol, which tunnels Kerberos protocol traffic through
+ an HTTPS proxy.
+
+Package: krb5-doc
+Architecture: all
+Conflicts: heimdal-docs
+Section: doc
+Depends: ${misc:Depends}
+Description: documentation for MIT Kerberos
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the installation, administrator, and user reference
+ manuals for MIT Kerberos and the man pages for the MIT Kerberos
+ configuration files.
+
+Package: libkrb5-3
+Section: libs
+Breaks: sssd (<= 1.2.1-4.3), libsmbclient (<= 2:3.6.1-2)
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends},
+ libkrb5support0 (= ${binary:Version})
+Suggests: krb5-doc, krb5-user
+Recommends: krb5-locales
+Multi-Arch: same
+Pre-Depends: ${misc:Pre-Depends}
+Description: MIT Kerberos runtime libraries
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the runtime library for the main Kerberos v5 API
+ used by applications and Kerberos clients.
+
+Package: libgssapi-krb5-2
+Section: libs
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}, libkrb5-3 (= ${binary:Version})
+Breaks: moonshot-gss-eap (<= 1.0)
+Suggests: krb5-doc, krb5-user
+Multi-Arch: same
+Pre-Depends: ${misc:Pre-Depends}
+Description: MIT Kerberos runtime libraries - krb5 GSS-API Mechanism
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the runtime library for the MIT Kerberos
+ implementation of GSS-API used by applications and Kerberos clients.
+
+Package: libgssrpc4
+Section: libs
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}
+Suggests: krb5-doc, krb5-user
+Multi-Arch: same
+Pre-Depends: ${misc:Pre-Depends}
+Description: MIT Kerberos runtime libraries - GSS enabled ONCRPC
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains an RPC library used by the Kerberos administrative
+ programs and potentially other applications.
+
+Package: libkadm5srv-mit11
+Conflicts: libkdb5-8
+Section: libs
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}
+Suggests: krb5-doc, krb5-user
+Multi-Arch: same
+Pre-Depends: ${misc:Pre-Depends}
+Description: MIT Kerberos runtime libraries - KDC and Admin Server
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the runtime library used by Kerberos administrative
+ servers.
+
+Package: libkadm5clnt-mit11
+Section: libs
+Architecture: any
+Conflicts: libkdb5-8
+Depends: ${misc:Depends}, ${shlibs:Depends}
+Suggests: krb5-doc, krb5-user
+Multi-Arch: same
+Pre-Depends: ${misc:Pre-Depends}
+Description: MIT Kerberos runtime libraries - Administration Clients
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the runtime library used by clients of the Kerberos
+ administration protocol.
+
+Package: libk5crypto3
+Section: libs
+Breaks: libkrb5-3 (<= 1.8~aa), libgssapi-krb5-2 (<= 1.10+dfsg~alpha1)
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}
+Suggests: krb5-doc, krb5-user
+Multi-Arch: same
+Pre-Depends: ${misc:Pre-Depends}
+Description: MIT Kerberos runtime libraries - Crypto Library
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the runtime cryptography libraries used by
+ applications and Kerberos clients.
+
+Package: libkdb5-9
+Section: libs
+Breaks: libkadm5srv-mit8 (<< 1.11+dfsg~), krb5-kdc (= 1.13~alpha1+dfsg-1)
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}
+Suggests: krb5-doc, krb5-user
+Multi-Arch: same
+Pre-Depends: ${misc:Pre-Depends}
+Description: MIT Kerberos runtime libraries - Kerberos database
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the internal Kerberos database libraries.
+
+Package: libkrb5support0
+Section: libs
+Breaks: libgssapi-krb5-2 (<< 1.13~alpha1-1),
+ libkadm5srv-mit9 (<< 1.13~alpha1-1), libkadm5clnt-mit9 (<< 1.13~alpha1-1),
+ libk5crypto3 (<< 1.16), libkdb5-8 (<< 1.16)
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}
+Multi-Arch: same
+Pre-Depends: ${misc:Pre-Depends}
+Description: MIT Kerberos runtime libraries - Support library
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains an internal runtime support library used by other
+ Kerberos libraries.
+
+Package: libkrad0
+Section: libs
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}
+Multi-Arch: same
+Pre-Depends: ${misc:Pre-Depends}
+Description: MIT Kerberos runtime libraries - RADIUS library
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains the internal support library for RADIUS functionality.
+
+Package: krb5-gss-samples
+Section: net
+Architecture: any
+Depends: ${misc:Depends}, ${shlibs:Depends}
+Description: MIT Kerberos GSS Sample applications
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains bgss-sample and gss-server, programs used to
+ test GSS-API mechanisms. These programs are most commonly used in
+ testing newly developed GSS-API mechanisms or in testing events
+ between Kerberos or GSS implementations.
+
+Package: krb5-locales
+Section: localization
+Architecture: all
+Depends: ${misc:Depends}, ${shlibs:Depends},
+Pre-Depends: ${misc:Pre-Depends}
+Multi-Arch: foreign
+Description: internationalization support for MIT Kerberos
+ Kerberos is a system for authenticating users and services on a network.
+ Kerberos is a trusted third-party service. That means that there is a
+ third party (the Kerberos server) that is trusted by all the entities on
+ the network (users and services, usually called "principals").
+ .
+ This is the MIT reference implementation of Kerberos V5.
+ .
+ This package contains internationalized messages for MIT Kerberos.
+
+Package: libkrad-dev
+Section: libdevel
+Architecture: any
+Depends: ${misc:Depends}, libkrad0 (= ${binary:Version}),
+ comerr-dev, libverto-dev (>= 0.2.4)
+Suggests: libkrb5-dev
+Replaces: libkrb5-dev (<< 1.12+dfsg-2)
+Breaks: krb5-multidev (<<1.12+dfsg-2), libkrb5-dev (<<1.12+dfsg-2)
+Description: MIT Kerberos RADIUS Library Development
+ This package includes development headers for libkrad0, the MIT
+ Kerberos RADIUS library. You should not use this RADIUS library in
+ packages unrelated to MIT Kerberos.
diff --git a/debian/copyright b/debian/copyright
new file mode 100644
index 000000000..a36e7d2e5
--- /dev/null
+++ b/debian/copyright
@@ -0,0 +1,1338 @@
+This package was debianized by Sam Hartman <hartmans@permabit.com> on
+Thu, 19 Oct 2000 16:05:06 -0400.
+
+It was downloaded from:
+
+ <http://web.mit.edu/kerberos/>
+
+Upstream Maintainers:
+
+ MIT Kerberos Team <krbdev@mit.edu>
+
+Copyright:
+
+Copyright (C) 1985-2018 by the Massachusetts Institute of Technology.
+
+All rights reserved.
+
+Redistribution and use in source and binary forms, with or without
+modification, are permitted provided that the following conditions are
+met:
+
+* Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+* Redistributions in binary form must reproduce the above copyright
+ notice, this list of conditions and the following disclaimer in the
+ documentation and/or other materials provided with the distribution.
+
+THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
+A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
+HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
+DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
+THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
+OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+
+Downloading of this software may constitute an export of cryptographic
+software from the United States of America that is subject to the
+United States Export Administration Regulations (EAR), 15 CFR 730-774.
+Additional laws or regulations may apply. It is the responsibility of
+the person or entity contemplating export to comply with all
+applicable export laws and regulations, including obtaining any
+required license from the U.S. government.
+
+The U.S. government prohibits export of encryption source code to
+certain countries and individuals, including, but not limited to, the
+countries of Cuba, Iran, North Korea, Sudan, Syria, and residents and
+nationals of those countries.
+
+Documentation components of this software distribution are licensed
+under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
+(http://creativecommons.org/licenses/by-sa/3.0/)
+
+Individual source code files are copyright MIT, Cygnus Support,
+Novell, OpenVision Technologies, Oracle, Red Hat, Sun Microsystems,
+FundsXpress, and others.
+
+Project Athena, Athena, Athena MUSE, Discuss, Hesiod, Kerberos, Moira,
+and Zephyr are trademarks of the Massachusetts Institute of Technology
+(MIT). No commercial use of these trademarks may be made without
+prior written permission of MIT.
+
+"Commercial use" means use of a name in a product or other for-profit
+manner. It does NOT prevent a commercial firm from referring to the
+MIT trademarks in order to convey information (although in doing so,
+recognition of their trademark status should be given).
+
+======================================================================
+
+The following copyright and permission notice applies to the
+OpenVision Kerberos Administration system located in "kadmin/create",
+"kadmin/dbutil", "kadmin/passwd", "kadmin/server", "lib/kadm5", and
+portions of "lib/rpc":
+
+ Copyright, OpenVision Technologies, Inc., 1993-1996, All Rights
+ Reserved
+
+ WARNING: Retrieving the OpenVision Kerberos Administration system
+ source code, as described below, indicates your acceptance of the
+ following terms. If you do not agree to the following terms, do
+ not retrieve the OpenVision Kerberos administration system.
+
+ You may freely use and distribute the Source Code and Object Code
+ compiled from it, with or without modification, but this Source
+ Code is provided to you "AS IS" EXCLUSIVE OF ANY WARRANTY,
+ INCLUDING, WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY OR
+ FITNESS FOR A PARTICULAR PURPOSE, OR ANY OTHER WARRANTY, WHETHER
+ EXPRESS OR IMPLIED. IN NO EVENT WILL OPENVISION HAVE ANY LIABILITY
+ FOR ANY LOST PROFITS, LOSS OF DATA OR COSTS OF PROCUREMENT OF
+ SUBSTITUTE GOODS OR SERVICES, OR FOR ANY SPECIAL, INDIRECT, OR
+ CONSEQUENTIAL DAMAGES ARISING OUT OF THIS AGREEMENT, INCLUDING,
+ WITHOUT LIMITATION, THOSE RESULTING FROM THE USE OF THE SOURCE
+ CODE, OR THE FAILURE OF THE SOURCE CODE TO PERFORM, OR FOR ANY
+ OTHER REASON.
+
+ OpenVision retains all copyrights in the donated Source Code.
+ OpenVision also retains copyright to derivative works of the Source
+ Code, whether created by OpenVision or by a third party. The
+ OpenVision copyright notice must be preserved if derivative works
+ are made based on the donated Source Code.
+
+ OpenVision Technologies, Inc. has donated this Kerberos
+ Administration system to MIT for inclusion in the standard Kerberos
+ 5 distribution. This donation underscores our commitment to
+ continuing Kerberos technology development and our gratitude for
+ the valuable work which has been performed by MIT and the Kerberos
+ community.
+
+======================================================================
+
+ Portions contributed by Matt Crawford "crawdad@fnal.gov" were work
+ performed at Fermi National Accelerator Laboratory, which is
+ operated by Universities Research Association, Inc., under contract
+ DE-AC02-76CHO3000 with the U.S. Department of Energy.
+
+======================================================================
+
+Portions of "src/lib/crypto" have the following copyright:
+
+ Copyright (C) 1998 by the FundsXpress, INC.
+
+ All rights reserved.
+
+ Export of this software from the United States of America may
+ require a specific license from the United States Government.
+ It is the responsibility of any person or organization
+ contemplating export to obtain such a license before exporting.
+
+ WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
+ distribute this software and its documentation for any purpose and
+ without fee is hereby granted, provided that the above copyright
+ notice appear in all copies and that both that copyright notice and
+ this permission notice appear in supporting documentation, and that
+ the name of FundsXpress. not be used in advertising or publicity
+ pertaining to distribution of the software without specific,
+ written prior permission. FundsXpress makes no representations
+ about the suitability of this software for any purpose. It is
+ provided "as is" without express or implied warranty.
+
+ THIS SOFTWARE IS PROVIDED "AS IS" AND WITHOUT ANY EXPRESS OR
+ IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED
+ WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE.
+
+======================================================================
+
+The implementation of the AES encryption algorithm in
+"src/lib/crypto/builtin/aes" has the following copyright:
+
+ Copyright (C) 2001, Dr Brian Gladman "brg@gladman.uk.net", Worcester, UK.
+ All rights reserved.
+
+ LICENSE TERMS
+
+ The free distribution and use of this software in both source and
+ binary form is allowed (with or without changes) provided that:
+
+ 1. distributions of this source code include the above copyright
+ notice, this list of conditions and the following disclaimer;
+
+ 2. distributions in binary form include the above copyright notice,
+ this list of conditions and the following disclaimer in the
+ documentation and/or other associated materials;
+
+ 3. the copyright holder's name is not used to endorse products
+ built using this software without specific written permission.
+
+ DISCLAIMER
+
+ This software is provided 'as is' with no explcit or implied
+ warranties in respect of any properties, including, but not limited
+ to, correctness and fitness for purpose.
+
+======================================================================
+
+Portions contributed by Red Hat, including the pre-authentication
+plug-in framework and the NSS crypto implementation, contain the
+following copyright:
+
+ Copyright (C) 2006 Red Hat, Inc.
+ Portions copyright (C) 2006 Massachusetts Institute of Technology
+ All Rights Reserved.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ * Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ * Redistributions in binary form must reproduce the above copyright
+ notice, this list of conditions and the following disclaimer in
+ the documentation and/or other materials provided with the
+ distribution.
+
+ * Neither the name of Red Hat, Inc., nor the names of its
+ contributors may be used to endorse or promote products derived
+ from this software without specific prior written permission.
+
+ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
+ FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
+ COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
+ INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
+ (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
+ SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+ HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
+ STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+ ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
+ OF THE POSSIBILITY OF SUCH DAMAGE.
+
+======================================================================
+
+The bundled verto source code is subject to the following license:
+
+ Copyright 2011 Red Hat, Inc.
+
+ Permission is hereby granted, free of charge, to any person
+ obtaining a copy of this software and associated documentation
+ files (the "Software"), to deal in the Software without
+ restriction, including without limitation the rights to use, copy,
+ modify, merge, publish, distribute, sublicense, and/or sell copies
+ of the Software, and to permit persons to whom the Software is
+ furnished to do so, subject to the following conditions:
+
+ The above copyright notice and this permission notice shall be
+ included in all copies or substantial portions of the Software.
+
+ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
+ EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
+ MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
+ NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
+ HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
+ WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+ OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
+ DEALINGS IN THE SOFTWARE.
+
+======================================================================
+
+The MS-KKDCP client implementation has the following copyright:
+
+ Copyright 2013,2014 Red Hat, Inc.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ 1. Redistributions of source code must retain the above
+ copyright notice, this list of conditions and the following
+ disclaimer.
+
+ 2. Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials
+ provided with the distribution.
+
+ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
+ FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
+ COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
+ INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
+ (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
+ SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+ HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
+ STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+ ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
+ OF THE POSSIBILITY OF SUCH DAMAGE.
+
+======================================================================
+
+The implementations of GSSAPI mechglue in GSSAPI-SPNEGO in
+"src/lib/gssapi", including the following files:
+
+ lib/gssapi/generic/gssapi_err_generic.et
+ lib/gssapi/mechglue/g_accept_sec_context.c
+ lib/gssapi/mechglue/g_acquire_cred.c
+ lib/gssapi/mechglue/g_canon_name.c
+ lib/gssapi/mechglue/g_compare_name.c
+ lib/gssapi/mechglue/g_context_time.c
+ lib/gssapi/mechglue/g_delete_sec_context.c
+ lib/gssapi/mechglue/g_dsp_name.c
+ lib/gssapi/mechglue/g_dsp_status.c
+ lib/gssapi/mechglue/g_dup_name.c
+ lib/gssapi/mechglue/g_exp_sec_context.c
+ lib/gssapi/mechglue/g_export_name.c
+ lib/gssapi/mechglue/g_glue.c
+ lib/gssapi/mechglue/g_imp_name.c
+ lib/gssapi/mechglue/g_imp_sec_context.c
+ lib/gssapi/mechglue/g_init_sec_context.c
+ lib/gssapi/mechglue/g_initialize.c
+ lib/gssapi/mechglue/g_inquire_context.c
+ lib/gssapi/mechglue/g_inquire_cred.c
+ lib/gssapi/mechglue/g_inquire_names.c
+ lib/gssapi/mechglue/g_process_context.c
+ lib/gssapi/mechglue/g_rel_buffer.c
+ lib/gssapi/mechglue/g_rel_cred.c
+ lib/gssapi/mechglue/g_rel_name.c
+ lib/gssapi/mechglue/g_rel_oid_set.c
+ lib/gssapi/mechglue/g_seal.c
+ lib/gssapi/mechglue/g_sign.c
+ lib/gssapi/mechglue/g_store_cred.c
+ lib/gssapi/mechglue/g_unseal.c
+ lib/gssapi/mechglue/g_userok.c
+ lib/gssapi/mechglue/g_utils.c
+ lib/gssapi/mechglue/g_verify.c
+ lib/gssapi/mechglue/gssd_pname_to_uid.c
+ lib/gssapi/mechglue/mglueP.h
+ lib/gssapi/mechglue/oid_ops.c
+ lib/gssapi/spnego/gssapiP_spnego.h
+ lib/gssapi/spnego/spnego_mech.c
+
+and the initial implementation of incremental propagation, including
+the following new or changed files:
+
+ include/iprop_hdr.h
+ kadmin/server/ipropd_svc.c
+ lib/kdb/iprop.x
+ lib/kdb/kdb_convert.c
+ lib/kdb/kdb_log.c
+ lib/kdb/kdb_log.h
+ lib/krb5/error_tables/kdb5_err.et
+ slave/kpropd_rpc.c
+ slave/kproplog.c
+
+are subject to the following license:
+
+ Copyright (C) 2004 Sun Microsystems, Inc.
+
+ Permission is hereby granted, free of charge, to any person
+ obtaining a copy of this software and associated documentation
+ files (the "Software"), to deal in the Software without
+ restriction, including without limitation the rights to use, copy,
+ modify, merge, publish, distribute, sublicense, and/or sell copies
+ of the Software, and to permit persons to whom the Software is
+ furnished to do so, subject to the following conditions:
+
+ The above copyright notice and this permission notice shall be
+ included in all copies or substantial portions of the Software.
+
+ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
+ EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
+ MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
+ NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
+ BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
+ ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
+ CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+ SOFTWARE.
+
+======================================================================
+
+Kerberos V5 includes documentation and software developed at the
+University of California at Berkeley, which includes this copyright
+notice:
+
+ Copyright (C) 1983 Regents of the University of California.
+ All rights reserved.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ 1. Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ 2. Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials provided
+ with the distribution.
+
+ 3. Neither the name of the University nor the names of its
+ contributors may be used to endorse or promote products derived
+ from this software without specific prior written permission.
+
+ THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS "AS IS"
+ AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
+ TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
+ PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS
+ OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+ SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+ LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
+ USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
+ ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
+ OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
+ OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
+ SUCH DAMAGE.
+
+======================================================================
+
+Portions contributed by Novell, Inc., including the LDAP database
+backend, are subject to the following license:
+
+ Copyright (C) 2004-2005, Novell, Inc.
+ All rights reserved.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ * Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ * Redistributions in binary form must reproduce the above copyright
+ notice, this list of conditions and the following disclaimer in
+ the documentation and/or other materials provided with the
+ distribution.
+
+ * The copyright holder's name is not used to endorse or promote
+ products derived from this software without specific prior
+ written permission.
+
+ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
+ FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
+ COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
+ INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
+ (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
+ SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+ HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
+ STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+ ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
+ OF THE POSSIBILITY OF SUCH DAMAGE.
+
+======================================================================
+
+Portions funded by Sandia National Laboratory and developed by the
+University of Michigan's Center for Information Technology
+Integration, including the PKINIT implementation, are subject to the
+following license:
+
+ COPYRIGHT (C) 2006-2007
+ THE REGENTS OF THE UNIVERSITY OF MICHIGAN
+ ALL RIGHTS RESERVED
+
+ Permission is granted to use, copy, create derivative works and
+ redistribute this software and such derivative works for any
+ purpose, so long as the name of The University of Michigan is not
+ used in any advertising or publicity pertaining to the use of
+ distribution of this software without specific, written prior
+ authorization. If the above copyright notice or any other
+ identification of the University of Michigan is included in any
+ copy of any portion of this software, then the disclaimer below
+ must also be included.
+
+ THIS SOFTWARE IS PROVIDED AS IS, WITHOUT REPRESENTATION FROM THE
+ UNIVERSITY OF MICHIGAN AS TO ITS FITNESS FOR ANY PURPOSE, AND
+ WITHOUT WARRANTY BY THE UNIVERSITY OF MICHIGAN OF ANY KIND, EITHER
+ EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION THE IMPLIED
+ WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
+ THE REGENTS OF THE UNIVERSITY OF MICHIGAN SHALL NOT BE LIABLE FOR
+ ANY DAMAGES, INCLUDING SPECIAL, INDIRECT, INCIDENTAL, OR
+ CONSEQUENTIAL DAMAGES, WITH RESPECT TO ANY CLAIM ARISING OUT OF OR
+ IN CONNECTION WITH THE USE OF THE SOFTWARE, EVEN IF IT HAS BEEN OR
+ IS HEREAFTER ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
+
+======================================================================
+
+The pkcs11.h file included in the PKINIT code has the following
+license:
+
+ Copyright 2006 g10 Code GmbH
+ Copyright 2006 Andreas Jellinghaus
+
+ This file is free software; as a special exception the author gives
+ unlimited permission to copy and/or distribute it, with or without
+ modifications, as long as this notice is preserved.
+
+ This file is distributed in the hope that it will be useful, but
+ WITHOUT ANY WARRANTY, to the extent permitted by law; without even
+ the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR
+ PURPOSE.
+
+======================================================================
+
+Portions contributed by Apple Inc. are subject to the following
+license:
+
+ Copyright 2004-2008 Apple Inc. All Rights Reserved.
+
+ Export of this software from the United States of America may
+ require a specific license from the United States Government.
+ It is the responsibility of any person or organization
+ contemplating export to obtain such a license before exporting.
+
+ WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
+ distribute this software and its documentation for any purpose and
+ without fee is hereby granted, provided that the above copyright
+ notice appear in all copies and that both that copyright notice and
+ this permission notice appear in supporting documentation, and that
+ the name of Apple Inc. not be used in advertising or publicity
+ pertaining to distribution of the software without specific,
+ written prior permission. Apple Inc. makes no representations
+ about the suitability of this software for any purpose. It is
+ provided "as is" without express or implied warranty.
+
+ THIS SOFTWARE IS PROVIDED "AS IS" AND WITHOUT ANY EXPRESS OR
+ IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED
+ WARRANTIES OF MERCHANTIBILITY AND FITNESS FOR A PARTICULAR PURPOSE.
+
+======================================================================
+
+The implementations of UTF-8 string handling in src/util/support and
+src/lib/krb5/unicode are subject to the following copyright and
+permission notice:
+
+ The OpenLDAP Public License
+ Version 2.8, 17 August 2003
+
+ Redistribution and use of this software and associated
+ documentation ("Software"), with or without modification, are
+ permitted provided that the following conditions are met:
+
+ 1. Redistributions in source form must retain copyright statements
+ and notices,
+
+ 2. Redistributions in binary form must reproduce applicable
+ copyright statements and notices, this list of conditions, and
+ the following disclaimer in the documentation and/or other
+ materials provided with the distribution, and
+
+ 3. Redistributions must contain a verbatim copy of this document.
+
+ The OpenLDAP Foundation may revise this license from time to time.
+ Each revision is distinguished by a version number. You may use
+ this Software under terms of this license revision or under the
+ terms of any subsequent revision of the license.
+
+ THIS SOFTWARE IS PROVIDED BY THE OPENLDAP FOUNDATION AND ITS
+ CONTRIBUTORS "AS IS" AND ANY EXPRESSED OR IMPLIED WARRANTIES,
+ INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
+ MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
+ DISCLAIMED. IN NO EVENT SHALL THE OPENLDAP FOUNDATION, ITS
+ CONTRIBUTORS, OR THE AUTHOR(S) OR OWNER(S) OF THE SOFTWARE BE
+ LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
+ CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT
+ OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
+ BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
+ LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
+ USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH
+ DAMAGE.
+
+ The names of the authors and copyright holders must not be used in
+ advertising or otherwise to promote the sale, use or other dealing
+ in this Software without specific, written prior permission. Title
+ to copyright in this Software shall at all times remain with
+ copyright holders.
+
+ OpenLDAP is a registered trademark of the OpenLDAP Foundation.
+
+ Copyright 1999-2003 The OpenLDAP Foundation, Redwood City,
+ California, USA. All Rights Reserved. Permission to copy and
+ distribute verbatim copies of this document is granted.
+
+======================================================================
+
+Marked test programs in src/lib/krb5/krb have the following copyright:
+
+ Copyright (C) 2006 Kungliga Tekniska Högskola
+ (Royal Institute of Technology, Stockholm, Sweden).
+ All rights reserved.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ 1. Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ 2. Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials provided
+ with the distribution.
+
+ 3. Neither the name of KTH nor the names of its contributors may be
+ used to endorse or promote products derived from this software
+ without specific prior written permission.
+
+ THIS SOFTWARE IS PROVIDED BY KTH AND ITS CONTRIBUTORS "AS IS" AND
+ ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
+ THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
+ PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL KTH OR ITS
+ CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+ SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+ LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
+ USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
+ ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
+ OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
+ OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
+ SUCH DAMAGE.
+
+======================================================================
+
+The KCM Mach RPC definition file used on OS X has the following
+copyright:
+
+ Copyright (C) 2009 Kungliga Tekniska Högskola
+ (Royal Institute of Technology, Stockholm, Sweden).
+ All rights reserved.
+
+ Portions Copyright (C) 2009 Apple Inc. All rights reserved.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ 1. Redistributions of source code must retain the above
+ copyright notice, this list of conditions and the following
+ disclaimer.
+
+ 2. Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials provided
+ with the distribution.
+
+ 3. Neither the name of the Institute nor the names of its
+ contributors may be used to endorse or promote products derived
+ from this software without specific prior written permission.
+
+ THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS "AS IS"
+ AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
+ TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
+ PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE INSTITUTE
+ OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+ SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+ LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
+ USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
+ ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
+ OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
+ OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
+ SUCH DAMAGE.
+
+======================================================================
+
+Portions of the RPC implementation in src/lib/rpc and
+src/include/gssrpc have the following copyright and permission notice:
+
+ Copyright (C) 2010, Oracle America, Inc.
+
+ All rights reserved.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ 1. Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ 2. Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials provided
+ with the distribution.
+
+ 3. Neither the name of the "Oracle America, Inc." nor the names of
+ its contributors may be used to endorse or promote products
+ derived from this software without specific prior written
+ permission.
+
+ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
+ FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
+ COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
+ INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
+ (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
+ SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+ HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
+ STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+ ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
+ OF THE POSSIBILITY OF SUCH DAMAGE.
+
+======================================================================
+
+ Copyright (C) 2006,2007,2009 NTT (Nippon Telegraph and Telephone
+ Corporation). All rights reserved.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ 1. Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer as
+ the first lines of this file unmodified.
+
+ 2. Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials provided
+ with the distribution.
+
+ THIS SOFTWARE IS PROVIDED BY NTT "AS IS" AND ANY EXPRESS OR IMPLIED
+ WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
+ OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
+ DISCLAIMED. IN NO EVENT SHALL NTT BE LIABLE FOR ANY DIRECT,
+ INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
+ (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
+ SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+ HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
+ STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+ ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
+ OF THE POSSIBILITY OF SUCH DAMAGE.
+
+======================================================================
+
+ Copyright 2000 by Carnegie Mellon University
+
+ All Rights Reserved
+
+ Permission to use, copy, modify, and distribute this software and
+ its documentation for any purpose and without fee is hereby
+ granted, provided that the above copyright notice appear in all
+ copies and that both that copyright notice and this permission
+ notice appear in supporting documentation, and that the name of
+ Carnegie Mellon University not be used in advertising or publicity
+ pertaining to distribution of the software without specific,
+ written prior permission.
+
+ CARNEGIE MELLON UNIVERSITY DISCLAIMS ALL WARRANTIES WITH REGARD TO
+ THIS SOFTWARE, INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
+ AND FITNESS, IN NO EVENT SHALL CARNEGIE MELLON UNIVERSITY BE LIABLE
+ FOR ANY SPECIAL, INDIRECT OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
+ WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN
+ AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING
+ OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS
+ SOFTWARE.
+
+======================================================================
+
+ Copyright (C) 2002 Naval Research Laboratory (NRL/CCS)
+
+ Permission to use, copy, modify and distribute this software and
+ its documentation is hereby granted, provided that both the
+ copyright notice and this permission notice appear in all copies of
+ the software, derivative works or modified versions, and any
+ portions thereof.
+
+ NRL ALLOWS FREE USE OF THIS SOFTWARE IN ITS "AS IS" CONDITION AND
+ DISCLAIMS ANY LIABILITY OF ANY KIND FOR ANY DAMAGES WHATSOEVER
+ RESULTING FROM THE USE OF THIS SOFTWARE.
+
+======================================================================
+
+Portions extracted from Internet RFCs have the following copyright
+notice:
+
+ Copyright (C) The Internet Society (2006).
+
+ This document is subject to the rights, licenses and restrictions
+ contained in BCP 78, and except as set forth therein, the authors
+ retain all their rights.
+
+ This document and the information contained herein are provided on
+ an "AS IS" basis and THE CONTRIBUTOR, THE ORGANIZATION HE/SHE
+ REPRESENTS OR IS SPONSORED BY (IF ANY), THE INTERNET SOCIETY AND
+ THE INTERNET ENGINEERING TASK FORCE DISCLAIM ALL WARRANTIES,
+ EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT
+ THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR
+ ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A
+ PARTICULAR PURPOSE.
+
+======================================================================
+
+ Copyright (C) 1991, 1992, 1994 by Cygnus Support.
+
+ Permission to use, copy, modify, and distribute this software and
+ its documentation for any purpose and without fee is hereby
+ granted, provided that the above copyright notice appear in all
+ copies and that both that copyright notice and this permission
+ notice appear in supporting documentation. Cygnus Support makes no
+ representations about the suitability of this software for any
+ purpose. It is provided "as is" without express or implied
+ warranty.
+
+======================================================================
+
+ Copyright (C) 2006 Secure Endpoints Inc.
+
+ Permission is hereby granted, free of charge, to any person
+ obtaining a copy of this software and associated documentation
+ files (the "Software"), to deal in the Software without
+ restriction, including without limitation the rights to use, copy,
+ modify, merge, publish, distribute, sublicense, and/or sell copies
+ of the Software, and to permit persons to whom the Software is
+ furnished to do so, subject to the following conditions:
+
+ The above copyright notice and this permission notice shall be
+ included in all copies or substantial portions of the Software.
+
+ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
+ EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
+ MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
+ NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
+ BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
+ ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
+ CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+ SOFTWARE.
+
+======================================================================
+
+Portions of the implementation of the Fortuna-like PRNG are subject to
+the following notice:
+
+ Copyright (C) 2005 Marko Kreen
+ All rights reserved.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ 1. Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ 2. Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials provided
+ with the distribution.
+
+ THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS "AS IS"
+ AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
+ TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
+ PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR
+ CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+ SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+ LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
+ USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
+ ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
+ OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
+ OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
+ SUCH DAMAGE.
+
+ Copyright (C) 1994 by the University of Southern California
+
+ EXPORT OF THIS SOFTWARE from the United States of America may
+ require a specific license from the United States Government. It
+ is the responsibility of any person or organization
+ contemplating export to obtain such a license before exporting.
+
+ WITHIN THAT CONSTRAINT, permission to copy, modify, and distribute
+ this software and its documentation in source and binary forms is
+ hereby granted, provided that any documentation or other materials
+ related to such distribution or use acknowledge that the software
+ was developed by the University of Southern California.
+
+ DISCLAIMER OF WARRANTY. THIS SOFTWARE IS PROVIDED "AS IS". The
+ University of Southern California MAKES NO REPRESENTATIONS OR
+ WARRANTIES, EXPRESS OR IMPLIED. By way of example, but not
+ limitation, the University of Southern California MAKES NO
+ REPRESENTATIONS OR WARRANTIES OF MERCHANTABILITY OR FITNESS FOR ANY
+ PARTICULAR PURPOSE. The University of Southern California shall not
+ be held liable for any liability nor for any direct, indirect, or
+ consequential damages with respect to any claim by the user or
+ distributor of the ksu software.
+
+======================================================================
+
+ Copyright (C) 1995
+ The President and Fellows of Harvard University
+
+ This code is derived from software contributed to Harvard by Jeremy
+ Rassen.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ 1. Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ 2. Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials provided
+ with the distribution.
+
+ 3. All advertising materials mentioning features or use of this
+ software must display the following acknowledgement:
+
+ This product includes software developed by the University of
+ California, Berkeley and its contributors.
+
+ 4. Neither the name of the University nor the names of its
+ contributors may be used to endorse or promote products derived
+ from this software without specific prior written permission.
+
+ THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS "AS IS"
+ AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
+ TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
+ PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS
+ OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+ SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+ LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
+ USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
+ ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
+ OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
+ OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
+ SUCH DAMAGE.
+
+======================================================================
+
+ Copyright (C) 2008 by the Massachusetts Institute of Technology.
+ Copyright 1995 by Richard P. Basch. All Rights Reserved.
+ Copyright 1995 by Lehman Brothers, Inc. All Rights Reserved.
+
+ Export of this software from the United States of America may
+ require a specific license from the United States Government. It
+ is the responsibility of any person or organization
+ contemplating export to obtain such a license before exporting.
+
+ WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
+ distribute this software and its documentation for any purpose and
+ without fee is hereby granted, provided that the above copyright
+ notice appear in all copies and that both that copyright notice and
+ this permission notice appear in supporting documentation, and that
+ the name of Richard P. Basch, Lehman Brothers and M.I.T. not be
+ used in advertising or publicity pertaining to distribution of the
+ software without specific, written prior permission. Richard P.
+ Basch, Lehman Brothers and M.I.T. make no representations about the
+ suitability of this software for any purpose. It is provided "as
+ is" without express or implied warranty.
+
+======================================================================
+
+The following notice applies to "src/lib/krb5/krb/strptime.c" and
+"src/include/k5-queue.h".
+
+ Copyright (C) 1997, 1998 The NetBSD Foundation, Inc.
+ All rights reserved.
+
+ This code was contributed to The NetBSD Foundation by Klaus Klein.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ 1. Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ 2. Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials provided
+ with the distribution.
+
+ 3. All advertising materials mentioning features or use of this
+ software must display the following acknowledgement:
+
+ This product includes software developed by the NetBSD
+ Foundation, Inc. and its contributors.
+
+ 4. Neither the name of The NetBSD Foundation nor the names of its
+ contributors may be used to endorse or promote products derived
+ from this software without specific prior written permission.
+
+ THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND
+ CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES,
+ INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
+ MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
+ DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS BE
+ LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
+ CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT
+ OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
+ BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
+ LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
+ USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH
+ DAMAGE.
+
+======================================================================
+
+The following notice applies to Unicode library files in
+"src/lib/krb5/unicode":
+
+ Copyright 1997, 1998, 1999 Computing Research Labs,
+ New Mexico State University
+
+ Permission is hereby granted, free of charge, to any person
+ obtaining a copy of this software and associated documentation
+ files (the "Software"), to deal in the Software without
+ restriction, including without limitation the rights to use, copy,
+ modify, merge, publish, distribute, sublicense, and/or sell copies
+ of the Software, and to permit persons to whom the Software is
+ furnished to do so, subject to the following conditions:
+
+ The above copyright notice and this permission notice shall be
+ included in all copies or substantial portions of the Software.
+
+ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
+ EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
+ MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
+ NONINFRINGEMENT. IN NO EVENT SHALL THE COMPUTING RESEARCH LAB OR
+ NEW MEXICO STATE UNIVERSITY BE LIABLE FOR ANY CLAIM, DAMAGES OR
+ OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR
+ OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE
+ OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
+
+======================================================================
+
+The following notice applies to "src/util/support/strlcpy.c":
+
+ Copyright (C) 1998 Todd C. Miller "Todd.Miller@courtesan.com"
+
+ Permission to use, copy, modify, and distribute this software for
+ any purpose with or without fee is hereby granted, provided that
+ the above copyright notice and this permission notice appear in all
+ copies.
+
+ THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL
+ WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED
+ WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE
+ AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR
+ CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS
+ OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT,
+ NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
+ CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
+
+======================================================================
+
+The following notice applies to "src/util/profile/argv_parse.c" and
+"src/util/profile/argv_parse.h":
+
+ Copyright 1999 by Theodore Ts'o.
+
+ Permission to use, copy, modify, and distribute this software for
+ any purpose with or without fee is hereby granted, provided that
+ the above copyright notice and this permission notice appear in all
+ copies. THE SOFTWARE IS PROVIDED "AS IS" AND THEODORE TS'O (THE
+ AUTHOR) DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE,
+ INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN
+ NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,
+ INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER
+ RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
+ OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR
+ IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. (Isn't
+ it sick that the U.S. culture of lawsuit-happy lawyers requires
+ this kind of disclaimer?)
+
+======================================================================
+
+The following notice applies to SWIG-generated code in
+"src/util/profile/profile_tcl.c":
+
+ Copyright (C) 1999-2000, The University of Chicago
+
+ This file may be freely redistributed without license or fee
+ provided this copyright message remains intact.
+
+======================================================================
+
+The following notice applies to portiions of "src/lib/rpc" and
+"src/include/gssrpc":
+
+ Copyright (C) 2000 The Regents of the University of Michigan. All
+ rights reserved.
+
+ Copyright (C) 2000 Dug Song "dugsong@UMICH.EDU". All rights
+ reserved, all wrongs reversed.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ 1. Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ 2. Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials provided
+ with the distribution.
+
+ 3. Neither the name of the University nor the names of its
+ contributors may be used to endorse or promote products derived
+ from this software without specific prior written permission.
+
+ THIS SOFTWARE IS PROVIDED "AS IS" AND ANY EXPRESS OR IMPLIED
+ WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
+ OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
+ DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
+ FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
+ CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT
+ OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
+ BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF
+ LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE
+ USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH
+ DAMAGE.
+
+======================================================================
+
+Implementations of the MD4 algorithm are subject to the following
+notice:
+
+ Copyright (C) 1990, RSA Data Security, Inc. All rights reserved.
+
+ License to copy and use this software is granted provided that it
+ is identified as the "RSA Data Security, Inc. MD4 Message Digest
+ Algorithm" in all material mentioning or referencing this software
+ or this function.
+
+ License is also granted to make and use derivative works provided
+ that such works are identified as "derived from the RSA Data
+ Security, Inc. MD4 Message Digest Algorithm" in all material
+ mentioning or referencing the derived work.
+
+ RSA Data Security, Inc. makes no representations concerning either
+ the merchantability of this software or the suitability of this
+ software for any particular purpose. It is provided "as is"
+ without express or implied warranty of any kind.
+
+ These notices must be retained in any copies of any part of this
+ documentation and/or software.
+
+======================================================================
+
+Implementations of the MD5 algorithm are subject to the following
+notice:
+
+ Copyright (C) 1990, RSA Data Security, Inc. All rights reserved.
+
+ License to copy and use this software is granted provided that it
+ is identified as the "RSA Data Security, Inc. MD5 Message- Digest
+ Algorithm" in all material mentioning or referencing this software
+ or this function.
+
+ License is also granted to make and use derivative works provided
+ that such works are identified as "derived from the RSA Data
+ Security, Inc. MD5 Message-Digest Algorithm" in all material
+ mentioning or referencing the derived work.
+
+ RSA Data Security, Inc. makes no representations concerning either
+ the merchantability of this software or the suitability of this
+ software for any particular purpose. It is provided "as is"
+ without express or implied warranty of any kind.
+
+ These notices must be retained in any copies of any part of this
+ documentation and/or software.
+
+======================================================================
+
+The following notice applies to
+"src/lib/crypto/crypto_tests/t_mddriver.c":
+
+ Copyright (C) 1990-2, RSA Data Security, Inc. Created 1990. All
+ rights reserved.
+
+ RSA Data Security, Inc. makes no representations concerning either
+ the merchantability of this software or the suitability of this
+ software for any particular purpose. It is provided "as is" without
+ express or implied warranty of any kind.
+
+ These notices must be retained in any copies of any part of this
+ documentation and/or software.
+
+======================================================================
+
+Portions of "src/lib/krb5" are subject to the following notice:
+
+ Copyright (C) 1994 CyberSAFE Corporation.
+ Copyright 1990,1991,2007,2008 by the Massachusetts Institute of Technology.
+ All Rights Reserved.
+
+ Export of this software from the United States of America may
+ require a specific license from the United States Government. It
+ is the responsibility of any person or organization
+ contemplating export to obtain such a license before exporting.
+
+ WITHIN THAT CONSTRAINT, permission to use, copy, modify, and
+ distribute this software and its documentation for any purpose and
+ without fee is hereby granted, provided that the above copyright
+ notice appear in all copies and that both that copyright notice and
+ this permission notice appear in supporting documentation, and that
+ the name of M.I.T. not be used in advertising or publicity
+ pertaining to distribution of the software without specific,
+ written prior permission. Furthermore if you modify this software
+ you must label your software as modified software and not
+ distribute it in such a fashion that it might be confused with the
+ original M.I.T. software. Neither M.I.T., the Open Computing
+ Security Group, nor CyberSAFE Corporation make any representations
+ about the suitability of this software for any purpose. It is
+ provided "as is" without express or implied warranty.
+
+======================================================================
+
+Portions contributed by PADL Software are subject to the following
+license:
+
+ Copyright (c) 2011, PADL Software Pty Ltd. All rights reserved.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ 1. Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ 2. Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials provided
+ with the distribution.
+
+ 3. Neither the name of PADL Software nor the names of its
+ contributors may be used to endorse or promote products derived
+ from this software without specific prior written permission.
+
+ THIS SOFTWARE IS PROVIDED BY PADL SOFTWARE AND CONTRIBUTORS "AS IS"
+ AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
+ TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
+ PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL PADL SOFTWARE
+ OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+ SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+ LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
+ USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
+ ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
+ OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
+ OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
+ SUCH DAMAGE.
+
+======================================================================
+
+The bundled libev source code is subject to the following license:
+
+ All files in libev are Copyright (C)2007,2008,2009 Marc Alexander
+ Lehmann.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ * Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ * Redistributions in binary form must reproduce the above copyright
+ notice, this list of conditions and the following disclaimer in
+ the documentation and/or other materials provided with the
+ distribution.
+
+ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
+ FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
+ COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
+ INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
+ (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
+ SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+ HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
+ STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+ ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
+ OF THE POSSIBILITY OF SUCH DAMAGE.
+
+ Alternatively, the contents of this package may be used under the
+ terms of the GNU General Public License ("GPL") version 2 or any
+ later version, in which case the provisions of the GPL are
+ applicable instead of the above. If you wish to allow the use of
+ your version of this package only under the terms of the GPL and
+ not to allow others to use your version of this file under the BSD
+ license, indicate your decision by deleting the provisions above
+ and replace them with the notice and other provisions required by
+ the GPL in this and the other files of this package. If you do not
+ delete the provisions above, a recipient may use your version of
+ this file under either the BSD or the GPL.
+
+ On Debian systems, the complete text of the GNU General Public License
+ version 2 can be found in `/usr/share/common-licenses/GPL-2'.
+
+======================================================================
+
+Files copied from the Intel AESNI Sample Library are subject to the
+following license:
+
+ Copyright (C) 2010, Intel Corporation
+ All rights reserved.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ * Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ * Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials
+ provided with the distribution.
+
+ * Neither the name of Intel Corporation nor the names of its
+ contributors may be used to endorse or promote products
+ derived from this software without specific prior written
+ permission.
+
+ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
+ FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
+ COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
+ INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
+ (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
+ SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+ HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
+ STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+ ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
+ OF THE POSSIBILITY OF SUCH DAMAGE.
+
+======================================================================
+
+The following notice applies to
+"src/ccapi/common/win/OldCC/autolock.hxx":
+
+ Copyright (C) 1998 by Danilo Almeida. All rights reserved.
+
+ Redistribution and use in source and binary forms, with or without
+ modification, are permitted provided that the following conditions
+ are met:
+
+ * Redistributions of source code must retain the above copyright
+ notice, this list of conditions and the following disclaimer.
+
+ * Redistributions in binary form must reproduce the above
+ copyright notice, this list of conditions and the following
+ disclaimer in the documentation and/or other materials provided
+ with the distribution.
+
+ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
+ FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
+ COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT,
+ INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
+ (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
+ SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+ HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
+ STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
+ ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
+ OF THE POSSIBILITY OF SUCH DAMAGE.
+
+======================================================================
+
+The Debian Packaging is licensed under the same terms as MIT Kerberos.
diff --git a/debian/gbp.conf b/debian/gbp.conf
new file mode 100644
index 000000000..6723fcce8
--- /dev/null
+++ b/debian/gbp.conf
@@ -0,0 +1,2 @@
+[DEFAULT]
+pristine-tar=True
diff --git a/debian/kdc.conf b/debian/kdc.conf
new file mode 100644
index 000000000..11565eb36
--- /dev/null
+++ b/debian/kdc.conf
@@ -0,0 +1,16 @@
+[kdcdefaults]
+ kdc_ports = 750,88
+
+[realms]
+ @MYREALM = {
+ database_name = /var/lib/krb5kdc/principal
+ admin_keytab = FILE:/etc/krb5kdc/kadm5.keytab
+ acl_file = /etc/krb5kdc/kadm5.acl
+ key_stash_file = /etc/krb5kdc/stash
+ kdc_ports = 750,88
+ max_life = 10h 0m 0s
+ max_renewable_life = 7d 0h 0m 0s
+ master_key_type = des3-hmac-sha1
+ #supported_enctypes = aes256-cts:normal aes128-cts:normal
+ default_principal_flags = +preauth
+ }
diff --git a/debian/krb5-admin-server.config b/debian/krb5-admin-server.config
new file mode 100644
index 000000000..99e4aaef5
--- /dev/null
+++ b/debian/krb5-admin-server.config
@@ -0,0 +1,10 @@
+#!/bin/sh
+
+set -e
+
+. /usr/share/debconf/confmodule
+db_version 2.0
+
+db_input high krb5-admin-server/newrealm || true
+db_go
+
diff --git a/debian/krb5-admin-server.init b/debian/krb5-admin-server.init
new file mode 100755
index 000000000..29c06c91a
--- /dev/null
+++ b/debian/krb5-admin-server.init
@@ -0,0 +1,124 @@
+#! /bin/sh
+### BEGIN INIT INFO
+# Provides: krb5-admin-server
+# Required-Start: $local_fs $remote_fs $network $syslog
+# Required-Stop: $local_fs $remote_fs $network $syslog
+# Should-Start: krb5-kdc
+# Should-Stop: krb5-kdc
+# Default-Start: 2 3 4 5
+# Default-Stop: 0 1 6
+# Short-Description: MIT Kerberos KDC administrative daemon
+# Description: Starts, stops, or restarts the MIT Kerberos KDC
+# administrative daemon (kadmind). This daemon answers
+# requests from kadmin clients and allows administrators
+# to create, delete, and modify principals in the KDC
+# database.
+### END INIT INFO
+
+# Author: Sam Hartman <hartmans@mit.edu>
+# Author: Russ Allbery <rra@debian.org>
+#
+# Based on the /etc/init.d/skeleton template as found in initscripts version
+# 2.86.ds1-15.
+
+PATH=/usr/sbin:/usr/bin:/sbin:/bin
+DESC="Kerberos administrative servers"
+NAME=kadmind
+DAEMON=/usr/sbin/$NAME
+DAEMON_ARGS=""
+PIDFILE=/var/run/$NAME.pid
+SCRIPTNAME=/etc/init.d/krb5-admin-server
+DEFAULT=/etc/default/krb5-admin-server
+
+# Exit if the package is not installed.
+[ -x "$DAEMON" ] || exit 0
+
+# Read configuration if it is present.
+[ -r "$DEFAULT" ] && . "$DEFAULT"
+
+# Get the setting of VERBOSE and other rcS variables.
+[ -f /etc/default/rcS ] && . /etc/default/rcS
+
+# Define LSB log functions (requires lsb-base >= 3.0-6).
+. /lib/lsb/init-functions
+
+# Return
+# 0 if daemon has been started
+# 1 if daemon was already running
+# 2 if daemon could not be started
+do_start()
+{
+ start-stop-daemon --start --quiet --pidfile $PIDFILE --startas $DAEMON --name $NAME --test \
+ > /dev/null || return 1
+ start-stop-daemon --start --quiet --pidfile $PIDFILE --startas $DAEMON --name $NAME \
+ -- -P $PIDFILE $DAEMON_ARGS || return 2
+}
+
+# Return
+# 0 if daemon has been stopped
+# 1 if daemon was already stopped
+# 2 if daemon could not be stopped
+# other if a failure occurred
+do_stop()
+{
+ start-stop-daemon --stop --quiet --retry=TERM/30/KILL/5 --pidfile $PIDFILE --name $NAME
+ RETVAL="$?"
+ [ "$RETVAL" = 2 ] && return 2
+ rm -f $PIDFILE
+ return "$RETVAL"
+}
+
+
+case "$1" in
+ start)
+ [ "$VERBOSE" != no ] && log_daemon_msg "Starting $DESC" "$NAME"
+ do_start
+ case "$?" in
+ 0|1) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
+ 2) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
+ esac
+ ;;
+
+ stop)
+ [ "$VERBOSE" != no ] && log_daemon_msg "Stopping $DESC" "$NAME"
+ do_stop
+ case "$?" in
+ 0|1) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
+ 2) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
+ esac
+ ;;
+
+ restart|force-reload)
+ if [ "$RUN_KADMIND" = false ] ; then
+ if [ "$VERBOSE" != no ] ; then
+ log_action_msg "Not restarting $DESC per configuration"
+ fi
+ exit 0
+ fi
+ log_daemon_msg "Restarting $DESC" "$NAME"
+ do_stop
+ case "$?" in
+ 0|1)
+ do_start
+ case "$?" in
+ 0) [ "$VERBOSE" != no ] && log_end_msg 0 ;;
+ *) [ "$VERBOSE" != no ] && log_end_msg 1 ;;
+ esac
+ ;;
+ *)
+ log_end_msg 1
+ ;;
+ esac
+ ;;
+
+ status)
+ status_of_proc -p $PIDFILE "$DAEMON" "$NAME" && exit 0 || exit $?
+ ;;
+
+ *)
+ echo "Usage: $SCRIPTNAME {start|stop|restart|force-reload|status}" >&2
+ exit 3
+ ;;
+esac
+
+:
diff --git a/debian/krb5-admin-server.install b/debian/krb5-admin-server.install
new file mode 100644
index 000000000..7fa0385eb
--- /dev/null
+++ b/debian/krb5-admin-server.install
@@ -0,0 +1,7 @@
+usr/sbin/kadmin.local
+usr/share/man/man8/kadmin.local.8
+usr/sbin/kadmind
+usr/share/man/man8/kadmind.8
+usr/sbin/kprop
+usr/share/man/man8/kprop.8
+usr/share/man/man5/kadm5.acl.5
diff --git a/debian/krb5-admin-server.links b/debian/krb5-admin-server.links
new file mode 100644
index 000000000..162d93f9e
--- /dev/null
+++ b/debian/krb5-admin-server.links
@@ -0,0 +1 @@
+usr/share/man/man8/kadmin.8.gz usr/share/man/man8/kadmin.local.8.gz
diff --git a/debian/krb5-admin-server.lintian-overrides b/debian/krb5-admin-server.lintian-overrides
new file mode 100644
index 000000000..543a9d790
--- /dev/null
+++ b/debian/krb5-admin-server.lintian-overrides
@@ -0,0 +1,2 @@
+# lintian gets confused because of the disable call for RUN_KADMIND removal
+krb5-admin-server: duplicate-updaterc.d-calls-in-postinst krb5-admin-server
diff --git a/debian/krb5-admin-server.postinst b/debian/krb5-admin-server.postinst
new file mode 100644
index 000000000..51bb317ce
--- /dev/null
+++ b/debian/krb5-admin-server.postinst
@@ -0,0 +1,15 @@
+#! /bin/sh
+
+set -e
+# This script is really only needed to display the newrealm note.
+
+if [ "configure" = "$1" ] || [ "reconfigure" = "$1" ] ; then
+ . /usr/share/debconf/confmodule
+ db_version 2.0
+
+ db_stop
+fi
+
+#DEBHELPER#
+
+exit 0
diff --git a/debian/krb5-admin-server.postrm b/debian/krb5-admin-server.postrm
new file mode 100644
index 000000000..8b202b3dc
--- /dev/null
+++ b/debian/krb5-admin-server.postrm
@@ -0,0 +1,11 @@
+#! /bin/sh
+
+set -e
+
+case "$1" in
+purge)
+ rm -f /etc/default/krb5-admin-server
+ ;;
+esac
+
+#DEBHELPER#
diff --git a/debian/krb5-admin-server.service b/debian/krb5-admin-server.service
new file mode 100644
index 000000000..799ad155a
--- /dev/null
+++ b/debian/krb5-admin-server.service
@@ -0,0 +1,16 @@
+[Unit]
+Description=Kerberos 5 Admin Server
+
+
+[Service]
+Type=simple
+ExecStart=/usr/sbin/kadmind -nofork $DAEMON_ARGS
+EnvironmentFile=-/etc/default/krb5-admin-server
+InaccessibleDirectories=-/etc/ssh -/etc/ssl/private /root
+ReadOnlyDirectories=/
+ReadWriteDirectories=-/var/tmp /tmp /var/lib/krb5kdc -/var/run /run
+CapabilityBoundingSet=CAP_NET_BIND_SERVICE
+Restart=on-abnormal
+
+[Install]
+WantedBy=multi-user.target
diff --git a/debian/krb5-admin-server.templates b/debian/krb5-admin-server.templates
new file mode 100644
index 000000000..1b40a8e42
--- /dev/null
+++ b/debian/krb5-admin-server.templates
@@ -0,0 +1,22 @@
+# These templates have been reviewed by the debian-l10n-english
+# team
+#
+# If modifications/additions/rewording are needed, please ask
+# for an advice to debian-l10n-english@lists.debian.org
+#
+# Even minor modifications require translation updates and such
+# changes should be coordinated with translators and reviewers.
+
+Template: krb5-admin-server/newrealm
+Type: note
+_Description: Setting up a Kerberos Realm
+ This package contains the administrative tools required to run the
+ Kerberos master server.
+ .
+ However, installing this package does not automatically set up a
+ Kerberos realm. This can be done later by running the "krb5_newrealm"
+ command.
+ .
+ Please also read the /usr/share/doc/krb5-kdc/README.KDC file
+ and the administration guide found in the krb5-doc package.
+
diff --git a/debian/krb5-doc.doc-base.admin b/debian/krb5-doc.doc-base.admin
new file mode 100644
index 000000000..5238e5af7
--- /dev/null
+++ b/debian/krb5-doc.doc-base.admin
@@ -0,0 +1,12 @@
+Document: admin
+Title: Kerberos Administration Guide
+Author: MIT
+Abstract: Administration and installation guide for MIT Kerberos Version 5.
+Section: System/Security
+
+Format: HTML
+Index: /usr/share/doc/krb5-doc/admin/index.html
+Files: /usr/share/doc/krb5-doc/admin/*
+
+Format: PDF
+Files: /usr/share/doc/krb5-doc/admin.pdf.gz
diff --git a/debian/krb5-doc.doc-base.appdev b/debian/krb5-doc.doc-base.appdev
new file mode 100644
index 000000000..3912e9252
--- /dev/null
+++ b/debian/krb5-doc.doc-base.appdev
@@ -0,0 +1,12 @@
+Document: appdev
+Title: Kerberos Application Developer Guide
+Author: MIT
+Abstract: Application development guide and API reference for MIT Kerberos.
+Section: System/Security
+
+Format: HTML
+Index: /usr/share/doc/krb5-doc/appdev/index.html
+Files: /usr/share/doc/krb5-doc/appdev/*
+
+Format: PDF
+Files: /usr/share/doc/krb5-doc/appdev.pdf.gz
diff --git a/debian/krb5-doc.doc-base.basic b/debian/krb5-doc.doc-base.basic
new file mode 100644
index 000000000..283c447ea
--- /dev/null
+++ b/debian/krb5-doc.doc-base.basic
@@ -0,0 +1,12 @@
+Document: basic
+Title: Kerberos Concepts
+Author: MIT
+Abstract: Basic concepts and introduction to Kerberos.
+Section: System/Security
+
+Format: HTML
+Index: /usr/share/doc/krb5-doc/basic/index.html
+Files: /usr/share/doc/krb5-doc/basic/*
+
+Format: PDF
+Files: /usr/share/doc/krb5-doc/basic.pdf.gz
diff --git a/debian/krb5-doc.doc-base.build b/debian/krb5-doc.doc-base.build
new file mode 100644
index 000000000..280cbddd0
--- /dev/null
+++ b/debian/krb5-doc.doc-base.build
@@ -0,0 +1,12 @@
+Document: build
+Title: Building MIT Kerberos
+Author: MIT
+Abstract: Configuration and compilation instructions for MIT Kerberos.
+Section: System/Security
+
+Format: HTML
+Index: /usr/share/doc/krb5-doc/build/index.html
+Files: /usr/share/doc/krb5-doc/build/*
+
+Format: PDF
+Files: /usr/share/doc/krb5-doc/build.pdf.gz
diff --git a/debian/krb5-doc.doc-base.plugindev b/debian/krb5-doc.doc-base.plugindev
new file mode 100644
index 000000000..7e0f4a097
--- /dev/null
+++ b/debian/krb5-doc.doc-base.plugindev
@@ -0,0 +1,12 @@
+Document: plugindev
+Title: Kerberos Plugin Module Developer Guide
+Author: MIT
+Abstract: Plugin module development guide for MIT Kerberos.
+Section: System/Security
+
+Format: HTML
+Index: /usr/share/doc/krb5-doc/plugindev/index.html
+Files: /usr/share/doc/krb5-doc/plugindev/*
+
+Format: PDF
+Files: /usr/share/doc/krb5-doc/plugindev.pdf.gz
diff --git a/debian/krb5-doc.doc-base.user b/debian/krb5-doc.doc-base.user
new file mode 100644
index 000000000..baf860c51
--- /dev/null
+++ b/debian/krb5-doc.doc-base.user
@@ -0,0 +1,12 @@
+Document: user
+Title: Kerberos User Guide
+Author: MIT
+Abstract: User's guide for MIT Kerberos.
+Section: System/Security
+
+Format: HTML
+Index: /usr/share/doc/krb5-doc/user/index.html
+Files: /usr/share/doc/krb5-doc/user/*
+
+Format: PDF
+Files: /usr/share/doc/krb5-doc/user.pdf.gz
diff --git a/debian/krb5-doc.docs b/debian/krb5-doc.docs
new file mode 100644
index 000000000..8dca7c2c0
--- /dev/null
+++ b/debian/krb5-doc.docs
@@ -0,0 +1,12 @@
+debian/README.KDC
+README
+NOTICE
+build/doc/html_subst/*.html
+build/doc/html_subst/admin/
+build/doc/html_subst/appdev/
+build/doc/html_subst/basic/
+build/doc/html_subst/build/
+build/doc/html_subst/plugindev/
+build/doc/html_subst/_static/
+build/doc/html_subst/user/
+build/doc/pdf_subst/*.pdf
diff --git a/debian/krb5-doc.install b/debian/krb5-doc.install
new file mode 100644
index 000000000..5e7868a86
--- /dev/null
+++ b/debian/krb5-doc.install
@@ -0,0 +1,6 @@
+usr/share/man/man5/k5login.5
+usr/share/man/man5/.k5login.5
+usr/share/man/man5/k5identity*
+usr/share/man/man5/.k5identity.5
+usr/share/man/man5/krb5.conf.5
+usr/share/man/man7/kerberos.7
diff --git a/debian/krb5-gss-samples.docs b/debian/krb5-gss-samples.docs
new file mode 100644
index 000000000..5ab7fd38d
--- /dev/null
+++ b/debian/krb5-gss-samples.docs
@@ -0,0 +1 @@
+src/appl/gss-sample/README
diff --git a/debian/krb5-gss-samples.install b/debian/krb5-gss-samples.install
new file mode 100644
index 000000000..fb07a88fe
--- /dev/null
+++ b/debian/krb5-gss-samples.install
@@ -0,0 +1,3 @@
+usr/bin/gss-*
+usr/sbin/gss-* usr/bin
+
diff --git a/debian/krb5-gss-samples.lintian-overrides b/debian/krb5-gss-samples.lintian-overrides
new file mode 100644
index 000000000..178edf642
--- /dev/null
+++ b/debian/krb5-gss-samples.lintian-overrides
@@ -0,0 +1,2 @@
+krb5-gss-samples: binary-without-manpage usr/bin/gss-client
+krb5-gss-samples: binary-without-manpage usr/bin/gss-server
diff --git a/debian/krb5-k5tls.install b/debian/krb5-k5tls.install
new file mode 100644
index 000000000..6476b95a7
--- /dev/null
+++ b/debian/krb5-k5tls.install
@@ -0,0 +1 @@
+usr/lib/*/krb5/plugins/tls/k5tls.so
diff --git a/debian/krb5-kdc-ldap.docs b/debian/krb5-kdc-ldap.docs
new file mode 100644
index 000000000..71e1b687f
--- /dev/null
+++ b/debian/krb5-kdc-ldap.docs
@@ -0,0 +1,3 @@
+src/plugins/kdb/ldap/libkdb_ldap/kerberos.ldif
+src/plugins/kdb/ldap/libkdb_ldap/kerberos.openldap.ldif
+src/plugins/kdb/ldap/libkdb_ldap/kerberos.schema
diff --git a/debian/krb5-kdc-ldap.insserv-override b/debian/krb5-kdc-ldap.insserv-override
new file mode 100644
index 000000000..716bac536
--- /dev/null
+++ b/debian/krb5-kdc-ldap.insserv-override
@@ -0,0 +1,10 @@
+### BEGIN INIT INFO
+# Provides: krb5-kdc
+# Required-Start: $local_fs $remote_fs $network $syslog
+# Required-Stop: $local_fs $remote_fs $network $syslog
+# Should-Start: slapd
+# Should-Stop: slapd
+# X-Start-Before: $x-display-manager
+# Default-Start: 2 3 4 5
+# Default-Stop: 0 1 6
+### END INIT INFO
diff --git a/debian/krb5-kdc-ldap.install b/debian/krb5-kdc-ldap.install
new file mode 100644
index 000000000..5b2c60309
--- /dev/null
+++ b/debian/krb5-kdc-ldap.install
@@ -0,0 +1,7 @@
+usr/sbin/kdb5_ldap_util
+usr/share/man/man8/kdb5_ldap_util.8
+usr/lib/*/krb5/*.so*
+usr/lib/*/krb5/plugins/kdb/kldap.so
+etc/insserv/overrides
+debian/slapd-before-kdc.conf lib/systemd/system/krb5-kdc.service.d
+debian/slapd-before-kdc.conf lib/systemd/system/krb5-admin-server.service.d
diff --git a/debian/krb5-kdc.NEWS b/debian/krb5-kdc.NEWS
new file mode 100644
index 000000000..7e65bc106
--- /dev/null
+++ b/debian/krb5-kdc.NEWS
@@ -0,0 +1,8 @@
+krb5 (1.13.1+dfsg-1) experimental; urgency=low
+
+ The KDC process now listens on TCP port 88 as well as UDP port 88 by
+ default. To disable listening on TCP, set kdc_tcp_ports to the empty
+ string in the [kdcdefaults] section of kdc.conf.
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Fri, 13 Mar 2015 17:26:53 -0400
+
diff --git a/debian/krb5-kdc.config b/debian/krb5-kdc.config
new file mode 100644
index 000000000..9e698b82f
--- /dev/null
+++ b/debian/krb5-kdc.config
@@ -0,0 +1,19 @@
+#!/bin/sh
+
+set -e
+
+. /usr/share/debconf/confmodule
+db_version 2.0
+
+db_input low krb5-kdc/debconf || true
+db_go
+
+db_get krb5-kdc/debconf
+if [ x"$RET" = xtrue ] ; then
+ if [ -f "/etc/default/krb5-kdc" ] ; then
+ . /etc/default/krb5-kdc
+ fi
+fi
+
+
+
diff --git a/debian/krb5-kdc.dirs.in b/debian/krb5-kdc.dirs.in
new file mode 100644
index 000000000..1fa2755bf
--- /dev/null
+++ b/debian/krb5-kdc.dirs.in
@@ -0,0 +1,5 @@
+usr/lib/${DEB_HOST_MULTIARCH}/krb5/plugins/kdb
+var/lib/krb5kdc
+etc/krb5kdc
+usr/share/doc/krb5-kdc/examples
+usr/share/krb5-kdc
diff --git a/debian/krb5-kdc.docs b/debian/krb5-kdc.docs
new file mode 100644
index 000000000..a46bf99e2
--- /dev/null
+++ b/debian/krb5-kdc.docs
@@ -0,0 +1,2 @@
+debian/README.KDC
+debian/README.Debian
diff --git a/debian/krb5-kdc.init b/debian/krb5-kdc.init
new file mode 100755
index 000000000..20998e990
--- /dev/null
+++ b/debian/krb5-kdc.init
@@ -0,0 +1,128 @@
+#! /bin/sh
+### BEGIN INIT INFO
+# Provides: krb5-kdc
+# Required-Start: $local_fs $remote_fs $network $syslog
+# Required-Stop: $local_fs $remote_fs $network $syslog
+# X-Start-Before: $x-display-manager
+# Default-Start: 2 3 4 5
+# Default-Stop: 0 1 6
+# Short-Description: MIT Kerberos KDC
+# Description: Starts, stops, or restarts the MIT Kerberos KDC. This
+# daemon responds to ticket requests from Kerberos
+# clients.
+### END INIT INFO
+
+# Author: Sam Hartman <hartmans@mit.edu>
+# Author: Russ Allbery <rra@debian.org>
+#
+# Based on the /etc/init.d/skeleton template as found in initscripts version
+# 2.86.ds1-15.
+
+PATH=/usr/sbin:/usr/bin:/sbin:/bin
+DESC="Kerberos KDC"
+NAME=krb5kdc
+DAEMON=/usr/sbin/$NAME
+DAEMON_ARGS=""
+PIDFILE=/var/run/$NAME.pid
+SCRIPTNAME=/etc/init.d/krb5-kdc
+
+# Exit if the package is not installed.
+[ -x "$DAEMON" ] || exit 0
+
+# Read configuration if it is present.
+[ -r /etc/default/krb5-kdc ] && . /etc/default/krb5-kdc
+
+# Get the setting of VERBOSE and other rcS variables.
+[ -f /etc/default/rcS ] && . /etc/default/rcS
+
+# Define LSB log functions (requires lsb-base >= 3.0-6).
+. /lib/lsb/init-functions
+
+
+# Return
+# 0 if daemon has been started
+# 1 if daemon was already running
+# 2 if daemon could not be started
+do_start_kdc()
+{
+ start-stop-daemon --start --quiet --pidfile $PIDFILE --startas $DAEMON --name $NAME --test \
+ > /dev/null || return 1
+ start-stop-daemon --start --quiet --pidfile $PIDFILE --startas $DAEMON --name $NAME \
+ -- -P $PIDFILE $DAEMON_ARGS || return 2
+}
+
+
+# Return
+# 0 if daemon has been stopped
+# 1 if daemon was already stopped
+# 2 if daemon could not be stopped
+# other if a failure occurred
+do_stop_kdc()
+{
+ start-stop-daemon --stop --quiet --retry=TERM/30/KILL/5 --pidfile $PIDFILE --name $NAME
+ RETVAL="$?"
+ [ "$RETVAL" = 2 ] && return 2
+ rm -f $PIDFILE
+ return "$RETVAL"
+}
+
+
+case "$1" in
+ start)
+ [ "$VERBOSE" != no ] && log_daemon_msg "Starting $DESC" "$NAME"
+ do_start_kdc
+ case "$?" in
+ 0|1)
+ [ "$VERBOSE" != no ] && log_end_msg 0
+ ;;
+ 2)
+ [ "$VERBOSE" != no ] && log_end_msg 1
+ ;;
+ esac
+ ;;
+
+ stop)
+ [ "$VERBOSE" != no ] && log_daemon_msg "Stopping $DESC" "$NAME"
+ do_stop_kdc
+ case "$?" in
+ 0|1)
+ [ "$VERBOSE" != no ] && log_progress_msg "krb524d"
+ ;;
+ 2)
+ [ "$VERBOSE" != no ] && log_end_msg 1
+ ;;
+ esac
+ ;;
+
+ restart|force-reload)
+ log_daemon_msg "Restarting $DESC" "$NAME"
+ do_stop_kdc
+ case "$?" in
+ 0|1)
+ do_start_kdc
+ case "$?" in
+ 0)
+ log_end_msg 0
+ ;;
+ 1|2)
+ log_end_msg 1
+ ;;
+ esac
+ ;;
+ *)
+ log_end_msg 1
+ ;;
+ esac
+ ;;
+
+ status)
+ status_of_proc -p $PIDFILE "$DAEMON" "$NAME" && exit 0 || exit $?
+ ;;
+
+ *)
+ echo "Usage: $SCRIPTNAME {start|stop|restart|force-reload|status}" >&2
+ exit 3
+ ;;
+esac
+
+:
diff --git a/debian/krb5-kdc.install b/debian/krb5-kdc.install
new file mode 100644
index 000000000..15b0e83c7
--- /dev/null
+++ b/debian/krb5-kdc.install
@@ -0,0 +1,8 @@
+usr/sbin/kproplog
+usr/share/man/man8/kproplog.8
+usr/sbin/kdb5_util
+usr/share/man/man8/kdb5_util.8
+usr/sbin/krb5kdc
+usr/share/man/man8/krb5kdc.8
+usr/share/man/man5/kdc.conf.5
+usr/lib/*/krb5/plugins/kdb/db2.so
diff --git a/debian/krb5-kdc.lintian-overrides b/debian/krb5-kdc.lintian-overrides
new file mode 100644
index 000000000..716b6824c
--- /dev/null
+++ b/debian/krb5-kdc.lintian-overrides
@@ -0,0 +1 @@
+krb5-kdc: non-standard-dir-perm
diff --git a/debian/krb5-kdc.news b/debian/krb5-kdc.news
new file mode 100644
index 000000000..40c877e7f
--- /dev/null
+++ b/debian/krb5-kdc.news
@@ -0,0 +1,15 @@
+krb5-kdc (1.14+dfsg-1) unstable; urgency=high
+
+ In this version of the kdc, a new package is introduced, krb5-kpropd. This package should be installed on all slave KDCs that need the kpropd daemon. Future versions of krb5-kdc will drop the kpropd binary. Today the only effect of installing krb5-kpropd is that init scripts and systemd service files will be installed for kpropd. If the krb5-kpropd package is not installed on slave KDCs by the time that the kpropd binaries are removed, then slave functionality will fail until the package is installed.
+
+
+
+ -- Sam Hartman <hartmans@debian.org> Thu, 25 Feb 2016 08:03:11 -0500
+
+krb5 (1.12.1+dfsg-11) unstable; urgency=medium
+
+ This version includes systemd unit files. In previous versions of krb5-admin-server, debconf was used to determine whether to use kadmind. With this version, update-rc.d krb5-admin-server disable should be used to disable the Kerberos administration daemon.
+
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 20 Oct 2014 16:39:32 -0400
+
diff --git a/debian/krb5-kdc.postinst b/debian/krb5-kdc.postinst
new file mode 100644
index 000000000..6e5a8be1d
--- /dev/null
+++ b/debian/krb5-kdc.postinst
@@ -0,0 +1,51 @@
+#! /bin/sh
+
+set -e
+
+# Failing to start should not break installs or upgrades
+init_error() {
+ true
+ }
+
+if [ "configure" = "$1" ] || [ "reconfigure" = "$1" ] ; then
+ . /usr/share/debconf/confmodule
+ db_version 2.0
+
+ db_get krb5-config/default_realm || true
+ KRB5LD_DEFAULT_REALM="$RET"
+ if [ -z "$KRB5LD_DEFAULT_REALM" ] ; then
+ KRB5LD_DEFAULT_REALM=EXAMPLE.COM
+ fi
+ export KRB5LD_DEFAULT_REALM
+
+ db_get krb5-kdc/debconf
+ DEBCONF="$RET"
+
+ if [ ! -f /etc/krb5kdc/kdc.conf ] && [ $DEBCONF = "true" ] ; then
+ sed -e "s/@MYREALM/$KRB5LD_DEFAULT_REALM/" \
+ /usr/share/krb5-kdc/kdc.conf.template > /etc/krb5kdc/kdc.conf
+ fi
+
+ if [ $DEBCONF = "true" ] ; then
+ if [ -f "/etc/default/krb5-kdc" ] ; then
+ . /etc/default/krb5-kdc
+ fi
+ cat <<'EOF' > /etc/default/krb5-kdc
+
+# Automatically generated. Only the value of DAEMON_ARGS will be preserved.
+# If you change anything in this file other than DAEMON_ARGS, first run
+# dpkg-reconfigure krb5-kdc and disable managing the KDC configuration with
+# debconf. Otherwise, changes will be overwritten.
+
+EOF
+ if [ -n "$DAEMON_ARGS" ] ; then
+ echo "DAEMON_ARGS=\"$DAEMON_ARGS\"" >> /etc/default/krb5-kdc
+ fi
+ fi
+
+ db_stop
+fi
+
+#DEBHELPER#
+
+exit 0
diff --git a/debian/krb5-kdc.postrm b/debian/krb5-kdc.postrm
new file mode 100644
index 000000000..43c7b5b31
--- /dev/null
+++ b/debian/krb5-kdc.postrm
@@ -0,0 +1,26 @@
+#!/bin/sh
+
+set -e
+
+if [ $1 = "purge" ] ; then
+ rm -f /etc/krb5kdc/kdc.conf 2>/dev/null || true
+ rm -f /etc/default/krb5-kdc 2>/dev/null || true
+ rm -f /etc/krb5kdc/kadm5.keytab 2>/dev/null || true
+ rm -f /etc/krb5kdc/kadm5.acl 2>/dev/null || true
+ rm -f /etc/krb5kdc/stash 2>/dev/null || true
+
+ # Prompt for whether we should remove the database.
+ if [ -d /var/lib/krb5kdc ] && [ -e /usr/share/debconf/confmodule ] ; then
+ . /usr/share/debconf/confmodule
+ db_version 2.0
+
+ db_input medium krb5-kdc/purge_data_too || true
+ db_go || true
+ db_get krb5-kdc/purge_data_too
+ if [ "$RET" = true ] ; then
+ rm -rf /var/lib/krb5kdc
+ fi
+ fi
+fi
+
+#DEBHELPER#
diff --git a/debian/krb5-kdc.prerm b/debian/krb5-kdc.prerm
new file mode 100644
index 000000000..b4b43cafd
--- /dev/null
+++ b/debian/krb5-kdc.prerm
@@ -0,0 +1,18 @@
+#! /bin/sh
+
+set -e
+
+init_error() {
+ echo failed to stop krb5-kdc
+ exit 1
+ }
+
+if test "remove" = "$1"; then
+ if which update-inetd >/dev/null 2>&1 ; then
+ update-inetd --remove '#?krb5_prop.*/usr/sbin/kpropd'
+ fi
+fi
+
+#DEBHELPER#
+
+exit 0
diff --git a/debian/krb5-kdc.service b/debian/krb5-kdc.service
new file mode 100644
index 000000000..fbbf843f0
--- /dev/null
+++ b/debian/krb5-kdc.service
@@ -0,0 +1,19 @@
+[Unit]
+Description=Kerberos 5 Key Distribution Center
+
+
+[Service]
+Type=forking
+PIDFile=/var/run/krb5-kdc.pid
+ExecReload=/bin/kill -HUP $MAINPID
+EnvironmentFile=-/etc/default/krb5-kdc
+ExecStart=/usr/sbin/krb5kdc -P /var/run/krb5-kdc.pid $DAEMON_ARGS
+InaccessibleDirectories=-/etc/ssh -/etc/ssl/private /root
+ReadOnlyDirectories=/
+ReadWriteDirectories=-/var/tmp /tmp /var/lib/krb5kdc -/var/run /run
+CapabilityBoundingSet=CAP_NET_BIND_SERVICE
+Restart=on-abnormal
+
+
+[Install]
+WantedBy=multi-user.target
diff --git a/debian/krb5-kdc.templates b/debian/krb5-kdc.templates
new file mode 100644
index 000000000..11e7e644d
--- /dev/null
+++ b/debian/krb5-kdc.templates
@@ -0,0 +1,33 @@
+# These templates have been reviewed by the debian-l10n-english
+# team
+#
+# If modifications/additions/rewording are needed, please ask
+# for an advice to debian-l10n-english@lists.debian.org
+#
+# Even minor modifications require translation updates and such
+# changes should be coordinated with translators and reviewers.
+
+Template: krb5-kdc/debconf
+Type: boolean
+Default: true
+_Description: Create the Kerberos KDC configuration automatically?
+ The Kerberos Key Distribution Center (KDC) configuration files, in
+ /etc/krb5kdc, may be created automatically.
+ .
+ By default, an example template will be copied into this directory
+ with local parameters filled in.
+ .
+ Administrators who already have infrastructure to manage their
+ Kerberos configuration may wish to disable these automatic
+ configuration changes.
+
+Template: krb5-kdc/purge_data_too
+Type: boolean
+Default: false
+_Description: Should the KDC database be deleted?
+ By default, removing this package will not delete the KDC database in
+ /var/lib/krb5kdc/principal since this database cannot be recovered once
+ it is deleted.
+ .
+ Choose this option if you wish to delete the KDC database now, deleting
+ all of the user accounts and passwords in the KDC.
diff --git a/debian/krb5-kpropd.init b/debian/krb5-kpropd.init
new file mode 100755
index 000000000..2553a8a95
--- /dev/null
+++ b/debian/krb5-kpropd.init
@@ -0,0 +1,127 @@
+#! /bin/sh
+### BEGIN INIT INFO
+# Provides: krb5-kpropd
+# Required-Start: $local_fs $remote_fs $network $syslog
+# Required-Stop: $local_fs $remote_fs $network $syslog
+# X-Start-Before: $x-display-manager
+# Default-Start: 2 3 4 5
+# Default-Stop: 0 1 6
+# Short-Description: MIT Kerberos slave KDC update server
+# Description: Starts, stops, or restarts the MIT Kerberos slave KDC
+# update server
+### END INIT INFO
+
+# Author: Sam Hartman <hartmans@mit.edu>
+# Author: Russ Allbery <rra@debian.org>
+#
+# Based on the /etc/init.d/skeleton template as found in initscripts version
+# 2.86.ds1-15.
+
+PATH=/usr/sbin:/usr/bin:/sbin:/bin
+DESC="Kerberos slave KDC update server"
+NAME=kpropd
+DAEMON=/usr/sbin/$NAME
+DAEMON_ARGS=""
+PIDFILE=/var/run/$NAME.pid
+SCRIPTNAME=/etc/init.d/kpropd
+
+# Exit if the package is not installed.
+[ -x "$DAEMON" ] || exit 0
+
+# Read configuration if it is present.
+[ -r /etc/default/kpropd ] && . /etc/default/kpropd
+
+# Get the setting of VERBOSE and other rcS variables.
+[ -f /etc/default/rcS ] && . /etc/default/rcS
+
+# Define LSB log functions (requires lsb-base >= 3.0-6).
+. /lib/lsb/init-functions
+
+
+# Return
+# 0 if daemon has been started
+# 1 if daemon was already running
+# 2 if daemon could not be started
+do_start_kpropd()
+{
+ start-stop-daemon --start --quiet --pidfile $PIDFILE --startas $DAEMON --name $NAME --test \
+ > /dev/null || return 1
+ start-stop-daemon --start --quiet --make-pidfile --background --pidfile $PIDFILE --startas $DAEMON --name $NAME \
+ -- -D $DAEMON_ARGS || return 2
+}
+
+
+# Return
+# 0 if daemon has been stopped
+# 1 if daemon was already stopped
+# 2 if daemon could not be stopped
+# other if a failure occurred
+do_stop_kpropd()
+{
+ start-stop-daemon --stop --quiet --retry=TERM/30/KILL/5 --pidfile $PIDFILE --name $NAME
+ RETVAL="$?"
+ [ "$RETVAL" = 2 ] && return 2
+ rm -f $PIDFILE
+ return "$RETVAL"
+}
+
+
+case "$1" in
+ start)
+ [ "$VERBOSE" != no ] && log_daemon_msg "Starting $DESC" "$NAME"
+ do_start_kpropd
+ case "$?" in
+ 0|1)
+ [ "$VERBOSE" != no ] && log_end_msg 0
+ ;;
+ 2)
+ [ "$VERBOSE" != no ] && log_end_msg 1
+ ;;
+ esac
+ ;;
+
+ stop)
+ [ "$VERBOSE" != no ] && log_daemon_msg "Stopping $DESC" "$NAME"
+ do_stop_kpropd
+ case "$?" in
+ 0|1)
+ [ "$VERBOSE" != no ] && log_progress_msg "krb524d"
+ ;;
+ 2)
+ [ "$VERBOSE" != no ] && log_end_msg 1
+ ;;
+ esac
+ ;;
+
+ restart|force-reload)
+ log_daemon_msg "Restarting $DESC" "$NAME"
+ do_stop_kpropd
+ case "$?" in
+ 0|1)
+ do_start_kpropd
+ case "$?" in
+ 0)
+ log_end_msg 0
+ ;;
+ 1|2)
+ log_end_msg 1
+ ;;
+ esac
+ ;;
+ *)
+ log_end_msg 1
+ ;;
+ esac
+ ;;
+
+ status)
+ status_of_proc -p $PIDFILE "$DAEMON" "$NAME" && exit 0 || exit $?
+ ;;
+
+ *)
+ echo "Usage: $SCRIPTNAME {start|stop|restart|force-reload|status}" >&2
+ exit 3
+ ;;
+esac
+
+:
diff --git a/debian/krb5-kpropd.install b/debian/krb5-kpropd.install
new file mode 100644
index 000000000..e6bf45ee4
--- /dev/null
+++ b/debian/krb5-kpropd.install
@@ -0,0 +1,2 @@
+usr/sbin/kpropd
+usr/share/man/man8/kpropd.8
diff --git a/debian/krb5-kpropd.postinst b/debian/krb5-kpropd.postinst
new file mode 100644
index 000000000..1f7623ca2
--- /dev/null
+++ b/debian/krb5-kpropd.postinst
@@ -0,0 +1,19 @@
+#! /bin/sh
+
+set -e
+
+# Only try to add the inetd line on an initial installation. Add it
+# commented out in a way that will not be automatically enabled, since the
+# Kerberos administrator should do that manually when ready.
+#
+# If update-inetd isn't available, don't bother, since it's just an example.
+if [ "configure" = "$1" ] && which update-inetd >/dev/null 2>&1 ; then
+ if [ -z "$2" ] || [ x"$2" = x"<unknown>" ] ; then
+ update-inetd --add --group Kerberos \
+ '#krb5_prop\tstream\ttcp\tnowait\troot\t/usr/sbin/kpropd kpropd'
+ fi
+fi
+
+#DEBHELPER#
+
+exit 0
diff --git a/debian/krb5-kpropd.prerm b/debian/krb5-kpropd.prerm
new file mode 100644
index 000000000..a3fa61c42
--- /dev/null
+++ b/debian/krb5-kpropd.prerm
@@ -0,0 +1,13 @@
+#! /bin/sh
+
+set -e
+
+if test "remove" = "$1"; then
+ if which update-inetd >/dev/null 2>&1 ; then
+ update-inetd --remove '#?krb5_prop.*/usr/sbin/kpropd'
+ fi
+fi
+
+#DEBHELPER#
+
+exit 0
diff --git a/debian/krb5-kpropd.service b/debian/krb5-kpropd.service
new file mode 100644
index 000000000..1a15d890f
--- /dev/null
+++ b/debian/krb5-kpropd.service
@@ -0,0 +1,15 @@
+[Unit]
+Description=Kerberos 5 slave KDC update server
+Conflicts=krb5-admin-server.service
+
+[Service]
+ExecReload=/bin/kill -HUP $MAINPID
+EnvironmentFile=-/etc/default/krb5-kpropd
+ExecStart=/usr/sbin/kpropd -D $DAEMON_ARGS
+InaccessibleDirectories=-/etc/ssh -/etc/ssl/private /root
+ReadOnlyDirectories=/
+ReadWriteDirectories=/var/tmp /tmp /var/lib/krb5kdc /var/run /run
+CapabilityBoundingSet=CAP_NET_BIND_SERVICE
+
+[Install]
+WantedBy=multi-user.target
diff --git a/debian/krb5-locales.install b/debian/krb5-locales.install
new file mode 100644
index 000000000..3270a4849
--- /dev/null
+++ b/debian/krb5-locales.install
@@ -0,0 +1 @@
+usr/share/locale/*
diff --git a/debian/krb5-multidev.dirs.in b/debian/krb5-multidev.dirs.in
new file mode 100644
index 000000000..2d7fc30d1
--- /dev/null
+++ b/debian/krb5-multidev.dirs.in
@@ -0,0 +1,3 @@
+usr/include/mit-krb5
+usr/lib/${DEB_HOST_MULTIARCH}/mit-krb5
+usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/mit-krb5
diff --git a/debian/krb5-multidev.install.in b/debian/krb5-multidev.install.in
new file mode 100644
index 000000000..d18ecc09b
--- /dev/null
+++ b/debian/krb5-multidev.install.in
@@ -0,0 +1,12 @@
+usr/lib/${DEB_HOST_MULTIARCH}/lib*.so usr/lib/${DEB_HOST_MULTIARCH}/mit-krb5
+usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/mit-krb5.pc usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig
+usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/mit-krb5-gssapi.pc usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig
+usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/gssrpc.pc usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/mit-krb5
+usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/kadm-client.pc usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/mit-krb5
+usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/kadm-server.pc usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/mit-krb5
+usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/kdb.pc usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/mit-krb5
+usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/krb5-gssapi.pc usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/mit-krb5
+usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/krb5.pc usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig/mit-krb5
+usr/include/* usr/include/mit-krb5
+usr/bin/krb5-config.mit
+usr/share/man/man1/krb5-config.mit.1
diff --git a/debian/krb5-multidev.links.in b/debian/krb5-multidev.links.in
new file mode 100644
index 000000000..e537e09fb
--- /dev/null
+++ b/debian/krb5-multidev.links.in
@@ -0,0 +1,2 @@
+usr/lib/${DEB_HOST_MULTIARCH}/mit-krb5/libkadm5clnt_mit.so usr/lib/${DEB_HOST_MULTIARCH}/mit-krb5/libkadm5clnt.so
+usr/lib/${DEB_HOST_MULTIARCH}/mit-krb5/libkadm5srv_mit.so usr/lib/${DEB_HOST_MULTIARCH}/mit-krb5/libkadm5srv.so
diff --git a/debian/krb5-otp.NEWS b/debian/krb5-otp.NEWS
new file mode 100644
index 000000000..e12cb0e4f
--- /dev/null
+++ b/debian/krb5-otp.NEWS
@@ -0,0 +1,7 @@
+krb5 (1.13~alpha1+dfsg-1) experimental; urgency=low
+ The default location of the socket used by the OTP plugin has moved
+ from /etc/krb5kdc to /run/krb5kdc/. If the "zero-conf" krb5-otp
+ functionality is in use, the software providing the other end of
+ the socket must be adjusted to use the new path.
+
+ -- Benjamin Kaduk <kaduk@mit.edu> Thu, 28 Aug 2014 23:49:41 -0400
diff --git a/debian/krb5-otp.install b/debian/krb5-otp.install
new file mode 100644
index 000000000..40c4118a5
--- /dev/null
+++ b/debian/krb5-otp.install
@@ -0,0 +1,2 @@
+usr/lib/*/krb5/plugins/preauth/otp.so
+
diff --git a/debian/krb5-otp.tmpfile b/debian/krb5-otp.tmpfile
new file mode 100644
index 000000000..eadeb51fa
--- /dev/null
+++ b/debian/krb5-otp.tmpfile
@@ -0,0 +1 @@
+d /var/run/krb5kdc 0755 root root
diff --git a/debian/krb5-pkinit.install b/debian/krb5-pkinit.install
new file mode 100644
index 000000000..ef214aa59
--- /dev/null
+++ b/debian/krb5-pkinit.install
@@ -0,0 +1,2 @@
+usr/lib/*/krb5/plugins/preauth/pkinit.so
+
diff --git a/debian/krb5-user.docs b/debian/krb5-user.docs
new file mode 100644
index 000000000..e845566c0
--- /dev/null
+++ b/debian/krb5-user.docs
@@ -0,0 +1 @@
+README
diff --git a/debian/krb5-user.install b/debian/krb5-user.install
new file mode 100644
index 000000000..203f613fa
--- /dev/null
+++ b/debian/krb5-user.install
@@ -0,0 +1,20 @@
+usr/bin/kdestroy
+usr/share/man/man1/kdestroy.1
+usr/bin/kinit
+usr/share/man/man1/kinit.1
+usr/bin/klist
+usr/share/man/man1/klist.1
+usr/bin/kpasswd
+usr/share/man/man1/kpasswd.1
+usr/bin/ksu
+usr/share/man/man1/ksu.1
+usr/bin/kvno
+usr/share/man/man1/kvno.1
+usr/bin/k5srvutil
+usr/share/man/man1/k5srvutil.1
+usr/bin/kadmin
+usr/share/man/man1/kadmin.1
+usr/bin/ktutil
+usr/share/man/man1/ktutil.1
+usr/bin/kswitch
+usr/share/man/man1/kswitch.1
diff --git a/debian/krb5-user.lintian-overrides b/debian/krb5-user.lintian-overrides
new file mode 100644
index 000000000..3b365c5bf
--- /dev/null
+++ b/debian/krb5-user.lintian-overrides
@@ -0,0 +1 @@
+krb5-user: setuid-binary
diff --git a/debian/krb5_newrealm b/debian/krb5_newrealm
new file mode 100755
index 000000000..205c93d36
--- /dev/null
+++ b/debian/krb5_newrealm
@@ -0,0 +1,41 @@
+#!/bin/sh -e
+
+cat <<eof
+This script should be run on the master KDC/admin server to initialize
+a Kerberos realm. It will ask you to type in a master key password.
+This password will be used to generate a key that is stored in
+/etc/krb5kdc/stash. You should try to remember this password, but it
+is much more important that it be a strong password than that it be
+remembered. However, if you lose the password and /etc/krb5kdc/stash,
+you cannot decrypt your Kerberos database.
+eof
+
+kdb5_util create -s
+service krb5-kdc start || true
+service krb5-admin-server start ||true
+if [ ! -r /etc/krb5kdc/kadm5.acl ] ; then
+ cat <<EOF >/etc/krb5kdc/kadm5.acl
+# This file Is the access control list for krb5 administration.
+# When this file is edited run service krb5-admin-server restart to activate
+# One common way to set up Kerberos administration is to allow any principal
+# ending in /admin is given full administrative rights.
+# To enable this, uncomment the following line:
+# */admin *
+EOF
+ fi
+cat <<eof
+
+
+Now that your realm is set up you may wish to create an administrative
+principal using the addprinc subcommand of the kadmin.local program.
+Then, this principal can be added to /etc/krb5kdc/kadm5.acl so that
+you can use the kadmin program on other computers. Kerberos admin
+principals usually belong to a single user and end in /admin. For
+example, if jruser is a Kerberos administrator, then in addition to
+the normal jruser principal, a jruser/admin principal should be
+created.
+
+Don't forget to set up DNS information so your clients can find your
+KDC and admin servers. Doing so is documented in the administration
+guide.
+eof
diff --git a/debian/krb5_newrealm.sgml b/debian/krb5_newrealm.sgml
new file mode 100644
index 000000000..88a40fe40
--- /dev/null
+++ b/debian/krb5_newrealm.sgml
@@ -0,0 +1,32 @@
+<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook V3.1//EN">
+<refentry>
+ <refmeta>
+ <refentrytitle>krb5_newrealm</refentrytitle>
+ <manvolnum>8</manvolnum>
+ </refmeta>
+ <refnamediv>
+ <refname>krb5_newrealm</refname>
+ <refpurpose>Create a new Kerberos Realm</refpurpose>
+ </refnamediv>
+ <refsynopsisdiv>
+ <!-- one of (CALLOUTLIST GLOSSLIST ITEMIZEDLIST ORDEREDLIST SEGMENTEDLIST SIMPLELIST VARIABLELIST CAUTION IMPORTANT NOTE TIP WARNING LITERALLAYOUT PROGRAMLISTING PROGRAMLISTINGCO SCREEN SCREENCO SCREENSHOT SYNOPSIS CMDSYNOPSIS FUNCSYNOPSIS FORMALPARA PARA SIMPARA ADDRESS BLOCKQUOTE GRAPHIC GRAPHICCO MEDIAOBJECT MEDIAOBJECTCO INFORMALEQUATION INFORMALEXAMPLE INFORMALFIGURE INFORMALTABLE EQUATION EXAMPLE FIGURE TABLE MSGSET PROCEDURE SIDEBAR QANDASET ANCHOR BRIDGEHEAD COMMENT HIGHLIGHTS ABSTRACT AUTHORBLURB EPIGRAPH INDEXTERM REFSECT2) -->
+ <cmdsynopsis>
+ <!-- one of (SBR GROUP ARG COMMAND) -->
+ <command>krb5_newrealm</command>
+ </cmdsynopsis>
+ </refsynopsisdiv>
+ <refsect1>
+ <title>Description</title> <para>This script attempts to create a
+ Kerberos realm. It assumes that none of the realm components
+ exists, except for the /etc/krb5.conf file. (Normally this file
+ is automatically generated at package installation, but if you
+ skipped the configuration step, you will need to manually generate
+ this file before running krb5_newrealm.)
+ It creates the database, initializes the stash file in
+ <filename>/etc/krb5kdc/stash</filename> containing the master key for
+ the database, starts the KDC and Kerberos admin server,
+ and creates a stub <filename>/etc/krb5kdc/kadm5.acl</filename> file.
+ </para>
+</refsect1>
+</refentry>
+
diff --git a/debian/libgssapi-krb5-2.dirs b/debian/libgssapi-krb5-2.dirs
new file mode 100644
index 000000000..ca510024e
--- /dev/null
+++ b/debian/libgssapi-krb5-2.dirs
@@ -0,0 +1 @@
+etc/gss/mech.d
diff --git a/debian/libgssapi-krb5-2.install b/debian/libgssapi-krb5-2.install
new file mode 100644
index 000000000..e867ca83a
--- /dev/null
+++ b/debian/libgssapi-krb5-2.install
@@ -0,0 +1 @@
+usr/lib/*/libgssapi_krb5.so.2*
diff --git a/debian/libgssapi-krb5-2.lintian-overrides b/debian/libgssapi-krb5-2.lintian-overrides
new file mode 100644
index 000000000..e2cd37686
--- /dev/null
+++ b/debian/libgssapi-krb5-2.lintian-overrides
@@ -0,0 +1 @@
+libgssapi-krb5-2: symbols-file-contains-debian-revision
diff --git a/debian/libgssapi-krb5-2.postinst b/debian/libgssapi-krb5-2.postinst
new file mode 100644
index 000000000..51df5dc9f
--- /dev/null
+++ b/debian/libgssapi-krb5-2.postinst
@@ -0,0 +1,14 @@
+#! /bin/sh
+
+set -e
+
+if [ "configure" = "$1" -a "x$2" != "x" ]; then
+ if dpkg --compare-versions $2 lt 1.12.1+dfsg-2\
+ && test -f /usr/etc/gss/mech; then
+ cp /usr/etc/gss/mech /etc/gss/mech
+ fi
+ fi
+
+#DEBHELPER#
+
+exit 0
diff --git a/debian/libgssapi-krb5-2.postrm b/debian/libgssapi-krb5-2.postrm
new file mode 100644
index 000000000..95b5e7245
--- /dev/null
+++ b/debian/libgssapi-krb5-2.postrm
@@ -0,0 +1,9 @@
+#!/bin/sh
+
+set -e
+
+if [ $1 = "purge" ] ; then
+ rm -f /etc/gss/mech.d/README 2>/dev/null
+fi
+
+#DEBHELPER#
diff --git a/debian/libgssapi-krb5-2.symbols b/debian/libgssapi-krb5-2.symbols
new file mode 100644
index 000000000..9b8660d9f
--- /dev/null
+++ b/debian/libgssapi-krb5-2.symbols
@@ -0,0 +1,168 @@
+libgssapi_krb5.so.2 libgssapi-krb5-2 #MINVER#
+ GSS_C_ATTR_LOCAL_LOGIN_USER@gssapi_krb5_2_MIT 1.9.1+dfsg
+ GSS_C_INQ_SSPI_SESSION_KEY@gssapi_krb5_2_MIT 1.7+dfsg
+ GSS_C_MA_AUTH_INIT@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_AUTH_INIT_ANON@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_AUTH_INIT_INIT@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_AUTH_TARG@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_AUTH_TARG_ANON@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_AUTH_TARG_INIT@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_CBINDINGS@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_COMPRESS@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_CONF_PROT@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_CTX_TRANS@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_DELEG_CRED@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_DEPRECATED@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_INTEG_PROT@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_ITOK_FRAMED@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_MECH_COMPOSITE@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_MECH_CONCRETE@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_MECH_GLUE@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_MECH_NEGO@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_MECH_PSEUDO@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_MIC@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_NOT_DFLT_MECH@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_NOT_MECH@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_OOS_DET@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_PFS@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_PROT_READY@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_REPLAY_DET@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_MA_WRAP@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ GSS_C_NT_ANONYMOUS@gssapi_krb5_2_MIT 1.6.dfsg.2
+ GSS_C_NT_COMPOSITE_EXPORT@gssapi_krb5_2_MIT 1.11+dfsg
+ GSS_C_NT_EXPORT_NAME@gssapi_krb5_2_MIT 1.6.dfsg.2
+ GSS_C_NT_HOSTBASED_SERVICE@gssapi_krb5_2_MIT 1.6.dfsg.2
+ GSS_C_NT_HOSTBASED_SERVICE_X@gssapi_krb5_2_MIT 1.6.dfsg.2
+ GSS_C_NT_MACHINE_UID_NAME@gssapi_krb5_2_MIT 1.6.dfsg.2
+ GSS_C_NT_STRING_UID_NAME@gssapi_krb5_2_MIT 1.6.dfsg.2
+ GSS_C_NT_USER_NAME@gssapi_krb5_2_MIT 1.6.dfsg.2
+ GSS_C_SEC_CONTEXT_SASL_SSF@gssapi_krb5_2_MIT 1.16
+ GSS_KRB5_CRED_NO_CI_FLAGS_X@gssapi_krb5_2_MIT 1.14+dfsg
+ GSS_KRB5_GET_CRED_IMPERSONATOR@gssapi_krb5_2_MIT 1.16
+ GSS_KRB5_NT_ENTERPRISE_NAME@gssapi_krb5_2_MIT 1.17
+ GSS_KRB5_NT_PRINCIPAL_NAME@gssapi_krb5_2_MIT 1.6.dfsg.2
+ HIDDEN@HIDDEN 1.6.dfsg.2
+ gss_accept_sec_context@gssapi_krb5_2_MIT 1.14+dfsg
+ gss_acquire_cred@gssapi_krb5_2_MIT 1.14+dfsg
+ gss_acquire_cred_from@gssapi_krb5_2_MIT 1.11+dfsg
+ gss_acquire_cred_impersonate_name@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_acquire_cred_with_password@gssapi_krb5_2_MIT 1.14+dfsg
+ gss_add_buffer_set_member@gssapi_krb5_2_MIT 1.7+dfsg
+ gss_add_cred@gssapi_krb5_2_MIT 1.10+dfsg~
+ gss_add_cred_from@gssapi_krb5_2_MIT 1.11+dfsg
+ gss_add_cred_impersonate_name@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_add_cred_with_password@gssapi_krb5_2_MIT 1.14+dfsg
+ gss_add_oid_set_member@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_authorize_localname@gssapi_krb5_2_MIT 1.9.1+dfsg
+ gss_canonicalize_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_compare_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_complete_auth_token@gssapi_krb5_2_MIT 1.7+dfsg
+ gss_context_time@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_create_empty_buffer_set@gssapi_krb5_2_MIT 1.7+dfsg
+ gss_create_empty_oid_set@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_decapsulate_token@gssapi_krb5_2_MIT 1.9.1+dfsg
+ gss_delete_name_attribute@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_delete_sec_context@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_display_mech_attr@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ gss_display_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_display_name_ext@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_display_status@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_duplicate_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_encapsulate_token@gssapi_krb5_2_MIT 1.9.1+dfsg
+ gss_export_cred@gssapi_krb5_2_MIT 1.11+dfsg
+ gss_export_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_export_name_composite@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_export_sec_context@gssapi_krb5_2_MIT 1.14+dfsg
+ gss_get_mic@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_get_mic_iov@gssapi_krb5_2_MIT 1.12~alpha1+dfsg
+ gss_get_mic_iov_length@gssapi_krb5_2_MIT 1.12~alpha1+dfsg
+ gss_get_name_attribute@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_import_cred@gssapi_krb5_2_MIT 1.11+dfsg
+ gss_import_name@gssapi_krb5_2_MIT 1.17
+ gss_import_sec_context@gssapi_krb5_2_MIT 1.14+dfsg
+ gss_indicate_mechs@gssapi_krb5_2_MIT 1.12.1+dfsg-2
+ gss_indicate_mechs_by_attrs@gssapi_krb5_2_MIT 1.12.1+dfsg-2
+ gss_init_sec_context@gssapi_krb5_2_MIT 1.14+dfsg
+ gss_inquire_attrs_for_mech@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ gss_inquire_context@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_inquire_cred@gssapi_krb5_2_MIT 1.10+dfsg~
+ gss_inquire_cred_by_mech@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_inquire_cred_by_oid@gssapi_krb5_2_MIT 1.16
+ gss_inquire_mech_for_saslname@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ gss_inquire_mechs_for_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_inquire_name@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_inquire_names_for_mech@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_inquire_saslname_for_mech@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ gss_inquire_sec_context_by_oid@gssapi_krb5_2_MIT 1.16
+ gss_krb5_ccache_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_krb5_copy_ccache@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_krb5_export_lucid_sec_context@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_krb5_free_lucid_sec_context@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_krb5_get_tkt_flags@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_krb5_import_cred@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ gss_krb5_set_allowable_enctypes@gssapi_krb5_2_MIT 1.9.1
+ gss_krb5_set_cred_rcache@gssapi_krb5_2_MIT 1.7+dfsg
+ gss_krb5int_make_seal_token_v3@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_krb5int_unseal_token_v3@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_localname@gssapi_krb5_2_MIT 1.9.1+dfsg
+ gss_map_name_to_any@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_mech_iakerb@gssapi_krb5_2_MIT 1.14+dfsg
+ gss_mech_krb5@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_mech_krb5_old@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_mech_krb5_wrong@gssapi_krb5_2_MIT 1.10.2+dfsg
+ gss_mech_set_krb5@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_mech_set_krb5_both@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_mech_set_krb5_old@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_nt_exported_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_nt_krb5_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_nt_krb5_principal@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_nt_machine_uid_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_nt_service_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_nt_service_name_v2@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_nt_string_uid_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_nt_user_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_oid_equal@gssapi_krb5_2_MIT 1.9.1+dfsg
+ gss_oid_to_str@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_pname_to_uid@gssapi_krb5_2_MIT 1.9.1+dfsg
+ gss_process_context_token@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_pseudo_random@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_release_any_name_mapping@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_release_buffer@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_release_buffer_set@gssapi_krb5_2_MIT 1.7+dfsg
+ gss_release_cred@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_release_iov_buffer@gssapi_krb5_2_MIT 1.7+dfsg
+ gss_release_name@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_release_oid@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_release_oid_set@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_seal@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_set_cred_option@gssapi_krb5_2_MIT 1.9+dfsg~beta1
+ gss_set_name_attribute@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_set_neg_mechs@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_set_sec_context_option@gssapi_krb5_2_MIT 1.7+dfsg
+ gss_sign@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_store_cred@gssapi_krb5_2_MIT 1.8+dfsg
+ gss_store_cred_into@gssapi_krb5_2_MIT 1.11+dfsg
+ gss_str_to_oid@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_test_oid_set_member@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_unseal@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_unwrap@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_unwrap_aead@gssapi_krb5_2_MIT 1.7+dfsg
+ gss_unwrap_iov@gssapi_krb5_2_MIT 1.7+dfsg
+ gss_userok@gssapi_krb5_2_MIT 1.9.1+dfsg
+ gss_verify@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_verify_mic@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_verify_mic_iov@gssapi_krb5_2_MIT 1.12~alpha1+dfsg
+ gss_wrap@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gss_wrap_aead@gssapi_krb5_2_MIT 1.7+dfsg
+ gss_wrap_iov@gssapi_krb5_2_MIT 1.7+dfsg
+ gss_wrap_iov_length@gssapi_krb5_2_MIT 1.7+dfsg
+ gss_wrap_size_limit@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gssapi_krb5_2_MIT@gssapi_krb5_2_MIT 1.6.dfsg.2
+ gssint_g_seqstate_init@gssapi_krb5_2_MIT 1.13~alpha1+dfsg
+ gsskrb5_extract_authtime_from_sec_context@gssapi_krb5_2_MIT 1.7+dfsg
+ gsskrb5_extract_authz_data_from_sec_context@gssapi_krb5_2_MIT 1.7+dfsg
+ gssspi_mech_invoke@gssapi_krb5_2_MIT 1.7+dfsg
+ gssspi_set_cred_option@gssapi_krb5_2_MIT 1.7+dfsg
+ krb5_gss_dbg_client_expcreds@gssapi_krb5_2_MIT 1.6.dfsg.2
+ krb5_gss_register_acceptor_identity@gssapi_krb5_2_MIT 1.6.dfsg.2
+ krb5_gss_use_kdc_context@gssapi_krb5_2_MIT 1.6.dfsg.2
diff --git a/debian/libgssrpc4.install b/debian/libgssrpc4.install
new file mode 100644
index 000000000..3e1224f1f
--- /dev/null
+++ b/debian/libgssrpc4.install
@@ -0,0 +1 @@
+usr/lib/*/libgssrpc.so.4*
diff --git a/debian/libgssrpc4.symbols b/debian/libgssrpc4.symbols
new file mode 100644
index 000000000..cc29bc5ae
--- /dev/null
+++ b/debian/libgssrpc4.symbols
@@ -0,0 +1,147 @@
+libgssrpc.so.4 libgssrpc4 #MINVER#
+ HIDDEN@HIDDEN 1.6.dfsg.2
+ gssrpc_4_MIT@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_auth_debug_gss@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_auth_debug_gssapi@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_auth_gssapi_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_auth_gssapi_create_default@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_auth_gssapi_display_status@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_auth_gssapi_seal_seq@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_auth_gssapi_unseal_seq@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_auth_gssapi_unwrap_data@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_auth_gssapi_wrap_data@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_authgss_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_authgss_create_default@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_authgss_get_private_data@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_authgss_service@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_authnone_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_authunix_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_authunix_create_default@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_bindresvport@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_bindresvport_sa@gssrpc_4_MIT 1.13.1+dfsg
+ gssrpc_callrpc@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_clnt_broadcast@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_clnt_create@gssrpc_4_MIT 1.9+dfsg
+ gssrpc_clnt_pcreateerror@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_clnt_perrno@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_clnt_perror@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_clnt_spcreateerror@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_clnt_sperrno@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_clnt_sperror@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_clntraw_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_clnttcp_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_clntudp_bufcreate@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_clntudp_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_get_myaddress@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_getrpcport@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_log_debug@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_log_hexdump@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_log_status@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_misc_debug_gss@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_misc_debug_gssapi@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_pmap_getmaps@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_pmap_getport@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_pmap_rmtcall@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_pmap_set@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_pmap_unset@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_registerrpc@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_rpc_createrr@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_auth_gss_ops@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_auth_gssapi_ops@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_auth_none@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_auth_none_ops@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_debug_gss@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_debug_gssapi@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_fdset@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_fdset_init@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_getreq@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_getreqset@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_maxfd@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_register@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_run@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_sendreply@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svc_unregister@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcauth_gss_get_principal@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcauth_gss_set_log_badauth2_func@gssrpc_4_MIT 1.12~beta2+dfsg
+ gssrpc_svcauth_gss_set_log_badauth_func@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcauth_gss_set_log_badverf_func@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcauth_gss_set_log_miscerr_func@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcauth_gss_set_svc_name@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcauth_gssapi_set_log_badauth2_func@gssrpc_4_MIT 1.12~beta2+dfsg
+ gssrpc_svcauth_gssapi_set_log_badauth_func@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcauth_gssapi_set_log_badverf_func@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcauth_gssapi_set_log_miscerr_func@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcauth_gssapi_set_names@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcauth_gssapi_unset_names@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcerr_auth@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcerr_decode@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcerr_noproc@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcerr_noprog@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcerr_progvers@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcerr_systemerr@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcerr_weakauth@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcfd_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcraw_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svctcp_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcudp_bufcreate@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcudp_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_svcudp_enablecache@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_accepted_reply@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_array@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_authgssapi_creds@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_authgssapi_init_arg@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_authgssapi_init_res@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_authunix_parms@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_bool@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_bytes@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_callhdr@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_callmsg@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_char@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_des_block@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_enum@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_free@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_gss_buf@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_int32@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_int@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_long@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_netobj@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_opaque@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_opaque_auth@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_pmap@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_pmaplist@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_pointer@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_reference@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_rejected_reply@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_replymsg@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_rmtcall_args@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_rmtcallres@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_rpc_gss_buf@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_rpc_gss_cred@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_rpc_gss_data@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_rpc_gss_init_args@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_rpc_gss_init_res@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_rpc_gss_unwrap_data@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_rpc_gss_wrap_data@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_short@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_sizeof@gssrpc_4_MIT 1.7dfsg~alpha1
+ gssrpc_xdr_string@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_u_char@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_u_int32@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_u_int@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_u_long@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_u_short@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_union@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_vector@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_void@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdr_wrapstring@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdralloc_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdralloc_getdata@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdralloc_release@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdrmem_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdrrec_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdrrec_endofrecord@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdrrec_eof@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdrrec_skiprecord@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xdrstdio_create@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xprt_register@gssrpc_4_MIT 1.6.dfsg.2
+ gssrpc_xprt_unregister@gssrpc_4_MIT 1.6.dfsg.2
diff --git a/debian/libk5crypto3.install b/debian/libk5crypto3.install
new file mode 100644
index 000000000..d6c3335fd
--- /dev/null
+++ b/debian/libk5crypto3.install
@@ -0,0 +1 @@
+usr/lib/*/libk5crypto.so.3*
diff --git a/debian/libk5crypto3.symbols b/debian/libk5crypto3.symbols
new file mode 100644
index 000000000..fdd00bd5d
--- /dev/null
+++ b/debian/libk5crypto3.symbols
@@ -0,0 +1,114 @@
+libk5crypto.so.3 libk5crypto3 #MINVER#
+ HIDDEN@HIDDEN 1.6.dfsg.2
+ is_coll_proof_cksum@k5crypto_3_MIT 1.6.dfsg.2
+ is_keyed_cksum@k5crypto_3_MIT 1.6.dfsg.2
+ k5_allow_weak_pbkdf2iter@k5crypto_3_MIT 1.12~beta2+dfsg
+ k5_enctype_to_ssf@k5crypto_3_MIT 1.16
+ k5_sha256@k5crypto_3_MIT 1.15~beta1
+ k5_sha256_final@k5crypto_3_MIT 1.10+dfsg~alpha1
+ k5_sha256_init@k5crypto_3_MIT 1.10+dfsg~alpha1
+ k5_sha256_update@k5crypto_3_MIT 1.10+dfsg~alpha1
+ k5crypto_3_MIT@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_block_size@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_checksum_length@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_crypto_length@k5crypto_3_MIT 1.7+dfsg
+ krb5_c_crypto_length_iov@k5crypto_3_MIT 1.7+dfsg
+ krb5_c_decrypt@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_decrypt_iov@k5crypto_3_MIT 1.7+dfsg
+ krb5_c_derive_prfplus@k5crypto_3_MIT 1.14+dfsg
+ krb5_c_encrypt@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_encrypt_iov@k5crypto_3_MIT 1.7+dfsg
+ krb5_c_encrypt_length@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_enctype_compare@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_free_state@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_fx_cf2_simple@k5crypto_3_MIT 1.7+dfsg
+ krb5_c_init_state@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_is_coll_proof_cksum@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_is_keyed_cksum@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_keyed_checksum_types@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_keylengths@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_make_checksum@k5crypto_3_MIT 1.8+dfsg
+ krb5_c_make_checksum_iov@k5crypto_3_MIT 1.7+dfsg
+ krb5_c_make_random_key@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_padding_length@k5crypto_3_MIT 1.7+dfsg
+ krb5_c_prf@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_prf_length@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_prfplus@k5crypto_3_MIT 1.14+dfsg
+ krb5_c_random_add_entropy@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_random_make_octets@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_random_os_entropy@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_random_seed@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_random_to_key@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_string_to_key@k5crypto_3_MIT 1.7+dfsg
+ krb5_c_string_to_key_with_params@k5crypto_3_MIT 1.7+dfsg
+ krb5_c_valid_cksumtype@k5crypto_3_MIT 1.6.dfsg.28
+ krb5_c_valid_enctype@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_verify_checksum@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_c_verify_checksum_iov@k5crypto_3_MIT 1.7+dfsg
+ krb5_calculate_checksum@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_checksum_size@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_cksumtype_to_string@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_decrypt@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_eblock_enctype@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_encrypt@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_encrypt_data@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_encrypt_size@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_enctype_to_name@k5crypto_3_MIT 1.9+dfsg~beta1
+ krb5_enctype_to_string@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_finish_key@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_finish_random_key@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_free_cksumtypes@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_init_random_key@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_k_create_key@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_decrypt@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_decrypt_iov@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_encrypt@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_encrypt_iov@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_free_key@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_key_enctype@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_key_keyblock@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_make_checksum@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_make_checksum_iov@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_prf@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_reference_key@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_verify_checksum@k5crypto_3_MIT 1.8+dfsg
+ krb5_k_verify_checksum_iov@k5crypto_3_MIT 1.8+dfsg
+ krb5_process_key@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_random_key@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_string_to_cksumtype@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_string_to_enctype@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_string_to_key@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_use_enctype@k5crypto_3_MIT 1.6.dfsg.2
+ krb5_verify_checksum@k5crypto_3_MIT 1.6.dfsg.2
+ krb5int_aes_decrypt@k5crypto_3_MIT 1.6.dfsg.2
+ krb5int_aes_enc_blk@k5crypto_3_MIT 1.10+dfsg~alpha1
+ krb5int_aes_enc_key@k5crypto_3_MIT 1.10+dfsg~alpha1
+ krb5int_aes_encrypt@k5crypto_3_MIT 1.6.dfsg.2
+ krb5int_arcfour_gsscrypt@k5crypto_3_MIT 1.8+dfsg
+ krb5int_c_combine_keys@k5crypto_3_MIT 1.6.dfsg.2
+ krb5int_c_copy_keyblock@k5crypto_3_MIT 1.8+dfsg
+ krb5int_c_copy_keyblock_contents@k5crypto_3_MIT 1.8+dfsg
+ krb5int_c_free_keyblock@k5crypto_3_MIT 1.6.dfsg.2
+ krb5int_c_free_keyblock_contents@k5crypto_3_MIT 1.6.dfsg.2
+ krb5int_c_init_keyblock@k5crypto_3_MIT 1.6.dfsg.2
+ krb5int_c_mandatory_cksumtype@k5crypto_3_MIT 1.6.dfsg.2
+ krb5int_c_weak_enctype@k5crypto_3_MIT 1.8+dfsg
+ krb5int_camellia_cbc_mac@k5crypto_3_MIT 1.9+dfsg~beta1
+ krb5int_cmac_checksum@k5crypto_3_MIT 1.9+dfsg~beta1
+ krb5int_derive_key@k5crypto_3_MIT 1.9+dfsg~beta2
+ krb5int_derive_random@k5crypto_3_MIT 1.15~beta1
+ krb5int_enc_aes128@k5crypto_3_MIT 1.9+dfsg~beta2
+ krb5int_enc_aes256@k5crypto_3_MIT 1.9+dfsg~beta2
+ krb5int_enc_arcfour@k5crypto_3_MIT 1.6.dfsg.2
+ krb5int_enc_camellia128@k5crypto_3_MIT 1.9+dfsg~beta2
+ krb5int_enc_camellia256@k5crypto_3_MIT 1.9+dfsg~beta2
+ krb5int_enc_des3@k5crypto_3_MIT 1.6.dfsg.2
+ krb5int_hash_md4@k5crypto_3_MIT 1.10+dfsg~alpha1
+ krb5int_hash_md5@k5crypto_3_MIT 1.6.dfsg.2
+ krb5int_hash_sha256@k5crypto_3_MIT 1.15~beta1
+ krb5int_hash_sha384@k5crypto_3_MIT 1.15~beta1
+ krb5int_hmac@k5crypto_3_MIT 1.8+dfsg
+ krb5int_nfold@k5crypto_3_MIT 1.10+dfsg~alpha1
+ mit_crc32@k5crypto_3_MIT 1.6.dfsg.2
+ valid_cksumtype@k5crypto_3_MIT 1.6.dfsg.2
+ valid_enctype@k5crypto_3_MIT 1.6.dfsg.2
diff --git a/debian/libkadm5clnt-mit11.install b/debian/libkadm5clnt-mit11.install
new file mode 100644
index 000000000..db6cb7986
--- /dev/null
+++ b/debian/libkadm5clnt-mit11.install
@@ -0,0 +1 @@
+usr/lib/*/libkadm5clnt_mit.so.11*
diff --git a/debian/libkadm5clnt-mit11.symbols b/debian/libkadm5clnt-mit11.symbols
new file mode 100644
index 000000000..f30dfedd5
--- /dev/null
+++ b/debian/libkadm5clnt-mit11.symbols
@@ -0,0 +1,122 @@
+libkadm5clnt_mit.so.11 libkadm5clnt-mit11 #MINVER#
+ HIDDEN@HIDDEN 1.15~beta1
+ _kadm5_check_handle@kadm5clnt_mit_11_MIT 1.15~beta1
+ _kadm5_chpass_principal_util@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_chpass_principal@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_chpass_principal_3@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_chpass_principal_util@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_create_policy@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_create_principal@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_create_principal_3@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_decrypt_key@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_delete_policy@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_delete_principal@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_destroy@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_flush@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_free_config_params@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_free_kadm5_key_data@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_free_key_data@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_free_name_list@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_free_policy_ent@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_free_principal_ent@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_free_strings@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_get_admin_service_name@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_get_config_params@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_get_policies@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_get_policy@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_get_principal@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_get_principal_keys@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_get_principals@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_get_privs@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_get_strings@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_init@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_init_anonymous@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_init_iprop@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_init_krb5_context@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_init_with_creds@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_init_with_password@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_init_with_skey@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_lock@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_modify_policy@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_modify_principal@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_purgekeys@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_randkey_principal@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_randkey_principal_3@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_rename_principal@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_set_string@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_setkey_principal@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_setkey_principal_3@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_setkey_principal_4@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_setv4key_principal@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5_unlock@kadm5clnt_mit_11_MIT 1.15~beta1
+ kadm5clnt_mit_11_MIT@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_aprof_finish@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_aprof_get_boolean@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_aprof_get_deltat@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_aprof_get_int32@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_aprof_get_string@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_aprof_getvals@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_aprof_init@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_flagnum_to_string@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_flags_to_strings@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_flagspec_to_mask@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_free_key_data_contents@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_keysalt_is_present@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_keysalt_iterate@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_klog_close@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_klog_init@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_klog_reopen@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_klog_set_context@kadm5clnt_mit_11_MIT 1.17
+ krb5_klog_syslog@kadm5clnt_mit_11_MIT 1.15~beta1
+ krb5_string_to_keysalts@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_chpass3_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_chpass_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_chrand3_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_chrand_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_chrand_ret@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_cpol_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_cprinc3_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_cprinc_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_dpol_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_dprinc_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_generic_ret@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_getpkeys_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_getpkeys_ret@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_getprivs_ret@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_gpol_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_gpol_ret@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_gpols_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_gpols_ret@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_gprinc_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_gprinc_ret@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_gprincs_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_gprincs_ret@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_kadm5_key_data@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_kadm5_policy_ent_rec@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_kadm5_principal_ent_rec@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_kadm5_ret_t@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_deltat@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_enctype@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_flags@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_int16@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_key_data_nocontents@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_key_salt_tuple@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_keyblock@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_kvno@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_octet@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_principal@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_salttype@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_timestamp@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_tl_data@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_ui_2@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_krb5_ui_4@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_mpol_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_mprinc_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_nullstring@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_nulltype@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_rprinc_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_setkey3_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_setkey4_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_setkey_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_setv4key_arg@kadm5clnt_mit_11_MIT 1.15~beta1
+ xdr_ui_4@kadm5clnt_mit_11_MIT 1.15~beta1
diff --git a/debian/libkadm5srv-mit11.install b/debian/libkadm5srv-mit11.install
new file mode 100644
index 000000000..01ae90c34
--- /dev/null
+++ b/debian/libkadm5srv-mit11.install
@@ -0,0 +1 @@
+usr/lib/*/libkadm5srv_mit.so.11*
diff --git a/debian/libkadm5srv-mit11.symbols b/debian/libkadm5srv-mit11.symbols
new file mode 100644
index 000000000..703ecba54
--- /dev/null
+++ b/debian/libkadm5srv-mit11.symbols
@@ -0,0 +1,142 @@
+libkadm5srv_mit.so.11 libkadm5srv-mit11 #MINVER#
+ HIDDEN@HIDDEN 1.15~beta1
+ _kadm5_check_handle@kadm5srv_mit_11_MIT 1.15~beta1
+ _kadm5_chpass_principal_util@kadm5srv_mit_11_MIT 1.15~beta1
+ hist_princ@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_chpass_principal@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_chpass_principal_3@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_chpass_principal_util@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_create_policy@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_create_principal@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_create_principal_3@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_decrypt_key@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_delete_policy@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_delete_principal@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_destroy@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_flush@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_free_config_params@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_free_kadm5_key_data@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_free_key_data@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_free_name_list@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_free_policy_ent@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_free_principal_ent@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_free_strings@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_get_config_params@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_get_policies@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_get_policy@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_get_principal@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_get_principal_keys@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_get_principals@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_get_privs@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_get_strings@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_init@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_init_anonymous@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_init_iprop@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_init_krb5_context@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_init_with_creds@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_init_with_password@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_init_with_skey@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_lock@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_modify_policy@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_modify_principal@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_purgekeys@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_randkey_principal@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_randkey_principal_3@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_rename_principal@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_set_string@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_set_use_password_server@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_setkey_principal@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_setkey_principal_3@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_setkey_principal_4@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_setv4key_principal@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5_unlock@kadm5srv_mit_11_MIT 1.15~beta1
+ kadm5srv_mit_11_MIT@kadm5srv_mit_11_MIT 1.15~beta1
+ kdb_delete_entry@kadm5srv_mit_11_MIT 1.15~beta1
+ kdb_free_entry@kadm5srv_mit_11_MIT 1.15~beta1
+ kdb_init_hist@kadm5srv_mit_11_MIT 1.15~beta1
+ kdb_init_master@kadm5srv_mit_11_MIT 1.15~beta1
+ kdb_iter_entry@kadm5srv_mit_11_MIT 1.15~beta1
+ kdb_put_entry@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_aprof_finish@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_aprof_get_boolean@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_aprof_get_deltat@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_aprof_get_int32@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_aprof_get_string@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_aprof_get_string_all@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_aprof_getvals@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_aprof_init@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_copy_key_data_contents@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_flagnum_to_string@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_flags_to_strings@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_flagspec_to_mask@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_free_key_data_contents@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_keysalt_is_present@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_keysalt_iterate@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_klog_close@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_klog_init@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_klog_reopen@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_klog_set_context@kadm5srv_mit_11_MIT 1.17
+ krb5_klog_syslog@kadm5srv_mit_11_MIT 1.15~beta1
+ krb5_string_to_keysalts@kadm5srv_mit_11_MIT 1.15~beta1
+ master_db@kadm5srv_mit_11_MIT 1.15~beta1
+ master_princ@kadm5srv_mit_11_MIT 1.15~beta1
+ osa_free_princ_ent@kadm5srv_mit_11_MIT 1.15~beta1
+ passwd_check@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_chpass3_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_chpass_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_chrand3_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_chrand_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_chrand_ret@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_cpol_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_cprinc3_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_cprinc_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_dpol_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_dprinc_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_generic_ret@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_getpkeys_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_getpkeys_ret@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_getprivs_ret@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_gpol_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_gpol_ret@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_gpols_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_gpols_ret@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_gprinc_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_gprinc_ret@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_gprincs_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_gprincs_ret@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_gstrings_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_gstrings_ret@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_kadm5_policy_ent_rec@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_kadm5_principal_ent_rec@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_kadm5_ret_t@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_deltat@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_enctype@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_flags@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_int16@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_key_data@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_key_data_nocontents@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_key_salt_tuple@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_keyblock@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_kvno@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_octet@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_principal@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_salttype@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_string_attr@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_timestamp@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_tl_data@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_ui_2@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_krb5_ui_4@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_mpol_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_mprinc_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_nullstring@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_nulltype@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_osa_princ_ent_rec@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_osa_pw_hist_ent@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_purgekeys_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_rprinc_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_setkey3_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_setkey4_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_setkey_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_setv4key_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_sstring_arg@kadm5srv_mit_11_MIT 1.15~beta1
+ xdr_ui_4@kadm5srv_mit_11_MIT 1.15~beta1
diff --git a/debian/libkdb-ldap1.install b/debian/libkdb-ldap1.install
new file mode 100644
index 000000000..0de326a9e
--- /dev/null
+++ b/debian/libkdb-ldap1.install
@@ -0,0 +1 @@
+usr/lib/*/libkdb_ldap*so.*
diff --git a/debian/libkdb5-9.install b/debian/libkdb5-9.install
new file mode 100644
index 000000000..6344e3c60
--- /dev/null
+++ b/debian/libkdb5-9.install
@@ -0,0 +1 @@
+usr/lib/*/libkdb5.so.*
diff --git a/debian/libkrad-dev.install b/debian/libkrad-dev.install
new file mode 100644
index 000000000..93111dda3
--- /dev/null
+++ b/debian/libkrad-dev.install
@@ -0,0 +1,2 @@
+usr/include/krad.h
+usr/lib/*/libkrad.so
diff --git a/debian/libkrad0.install b/debian/libkrad0.install
new file mode 100644
index 000000000..bb3a01061
--- /dev/null
+++ b/debian/libkrad0.install
@@ -0,0 +1 @@
+usr/lib/*/libkrad.so.0*
diff --git a/debian/libkrad0.symbols b/debian/libkrad0.symbols
new file mode 100644
index 000000000..5d4de6b65
--- /dev/null
+++ b/debian/libkrad0.symbols
@@ -0,0 +1,26 @@
+libkrad.so.0 libkrad0 #MINVER#
+ HIDDEN@HIDDEN 1.12~alpha1+dfsg
+ krad_0_MIT@krad_0_MIT 1.12~alpha1+dfsg
+ krad_attr_name2num@krad_0_MIT 1.12~alpha1+dfsg
+ krad_attr_num2name@krad_0_MIT 1.12~alpha1+dfsg
+ krad_attrset_add@krad_0_MIT 1.12~alpha1+dfsg
+ krad_attrset_add_number@krad_0_MIT 1.12~alpha1+dfsg
+ krad_attrset_copy@krad_0_MIT 1.12~alpha1+dfsg
+ krad_attrset_del@krad_0_MIT 1.12~alpha1+dfsg
+ krad_attrset_free@krad_0_MIT 1.12~alpha1+dfsg
+ krad_attrset_get@krad_0_MIT 1.12~alpha1+dfsg
+ krad_attrset_new@krad_0_MIT 1.12~alpha1+dfsg
+ krad_client_free@krad_0_MIT 1.12~alpha1+dfsg
+ krad_client_new@krad_0_MIT 1.12~alpha1+dfsg
+ krad_client_send@krad_0_MIT 1.12~alpha1+dfsg
+ krad_code_name2num@krad_0_MIT 1.12~alpha1+dfsg
+ krad_code_num2name@krad_0_MIT 1.12~alpha1+dfsg
+ krad_packet_bytes_needed@krad_0_MIT 1.12~alpha1+dfsg
+ krad_packet_decode_request@krad_0_MIT 1.12~alpha1+dfsg
+ krad_packet_decode_response@krad_0_MIT 1.12~alpha1+dfsg
+ krad_packet_encode@krad_0_MIT 1.12~alpha1+dfsg
+ krad_packet_free@krad_0_MIT 1.12~alpha1+dfsg
+ krad_packet_get_attr@krad_0_MIT 1.12~alpha1+dfsg
+ krad_packet_get_code@krad_0_MIT 1.12~alpha1+dfsg
+ krad_packet_new_request@krad_0_MIT 1.12~alpha1+dfsg
+ krad_packet_new_response@krad_0_MIT 1.12~alpha1+dfsg
diff --git a/debian/libkrb5-3.dirs.in b/debian/libkrb5-3.dirs.in
new file mode 100644
index 000000000..27b1e69b3
--- /dev/null
+++ b/debian/libkrb5-3.dirs.in
@@ -0,0 +1 @@
+usr/lib/${DEB_HOST_MULTIARCH}/krb5/plugins/libkrb5
diff --git a/debian/libkrb5-3.docs b/debian/libkrb5-3.docs
new file mode 100644
index 000000000..151b8ffef
--- /dev/null
+++ b/debian/libkrb5-3.docs
@@ -0,0 +1,2 @@
+README
+debian/README.Debian
diff --git a/debian/libkrb5-3.install b/debian/libkrb5-3.install
new file mode 100644
index 000000000..ddc35ab19
--- /dev/null
+++ b/debian/libkrb5-3.install
@@ -0,0 +1,2 @@
+usr/lib/*/libkrb5.so.3*
+usr/lib/*/krb5/plugins/preauth/spake.so
diff --git a/debian/libkrb5-3.lintian-overrides b/debian/libkrb5-3.lintian-overrides
new file mode 100644
index 000000000..604db7efe
--- /dev/null
+++ b/debian/libkrb5-3.lintian-overrides
@@ -0,0 +1 @@
+libkrb5-3: package-contains-empty-directory */plugins/libkrb5/
diff --git a/debian/libkrb5-3.symbols b/debian/libkrb5-3.symbols
new file mode 100644
index 000000000..f1269d551
--- /dev/null
+++ b/debian/libkrb5-3.symbols
@@ -0,0 +1,682 @@
+libkrb5.so.3 libkrb5-3 #MINVER#
+ HIDDEN@HIDDEN 1.6.dfsg.2
+ _krb5_conf_boolean@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_ad_kdcissued@krb5_3_MIT 1.8+dfsg
+ decode_krb5_ad_signedpath@krb5_3_MIT 1.8+dfsg
+ decode_krb5_ap_rep@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_ap_rep_enc_part@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_ap_req@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_as_rep@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_as_req@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_authdata@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_authenticator@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_cammac@krb5_3_MIT 1.14+dfsg
+ decode_krb5_cred@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_enc_cred_part@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_enc_data@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_enc_kdc_rep_part@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_enc_priv_part@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_enc_sam_response_enc_2@krb5_3_MIT 1.7dfsg
+ decode_krb5_enc_tkt_part@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_encryption_key@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_error@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_etype_info2@krb5_3_MIT 1.7dfsg
+ decode_krb5_etype_info@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_fast_req@krb5_3_MIT 1.7dfsg
+ decode_krb5_fast_response@krb5_3_MIT 1.11+dfsg
+ decode_krb5_iakerb_finished@krb5_3_MIT 1.9+dfsg~beta1
+ decode_krb5_iakerb_header@krb5_3_MIT 1.9+dfsg~beta1
+ decode_krb5_kdc_req_body@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_kkdcp_message@krb5_3_MIT 1.13~alpha1+dfsg
+ decode_krb5_otp_tokeninfo@krb5_3_MIT 1.11+dfsg
+ decode_krb5_pa_enc_ts@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_pa_for_user@krb5_3_MIT 1.7dfsg
+ decode_krb5_pa_fx_fast_reply@krb5_3_MIT 1.11+dfsg
+ decode_krb5_pa_fx_fast_request@krb5_3_MIT 1.7dfsg
+ decode_krb5_pa_otp_challenge@krb5_3_MIT 1.11+dfsg
+ decode_krb5_pa_otp_enc_req@krb5_3_MIT 1.11+dfsg
+ decode_krb5_pa_otp_req@krb5_3_MIT 1.11+dfsg
+ decode_krb5_pa_pac_req@krb5_3_MIT 1.7dfsg
+ decode_krb5_pa_s4u_x509_user@krb5_3_MIT 1.8+dfsg
+ decode_krb5_pa_spake@krb5_3_MIT 1.17
+ decode_krb5_padata_sequence@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_priv@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_safe@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_sam_challenge_2@krb5_3_MIT 1.11+dfsg
+ decode_krb5_sam_challenge_2_body@krb5_3_MIT 1.11+dfsg
+ decode_krb5_sam_response_2@krb5_3_MIT 1.7dfsg
+ decode_krb5_secure_cookie@krb5_3_MIT 1.14+dfsg
+ decode_krb5_setpw_req@krb5_3_MIT 1.7dfsg
+ decode_krb5_spake_factor@krb5_3_MIT 1.17
+ decode_krb5_tgs_rep@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_tgs_req@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_ticket@krb5_3_MIT 1.6.dfsg.2
+ decode_krb5_typed_data@krb5_3_MIT 1.7dfsg
+ decode_utf8_strings@krb5_3_MIT 1.14+dfsg
+ encode_krb5_ad_kdcissued@krb5_3_MIT 1.8+dfsg
+ encode_krb5_ad_signedpath@krb5_3_MIT 1.8+dfsg
+ encode_krb5_ad_signedpath_data@krb5_3_MIT 1.8+dfsg
+ encode_krb5_ap_rep@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_ap_rep_enc_part@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_ap_req@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_as_rep@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_as_req@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_authdata@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_authenticator@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_cammac@krb5_3_MIT 1.14+dfsg
+ encode_krb5_checksum@krb5_3_MIT 1.8+dfsg
+ encode_krb5_cred@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_enc_cred_part@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_enc_data@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_enc_kdc_rep_part@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_enc_priv_part@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_enc_sam_response_enc_2@krb5_3_MIT 1.7dfsg
+ encode_krb5_enc_tkt_part@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_encryption_key@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_error@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_etype_info2@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_etype_info@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_fast_response@krb5_3_MIT 1.7dfsg
+ encode_krb5_iakerb_finished@krb5_3_MIT 1.9+dfsg~beta1
+ encode_krb5_iakerb_header@krb5_3_MIT 1.9+dfsg~beta1
+ encode_krb5_kdc_req_body@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_kkdcp_message@krb5_3_MIT 1.13~alpha1+dfsg
+ encode_krb5_otp_tokeninfo@krb5_3_MIT 1.11+dfsg
+ encode_krb5_pa_enc_ts@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_pa_for_user@krb5_3_MIT 1.7dfsg
+ encode_krb5_pa_fx_fast_reply@krb5_3_MIT 1.7dfsg
+ encode_krb5_pa_otp_challenge@krb5_3_MIT 1.11+dfsg
+ encode_krb5_pa_otp_enc_req@krb5_3_MIT 1.11+dfsg
+ encode_krb5_pa_otp_req@krb5_3_MIT 1.11+dfsg
+ encode_krb5_pa_s4u_x509_user@krb5_3_MIT 1.8+dfsg
+ encode_krb5_pa_spake@krb5_3_MIT 1.17
+ encode_krb5_padata_sequence@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_pkinit_supp_pub_info@krb5_3_MIT 1.10+dfsg~alpha1
+ encode_krb5_priv@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_s4u_userid@krb5_3_MIT 1.8+dfsg
+ encode_krb5_safe@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_sam_challenge_2@krb5_3_MIT 1.9+dfsg~beta1
+ encode_krb5_sam_challenge_2_body@krb5_3_MIT 1.9+dfsg~beta1
+ encode_krb5_sam_response_2@krb5_3_MIT 1.7dfsg
+ encode_krb5_secure_cookie@krb5_3_MIT 1.14+dfsg
+ encode_krb5_sp80056a_other_info@krb5_3_MIT 1.10+dfsg~alpha1
+ encode_krb5_spake_factor@krb5_3_MIT 1.17
+ encode_krb5_tgs_rep@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_tgs_req@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_ticket@krb5_3_MIT 1.6.dfsg.2
+ encode_krb5_typed_data@krb5_3_MIT 1.10+dfsg~alpha1
+ encode_utf8_strings@krb5_3_MIT 1.14+dfsg
+ et_asn1_error_table@krb5_3_MIT 1.6.dfsg.2
+ et_k524_error_table@krb5_3_MIT 1.6.dfsg.2
+ et_kdb5_error_table@krb5_3_MIT 1.6.dfsg.2
+ et_krb5_error_table@krb5_3_MIT 1.6.dfsg.2
+ et_kv5m_error_table@krb5_3_MIT 1.6.dfsg.2
+ et_prof_error_table@krb5_3_MIT 1.6.dfsg.2
+ initialize_asn1_error_table@krb5_3_MIT 1.6.dfsg.2
+ initialize_k524_error_table@krb5_3_MIT 1.6.dfsg.2
+ initialize_k5e1_error_table@krb5_3_MIT 1.9+dfsg~beta1
+ initialize_kdb5_error_table@krb5_3_MIT 1.6.dfsg.2
+ initialize_krb5_error_table@krb5_3_MIT 1.6.dfsg.2
+ initialize_kv5m_error_table@krb5_3_MIT 1.6.dfsg.2
+ initialize_prof_error_table@krb5_3_MIT 1.6.dfsg.2
+ k5_authind_decode@krb5_3_MIT 1.15~beta1
+ k5_build_conf_principals@krb5_3_MIT 1.12~alpha1+dfsg
+ k5_ccselect_free_context@krb5_3_MIT 1.10+dfsg~alpha1
+ k5_change_error_message_code@krb5_3_MIT 1.13~alpha1+dfsg
+ k5_etypes_contains@krb5_3_MIT 1.11+dfsg
+ k5_expand_path_tokens@krb5_3_MIT 1.11+dfsg
+ k5_expand_path_tokens_extra@krb5_3_MIT 1.11+dfsg
+ k5_free_algorithm_identifier@krb5_3_MIT 1.11+dfsg
+ k5_free_cammac@krb5_3_MIT 1.14+dfsg
+ k5_free_data_ptr_list@krb5_3_MIT 1.14+dfsg
+ k5_free_kkdcp_message@krb5_3_MIT 1.13~alpha1+dfsg
+ k5_free_otp_tokeninfo@krb5_3_MIT 1.11+dfsg
+ k5_free_pa_otp_challenge@krb5_3_MIT 1.11+dfsg
+ k5_free_pa_otp_req@krb5_3_MIT 1.11+dfsg
+ k5_free_pa_spake@krb5_3_MIT 1.17
+ k5_free_secure_cookie@krb5_3_MIT 1.14+dfsg
+ k5_free_serverlist@krb5_3_MIT 1.10+dfsg~alpha1
+ k5_free_spake_factor@krb5_3_MIT 1.17
+ k5_hostrealm_free_context@krb5_3_MIT 1.12~alpha1+dfsg
+ k5_init_trace@krb5_3_MIT 1.12~alpha1+dfsg
+ k5_is_string_numeric@krb5_3_MIT 1.15~beta1
+ k5_kt_get_principal@krb5_3_MIT 1.10+dfsg~alpha1
+ k5_localauth_free_context@krb5_3_MIT 1.12~alpha1+dfsg
+ k5_locate_kdc@krb5_3_MIT 1.10+dfsg~alpha1
+ k5_marshal_cred@krb5_3_MIT 1.13~alpha1+dfsg
+ k5_marshal_princ@krb5_3_MIT 1.13~alpha1+dfsg
+ k5_os_free_context@krb5_3_MIT 1.12~alpha1+dfsg
+ k5_os_init_context@krb5_3_MIT 1.12~alpha1+dfsg
+ k5_parse_host_string@krb5_3_MIT 1.15~beta1
+ k5_plugin_free_modules@krb5_3_MIT 1.9+dfsg~beta1
+ k5_plugin_load@krb5_3_MIT 1.9+dfsg~beta1
+ k5_plugin_load_all@krb5_3_MIT 1.9+dfsg~beta1
+ k5_plugin_register@krb5_3_MIT 1.9+dfsg~beta1
+ k5_plugin_register_dyn@krb5_3_MIT 1.10+dfsg~alpha1
+ k5_unmarshal_cred@krb5_3_MIT 1.13~alpha1+dfsg
+ k5_unmarshal_princ@krb5_3_MIT 1.13~alpha1+dfsg
+ k5_unwrap_cammac_svc@krb5_3_MIT 1.15~beta1
+ k5_zapfree_pa_data@krb5_3_MIT 1.14+dfsg
+ krb524_convert_creds_kdc@krb5_3_MIT 1.6.dfsg.2
+ krb524_init_ets@krb5_3_MIT 1.6.dfsg.2
+ krb5_3_MIT@krb5_3_MIT 1.6.dfsg.2
+ krb5_425_conv_principal@krb5_3_MIT 1.6.dfsg.2
+ krb5_524_conv_principal@krb5_3_MIT 1.6.dfsg.2
+ krb5_524_convert_creds@krb5_3_MIT 1.6.dfsg.2
+ krb5_address_compare@krb5_3_MIT 1.6.dfsg.2
+ krb5_address_order@krb5_3_MIT 1.6.dfsg.2
+ krb5_address_search@krb5_3_MIT 1.6.dfsg.2
+ krb5_allow_weak_crypto@krb5_3_MIT 1.8+dfsg
+ krb5_aname_to_localname@krb5_3_MIT 1.6.dfsg.2
+ krb5_anonymous_principal@krb5_3_MIT 1.8+dfsg
+ krb5_anonymous_realm@krb5_3_MIT 1.8+dfsg
+ krb5_appdefault_boolean@krb5_3_MIT 1.6.dfsg.2
+ krb5_appdefault_string@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_free@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_genaddrs@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_get_authdata_context@krb5_3_MIT 1.8+dfsg
+ krb5_auth_con_get_checksum_func@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getaddrs@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getauthenticator@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getflags@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getivector@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getkey@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getkey_k@krb5_3_MIT 1.8+dfsg
+ krb5_auth_con_getlocalseqnumber@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getlocalsubkey@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getpermetypes@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getrcache@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getrecvsubkey@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getrecvsubkey_k@krb5_3_MIT 1.8+dfsg
+ krb5_auth_con_getremoteseqnumber@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getremotesubkey@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getsendsubkey@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_getsendsubkey_k@krb5_3_MIT 1.8+dfsg
+ krb5_auth_con_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_initivector@krb5_3_MIT 1.16
+ krb5_auth_con_set_authdata_context@krb5_3_MIT 1.8+dfsg
+ krb5_auth_con_set_checksum_func@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_set_req_cksumtype@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_set_safe_cksumtype@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_setaddrs@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_setflags@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_setivector@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_setpermetypes@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_setports@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_setrcache@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_setrecvsubkey@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_setrecvsubkey_k@krb5_3_MIT 1.9+dfsg~beta1
+ krb5_auth_con_setsendsubkey@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_con_setsendsubkey_k@krb5_3_MIT 1.9+dfsg~beta1
+ krb5_auth_con_setuseruserkey@krb5_3_MIT 1.6.dfsg.2
+ krb5_auth_to_rep@krb5_3_MIT 1.6.dfsg.2
+ krb5_authdata_context_copy@krb5_3_MIT 1.8+dfsg
+ krb5_authdata_context_free@krb5_3_MIT 1.8+dfsg
+ krb5_authdata_context_init@krb5_3_MIT 1.8+dfsg
+ krb5_authdata_delete_attribute@krb5_3_MIT 1.8+dfsg
+ krb5_authdata_export_attributes@krb5_3_MIT 1.8+dfsg
+ krb5_authdata_export_authdata@krb5_3_MIT 1.8+dfsg
+ krb5_authdata_export_internal@krb5_3_MIT 1.8+dfsg
+ krb5_authdata_free_internal@krb5_3_MIT 1.8+dfsg
+ krb5_authdata_get_attribute@krb5_3_MIT 1.8+dfsg
+ krb5_authdata_get_attribute_types@krb5_3_MIT 1.8+dfsg
+ krb5_authdata_import_attributes@krb5_3_MIT 1.8+dfsg
+ krb5_authdata_set_attribute@krb5_3_MIT 1.8+dfsg
+ krb5_build_principal@krb5_3_MIT 1.6.dfsg.2
+ krb5_build_principal_alloc_va@krb5_3_MIT 1.7dfsg
+ krb5_build_principal_ext@krb5_3_MIT 1.6.dfsg.2
+ krb5_build_principal_va@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_cache_match@krb5_3_MIT 1.10+dfsg~alpha1
+ krb5_cc_close@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_copy_creds@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_default@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_default_name@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_destroy@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_dfl_ops@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_dup@krb5_3_MIT 1.9+dfsg~beta1
+ krb5_cc_end_seq_get@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_file_ops@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_gen_new@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_get_config@krb5_3_MIT 1.8+dfsg
+ krb5_cc_get_full_name@krb5_3_MIT 1.10+dfsg~alpha1
+ krb5_cc_get_name@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_get_principal@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_get_type@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_initialize@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_move@krb5_3_MIT 1.11+dfsg
+ krb5_cc_new_unique@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_next_cred@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_register@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_remove_cred@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_resolve@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_retrieve_cred@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_select@krb5_3_MIT 1.10+dfsg~alpha1
+ krb5_cc_set_config@krb5_3_MIT 1.8+dfsg
+ krb5_cc_set_default_name@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_set_flags@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_start_seq_get@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_store_cred@krb5_3_MIT 1.6.dfsg.2
+ krb5_cc_support_switch@krb5_3_MIT 1.10+dfsg~alpha1
+ krb5_cc_switch@krb5_3_MIT 1.10+dfsg~alpha1
+ krb5_cccol_cursor_free@krb5_3_MIT 1.6.dfsg.2
+ krb5_cccol_cursor_new@krb5_3_MIT 1.6.dfsg.2
+ krb5_cccol_cursor_next@krb5_3_MIT 1.6.dfsg.2
+ krb5_cccol_have_content@krb5_3_MIT 1.11+dfsg
+ krb5_change_cache@krb5_3_MIT 1.6.dfsg.2
+ krb5_change_password@krb5_3_MIT 1.6.dfsg.2
+ krb5_check_clockskew@krb5_3_MIT 1.10+dfsg~alpha1
+ krb5_check_transited_list@krb5_3_MIT 1.6.dfsg.2
+ krb5_chpw_message@krb5_3_MIT 1.11+dfsg
+ krb5_chpw_result_code_string@krb5_3_MIT 1.6.dfsg.2
+ krb5_clear_error_message@krb5_3_MIT 1.6.dfsg.2
+ krb5_copy_addr@krb5_3_MIT 1.6.dfsg.2
+ krb5_copy_addresses@krb5_3_MIT 1.6.dfsg.2
+ krb5_copy_authdata@krb5_3_MIT 1.6.dfsg.2
+ krb5_copy_authenticator@krb5_3_MIT 1.6.dfsg.2
+ krb5_copy_checksum@krb5_3_MIT 1.6.dfsg.2
+ krb5_copy_context@krb5_3_MIT 1.6.dfsg.2
+ krb5_copy_creds@krb5_3_MIT 1.6.dfsg.2
+ krb5_copy_data@krb5_3_MIT 1.6.dfsg.2
+ krb5_copy_error_message@krb5_3_MIT 1.7dfsg
+ krb5_copy_keyblock@krb5_3_MIT 1.6.dfsg.2
+ krb5_copy_keyblock_contents@krb5_3_MIT 1.6.dfsg.2
+ krb5_copy_principal@krb5_3_MIT 1.6.dfsg.2
+ krb5_copy_ticket@krb5_3_MIT 1.6.dfsg.2
+ krb5_crypto_us_timeofday@krb5_3_MIT 1.6.dfsg.2
+ krb5_decode_authdata_container@krb5_3_MIT 1.7dfsg
+ krb5_decode_ticket@krb5_3_MIT 1.6.dfsg.2
+ krb5_decrypt_tkt_part@krb5_3_MIT 1.6.dfsg.2
+ krb5_deltat_to_string@krb5_3_MIT 1.6.dfsg.2
+ krb5_encode_authdata_container@krb5_3_MIT 1.7dfsg
+ krb5_encode_kdc_rep@krb5_3_MIT 1.6.dfsg.2
+ krb5_encrypt_helper@krb5_3_MIT 1.6.dfsg.2
+ krb5_encrypt_tkt_part@krb5_3_MIT 1.6.dfsg.2
+ krb5_expand_hostname@krb5_3_MIT 1.15~beta1
+ krb5_externalize_data@krb5_3_MIT 1.6.dfsg.2
+ krb5_externalize_opaque@krb5_3_MIT 1.6.dfsg.2
+ krb5_fcc_ops@krb5_3_MIT 1.6.dfsg.2
+ krb5_find_authdata@krb5_3_MIT 1.10+dfsg~alpha1
+ krb5_find_serializer@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_ad_kdcissued@krb5_3_MIT 1.8+dfsg
+ krb5_free_ad_signedpath@krb5_3_MIT 1.8+dfsg
+ krb5_free_address@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_addresses@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_ap_rep@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_ap_rep_enc_part@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_ap_req@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_authdata@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_authenticator@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_authenticator_contents@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_checksum@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_checksum_contents@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_config_files@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_context@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_cred@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_cred_contents@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_cred_enc_part@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_creds@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_data@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_data_contents@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_default_realm@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_enc_data@krb5_3_MIT 1.7dfsg
+ krb5_free_enc_kdc_rep_part@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_enc_sam_response_enc_2@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_enc_sam_response_enc_2_contents@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_enc_tkt_part@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_enctypes@krb5_3_MIT 1.12~alpha1+dfsg
+ krb5_free_error@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_error_message@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_etype_info@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_fast_armored_req@krb5_3_MIT 1.7dfsg
+ krb5_free_fast_req@krb5_3_MIT 1.7dfsg
+ krb5_free_fast_response@krb5_3_MIT 1.11+dfsg
+ krb5_free_host_realm@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_iakerb_finished@krb5_3_MIT 1.9+dfsg~beta1
+ krb5_free_iakerb_header@krb5_3_MIT 1.9+dfsg~beta1
+ krb5_free_kdc_rep@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_kdc_req@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_keyblock@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_keyblock_contents@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_keytab_entry_contents@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_last_req@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_octet_data@krb5_3_MIT 1.10+dfsg~alpha1
+ krb5_free_pa_data@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_pa_enc_ts@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_pa_for_user@krb5_3_MIT 1.7dfsg
+ krb5_free_pa_pac_req@krb5_3_MIT 1.7dfsg
+ krb5_free_pa_s4u_x509_user@krb5_3_MIT 1.8+dfsg
+ krb5_free_principal@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_priv@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_priv_enc_part@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_realm_tree@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_safe@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_sam_challenge_2@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_sam_challenge_2_body@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_sam_challenge_2_body_contents@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_sam_challenge_2_contents@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_sam_response_2@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_sam_response_2_contents@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_string@krb5_3_MIT 1.10+dfsg~alpha1
+ krb5_free_tgt_creds@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_ticket@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_tickets@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_tkt_authent@krb5_3_MIT 1.6.dfsg.2
+ krb5_free_unparsed_name@krb5_3_MIT 1.6.dfsg.2
+ krb5_fwd_tgt_creds@krb5_3_MIT 1.6.dfsg.2
+ krb5_gen_portaddr@krb5_3_MIT 1.6.dfsg.2
+ krb5_gen_replay_name@krb5_3_MIT 1.6.dfsg.2
+ krb5_generate_seq_number@krb5_3_MIT 1.6.dfsg.2
+ krb5_generate_subkey@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_cred_via_tkt@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_credentials@krb5_3_MIT 1.10+dfsg~
+ krb5_get_credentials_for_proxy@krb5_3_MIT 1.8+dfsg
+ krb5_get_credentials_for_user@krb5_3_MIT 1.8+dfsg
+ krb5_get_credentials_renew@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_credentials_validate@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_default_config_files@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_default_in_tkt_ktypes@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_default_realm@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_error_message@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_etype_info@krb5_3_MIT 1.17
+ krb5_get_fallback_host_realm@krb5_3_MIT 1.7dfsg
+ krb5_get_host_realm@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_in_tkt_with_keytab@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_in_tkt_with_password@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_in_tkt_with_skey@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_keytab@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_alloc@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_free@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_free_pa@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_get_fast_flags@krb5_3_MIT 1.8+dfsg
+ krb5_get_init_creds_opt_get_pa@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_set_address_list@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_set_anonymous@krb5_3_MIT 1.8+dfsg
+ krb5_get_init_creds_opt_set_canonicalize@krb5_3_MIT 1.7dfsg
+ krb5_get_init_creds_opt_set_change_password_prompt@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_set_etype_list@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_set_expire_callback@krb5_3_MIT 1.9+dfsg~beta1
+ krb5_get_init_creds_opt_set_fast_ccache@krb5_3_MIT 1.9+dfsg~beta1
+ krb5_get_init_creds_opt_set_fast_ccache_name@krb5_3_MIT 1.8+dfsg
+ krb5_get_init_creds_opt_set_fast_flags@krb5_3_MIT 1.8+dfsg
+ krb5_get_init_creds_opt_set_forwardable@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_set_in_ccache@krb5_3_MIT 1.11+dfsg
+ krb5_get_init_creds_opt_set_out_ccache@krb5_3_MIT 1.8+dfsg
+ krb5_get_init_creds_opt_set_pa@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_set_pac_request@krb5_3_MIT 1.15~beta1
+ krb5_get_init_creds_opt_set_preauth_list@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_set_proxiable@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_set_renew_life@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_set_responder@krb5_3_MIT 1.11+dfsg
+ krb5_get_init_creds_opt_set_salt@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_opt_set_tkt_life@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_init_creds_password@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_notification_message@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_permitted_enctypes@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_profile@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_prompt_types@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_realm_domain@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_renewed_creds@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_server_rcache@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_tgs_ktypes@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_time_offsets@krb5_3_MIT 1.6.dfsg.2
+ krb5_get_validated_creds@krb5_3_MIT 1.6.dfsg.2
+ krb5_init_context@krb5_3_MIT 1.6.dfsg.2
+ krb5_init_context_profile@krb5_3_MIT 1.10+dfsg~alpha1
+ krb5_init_creds_free@krb5_3_MIT 1.8+dfsg
+ krb5_init_creds_get@krb5_3_MIT 1.8+dfsg
+ krb5_init_creds_get_creds@krb5_3_MIT 1.8+dfsg
+ krb5_init_creds_get_error@krb5_3_MIT 1.8+dfsg
+ krb5_init_creds_get_times@krb5_3_MIT 1.8+dfsg
+ krb5_init_creds_init@krb5_3_MIT 1.8+dfsg
+ krb5_init_creds_set_keytab@krb5_3_MIT 1.8+dfsg
+ krb5_init_creds_set_password@krb5_3_MIT 1.8+dfsg
+ krb5_init_creds_set_service@krb5_3_MIT 1.8+dfsg
+ krb5_init_creds_step@krb5_3_MIT 1.8.1+dfsg
+ krb5_init_keyblock@krb5_3_MIT 1.6.dfsg.2
+ krb5_init_secure_context@krb5_3_MIT 1.6.dfsg.2
+ krb5_internalize_opaque@krb5_3_MIT 1.6.dfsg.2
+ krb5_is_config_principal@krb5_3_MIT 1.8+dfsg
+ krb5_is_permitted_enctype@krb5_3_MIT 1.6.dfsg.2
+ krb5_is_referral_realm@krb5_3_MIT 1.6.dfsg.2
+ krb5_is_thread_safe@krb5_3_MIT 1.6.dfsg.2
+ krb5_kdc_rep_decrypt_proc@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_add_entry@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_client_default@krb5_3_MIT 1.11+dfsg
+ krb5_kt_close@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_default@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_default_name@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_dfl_ops@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_dup@krb5_3_MIT 1.12~alpha1+dfsg
+ krb5_kt_end_seq_get@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_free_entry@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_get_entry@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_get_name@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_get_type@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_have_content@krb5_3_MIT 1.11+dfsg
+ krb5_kt_next_entry@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_read_service_key@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_register@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_remove_entry@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_resolve@krb5_3_MIT 1.6.dfsg.2
+ krb5_kt_start_seq_get@krb5_3_MIT 1.6.dfsg.2
+ krb5_ktf_ops@krb5_3_MIT 1.6.dfsg.2
+ krb5_ktf_writable_ops@krb5_3_MIT 1.6.dfsg.2
+ krb5_kts_ops@krb5_3_MIT 1.6.dfsg.2
+ krb5_kuserok@krb5_3_MIT 1.6.dfsg.2
+ krb5_lock_file@krb5_3_MIT 1.6.dfsg.2
+ krb5_make_authdata_kdc_issued@krb5_3_MIT 1.8+dfsg
+ krb5_make_full_ipaddr@krb5_3_MIT 1.6.dfsg.2
+ krb5_make_fulladdr@krb5_3_MIT 1.6.dfsg.2
+ krb5_mcc_ops@krb5_3_MIT 1.6.dfsg.2
+ krb5_merge_authdata@krb5_3_MIT 1.7dfsg
+ krb5_mk_1cred@krb5_3_MIT 1.6.dfsg.2
+ krb5_mk_error@krb5_3_MIT 1.6.dfsg.2
+ krb5_mk_ncred@krb5_3_MIT 1.6.dfsg.2
+ krb5_mk_priv@krb5_3_MIT 1.6.dfsg.2
+ krb5_mk_rep@krb5_3_MIT 1.7dfsg
+ krb5_mk_rep_dce@krb5_3_MIT 1.7dfsg
+ krb5_mk_req@krb5_3_MIT 1.7dfsg
+ krb5_mk_req_extended@krb5_3_MIT 1.7dfsg
+ krb5_mk_safe@krb5_3_MIT 1.6.dfsg.2
+ krb5_net_read@krb5_3_MIT 1.6.dfsg.2
+ krb5_net_write@krb5_3_MIT 1.6.dfsg.2
+ krb5_os_localaddr@krb5_3_MIT 1.6.dfsg.2
+ krb5_overridekeyname@krb5_3_MIT 1.6.dfsg.2
+ krb5_pac_add_buffer@krb5_3_MIT 1.7dfsg
+ krb5_pac_free@krb5_3_MIT 1.7dfsg
+ krb5_pac_get_buffer@krb5_3_MIT 1.7dfsg
+ krb5_pac_get_types@krb5_3_MIT 1.7dfsg
+ krb5_pac_init@krb5_3_MIT 1.7dfsg
+ krb5_pac_parse@krb5_3_MIT 1.7dfsg
+ krb5_pac_sign@krb5_3_MIT 1.10+dfsg~alpha1
+ krb5_pac_sign_ext@krb5_3_MIT 1.17
+ krb5_pac_verify@krb5_3_MIT 1.7dfsg
+ krb5_pac_verify_ext@krb5_3_MIT 1.17
+ krb5_parse_name@krb5_3_MIT 1.6.dfsg.2
+ krb5_parse_name_flags@krb5_3_MIT 1.7dfsg
+ krb5_prepend_error_message@krb5_3_MIT 1.14+dfsg
+ krb5_principal2salt@krb5_3_MIT 1.6.dfsg.2
+ krb5_principal2salt_norealm@krb5_3_MIT 1.6.dfsg.2
+ krb5_principal_compare@krb5_3_MIT 1.6.dfsg.2
+ krb5_principal_compare_any_realm@krb5_3_MIT 1.7dfsg
+ krb5_principal_compare_flags@krb5_3_MIT 1.7dfsg
+ krb5_prompter_posix@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_close@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_default@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_default_name@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_default_type@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_destroy@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_dfl_close@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_dfl_close_no_free@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_dfl_destroy@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_dfl_expunge@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_dfl_get_name@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_dfl_get_span@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_dfl_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_dfl_ops@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_dfl_recover@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_dfl_resolve@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_dfl_store@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_expunge@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_free_entry@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_get_lifespan@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_get_name@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_get_type@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_hash_message@krb5_3_MIT 1.7dfsg
+ krb5_rc_initialize@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_io_close@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_io_creat@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_io_destroy@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_io_mark@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_io_move@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_io_open@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_io_read@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_io_size@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_io_sync@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_io_unmark@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_io_write@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_recover@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_recover_or_initialize@krb5_3_MIT 1.7dfsg
+ krb5_rc_register_type@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_resolve@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_resolve_full@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_resolve_type@krb5_3_MIT 1.6.dfsg.2
+ krb5_rc_store@krb5_3_MIT 1.6.dfsg.2
+ krb5_rd_cred@krb5_3_MIT 1.6.dfsg.2
+ krb5_rd_error@krb5_3_MIT 1.6.dfsg.2
+ krb5_rd_priv@krb5_3_MIT 1.6.dfsg.2
+ krb5_rd_rep@krb5_3_MIT 1.6.dfsg.2
+ krb5_rd_rep_dce@krb5_3_MIT 1.7dfsg
+ krb5_rd_req@krb5_3_MIT 1.6.dfsg.2
+ krb5_rd_req_decoded@krb5_3_MIT 1.6.dfsg.2
+ krb5_rd_req_decoded_anyflag@krb5_3_MIT 1.6.dfsg.2
+ krb5_rd_safe@krb5_3_MIT 1.6.dfsg.2
+ krb5_read_message@krb5_3_MIT 1.6.dfsg.2
+ krb5_read_password@krb5_3_MIT 1.6.dfsg.2
+ krb5_realm_compare@krb5_3_MIT 1.6.dfsg.2
+ krb5_recvauth@krb5_3_MIT 1.6.dfsg.2
+ krb5_recvauth_version@krb5_3_MIT 1.6.dfsg.2
+ krb5_register_serializer@krb5_3_MIT 1.6.dfsg.2
+ krb5_responder_get_challenge@krb5_3_MIT 1.11+dfsg
+ krb5_responder_list_questions@krb5_3_MIT 1.11+dfsg
+ krb5_responder_otp_challenge_free@krb5_3_MIT 1.11+dfsg
+ krb5_responder_otp_get_challenge@krb5_3_MIT 1.11+dfsg
+ krb5_responder_otp_set_answer@krb5_3_MIT 1.11+dfsg
+ krb5_responder_pkinit_challenge_free@krb5_3_MIT 1.12~alpha1+dfsg
+ krb5_responder_pkinit_get_challenge@krb5_3_MIT 1.12~alpha1+dfsg
+ krb5_responder_pkinit_set_answer@krb5_3_MIT 1.12~alpha1+dfsg
+ krb5_responder_set_answer@krb5_3_MIT 1.11+dfsg
+ krb5_salttype_to_string@krb5_3_MIT 1.6.dfsg.2
+ krb5_sendauth@krb5_3_MIT 1.6.dfsg.2
+ krb5_sendto_kdc@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_address_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_auth_context_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_authdata_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_authenticator_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_ccache_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_checksum_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_context_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_keyblock_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_keytab_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_pack_bytes@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_pack_int32@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_pack_int64@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_principal_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_rcache_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_unpack_bytes@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_unpack_int32@krb5_3_MIT 1.6.dfsg.2
+ krb5_ser_unpack_int64@krb5_3_MIT 1.6.dfsg.2
+ krb5_server_decrypt_ticket_keytab@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_config_files@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_debugging_time@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_default_in_tkt_ktypes@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_default_realm@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_default_tgs_enctypes@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_default_tgs_ktypes@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_error_message@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_kdc_recv_hook@krb5_3_MIT 1.15~beta1
+ krb5_set_kdc_send_hook@krb5_3_MIT 1.15~beta1
+ krb5_set_password@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_password_using_ccache@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_principal_realm@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_real_time@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_time_offsets@krb5_3_MIT 1.6.dfsg.2
+ krb5_set_trace_callback@krb5_3_MIT 1.10.2+dfsg
+ krb5_set_trace_filename@krb5_3_MIT 1.10.2+dfsg
+ krb5_size_opaque@krb5_3_MIT 1.6.dfsg.2
+ krb5_sname_match@krb5_3_MIT 1.10+dfsg~alpha1
+ krb5_sname_to_principal@krb5_3_MIT 1.13~alpha1+dfsg
+ krb5_string_to_deltat@krb5_3_MIT 1.6.dfsg.2
+ krb5_string_to_salttype@krb5_3_MIT 1.13~alpha1+dfsg
+ krb5_string_to_timestamp@krb5_3_MIT 1.6.dfsg.2
+ krb5_timeofday@krb5_3_MIT 1.6.dfsg.2
+ krb5_timestamp_to_sfstring@krb5_3_MIT 1.6.dfsg.2
+ krb5_timestamp_to_string@krb5_3_MIT 1.6.dfsg.2
+ krb5_tkt_creds_free@krb5_3_MIT 1.9+dfsg~beta1
+ krb5_tkt_creds_get@krb5_3_MIT 1.9+dfsg
+ krb5_tkt_creds_get_creds@krb5_3_MIT 1.9+dfsg~beta1
+ krb5_tkt_creds_get_times@krb5_3_MIT 1.9+dfsg~beta1
+ krb5_tkt_creds_init@krb5_3_MIT 1.9+dfsg~beta1
+ krb5_tkt_creds_step@krb5_3_MIT 1.9+dfsg~beta1
+ krb5_unlock_file@krb5_3_MIT 1.6.dfsg.2
+ krb5_unpack_full_ipaddr@krb5_3_MIT 1.6.dfsg.2
+ krb5_unparse_name@krb5_3_MIT 1.6.dfsg.2
+ krb5_unparse_name_ext@krb5_3_MIT 1.6.dfsg.2
+ krb5_unparse_name_flags@krb5_3_MIT 1.7dfsg
+ krb5_unparse_name_flags_ext@krb5_3_MIT 1.7dfsg
+ krb5_us_timeofday@krb5_3_MIT 1.6.dfsg.2
+ krb5_use_natural_time@krb5_3_MIT 1.6.dfsg.2
+ krb5_verify_authdata_kdc_issued@krb5_3_MIT 1.8+dfsg
+ krb5_verify_init_creds@krb5_3_MIT 1.6.dfsg.2
+ krb5_verify_init_creds_opt_init@krb5_3_MIT 1.6.dfsg.2
+ krb5_verify_init_creds_opt_set_ap_req_nofail@krb5_3_MIT 1.6.dfsg.2
+ krb5_vprepend_error_message@krb5_3_MIT 1.14+dfsg
+ krb5_vset_error_message@krb5_3_MIT 1.6.dfsg.2
+ krb5_vwrap_error_message@krb5_3_MIT 1.14+dfsg
+ krb5_walk_realm_tree@krb5_3_MIT 1.6.dfsg.2
+ krb5_wrap_error_message@krb5_3_MIT 1.14+dfsg
+ krb5_write_message@krb5_3_MIT 1.6.dfsg.2
+ krb5int_accessor@krb5_3_MIT 1.6.dfsg.2
+ krb5int_cc_default@krb5_3_MIT 1.6.dfsg.2
+ krb5int_cleanup_library@krb5_3_MIT 1.6.dfsg.2
+ krb5int_copy_data_contents@krb5_3_MIT 1.11+dfsg
+ krb5int_copy_data_contents_add0@krb5_3_MIT 1.7dfsg
+ krb5int_find_pa_data@krb5_3_MIT 1.7dfsg
+ krb5int_foreach_localaddr@krb5_3_MIT 1.6.dfsg.2
+ krb5int_free_data_list@krb5_3_MIT 1.8+dfsg
+ krb5int_get_authdata_containee_types@krb5_3_MIT 1.8+dfsg
+ krb5int_init_context_kdc@krb5_3_MIT 1.6.dfsg.2
+ krb5int_initialize_library@krb5_3_MIT 1.6.dfsg.2
+ krb5int_parse_enctype_list@krb5_3_MIT 1.11+dfsg
+ krb5int_random_string@krb5_3_MIT 1.12~alpha1+dfsg
+ krb5int_tgtname@krb5_3_MIT 1.9+dfsg~beta1
+ krb5int_trace@krb5_3_MIT 1.9+dfsg~beta1
+ profile_abandon@krb5_3_MIT 1.6.dfsg.2
+ profile_add_relation@krb5_3_MIT 1.6.dfsg.2
+ profile_clear_relation@krb5_3_MIT 1.6.dfsg.2
+ profile_flush@krb5_3_MIT 1.6.dfsg.2
+ profile_flush_to_buffer@krb5_3_MIT 1.13~alpha1+dfsg
+ profile_flush_to_file@krb5_3_MIT 1.13~alpha1+dfsg
+ profile_free_buffer@krb5_3_MIT 1.13~alpha1+dfsg
+ profile_free_list@krb5_3_MIT 1.6.dfsg.2
+ profile_get_boolean@krb5_3_MIT 1.6.dfsg.2
+ profile_get_integer@krb5_3_MIT 1.6.dfsg.2
+ profile_get_relation_names@krb5_3_MIT 1.6.dfsg.2
+ profile_get_string@krb5_3_MIT 1.6.dfsg.2
+ profile_get_subsection_names@krb5_3_MIT 1.6.dfsg.2
+ profile_get_values@krb5_3_MIT 1.6.dfsg.2
+ profile_init@krb5_3_MIT 1.6.dfsg.2
+ profile_init_flags@krb5_3_MIT 1.13~alpha1+dfsg
+ profile_init_path@krb5_3_MIT 1.6.dfsg.2
+ profile_init_vtable@krb5_3_MIT 1.13~alpha1+dfsg
+ profile_iterator@krb5_3_MIT 1.6.dfsg.2
+ profile_iterator_create@krb5_3_MIT 1.6.dfsg.2
+ profile_iterator_free@krb5_3_MIT 1.6.dfsg.2
+ profile_release@krb5_3_MIT 1.6.dfsg.2
+ profile_release_string@krb5_3_MIT 1.6.dfsg.2
+ profile_rename_section@krb5_3_MIT 1.6.dfsg.2
+ profile_ser_externalize@krb5_3_MIT 1.6.dfsg.2
+ profile_ser_internalize@krb5_3_MIT 1.6.dfsg.2
+ profile_ser_size@krb5_3_MIT 1.6.dfsg.2
+ profile_update_relation@krb5_3_MIT 1.6.dfsg.2
diff --git a/debian/libkrb5-dev.dirs.in b/debian/libkrb5-dev.dirs.in
new file mode 100644
index 000000000..c7d77306d
--- /dev/null
+++ b/debian/libkrb5-dev.dirs.in
@@ -0,0 +1,4 @@
+usr/lib/${DEB_HOST_MULTIARCH}
+usr/lib/${DEB_HOST_MULTIARCH}/pkgconfig
+usr/include
+usr/share/aclocal
diff --git a/debian/libkrb5-dev.links b/debian/libkrb5-dev.links
new file mode 100644
index 000000000..1a6b05265
--- /dev/null
+++ b/debian/libkrb5-dev.links
@@ -0,0 +1,2 @@
+usr/bin/krb5-config.mit usr/bin/krb5-config
+usr/share/man/man1/krb5-config.mit.1.gz usr/share/man/man1/krb5-config.1.gz
diff --git a/debian/libkrb5support0.install b/debian/libkrb5support0.install
new file mode 100644
index 000000000..c6776ca52
--- /dev/null
+++ b/debian/libkrb5support0.install
@@ -0,0 +1 @@
+usr/lib/*/libkrb5support.so.0*
diff --git a/debian/libkrb5support0.symbols b/debian/libkrb5support0.symbols
new file mode 100644
index 000000000..11595c397
--- /dev/null
+++ b/debian/libkrb5support0.symbols
@@ -0,0 +1,103 @@
+libkrb5support.so.0 libkrb5support0 #MINVER#
+ HIDDEN@HIDDEN 1.7dfsg~beta2
+ k5_base64_decode@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_base64_encode@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_bcmp@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_buf_add@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_buf_add_fmt@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_buf_add_len@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_buf_add_vfmt@krb5support_0_MIT 1.17
+ k5_buf_free@krb5support_0_MIT 1.13~alpha1+dfsg
+ k5_buf_get_space@krb5support_0_MIT 1.13~alpha1+dfsg
+ k5_buf_init_dynamic@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_buf_init_dynamic_zap@krb5support_0_MIT 1.17
+ k5_buf_init_fixed@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_buf_status@krb5support_0_MIT 1.13~alpha1+dfsg
+ k5_buf_truncate@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_clear_error@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_dir_filenames@krb5support_0_MIT 1.17
+ k5_free_error@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_free_filenames@krb5support_0_MIT 1.17
+ k5_get_error@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_hashtab_add@krb5support_0_MIT 1.17
+ k5_hashtab_create@krb5support_0_MIT 1.17
+ k5_hashtab_free@krb5support_0_MIT 1.17
+ k5_hashtab_get@krb5support_0_MIT 1.17
+ k5_hashtab_remove@krb5support_0_MIT 1.17
+ k5_hex_decode@krb5support_0_MIT 1.17
+ k5_hex_encode@krb5support_0_MIT 1.17
+ k5_json_array_add@krb5support_0_MIT 1.11+dfsg
+ k5_json_array_create@krb5support_0_MIT 1.11+dfsg
+ k5_json_array_fmt@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_json_array_get@krb5support_0_MIT 1.11+dfsg
+ k5_json_array_length@krb5support_0_MIT 1.11+dfsg
+ k5_json_array_set@krb5support_0_MIT 1.11+dfsg
+ k5_json_bool_create@krb5support_0_MIT 1.11+dfsg
+ k5_json_bool_value@krb5support_0_MIT 1.11+dfsg
+ k5_json_decode@krb5support_0_MIT 1.11+dfsg
+ k5_json_encode@krb5support_0_MIT 1.11+dfsg
+ k5_json_get_tid@krb5support_0_MIT 1.11+dfsg
+ k5_json_null_create@krb5support_0_MIT 1.11+dfsg
+ k5_json_null_create_val@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_json_number_create@krb5support_0_MIT 1.11+dfsg
+ k5_json_number_value@krb5support_0_MIT 1.11+dfsg
+ k5_json_object_count@krb5support_0_MIT 1.11+dfsg
+ k5_json_object_create@krb5support_0_MIT 1.11+dfsg
+ k5_json_object_get@krb5support_0_MIT 1.11+dfsg
+ k5_json_object_iterate@krb5support_0_MIT 1.11+dfsg
+ k5_json_object_set@krb5support_0_MIT 1.11+dfsg
+ k5_json_release@krb5support_0_MIT 1.11+dfsg
+ k5_json_retain@krb5support_0_MIT 1.11+dfsg
+ k5_json_string_create@krb5support_0_MIT 1.11+dfsg
+ k5_json_string_create_base64@krb5support_0_MIT 1.11+dfsg
+ k5_json_string_create_len@krb5support_0_MIT 1.11+dfsg
+ k5_json_string_unbase64@krb5support_0_MIT 1.11+dfsg
+ k5_json_string_utf8@krb5support_0_MIT 1.11+dfsg
+ k5_once@krb5support_0_MIT 1.15~beta1
+ k5_os_mutex_destroy@krb5support_0_MIT 1.15~beta1
+ k5_os_mutex_init@krb5support_0_MIT 1.15~beta1
+ k5_os_mutex_lock@krb5support_0_MIT 1.15~beta1
+ k5_os_mutex_unlock@krb5support_0_MIT 1.15~beta1
+ k5_path_isabs@krb5support_0_MIT 1.10+dfsg~alpha1
+ k5_path_join@krb5support_0_MIT 1.10+dfsg~alpha1
+ k5_path_split@krb5support_0_MIT 1.10+dfsg~alpha1
+ k5_set_error@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_set_error_info_callout_fn@krb5support_0_MIT 1.12~alpha1+dfsg
+ k5_strerror_r@krb5support_0_MIT 1.13~alpha1+dfsg
+ k5_utf16le_to_utf8@krb5support_0_MIT 1.16
+ k5_utf8_to_utf16le@krb5support_0_MIT 1.16
+ k5_vset_error@krb5support_0_MIT 1.12~alpha1+dfsg
+ krb5int_close_plugin@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_close_plugin_dirs@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_free_plugin_dir_data@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_free_plugin_dir_func@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_freeaddrinfo@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_gai_strerror@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_get_plugin_data@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_get_plugin_dir_data@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_get_plugin_dir_func@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_get_plugin_func@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_getaddrinfo@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_getnameinfo@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_getspecific@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_gmt_mktime@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_in6addr_any@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_key_delete@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_key_register@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_mutex_alloc@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_mutex_free@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_mutex_lock@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_mutex_unlock@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_open_plugin@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_open_plugin_dirs@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_pthread_loaded@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_setspecific@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_strlcat@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_strlcpy@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_ucs4_to_utf8@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_utf8_lentab@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_utf8_mintab@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_utf8_next@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_utf8_to_ucs4@krb5support_0_MIT 1.7dfsg~beta2
+ krb5int_zap@krb5support_0_MIT 1.8+dfsg~alpha1
+ krb5support_0_MIT@krb5support_0_MIT 1.7dfsg~beta2
diff --git a/debian/news b/debian/news
new file mode 100644
index 000000000..9cd6e7cf3
--- /dev/null
+++ b/debian/news
@@ -0,0 +1,7 @@
+krb5 (1.12.1+dfsg-11) unstable; urgency=medium
+
+ This version includes systemd unit files. In previous versions of krb5-admin-server, debconf was used to determine whether to use kadmind. With this version, update-rc.d krb5-admin-server disable should be used to disable the Kerberos administration daemon.
+
+
+ -- Sam Hartman <hartmans@debian.org> Mon, 20 Oct 2014 16:39:32 -0400
+
diff --git a/debian/patches/debian-local/0001-Debian-HURD-compatibility.patch b/debian/patches/debian-local/0001-Debian-HURD-compatibility.patch
new file mode 100644
index 000000000..9f7778fcd
--- /dev/null
+++ b/debian/patches/debian-local/0001-Debian-HURD-compatibility.patch
@@ -0,0 +1,135 @@
+From 85fcf9fc43e0b10fd0f90e056200ed028e50d297 Mon Sep 17 00:00:00 2001
+From: Sam Hartman <hartmans@debian.org>
+Date: Mon, 26 Dec 2011 18:05:13 -0500
+Subject: Debian: HURD compatibility
+
+HURD has no MAXPATHLEN or MAXHOSTLEN.
+
+Patch-Category: debian-local
+---
+ src/clients/ksu/ksu.h | 4 ++++
+ src/include/k5-int.h | 3 +++
+ src/kadmin/ktutil/ktutil_funcs.c | 4 ++++
+ src/kprop/kprop_util.c | 4 ++++
+ src/lib/gssapi/spnego/spnego_mech.c | 3 +++
+ src/lib/krb5/os/sn2princ.c | 4 ++++
+ src/plugins/kdb/db2/libdb2/include/db-int.h | 4 ++++
+ src/tests/resolve/resolve.c | 4 ++++
+ 8 files changed, 30 insertions(+)
+
+diff --git a/src/clients/ksu/ksu.h b/src/clients/ksu/ksu.h
+index 3bf0bd4384..f680b332c3 100644
+--- a/src/clients/ksu/ksu.h
++++ b/src/clients/ksu/ksu.h
+@@ -56,6 +56,10 @@
+ #define MAX_CMD 2048 /* this is temp, should use realloc instead,
+ as done in most of the code */
+
++#ifndef MAXPATHLEN
++# define MAXPATHLEN 4096
++#endif
++
+
+ extern int optind;
+ extern char * optarg;
+diff --git a/src/include/k5-int.h b/src/include/k5-int.h
+index 652242207a..e4f1678be6 100644
+--- a/src/include/k5-int.h
++++ b/src/include/k5-int.h
+@@ -589,6 +589,9 @@ extern char *strdup (const char *);
+ #ifdef HAVE_SYS_PARAM_H
+ #include <sys/param.h> /* MAXPATHLEN */
+ #endif
++#ifndef MAXPATHLEN
++# define MAXPATHLEN 4096
++#endif
+
+ #ifdef HAVE_SYS_FILE_H
+ #include <sys/file.h> /* prototypes for file-related
+diff --git a/src/kadmin/ktutil/ktutil_funcs.c b/src/kadmin/ktutil/ktutil_funcs.c
+index 6d119a2b64..fb7fa22f54 100644
+--- a/src/kadmin/ktutil/ktutil_funcs.c
++++ b/src/kadmin/ktutil/ktutil_funcs.c
+@@ -34,6 +34,10 @@
+ #include <string.h>
+ #include <ctype.h>
+
++#ifndef MAXPATHLEN
++# define MAXPATHLEN 4096
++#endif
++
+ /*
+ * Free a kt_list
+ */
+diff --git a/src/kprop/kprop_util.c b/src/kprop/kprop_util.c
+index c32d174b95..d72ab18967 100644
+--- a/src/kprop/kprop_util.c
++++ b/src/kprop/kprop_util.c
+@@ -32,6 +32,10 @@
+ #include <sys/types.h>
+ #include <sys/socket.h>
+
++#ifndef MAXHOSTNAMELEN
++#define MAXHOSTNAMELEN 256
++#endif
++
+ /*
+ * Convert an IPv4 or IPv6 socket address to a newly allocated krb5_address.
+ * There is similar code elsewhere in the tree, so this should possibly become
+diff --git a/src/lib/gssapi/spnego/spnego_mech.c b/src/lib/gssapi/spnego/spnego_mech.c
+index 9d6027ce80..585d8a6581 100644
+--- a/src/lib/gssapi/spnego/spnego_mech.c
++++ b/src/lib/gssapi/spnego/spnego_mech.c
+@@ -65,6 +65,9 @@
+ #include "gssapiP_spnego.h"
+ #include <gssapi_err_generic.h>
+
++#ifndef MAXHOSTNAMELEN
++#define MAXHOSTNAMELEN 256
++#endif
+
+ #undef g_token_size
+ #undef g_verify_token_header
+diff --git a/src/lib/krb5/os/sn2princ.c b/src/lib/krb5/os/sn2princ.c
+index 5932fd9b3f..187daa84d6 100644
+--- a/src/lib/krb5/os/sn2princ.c
++++ b/src/lib/krb5/os/sn2princ.c
+@@ -126,6 +126,10 @@ find_trailer(const char *hostname)
+ return p;
+ }
+
++#ifndef MAXHOSTNAMELEN
++# define MAXHOSTNAMELEN 256
++#endif
++
+ krb5_error_code KRB5_CALLCONV
+ krb5_sname_to_principal(krb5_context context, const char *hostname,
+ const char *sname, krb5_int32 type,
+diff --git a/src/plugins/kdb/db2/libdb2/include/db-int.h b/src/plugins/kdb/db2/libdb2/include/db-int.h
+index 7e981d4a5f..d83b3b6a6f 100644
+--- a/src/plugins/kdb/db2/libdb2/include/db-int.h
++++ b/src/plugins/kdb/db2/libdb2/include/db-int.h
+@@ -280,4 +280,8 @@ void __dbpanic __P((DB *dbp));
+ #ifndef O_BINARY
+ #define O_BINARY 0 /* Needed for Win32 compiles */
+ #endif
++
++#ifndef MAXPATHLEN
++# define MAXPATHLEN 4096
++#endif
+ #endif /* _DB_INT_H_ */
+diff --git a/src/tests/resolve/resolve.c b/src/tests/resolve/resolve.c
+index 7339d21bd9..38f725322b 100644
+--- a/src/tests/resolve/resolve.c
++++ b/src/tests/resolve/resolve.c
+@@ -73,6 +73,10 @@ char *strchr();
+ #include <netinet/in.h>
+ #include <netdb.h>
+
++#ifndef MAXHOSTNAMELEN
++# define MAXHOSTNAMELEN 256
++#endif
++
+ int
+ main(argc, argv)
+ int argc;
diff --git a/debian/patches/debian-local/0002-debian-Handle-multi-arch-paths-in-krb5-config.patch b/debian/patches/debian-local/0002-debian-Handle-multi-arch-paths-in-krb5-config.patch
new file mode 100644
index 000000000..3f6a4bd0a
--- /dev/null
+++ b/debian/patches/debian-local/0002-debian-Handle-multi-arch-paths-in-krb5-config.patch
@@ -0,0 +1,66 @@
+From 8cbb465da2e4ae37b8afd884910506422eadd0f8 Mon Sep 17 00:00:00 2001
+From: Sam Hartman <hartmans@debian.org>
+Date: Mon, 26 Dec 2011 18:19:53 -0500
+Subject: debian: Handle multi-arch paths in krb5-config
+
+We cannot use @libdir@ because that will include the
+multi-arch prefix in the built krb5-config, but we want krb5-config to
+be identical on all arches so that krb5-multidev can be multi-arch:
+same. So, instead, figure out our multi-arch tripple by calling CC
+directly.
+
+Based on an approach suggested by Hugh McMaster.
+
+Also include --deps in the usage output, since it is a valid argument.
+
+Patch-Category: debian-local
+---
+ src/build-tools/krb5-config.in | 17 ++++++++++-------
+ 1 file changed, 10 insertions(+), 7 deletions(-)
+
+diff --git a/src/build-tools/krb5-config.in b/src/build-tools/krb5-config.in
+index f6184da3fb..ac2f5827d3 100755
+--- a/src/build-tools/krb5-config.in
++++ b/src/build-tools/krb5-config.in
+@@ -26,11 +26,18 @@
+
+ # Configurable parameters set by autoconf
+ version_string="Kerberos 5 release @KRB5_VERSION@"
++CC=${CC-cc}
++tripple=`$CC -print-multiarch 2>/dev/null|| ( $CC -dumpmachine | sed 's/-pc//' )`
++if [ x$tripple = x ]; then
++ echo >&2 Failed to find installation architecture
++ exit 2
++fi
++
+
+ prefix=@prefix@
+ exec_prefix=@exec_prefix@
+-includedir=@includedir@
+-libdir=@libdir@
++includedir=@prefix@/include/mit-krb5
++libdir=@prefix@/lib/${tripple}/mit-krb5
+ CC_LINK='@CC_LINK@'
+ KDB5_DB_LIB=@KDB5_DB_LIB@
+ LDFLAGS='@LDFLAGS@'
+@@ -138,6 +145,7 @@ if test -n "$do_help"; then
+ echo " [--defktname] Show built-in default keytab name"
+ echo " [--defcktname] Show built-in default client keytab name"
+ echo " [--cflags] Compile time CFLAGS"
++ echo " [--deps] Include dependent libraries"
+ echo " [--libs] List libraries required to link [LIBRARIES]"
+ echo "Libraries:"
+ echo " krb5 Kerberos 5 application"
+@@ -208,12 +216,7 @@ fi
+
+
+ if test -n "$do_libs"; then
+- # Assumes /usr/lib is the standard library directory everywhere...
+- if test "$libdir" = /usr/lib; then
+- libdirarg=
+- else
+ libdirarg="-L$libdir"
+- fi
+ # Ugly gross hack for our build tree
+ lib_flags=`echo $CC_LINK | sed -e 's/\$(CC)//' \
+ -e 's/\$(PURE)//' \
diff --git a/debian/patches/debian-local/0003-debian-osconf.hin-path-changes.patch b/debian/patches/debian-local/0003-debian-osconf.hin-path-changes.patch
new file mode 100644
index 000000000..bb5aac91b
--- /dev/null
+++ b/debian/patches/debian-local/0003-debian-osconf.hin-path-changes.patch
@@ -0,0 +1,36 @@
+From d0706297a8a7a9fb45deb0973e15506dc31b1c83 Mon Sep 17 00:00:00 2001
+From: Sam Hartman <hartmans@debian.org>
+Date: Mon, 26 Dec 2011 18:20:11 -0500
+Subject: debian: osconf.hin path changes
+
+Patch-Category: debian-local
+---
+ src/include/osconf.hin | 8 ++++----
+ 1 file changed, 4 insertions(+), 4 deletions(-)
+
+diff --git a/src/include/osconf.hin b/src/include/osconf.hin
+index c24717be67..c103424955 100644
+--- a/src/include/osconf.hin
++++ b/src/include/osconf.hin
+@@ -70,8 +70,8 @@
+ #endif
+
+ #define KDC_DIR "@LOCALSTATEDIR/krb5kdc"
+-#define KDC_RUN_DIR "@RUNSTATEDIR/krb5kdc"
+-#define DEFAULT_KDB_FILE KDC_DIR "/principal"
++#define KDC_RUN_DIR "/run/krb5kdc"
++#define DEFAULT_KDB_FILE "/var/lib/krb5kdc/principal"
+ #define DEFAULT_KEYFILE_STUB KDC_DIR "/.k5."
+ #define KRB5_DEFAULT_ADMIN_ACL KDC_DIR "/krb5_adm.acl"
+ /* Used by old admin server */
+@@ -125,8 +125,8 @@
+ * krb5 replica support follows
+ */
+
+-#define KPROP_DEFAULT_FILE KDC_DIR "/replica_datatrans"
+-#define KPROPD_DEFAULT_FILE KDC_DIR "/from_master"
++#define KPROP_DEFAULT_FILE "/var/lib/krb5kdc/replica_datatrans"
++#define KPROPD_DEFAULT_FILE "/var/lib/krb5kdc/from_master"
+ #define KPROPD_DEFAULT_KDB5_UTIL "@SBINDIR/kdb5_util"
+ #define KPROPD_DEFAULT_KPROP "@SBINDIR/kprop"
+ #define KPROPD_DEFAULT_KRB_DB DEFAULT_KDB_FILE
diff --git a/debian/patches/debian-local/0004-debian-install-ldap-library-in-subdirectory.patch b/debian/patches/debian-local/0004-debian-install-ldap-library-in-subdirectory.patch
new file mode 100644
index 000000000..e28dd7065
--- /dev/null
+++ b/debian/patches/debian-local/0004-debian-install-ldap-library-in-subdirectory.patch
@@ -0,0 +1,41 @@
+From de937376c58397109ef2bf087ce4073caa37fb29 Mon Sep 17 00:00:00 2001
+From: Sam Hartman <hartmans@debian.org>
+Date: Mon, 26 Dec 2011 18:12:39 -0500
+Subject: debian: install ldap library in subdirectory
+
+Debian received a request to install the internal ldap library not in
+the main lib directory.
+
+We are changing SHLIB_DIRS from the default that upstream sets in the
+makefile includes; assign unconditionally the full value.
+
+Patch-Category: debian-local
+---
+ src/plugins/kdb/ldap/Makefile.in | 1 +
+ src/plugins/kdb/ldap/ldap_util/Makefile.in | 1 +
+ 2 files changed, 2 insertions(+)
+
+diff --git a/src/plugins/kdb/ldap/Makefile.in b/src/plugins/kdb/ldap/Makefile.in
+index 94df816eb5..2ed562b110 100644
+--- a/src/plugins/kdb/ldap/Makefile.in
++++ b/src/plugins/kdb/ldap/Makefile.in
+@@ -20,6 +20,7 @@ SHLIB_EXPDEPS = \
+ $(TOPLIBD)/libkrb5$(SHLIBEXT) \
+ $(TOPLIBD)/lib$(SUPPORT_LIBNAME)$(SHLIBEXT)
+ SHLIB_EXPLIBS= -lkdb_ldap $(GSSRPC_LIBS) -lkrb5 -lcom_err -lk5crypto -lkrb5support $(LIBS)
++SHLIB_DIRS=-L$(TOPLIBD) -Wl,-rpath,$(KRB5_LIBDIR)/krb5
+
+ SRCS= $(srcdir)/ldap_exp.c
+
+diff --git a/src/plugins/kdb/ldap/ldap_util/Makefile.in b/src/plugins/kdb/ldap/ldap_util/Makefile.in
+index 8669c2436c..2d92a26be5 100644
+--- a/src/plugins/kdb/ldap/ldap_util/Makefile.in
++++ b/src/plugins/kdb/ldap/ldap_util/Makefile.in
+@@ -2,6 +2,7 @@ mydir=plugins$(S)kdb$(S)ldap$(S)ldap_util
+ BUILDTOP=$(REL)..$(S)..$(S)..$(S)..
+ DEFINES = -DKDB4_DISABLE
+ LOCALINCLUDES = -I. -I$(srcdir)/../libkdb_ldap -I$(top_srcdir)/lib/kdb
++PROG_LIBPATH=-L$(TOPLIBD) $(KRB4_LIBPATH) -Wl,-rpath,$(KRB5_LIBDIR)/krb5
+ #KDB_DEP_LIB=$(DL_LIB) $(THREAD_LINKOPTS)
+ KDB_DEP_LIB=$(DL_LIB) -lkdb_ldap $(THREAD_LINKOPTS)
+
diff --git a/debian/patches/debian-local/0005-gssapi-never-unload-mechanisms.patch b/debian/patches/debian-local/0005-gssapi-never-unload-mechanisms.patch
new file mode 100644
index 000000000..501ae30a5
--- /dev/null
+++ b/debian/patches/debian-local/0005-gssapi-never-unload-mechanisms.patch
@@ -0,0 +1,34 @@
+From dd3d9bb7d1c07fd5e12b5a0595a8aa351cdaff82 Mon Sep 17 00:00:00 2001
+From: Benjamin Kaduk <kaduk@mit.edu>
+Date: Fri, 29 Mar 2013 17:18:40 -0400
+Subject: gssapi: never unload mechanisms
+
+It turns out that many GSSAPI mechanisms link to the main gss-api
+library creating a circular reference. Depending on how the linker
+breaks the cycle at process exit time, the linker may unload the GSS
+library after unloading the mechanisms. The explicit dlclose from the
+GSS library tends to cause a libdl assertion failure at that
+point. So, never unload plugins. They are refcounted, so dlopen
+handles will not leak, although obviously the memory from the plugin
+is never reclaimed.
+
+ticket: 7135
+
+Patch-Category: debian-local
+---
+ src/lib/gssapi/mechglue/g_initialize.c | 2 --
+ 1 file changed, 2 deletions(-)
+
+diff --git a/src/lib/gssapi/mechglue/g_initialize.c b/src/lib/gssapi/mechglue/g_initialize.c
+index 0ad11c0b02..a3926e166e 100644
+--- a/src/lib/gssapi/mechglue/g_initialize.c
++++ b/src/lib/gssapi/mechglue/g_initialize.c
+@@ -559,8 +559,6 @@ releaseMechInfo(gss_mech_info *pCf)
+ generic_gss_release_oid(&minor_status, &cf->mech_type);
+ if (cf->freeMech)
+ zapfree(cf->mech, sizeof(*cf->mech));
+- if (cf->dl_handle != NULL)
+- krb5int_close_plugin(cf->dl_handle);
+ if (cf->int_mech_type != GSS_C_NO_OID)
+ generic_gss_release_oid(&minor_status, &cf->int_mech_type);
+
diff --git a/debian/patches/debian-local/0006-Add-substpdf-target.patch b/debian/patches/debian-local/0006-Add-substpdf-target.patch
new file mode 100644
index 000000000..7a287f162
--- /dev/null
+++ b/debian/patches/debian-local/0006-Add-substpdf-target.patch
@@ -0,0 +1,40 @@
+From cbb7f2bbb739cc8766cacc64141a1a5a87642692 Mon Sep 17 00:00:00 2001
+From: Ben Kaduk <kaduk@mit.edu>
+Date: Fri, 29 Mar 2013 20:53:37 -0400
+Subject: Add substpdf target
+
+Akin to substhtml, so that we can build PDF documents without
+overwriting the upstream-provided versions and causing debian/rules clean
+to not return to the original state.
+
+Patch-Category: debian-local
+---
+ src/doc/Makefile.in | 15 +++++++++++++++
+ 1 file changed, 15 insertions(+)
+
+diff --git a/src/doc/Makefile.in b/src/doc/Makefile.in
+index 1fb5fea927..043de76fa5 100644
+--- a/src/doc/Makefile.in
++++ b/src/doc/Makefile.in
+@@ -87,6 +87,21 @@ pdf: $(PDFDIR)
+ rm -f *.dvi *.log *.ind *.aux *.toc *.syn *.idx *.out *.ilg *.pla \
+ )
+
++substpdf: rst_composite
++ $(SPHINX_BUILD) -t pathsubs -b latex -q rst_composite pdf_subst
++ mv pdf_subst/Makefile pdf_subst/GMakefile
++ (cd pdf_subst && \
++ for i in $(PDFDOCS); do \
++ texfile=`echo $${i}.tex` && \
++ idxfile=`echo $${i}.idx` && \
++ pdflatex $(LATEXOPTS) $$texfile && \
++ pdflatex $(LATEXOPTS) $$texfile && \
++ makeindex -s python.ist $$idxfile || true; \
++ pdflatex $(LATEXOPTS) $$texfile && \
++ pdflatex $(LATEXOPTS) $$texfile; done && \
++ rm -f *.dvi *.log *.ind *.aux *.toc *.syn *.idx *.out *.ilg *.pla \
++ )
++
+ # Use doxygen to generate API documentation, translate it into RST
+ # format, and then create a composite of $(docsrc)'s RST and the
+ # generated files in rst_composite. Used by the html and substhtml targets.
diff --git a/debian/patches/debian-local/0007-Fix-pkg-config-library-include-paths.patch b/debian/patches/debian-local/0007-Fix-pkg-config-library-include-paths.patch
new file mode 100644
index 000000000..1c67b9a42
--- /dev/null
+++ b/debian/patches/debian-local/0007-Fix-pkg-config-library-include-paths.patch
@@ -0,0 +1,102 @@
+From baeaf3b108107146437608f3fc14249e3cdaed99 Mon Sep 17 00:00:00 2001
+From: Jelmer Vernooij <jelmer@debian.org>
+Date: Wed, 27 Aug 2014 16:40:29 -0400
+Subject: Fix pkg-config library/include paths
+
+Include library and include flags in pkg-config files, so they work when the
+symlinks provided by libkrb5-dev are not installed.
+
+Patch-Category: debian-local
+---
+ src/build-tools/gssrpc.pc.in | 4 ++--
+ src/build-tools/kadm-client.pc.in | 4 ++--
+ src/build-tools/kadm-server.pc.in | 4 ++--
+ src/build-tools/kdb.pc.in | 4 ++--
+ src/build-tools/mit-krb5-gssapi.pc.in | 4 ++--
+ src/build-tools/mit-krb5.pc.in | 4 ++--
+ 6 files changed, 12 insertions(+), 12 deletions(-)
+
+diff --git a/src/build-tools/gssrpc.pc.in b/src/build-tools/gssrpc.pc.in
+index ca909217eb..e08c2e840a 100644
+--- a/src/build-tools/gssrpc.pc.in
++++ b/src/build-tools/gssrpc.pc.in
+@@ -1,7 +1,7 @@
+ prefix=@prefix@
+ exec_prefix=@exec_prefix@
+-libdir=@libdir@
+-includedir=@includedir@
++libdir=@libdir@/mit-krb5
++includedir=@includedir@/mit-krb5
+ vendor=MIT
+
+ Name: gssrpc
+diff --git a/src/build-tools/kadm-client.pc.in b/src/build-tools/kadm-client.pc.in
+index c8d1cd1262..de56a75213 100644
+--- a/src/build-tools/kadm-client.pc.in
++++ b/src/build-tools/kadm-client.pc.in
+@@ -1,7 +1,7 @@
+ prefix=@prefix@
+ exec_prefix=@exec_prefix@
+-libdir=@libdir@
+-includedir=@includedir@
++libdir=@libdir@/mit-krb5
++includedir=@includedir@/mit-krb5
+
+ Name: kadm-client
+ Description: Kerberos administration client library
+diff --git a/src/build-tools/kadm-server.pc.in b/src/build-tools/kadm-server.pc.in
+index cd2f86c649..a73ff86cfe 100644
+--- a/src/build-tools/kadm-server.pc.in
++++ b/src/build-tools/kadm-server.pc.in
+@@ -1,7 +1,7 @@
+ prefix=@prefix@
+ exec_prefix=@exec_prefix@
+-libdir=@libdir@
+-includedir=@includedir@
++libdir=@libdir@/mit-krb5
++includedir=@includedir@/mit-krb5
+
+ Name: kadm-server
+ Description: Kerberos administration server library
+diff --git a/src/build-tools/kdb.pc.in b/src/build-tools/kdb.pc.in
+index 461a8d01d0..356501d38c 100644
+--- a/src/build-tools/kdb.pc.in
++++ b/src/build-tools/kdb.pc.in
+@@ -1,7 +1,7 @@
+ prefix=@prefix@
+ exec_prefix=@exec_prefix@
+-libdir=@libdir@
+-includedir=@includedir@
++libdir=@libdir@/mit-krb5
++includedir=@includedir@/mit-krb5
+
+ KDB5_DB_LIB=@KDB5_DB_LIB@
+
+diff --git a/src/build-tools/mit-krb5-gssapi.pc.in b/src/build-tools/mit-krb5-gssapi.pc.in
+index 7b91b19f19..b2b243630c 100644
+--- a/src/build-tools/mit-krb5-gssapi.pc.in
++++ b/src/build-tools/mit-krb5-gssapi.pc.in
+@@ -1,7 +1,7 @@
+ prefix=@prefix@
+ exec_prefix=@exec_prefix@
+-libdir=@libdir@
+-includedir=@includedir@
++libdir=@libdir@/mit-krb5
++includedir=@includedir@/mit-krb5
+
+ Name: mit-krb5-gssapi
+ Description: Kerberos implementation of the GSSAPI
+diff --git a/src/build-tools/mit-krb5.pc.in b/src/build-tools/mit-krb5.pc.in
+index 030881512f..058e75f24d 100644
+--- a/src/build-tools/mit-krb5.pc.in
++++ b/src/build-tools/mit-krb5.pc.in
+@@ -1,7 +1,7 @@
+ prefix=@prefix@
+ exec_prefix=@exec_prefix@
+-libdir=@libdir@
+-includedir=@includedir@
++libdir=@libdir@/mit-krb5
++includedir=@includedir@/mit-krb5
+
+ defccname=@DEFCCNAME@
+ defktname=@DEFKTNAME@
diff --git a/debian/patches/debian-local/0008-Use-isystem-for-include-paths.patch b/debian/patches/debian-local/0008-Use-isystem-for-include-paths.patch
new file mode 100644
index 000000000..6465bb039
--- /dev/null
+++ b/debian/patches/debian-local/0008-Use-isystem-for-include-paths.patch
@@ -0,0 +1,109 @@
+From d2a401455564fa2a51c78a0856492dfe3329a68f Mon Sep 17 00:00:00 2001
+From: Jelmer Vernooij <jelmer@debian.org>
+Date: Wed, 3 Sep 2014 22:41:55 -0400
+Subject: Use -isystem for include paths
+
+ This is necessary so Kerberos headers files are classified as "system headers"
+ by the compiler, and thus not subject to the same strict warnings as
+ other headers (which breaks compilation if -Werror is specified).
+ .
+ This fixes the build of folks using -Werror and including Kerberos headers
+ when the latter are installed in a non-standard location (e.g.
+ /usr/include/tuple/mit-krb5, as Debian is doing).
+(cherry picked from commit d8520c1d1c218e3c766009abc728b207c0421232)
+
+Author: Jelmer Vernooij <jelmer@debian.org>
+Bug-Debian: http://bugs.debian.org/751760
+Patch-Category: debian-local
+---
+ src/build-tools/gssrpc.pc.in | 2 +-
+ src/build-tools/kadm-client.pc.in | 2 +-
+ src/build-tools/kadm-server.pc.in | 2 +-
+ src/build-tools/kdb.pc.in | 2 +-
+ src/build-tools/krb5-config.in | 2 +-
+ src/build-tools/mit-krb5-gssapi.pc.in | 2 +-
+ src/build-tools/mit-krb5.pc.in | 2 +-
+ 7 files changed, 7 insertions(+), 7 deletions(-)
+
+diff --git a/src/build-tools/gssrpc.pc.in b/src/build-tools/gssrpc.pc.in
+index e08c2e840a..fb4f489f87 100644
+--- a/src/build-tools/gssrpc.pc.in
++++ b/src/build-tools/gssrpc.pc.in
+@@ -7,6 +7,6 @@ vendor=MIT
+ Name: gssrpc
+ Description: GSSAPI RPC implementation
+ Version: @KRB5_VERSION@
+-Cflags: -I${includedir}
++Cflags: -isystem ${includedir}
+ Libs: -L${libdir} -lgssrpc
+ Requires.private: mit-krb5-gssapi
+diff --git a/src/build-tools/kadm-client.pc.in b/src/build-tools/kadm-client.pc.in
+index de56a75213..47541ac2af 100644
+--- a/src/build-tools/kadm-client.pc.in
++++ b/src/build-tools/kadm-client.pc.in
+@@ -7,5 +7,5 @@ Name: kadm-client
+ Description: Kerberos administration client library
+ Version: @KRB5_VERSION@
+ Requires.private: mit-krb5-gssapi gssrpc
+-Cflags: -I${includedir}
++Cflags: -isystem ${includedir}
+ Libs: -L${libdir} -lkadm5clnt_mit
+diff --git a/src/build-tools/kadm-server.pc.in b/src/build-tools/kadm-server.pc.in
+index a73ff86cfe..5ce4b733c4 100644
+--- a/src/build-tools/kadm-server.pc.in
++++ b/src/build-tools/kadm-server.pc.in
+@@ -7,5 +7,5 @@ Name: kadm-server
+ Description: Kerberos administration server library
+ Version: @KRB5_VERSION@
+ Requires.private: kdb mit-krb5-gssapi
+-Cflags: -I${includedir}
++Cflags: -isystem ${includedir}
+ Libs: -L${libdir} -lkadm5srv_mit
+diff --git a/src/build-tools/kdb.pc.in b/src/build-tools/kdb.pc.in
+index 356501d38c..d39eeef889 100644
+--- a/src/build-tools/kdb.pc.in
++++ b/src/build-tools/kdb.pc.in
+@@ -9,6 +9,6 @@ Name: kdb
+ Description: Kerberos database access libraries
+ Version: @KRB5_VERSION@
+ Requires.private: mit-krb5-gssapi mit-krb5 gssrpc
+-Cflags: -I${includedir}
++Cflags: -isystem ${includedir}
+ Libs: -L${libdir} -lkdb5
+ Libs.private: ${KDB5_DB_LIB}
+diff --git a/src/build-tools/krb5-config.in b/src/build-tools/krb5-config.in
+index ac2f5827d3..010457e153 100755
+--- a/src/build-tools/krb5-config.in
++++ b/src/build-tools/krb5-config.in
+@@ -208,7 +208,7 @@ fi
+
+ if test -n "$do_cflags"; then
+ if test x"$includedir" != x"/usr/include" ; then
+- echo "-I${includedir}"
++ echo "-isystem ${includedir}"
+ else
+ echo ''
+ fi
+diff --git a/src/build-tools/mit-krb5-gssapi.pc.in b/src/build-tools/mit-krb5-gssapi.pc.in
+index b2b243630c..f919222699 100644
+--- a/src/build-tools/mit-krb5-gssapi.pc.in
++++ b/src/build-tools/mit-krb5-gssapi.pc.in
+@@ -7,5 +7,5 @@ Name: mit-krb5-gssapi
+ Description: Kerberos implementation of the GSSAPI
+ Version: @KRB5_VERSION@
+ Requires.private: mit-krb5
+-Cflags: -I${includedir}
++Cflags: -isystem ${includedir}
+ Libs: -L${libdir} -lgssapi_krb5
+diff --git a/src/build-tools/mit-krb5.pc.in b/src/build-tools/mit-krb5.pc.in
+index 058e75f24d..455427a42e 100644
+--- a/src/build-tools/mit-krb5.pc.in
++++ b/src/build-tools/mit-krb5.pc.in
+@@ -10,6 +10,6 @@ defcktname=@DEFCKTNAME@
+ Name: mit-krb5
+ Description: An implementation of Kerberos network authentication
+ Version: @KRB5_VERSION@
+-Cflags: -I${includedir}
++Cflags: -isystem ${includedir}
+ Libs: -L${libdir} -lkrb5 -lk5crypto -lcom_err
+ Libs.private: -lkrb5support
diff --git a/debian/patches/series b/debian/patches/series
new file mode 100644
index 000000000..af6dbebb6
--- /dev/null
+++ b/debian/patches/series
@@ -0,0 +1,11 @@
+debian-local/0001-Debian-HURD-compatibility.patch
+debian-local/0002-debian-Handle-multi-arch-paths-in-krb5-config.patch
+debian-local/0003-debian-osconf.hin-path-changes.patch
+debian-local/0004-debian-install-ldap-library-in-subdirectory.patch
+debian-local/0005-gssapi-never-unload-mechanisms.patch
+debian-local/0006-Add-substpdf-target.patch
+debian-local/0007-Fix-pkg-config-library-include-paths.patch
+debian-local/0008-Use-isystem-for-include-paths.patch
+upstream/0009-Remove-erroneous-text-from-kinit-man-page.patch
+upstream/0010-Fix-memory-leak-in-none-replay-cache-type.patch
+upstream/0011-Document-the-double-colon-behavior-of-DIR-ccaches.patch
diff --git a/debian/patches/upstream/0009-Remove-erroneous-text-from-kinit-man-page.patch b/debian/patches/upstream/0009-Remove-erroneous-text-from-kinit-man-page.patch
new file mode 100644
index 000000000..9f2b9a013
--- /dev/null
+++ b/debian/patches/upstream/0009-Remove-erroneous-text-from-kinit-man-page.patch
@@ -0,0 +1,63 @@
+From d7c778325a6f690dc16213e797dbdc3a84458ae8 Mon Sep 17 00:00:00 2001
+From: Isaac Boukris <iboukris@gmail.com>
+Date: Mon, 7 Jan 2019 21:09:34 +0200
+Subject: Remove erroneous text from kinit man page
+
+Commit 4c4859fa83295db5c26f47b96c719060cfd9e2b1 changed the kinit man
+page to state that kinit -E (enterprise) implies -C (canonicalize).
+The client does not automatically set the canonicalize option when
+getting tickets for an enterprise principal, and Windows KDCs can
+issue tickets for enterprise principals without canonicalizing the
+principal (contrary to the implication of RFC 6806 section 5). Remove
+the misleading text.
+
+[ghudson@mit.edu: updated RST man page and regenerated nroff file;
+rewrote commit message]
+
+(cherry picked from commit 8e31335a7722a2f7f1722506befe4fd26d3e3f3f)
+
+ticket: 8779
+version_fixed: 1.17.1
+
+Patch-Category: upstream
+---
+ doc/user/user_commands/kinit.rst | 3 +--
+ src/man/kinit.man | 5 ++---
+ 2 files changed, 3 insertions(+), 5 deletions(-)
+
+diff --git a/doc/user/user_commands/kinit.rst b/doc/user/user_commands/kinit.rst
+index d692e2791a..e12e88a372 100644
+--- a/doc/user/user_commands/kinit.rst
++++ b/doc/user/user_commands/kinit.rst
+@@ -92,8 +92,7 @@ OPTIONS
+ requested.
+
+ **-E**
+- treats the principal name as an enterprise name (implies the
+- **-C** option).
++ treats the principal name as an enterprise name.
+
+ **-v**
+ requests that the ticket-granting ticket in the cache (with the
+diff --git a/src/man/kinit.man b/src/man/kinit.man
+index d121cff749..a3dcfe26cc 100644
+--- a/src/man/kinit.man
++++ b/src/man/kinit.man
+@@ -1,6 +1,6 @@
+ .\" Man page generated from reStructuredText.
+ .
+-.TH "KINIT" "1" " " "1.17" "MIT Kerberos"
++.TH "KINIT" "1" " " "1.18" "MIT Kerberos"
+ .SH NAME
+ kinit \- obtain and cache Kerberos ticket-granting ticket
+ .
+@@ -113,8 +113,7 @@ KDC to reply with a different client principal from the one
+ requested.
+ .TP
+ \fB\-E\fP
+-treats the principal name as an enterprise name (implies the
+-\fB\-C\fP option).
++treats the principal name as an enterprise name.
+ .TP
+ \fB\-v\fP
+ requests that the ticket\-granting ticket in the cache (with the
diff --git a/debian/patches/upstream/0010-Fix-memory-leak-in-none-replay-cache-type.patch b/debian/patches/upstream/0010-Fix-memory-leak-in-none-replay-cache-type.patch
new file mode 100644
index 000000000..0dde59dc9
--- /dev/null
+++ b/debian/patches/upstream/0010-Fix-memory-leak-in-none-replay-cache-type.patch
@@ -0,0 +1,33 @@
+From c736896c4a0e6402e4876163647e320b1fc62d21 Mon Sep 17 00:00:00 2001
+From: Corene Casper <C.Casper@Dell.com>
+Date: Sat, 16 Feb 2019 00:49:26 -0500
+Subject: Fix memory leak in 'none' replay cache type
+
+Commit 0f06098e2ab419d02e89a1ca6bc9f2828f6bdb1e fixed part of a memory
+leak in the 'none' replay cache type by freeing the outer container,
+but we also need to free the mutex.
+
+[ghudson@mit.edu: wrote commit message]
+
+(cherry picked from commit af2a3115cb8feb5174151b4b40223ae45aa9db17)
+
+ticket: 8783
+version_fixed: 1.17.1
+
+Patch-Category: upstream
+---
+ src/lib/krb5/rcache/rc_none.c | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/src/lib/krb5/rcache/rc_none.c b/src/lib/krb5/rcache/rc_none.c
+index e30aed09f1..0b2274df7f 100644
+--- a/src/lib/krb5/rcache/rc_none.c
++++ b/src/lib/krb5/rcache/rc_none.c
+@@ -50,6 +50,7 @@ krb5_rc_none_noargs(krb5_context ctx, krb5_rcache rc)
+ static krb5_error_code KRB5_CALLCONV
+ krb5_rc_none_close(krb5_context ctx, krb5_rcache rc)
+ {
++ k5_mutex_destroy(&rc->lock);
+ free (rc);
+ return 0;
+ }
diff --git a/debian/patches/upstream/0011-Document-the-double-colon-behavior-of-DIR-ccaches.patch b/debian/patches/upstream/0011-Document-the-double-colon-behavior-of-DIR-ccaches.patch
new file mode 100644
index 000000000..5f2411c98
--- /dev/null
+++ b/debian/patches/upstream/0011-Document-the-double-colon-behavior-of-DIR-ccaches.patch
@@ -0,0 +1,33 @@
+From a243df875ff905d1c676bd726b19bafea07b628c Mon Sep 17 00:00:00 2001
+From: Robbie Harwood <rharwood@redhat.com>
+Date: Wed, 6 Mar 2019 18:01:50 -0500
+Subject: Document the double-colon behavior of DIR ccaches
+
+(cherry picked from commit 5ba6e02a7b96ddd15dde01db0f9aff3d65773a8e)
+
+ticket: 8789
+version_fixed: 1.17.1
+
+Patch-Category: upstream
+---
+ doc/basic/ccache_def.rst | 7 +++++++
+ 1 file changed, 7 insertions(+)
+
+diff --git a/doc/basic/ccache_def.rst b/doc/basic/ccache_def.rst
+index d147f0d7aa..53542adde9 100644
+--- a/doc/basic/ccache_def.rst
++++ b/doc/basic/ccache_def.rst
+@@ -51,6 +51,13 @@ library.
+ requirement is for parent directory to exist and the current
+ process must have permissions to create the directory if it does
+ not exist. See :ref:`col_ccache` for details. New in release 1.10.
++ The following residual forms are supported:
++
++ * DIR:dirname
++ * DIR::dirpath/filename - a single cache within the directory
++
++ Switching to a ccache of the latter type causes it to become the
++ primary for the directory.
+
+ #. **FILE** caches are the simplest and most portable. A simple flat
+ file format is used to store one credential after another. This is
diff --git a/debian/po/POTFILES.in b/debian/po/POTFILES.in
new file mode 100644
index 000000000..094f9687b
--- /dev/null
+++ b/debian/po/POTFILES.in
@@ -0,0 +1,2 @@
+[type: gettext/rfc822deb] krb5-admin-server.templates
+[type: gettext/rfc822deb] krb5-kdc.templates
diff --git a/debian/po/ca.po b/debian/po/ca.po
new file mode 100644
index 000000000..62e7b3593
--- /dev/null
+++ b/debian/po/ca.po
@@ -0,0 +1,140 @@
+# krb5 po-debconf translation to Catalan
+# Copyright (C) 2006, 2008, 2009 Software in the Public Interest
+# This file is distributed under the same license as the PACKAGE package.
+# Innocent De Marchi <tangram.peces@gmail.com>, 2011.
+#
+msgid ""
+msgstr ""
+"Project-Id-Version: 1.6.dfsg.4~beta1-10\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2011-06-17 18:08+0100\n"
+"Last-Translator: Innocent De Marchi <tangram.peces@gmail.com>\n"
+"Language-Team: catalan <debian-l10n-catalan@lists.debian.org>\n"
+"Language: \n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=utf-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+"X-Poedit-Language: Catalan\n"
+"X-Poedit-Country: SPAIN\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Configuració d'un regne Kerberos."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Aquest paquet conté les eines administratives necessàries per executar el "
+"servidor principal de Kerberos."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"No obstant això, amb la instal lació d'aquest paquet no es configura "
+"automàticament un regne Kerberos. Això es pot fer més endavant mitjançant "
+"l'execució de l'ordre «krb5_newrealm »."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Llegiu també el fitxer «/usr/share/doc/krb5-kdc/README.KDC» i la guia "
+"d'administració disponible en el paquet «krb5-doc»."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Generar la configuració de Kerberos KDC de forma automàtica?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Els fitxer de configuració del «Kerberos Key Distribution Center» (KDC), a «/"
+"etc/krb5kdc», es poden generar automàticament."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Per defecte, una plantilla d'exemple, amb els paràmetres locals emplenats, "
+"es copiarà en aquest directori."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Els administradors que ja tenen la infraestructura per administrar la "
+"configuració de Kerberos probablement voldran deshabilitar els canvis de la "
+"configuració automàtica."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Voleu esborrar la base de dades KDC?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Per defecte, la desinstal·lació d'aquest paquet no esborrarà la base de "
+"dades de KDC a «/var/lib/krb5kdc/principal», degut a que aquesta base de "
+"dades no es recuperable desprès d'esborrar-la."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Seleccioneu aquesta opció si desitja esborrar la base de dades KDC ara, "
+"esborrant tots els comptes d'usuari i contrasenyes en el KDC."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr ""
+#~ "Voleu executar el dimoni d'administració de Kerberos V5 («kadmind»)?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind gestiona les peticions per afegir, modificar i esborrar els "
+#~ "registres a la base de dades Kerberos."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "És necessari pel programa «kpasswd», que s'utilitza per canviar les "
+#~ "contrasenyes. Amb les configuracions estàndard, aquest dimoni s'ha "
+#~ "d'executar en el KDC principal"
diff --git a/debian/po/cs.po b/debian/po/cs.po
new file mode 100644
index 000000000..d10847303
--- /dev/null
+++ b/debian/po/cs.po
@@ -0,0 +1,225 @@
+#
+# Translators, if you are not familiar with the PO format, gettext
+# documentation is worth reading, especially sections dedicated to
+# this format, e.g. by running:
+# info -n '(gettext)PO Files'
+# info -n '(gettext)Header Entry'
+#
+# Some information specific to po-debconf are available at
+# /usr/share/doc/po-debconf/README-trans
+# or http://www.debian.org/intl/l10n/po-debconf/README-trans
+#
+# Developers do not need to manually edit POT or PO files.
+#
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2009-03-07 20:26+0100\n"
+"Last-Translator: Miroslav Kure <kurem@debian.cz>\n"
+"Language-Team: Czech <debian-l10n-czech@lists.debian.org>\n"
+"Language: cs\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Nastavení Kerberovy říše"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Tento balík obsahuje nezbytné administrativní nástroje pro běh hlavního "
+"kerberovského serveru."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Pouhou instalací tohoto balíku se však Kerberova říše nenastaví. Pro "
+"vytvoření říše spusťte po instalaci příkaz „krb5_newrealm“."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Také je vhodné si přečíst soubor /usr/share/doc/krb5-kdc/README.KDC a "
+"příručku administrátora v balíku krb5-doc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Vytvořit nastavení KDC automaticky?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Konfigurační soubory KDC (Kerberos Key Domain Controller) v /etc/krb5kdc "
+"mohou být vytvořeny automaticky."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Standardně se do tohoto adresáře nakopíruje ukázková šablona s "
+"předvyplněnými lokálními údaji."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Administrátoři, kteří již disponují infrastrukturou pro správu konfigurace "
+"Kerbera, budou nejspíš chtít tyto automatické změny v konfiguraci zakázat."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Má se smazat KDC databáze?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Ve výchozím nastavení se při odstranění balíku ze systému nesmaže KDC "
+"databáze ve /var/lib/krb5kdc/principal, protože ji po smazání nelze obnovit."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Chcete-li nyní smazat KDC databázi, tuto volbu povolte. Smazáním databáze se "
+"odstraní všechny uživatelské účty a všechna hesla v KDC."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Spustit administrační daemon Kerbera v5 (kadmind)?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind obsluhuje požadavky na přidání/změnu/smazání záznamů v databázi "
+#~ "Kerbera."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Také je vyžadován programem kpasswd, který se používá pro změnu hesel. "
+#~ "Tento daemon obvykle běží na hlavním KDC."
+
+#~ msgid "Kerberos V4 compatibility mode to use:"
+#~ msgstr "Režim zpětné kompatibility s Kerberem v4:"
+
+#~ msgid ""
+#~ "By default, Kerberos V4 requests are allowed from principals that do not "
+#~ "require preauthentication (\"nopreauth\"). This allows Kerberos V4 "
+#~ "services to exist while requiring most users to use Kerberos V5 clients "
+#~ "to get their initial tickets. These tickets can then be converted to "
+#~ "Kerberos V4 tickets."
+#~ msgstr ""
+#~ "Ve výchozím nastavení jsou povoleny požadavky z Kerbera v4, které "
+#~ "nevyžadují předautentizaci („nopreauth“). To umožňuje, aby existovaly "
+#~ "služby Kerbera v4, ovšem vyžaduje, aby většina klientů používala pro "
+#~ "získání prvotního lístku klienta Kerbera v5. Tyto lístky pak mohou být "
+#~ "přeměněny na lístky Kerbera v4."
+
+#~ msgid ""
+#~ "Alternatively, the mode can be set to \"full\", allowing Kerberos V4 "
+#~ "clients to get initial tickets even when preauthentication would normally "
+#~ "be required; to \"disable\", returning protocol version errors to all "
+#~ "Kerberos V4 clients; or to \"none\", which tells the KDC to not respond "
+#~ "to Kerberos V4 requests at all."
+#~ msgstr ""
+#~ "Volitelně můžete zapnout plnou podporu („full“), což umožní klientům "
+#~ "Kerbera v4 získat prvotní lístky i když by normálně byla vyžadována "
+#~ "předautentizace. Možnost zakázat („disable“) bude všem klientům Kerbera "
+#~ "v4 vracet chyby o nepodporované verzi, režim žádný („none“) znamená, že "
+#~ "Kerberos nebude na tyto požadavky odpovídat vůbec."
+
+#~ msgid "Run a Kerberos V5 to Kerberos V4 ticket conversion daemon?"
+#~ msgstr "Spustit daemon pro konverzi lístků Kerbera v5 na lístky Kerbera v4?"
+
+#~ msgid ""
+#~ "The krb524d daemon converts Kerberos V5 tickets into Kerberos V4 tickets "
+#~ "for programs, such as krb524init, that obtain Kerberos V4 tickets for "
+#~ "compatibility with old applications."
+#~ msgstr ""
+#~ "Daemon krb524d převádí lístky z Kerbera5 na lístky Kerbera4 pro programy "
+#~ "typu krb524init, které vyžadují lístky Kerbera v4 pro zajištění "
+#~ "kompatibility se staršími aplikacemi."
+
+#~ msgid ""
+#~ "It is recommended to enable that daemon if Kerberos V4 is enabled, "
+#~ "especially when Kerberos V4 compatibility is set to \"nopreauth\"."
+#~ msgstr ""
+#~ "Jestliže používáte aplikace pro Kerbera v4, doporučuje se povolit i "
+#~ "tohoto daemona, obzvláště pokud je kompatibilita s Kerberem v4 nastavena "
+#~ "na „nopreauth“."
+
+#~ msgid "Should the data be purged as well as the package files?"
+#~ msgstr "Mají se při úplném odstranění balíku smazat i data?"
+
+#~ msgid "disable"
+#~ msgstr "zakázat"
+
+#~ msgid "full"
+#~ msgstr "plný"
+
+#~ msgid "nopreauth"
+#~ msgstr "nopreauth"
+
+#~ msgid "none"
+#~ msgstr "žádný"
+
+#~ msgid ""
+#~ "Don't forget to set up DNS information so your clients can find your KDC "
+#~ "and admin servers. Doing so is documented in the administration guide."
+#~ msgstr ""
+#~ "Nezapomeňte nastavit DNS, aby klienti mohli najít váš KDC a "
+#~ "administrátorské servery. Vše je popsáno v příručce administrátora."
+
+#~ msgid ""
+#~ "Many sites will wish to have this script automatically create Kerberos "
+#~ "KDC configuration files in /etc/krb5kdc. By default an example template "
+#~ "will be copied into this directory with local parameters filled in. Some "
+#~ "sites who already have infrastructure to manage their own Kerberos "
+#~ "configuration will wish to disable any automatic configuration changes."
+#~ msgstr ""
+#~ "Mnoho správců bude chtít, aby za ně debconf provedl počáteční nastavení "
+#~ "kerberova KDC v /etc/krb5kdc. Standardně se do tohoto adresáře zkopíruje "
+#~ "šablona s předvyplněnými parametry. Některé servery, které již mají svou "
+#~ "vlastní infrastrukturu pro správu Kerbera, asi tuto automatickou "
+#~ "konfiguraci nepovolí, aby se jim nepřepsalo nastavení."
diff --git a/debian/po/da.po b/debian/po/da.po
new file mode 100644
index 000000000..2ff54e25a
--- /dev/null
+++ b/debian/po/da.po
@@ -0,0 +1,137 @@
+# Dansih translation krb5.
+# Copyright (C) 2010 krb5 & nedenstående oversættere.
+# This file is distributed under the same license as the krb5 package.
+# Claus Hindsgaul <claus_h@image.dk>, 2006.
+# Joe Hansen <joedalton2@yahoo.dk>, 2010.
+#
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2010-06-02 17:30+01:00\n"
+"Last-Translator: Joe Hansen <joedalton2@yahoo.dk>\n"
+"Language-Team: Danish <debian-l10n-danish@lists.debian.org> \n"
+"Language: \n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Sætter et Kerberos-rige op"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Denne pakke indeholder de administrative værktøjer krævet til at køre "
+"Kerberos' masterserver."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Installation af denne pakke medfører dog ikke automatisk, at et Kerberos-"
+"rige bliver sat op. Dette kan gøres senere ved at køre kommandoen "
+"»krb5_newrealm«."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Læs venligst også filen /usr/share/doc/krb5-kdc/README.KDC og "
+"administrationsvejledningen, der kan ses i pakken krb5-doc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Opret automatisk Kerberos KDC-konfigurationen?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Konfigurationsfilerne for Kerberos Key Distribution Center (KDC) i /etc/"
+"krb5kdc, kan oprettes automatisk."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Som standard vil en eksempelskabelon blive kopieret ind i denne mappe med "
+"lokale parametre udfyldt."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Administratorer, som allerede har infrastruktur til håndtering af deres "
+"Kerberoskonfiguration, vil måske ønske at deaktivere disse automatiske "
+"konfigurationsændringer."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Skal KDC-databasen slettes?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Som udgangspunkt vil KDC-databasen i /var/lib/krb5kdc/principal ikke blive "
+"slettet, når pakken afinstalleres, da denne database ikke kan genskabes, når "
+"den er slettet."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Vælg denne indstilling hvis du ønsker at slette KDC-databasen nu, dermed "
+"slettes alle brugerkonti og adgangskoder i KDC'en."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Skal administrationsdæmonen Kerberos5 (kadmind) køres?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmindservere anmoder om at tilføje/ændre/fjerne vigtige ting i "
+#~ "kerberosdatabasen."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Den er krævet af kpasswd-programmet, brugt til at ændre adgangskoder. Med "
+#~ "standardopsætning, skal denne dæmon køre på master-KDC'en."
diff --git a/debian/po/de.po b/debian/po/de.po
new file mode 100644
index 000000000..53e8e2876
--- /dev/null
+++ b/debian/po/de.po
@@ -0,0 +1,277 @@
+# Translation of krb5 debconf templates to German
+# Copyright (C):
+# Jens Nachtigall <nachtigall@web.de>, 2005.
+# Helge Kreutzmann <debian@helgefjell.de>, 2007-2009.
+# This file is distributed under the same license as the krb5 package.
+#
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5 1.6.dfsg.4~beta1-10\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2009-03-05 22:45+0100\n"
+"Last-Translator: Helge Kreutzmann <debian@helgefjell.de>\n"
+"Language-Team: de <debian-l10n-german@lists.debian.org>\n"
+"Language: \n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=iso-8859-15\n"
+"Content-Transfer-Encoding: 8bit\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Einrichten des Kerberos-Realm"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Dieses Paket enthlt die administrativen Werkzeuge, die zum Betrieb des "
+"Kerberos-Master-Servers bentigt werden."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Allerdings fhrt die Installation dieses Pakets nicht automatisch zur "
+"Einrichtung einer Kerberos-Realm. Dies kann spter mit dem Befehl "
+"krb5_newrealm erfolgen."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Bitte lesen Sie auch die Datei /usr/share/doc/krb5-kdc/README.KDC und den "
+"administrativen Leitfaden im krb5-doc-Paket."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Die Kerberos-KDC-Konfiguration automatisch erstellen?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Die Konfigurationsdateien des Kerberos Key Distribution Center (KDC) in /"
+"etc/krb5kdc knnen automatisch erstellt werden."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Standardmig wird eine Beispielvorlage in dieses Verzeichnis kopiert, in "
+"der lokale Parameter eingetragen sind."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Administratoren, die bereits ber eine Infrastruktur zur Verwaltung ihrer "
+"Kerberos-Konfiguration verfgen, mchten diese automatischen "
+"Konfigurationsnderungen eventuell deaktivieren."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Soll die KDC-Datenbank gelscht werden?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Standardmig wird whrend des Entfernens des Paketes die KDC-Datenbank in /"
+"var/lib/krb5kdc/principal nicht entfernt, da diese Datenbank nicht "
+"wiederhergestellt werden kann, nachdem sie gelscht wurde."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Whlen Sie diese Option, falls Sie mchten, dass die KDC-Datenbank jetzt "
+"gelscht werden soll. Dies lscht alle Benutzerkonten und Passwrter in dem "
+"KDC."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Soll der Kerberos V5-Administrations-Daemon (kadmind) laufen?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind bedient Anfragen, um Prinzipale in der Kerberos-Datenbank "
+#~ "hinzuzufgen/zu verndern/zu entfernen."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Es wird vom Kpasswd-Programm bentigt, dass zum ndern von Passwrtern "
+#~ "verwendet wird. Im Normalfall sollte der Daemon auf dem Master-KDC laufen."
+
+#~ msgid "Kerberos V4 compatibility mode to use:"
+#~ msgstr "Zu benutzender Kerberos V4-Kompatibilitts-Modus:"
+
+#~ msgid ""
+#~ "By default, Kerberos V4 requests are allowed from principals that do not "
+#~ "require preauthentication (\"nopreauth\"). This allows Kerberos V4 "
+#~ "services to exist while requiring most users to use Kerberos V5 clients "
+#~ "to get their initial tickets. These tickets can then be converted to "
+#~ "Kerberos V4 tickets."
+#~ msgstr ""
+#~ "Standardmig werden Kerberos V4-Anfragen von Prinzipalen erlaubt, die "
+#~ "keine vorherige Authentifizierung bentigen (nopreauth). Das ermglicht "
+#~ "Kerberos V4-Dienste zu betreiben, whrend gleichzeitig die meisten "
+#~ "Benutzer Kerberos V5-Clients verwenden mssen, um ihr anfngliches Ticket "
+#~ "zu bekommen. Diese Tickets knnen in Kerberos V4-Tickets umgewandelt "
+#~ "werden. "
+
+#~ msgid ""
+#~ "Alternatively, the mode can be set to \"full\", allowing Kerberos V4 "
+#~ "clients to get initial tickets even when preauthentication would normally "
+#~ "be required; to \"disable\", returning protocol version errors to all "
+#~ "Kerberos V4 clients; or to \"none\", which tells the KDC to not respond "
+#~ "to Kerberos V4 requests at all."
+#~ msgstr ""
+#~ "Alternativ kann der Modus auch auf full gesetzt werden, wodurch "
+#~ "Kerberos V4-Clients anfngliche Tickets ohne vorherige Authentifizierung "
+#~ "erhalten knnen, selbst wenn prauth normalerweise ntig wre. Eine "
+#~ "weitere Mglichkeit ist disable, wobei dann Protokollversionsfehler an "
+#~ "alle Kerberos V4-Clients gesandt werden und none, der den KDC anweist, "
+#~ "auf Kerberos V4-Anfragen berhaupt nicht zu reagieren."
+
+#~ msgid "Run a Kerberos V5 to Kerberos V4 ticket conversion daemon?"
+#~ msgstr "Einen Kerberos V5-auf-V4 Ticket-Konvertier-Daemon betreiben?"
+
+#~ msgid ""
+#~ "The krb524d daemon converts Kerberos V5 tickets into Kerberos V4 tickets "
+#~ "for programs, such as krb524init, that obtain Kerberos V4 tickets for "
+#~ "compatibility with old applications."
+#~ msgstr ""
+#~ "Der Krb524d-Daemon konvertiert V5-Tickets in V4-Tickest fr Programme wie "
+#~ "Krb524init, die Kerberos V4-Tickets zur Kompatibilitt fr ltere "
+#~ "Anwendungen besorgen."
+
+#~ msgid ""
+#~ "It is recommended to enable that daemon if Kerberos V4 is enabled, "
+#~ "especially when Kerberos V4 compatibility is set to \"nopreauth\"."
+#~ msgstr ""
+#~ "Es wird empfohlen, diesen Daemon zu aktivieren, falls Kerberos V4 "
+#~ "aktiviert ist, insbesondere wenn Kerberos V4-Kompatibilitt auf "
+#~ "nopreauth gesetzt ist."
+
+#~ msgid "Should the data be purged as well as the package files?"
+#~ msgstr ""
+#~ "Sollen die Daten genauso wie die Paket-Dateien vollstndig entfernt "
+#~ "werden?"
+
+#~ msgid "disable"
+#~ msgstr "deaktivieren"
+
+#~ msgid "full"
+#~ msgstr "komplett"
+
+#~ msgid "nopreauth"
+#~ msgstr "nopreauth"
+
+#~ msgid "none"
+#~ msgstr "keinen"
+
+#~ msgid ""
+#~ "This package contains the administrative tools necessary to run on the "
+#~ "Kerberos master server. However, installing this package does not "
+#~ "automatically set up a Kerberos realm. Doing so requires entering "
+#~ "passwords and as such is not well-suited for package installation. To "
+#~ "create the realm, run the krb5_newrealm command. You may also wish to "
+#~ "read /usr/share/doc/krb5-kdc/README.KDC and the administration guide "
+#~ "found in the krb5-doc package."
+#~ msgstr ""
+#~ "Dieses Paket enthlt die administrativen Werkzeuge, die fr den Kerberos-"
+#~ "Masterserver bentigt werden. Die Installation dieses Pakets bedeutet "
+#~ "jedoch nicht, dass der Kerberos-Realm automatisch eingerichtet wird. Dazu "
+#~ "wre die Eingabe von Passwrtern notwendig und deshalb ist dies nicht "
+#~ "sonderlich fr die Paket-Installation geeignet. Um den Realm zu "
+#~ "erstellen, fhren Sie bitte den Befehl krb5_newrealm aus. Lesen Sie "
+#~ "eventuell auch /usr/share/doc/krb5-kdc/README.KDC oder den "
+#~ "Administrations-Leitfaden, welcher im Paket krb5-doc zu finden ist."
+
+#~ msgid ""
+#~ "Don't forget to set up DNS information so your clients can find your KDC "
+#~ "and admin servers. Doing so is documented in the administration guide."
+#~ msgstr ""
+#~ "Vergessen Sie nicht DNS einzurichten, damit Ihre Clients auch Ihre KDC- "
+#~ "und Admin-Server finden. Wie Sie dazu vorgehen mssen, steht im "
+#~ "Administrations-Leitfaden."
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database. It also must be running for the kpasswd program to be used to "
+#~ "change passwords. Normally, this daemon runs on the master KDC."
+#~ msgstr ""
+#~ "Kadmind beantwortet Anfragen um Principals in die Kerberos-Datenbank "
+#~ "einzufgen, zu verndern oder aus der Datenbank zu entfernen. Kadmind "
+#~ "muss laufen, damit das Programm kpasswd in der Lage ist, Passwrter zu "
+#~ "verndern. Normalerweise luft dieser Daemon auf dem Master-KDC."
+
+#~ msgid ""
+#~ "Many sites will wish to have this script automatically create Kerberos "
+#~ "KDC configuration files in /etc/krb5kdc. By default an example template "
+#~ "will be copied into this directory with local parameters filled in. Some "
+#~ "sites who already have infrastructure to manage their own Kerberos "
+#~ "configuration will wish to disable any automatic configuration changes."
+#~ msgstr ""
+#~ "Viele Sites werden es bevorzugen, wenn dieses Skript automatisch die "
+#~ "Kerberos-KDC-Konfigurationsdateien in /etc/krb5kdc erstellt. "
+#~ "Standardmig wird eine Beispiel-Vorlage in dieses Verzeichnis kopiert "
+#~ "und mit lokalen Parametern ausgefllt. Einige Sites, welche bereits die "
+#~ "Infrastruktur besitzen um Ihre eigene Kerberos-Konfiguration zu "
+#~ "verwalten, werden es bevorzugen, jede automatische Vernderung der "
+#~ "Konfiguration zu deaktivieren."
+
+#~ msgid "disable, full, nopreauth, none"
+#~ msgstr "deaktivieren, total, ohne vorherige Authenfizierung, keiner"
+
+#~ msgid "Run a krb524d?"
+#~ msgstr "Soll krb524d laufen?"
+
+#~ msgid ""
+#~ "Krb524d is a daemon that converts Kerberos5 tickets into Kerberos4 "
+#~ "tickets for the krb524init program. If you have Kerberos4 enabled at "
+#~ "all, then you probably want to run this program. Especially when "
+#~ "Kerberos4 compatibility is set to nopreauth, krb524d is important if you "
+#~ "have any Kerberos4 services."
+#~ msgstr ""
+#~ "Krb524d ist ein Daemon, der Kerberos5-Tickets fr das Programm krb524init "
+#~ "in Kerberos4-Tickets umwandelt. Haben Sie Kerberos4 aktiviert, dann "
+#~ "sollten Sie wahrscheinlich diesen Dienst laufen lassen. Insbesondere wenn "
+#~ "der Kerberos4-Kompatibilitts-Modus auf ohne vorherige "
+#~ "Authentifizierung gesetzt ist, ist krb524d wichtig, wenn Sie "
+#~ "irgendwelche Kerberos4-Dienste haben."
diff --git a/debian/po/es.po b/debian/po/es.po
new file mode 100644
index 000000000..4bf035e6e
--- /dev/null
+++ b/debian/po/es.po
@@ -0,0 +1,216 @@
+# krb5 po-debconf translation to Spanish
+# Copyright (C) 2006, 2008, 2009 Software in the Public Interest
+# This file is distributed under the same license as the krb5 package.
+#
+# Changes:
+# - Initial translation
+# Fernando Cerezal López <kryptos21@gmail.com>, 2006
+#
+# - Updates
+# Diego Lucio D'Onofrio <therealnuke@gmail.com>, 2008
+# Ignacio Mondino <ignacio.mondino@gmail.com>, 2008
+# Francisco Javier Cuadrado <fcocuadrado@gmail.com>, 2009
+#
+# Traductores, si no conocen el formato PO, merece la pena leer la
+# documentación de gettext, especialmente las secciones dedicadas a este
+# formato, por ejemplo ejecutando:
+# info -n '(gettext)PO Files'
+# info -n '(gettext)Header Entry'
+#
+# Equipo de traducción al español, por favor lean antes de traducir
+# los siguientes documentos:
+#
+# - El proyecto de traducción de Debian al español
+# http://www.debian.org/intl/spanish/
+# especialmente las notas y normas de traducción en
+# http://www.debian.org/intl/spanish/notas
+#
+# - La guía de traducción de po's de debconf:
+# /usr/share/doc/po-debconf/README-trans
+# o http://www.debian.org/intl/l10n/po-debconf/README-trans
+#
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5 1.6.dfsg.4~beta1-10\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2009-03-09 18:12+0100\n"
+"Last-Translator: Francisco Javier Cuadrado <fcocuadrado@gmail.com>\n"
+"Language-Team: Debian l10n Spanish <debian-l10n-spanish@lists.debian.org>\n"
+"Language: \n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Configuración de un reino de Kerberos"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Este paquete contiene las herramientas administrativas necesarias para "
+"ejecutar el servidor maestro Kerberos."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Sin embargo, el instalar este paquete no configura automáticamente un reino "
+"de Kerberos. Esto se puede hacer más tarde ejecutando la orden "
+"«krb5_newrealm»."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Por favor, lea también el fichero «/usr/share/doc/krb5-kdc/README.KDC» y la "
+"guía de administración que se encuentra en el paquete krb5-doc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "¿Desea crear la configuración del KDC de Kerberos automáticamente?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Los archivos de configuración, ubicados en «/etc/krb5kdc», del centro de "
+"distribución de claves de Kerberos (KDC) se podrán crear automáticamente."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Por omisión, una plantilla de ejemplo se copiará en este directorio con los "
+"parámetros locales completados."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Los administradores que ya posean la infraestructura para manejar su "
+"configuración de Kerberos podrían querer deshabilitar estos cambios de "
+"configuración automáticos."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "¿Desea eliminar la base de datos de KDC?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Por omisión, eliminar este paquete no borrará la base de datos KDC en «/var/"
+"lib/krb5kdc/principal», ya que esta base de datos no se puede recuperar una "
+"vez eliminada."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Seleccione esta opción si desea eliminar la base de datos de KDC ahora, "
+"eliminando todas las cuentas de usuarios y contraseñas en KDC."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr ""
+#~ "¿Desea ejecutar el demonio de administración de Kerberos V5 (kadmind)?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind sirve peticiones para agregar/modificar/quitar principales de la "
+#~ "base de datos de Kerberos."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "El programa kpasswd necesita esto para poder cambiar las contraseñas. Con "
+#~ "la configuración estándar, este demonio debe ejecutarse en el KDC maestro."
+
+#~ msgid "Kerberos V4 compatibility mode to use:"
+#~ msgstr "Modo de compatibilidad con Kerberos V4 a utilizar:"
+
+#~ msgid ""
+#~ "By default, Kerberos V4 requests are allowed from principals that do not "
+#~ "require preauthentication (\"nopreauth\"). This allows Kerberos V4 "
+#~ "services to exist while requiring most users to use Kerberos V5 clients "
+#~ "to get their initial tickets. These tickets can then be converted to "
+#~ "Kerberos V4 tickets."
+#~ msgstr ""
+#~ "Por omisión, se permiten las peticiones Kerberos V4 desde los principales "
+#~ "que no necesiten preautenticación («nopreauth»). Esto permite que los "
+#~ "servicios de Kerberos V4 existan mientras se solicita a la mayoría de los "
+#~ "usuarios que utilicen clientes Kerberos V5 para obtener sus «tickets» "
+#~ "iniciales. Estos «tickets» se pueden convertir entonces a «tickets» de "
+#~ "Kerberos V4."
+
+#~ msgid ""
+#~ "Alternatively, the mode can be set to \"full\", allowing Kerberos V4 "
+#~ "clients to get initial tickets even when preauthentication would normally "
+#~ "be required; to \"disable\", returning protocol version errors to all "
+#~ "Kerberos V4 clients; or to \"none\", which tells the KDC to not respond "
+#~ "to Kerberos V4 requests at all."
+#~ msgstr ""
+#~ "Alternativamente, el modo puede ser establecido como «full», permitiendo "
+#~ "a losclientes de Kerberos V4 conseguir «tickets» iniciales aún cuando "
+#~ "normalmente se requiera preautenticación; como «disable», devolviendo "
+#~ "errores de versión de protocolo a todos los clientes de Kerberos V4; o "
+#~ "como «none», lo cual ordenará a KDC no responder nada las peticiones de "
+#~ "Kerberos V4 de ninguna forma."
+
+#~ msgid "Run a Kerberos V5 to Kerberos V4 ticket conversion daemon?"
+#~ msgstr ""
+#~ "¿Desea ejecutar el demonio de conversión de «tickets» de Kerberos V5 a "
+#~ "Kerberos V4?"
+
+#~ msgid ""
+#~ "The krb524d daemon converts Kerberos V5 tickets into Kerberos V4 tickets "
+#~ "for programs, such as krb524init, that obtain Kerberos V4 tickets for "
+#~ "compatibility with old applications."
+#~ msgstr ""
+#~ "El demonio krb524d convierte los «tickets» de Kerberos V5 a «tickets» de "
+#~ "Kerberos V4 para que programas tales como krb524init obtengan «tickets» "
+#~ "Kerberos V4 compatibles con aplicaciones antiguas."
+
+#~ msgid ""
+#~ "It is recommended to enable that daemon if Kerberos V4 is enabled, "
+#~ "especially when Kerberos V4 compatibility is set to \"nopreauth\"."
+#~ msgstr ""
+#~ "Es recomendable habilitar este demonio si Kerberos V4 está habilitado, "
+#~ "especialmente cuando la compatibilidad de Kerberos V4 está establecida "
+#~ "como «nopreauth»."
diff --git a/debian/po/eu.po b/debian/po/eu.po
new file mode 100644
index 000000000..2a899d132
--- /dev/null
+++ b/debian/po/eu.po
@@ -0,0 +1,183 @@
+# translation of krb5-eu.po to Euskara
+# Copyright (C) YEAR THE PACKAGE'S COPYRIGHT HOLDER
+# This file is distributed under the same license as the PACKAGE package.
+#
+# Piarres Beobide <pi@beobide.net>, 2007, 2008.
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5-eu\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2008-05-22 15:38+0200\n"
+"Last-Translator: Piarres Beobide <pi@beobide.net>\n"
+"Language-Team: Euskara <debian-l10n-basque@lists.debian.org>\n"
+"Language: \n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+"X-Generator: KBabel 1.11.4\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Kerberos eremu bat ezartzen"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Pakete honek Kerberos zerbitzari nagusia abiarazteko lanabes "
+"administratiboak ditu."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Hala ere, pakete hau instalatzeak ez du Kerberos eremu bat automatikoki "
+"konfiguratzen. Hori beranduago egin daiteke \"krb5_newrealm\" komandoa "
+"erabiliaz."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Mesedez irakurri ere /usr/share/doc/krb5-kdc/README.KDC fitxategia eta krb5-"
+"doc paketean aurki daitekeen administrazio gidaliburua."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Kerberos KDC konfigurazioa automatikoki sortu?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Kerberos gako banaketa zentru (KDC) konfigurazio fitxategiak, automatikoki "
+"sortuko dira /etc/krb5kdc direktorioan."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Lehenespen bezala, parametro lokalak beterik dituen adibide txantiloi bat "
+"kopiatuko da direktorio horretan."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Kerberos konfigurazioa kudeatzeko azpiegitura duten kudeatzaileek "
+"konfigurazio aldaketa automatiko hauek ezgaitu nahi ditzakete."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "KDC datu-basea ezabatu egin behar al da?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Lehenespen bezala, pakete hu garbitzean ez da /var/lib/krb5kdc/principal-eko "
+"KDC datu-basea ezabatuko ezin bait da berreskuratu ezabatzen bada."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Aukera hau hautatu paketea garbitzean KDC datu-basea ezabatzea nahi baduzu, "
+"horrela KDC-an dauden erabiltzaile kontu eta pasahitz guztiak ezabatuko dira."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Kerberos 5 administrazio deabrua (kadmind) abiarazi?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind-ek Kerberos datu-baseko gehitze/eraldatze/ezabatze eskaera "
+#~ "nagusiak zerbitzatzen ditu."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Hau pasahitzak aldatzeko erabiltzen den kpasswd programaren eskakizun bat "
+#~ "da. Konfigurazio estandarrarekin, deabru hau KDC nagusian abiarazi behar "
+#~ "da."
+
+#~ msgid "Kerberos V4 compatibility mode to use:"
+#~ msgstr "Erabiliko den Kerberos 4 bateragarritasun modua:"
+
+#~ msgid ""
+#~ "By default, Kerberos V4 requests are allowed from principals that do not "
+#~ "require preauthentication (\"nopreauth\"). This allows Kerberos V4 "
+#~ "services to exist while requiring most users to use Kerberos V5 clients "
+#~ "to get their initial tickets. These tickets can then be converted to "
+#~ "Kerberos V4 tickets."
+#~ msgstr ""
+#~ "Lehenespen bezala, Kerberos 4 eskaerak onartzen dira aurreautentifikazioa "
+#~ "(\"nopreauth\") eskatzen ez duten nagusietatik onartzen dira. Honek "
+#~ "Kerberos 4 zerbitzuak egoteko aukera ematen du erabiltzaile gehienei "
+#~ "Kerberos 5 bezeroak eskatzen zaienean hasierako tiketak eskuratzeko. "
+#~ "Tiket horiek Kerberos 4 tiketak bihurtu daitezke."
+
+#~ msgid ""
+#~ "Alternatively, the mode can be set to \"full\", allowing Kerberos V4 "
+#~ "clients to get initial tickets even when preauthentication would normally "
+#~ "be required; to \"disable\", returning protocol version errors to all "
+#~ "Kerberos V4 clients; or to \"none\", which tells the KDC to not respond "
+#~ "to Kerberos V4 requests at all."
+#~ msgstr ""
+#~ "Bestela, modua \"full\" bezala ezarri daiteke Kerberos 4 bezeroei hasiera "
+#~ "tiketak eskuratzen uzteko nahiz arruntean aurreautentifikazioa eskatuko "
+#~ "zen; \"disable\" Kerberos 4 bezeroei protokolo errore bat itzultzeko; edo "
+#~ "\"none\" bezala ezarri KDC-al Kerberos 4 eskaerei ez erantzuteko."
+
+#~ msgid "Run a Kerberos V5 to Kerberos V4 ticket conversion daemon?"
+#~ msgstr "Kerberos 5-etik Kerberos 4-ra tiketak bihurtzeko deabrua abiarazi?"
+
+#~ msgid ""
+#~ "The krb524d daemon converts Kerberos V5 tickets into Kerberos V4 tickets "
+#~ "for programs, such as krb524init, that obtain Kerberos V4 tickets for "
+#~ "compatibility with old applications."
+#~ msgstr ""
+#~ "krb524d deabruak Kerberos 5 tiketak Kerberos 4-ra bihurtzen ditu "
+#~ "krb524init bezala aplikazioa zaharrekin bateragarritasuna mantentzeko "
+#~ "kerberos 4 tiketak eskuratzen dituzten programentzat."
+
+#~ msgid ""
+#~ "It is recommended to enable that daemon if Kerberos V4 is enabled, "
+#~ "especially when Kerberos V4 compatibility is set to \"nopreauth\"."
+#~ msgstr ""
+#~ "Gomendagarria da deabrua gaitzea Kerberos 4 instalaturik badago bereiziki "
+#~ "\"nopreauth\" bateragarritasun modua ezarririk badago."
diff --git a/debian/po/fi.po b/debian/po/fi.po
new file mode 100644
index 000000000..3668cf0e6
--- /dev/null
+++ b/debian/po/fi.po
@@ -0,0 +1,132 @@
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5_1.6.dfsg.3~beta1-2\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2009-03-14 20:56+0200\n"
+"Last-Translator: Esko Arajärvi <edu@iki.fi>\n"
+"Language-Team: Finnish <debian-l10n-finnish@lists.debian.org>\n"
+"Language: fi\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+"X-Poedit-Language: Finnish\n"
+"X-Poedit-Country: FINLAND\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Kerberos-toimialueen asetus"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Tämä paketti sisältää Kerberos-isäntäpalvelimen pidossa tarvittavat "
+"ylläpitotyökalut."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Paketin asentaminen ei kuitenkaan automaattisesti aseta Kerberos-"
+"toimialuetta. Tämä voidaan tehdä myöhemmin ajamalla komento ”krb5_newrealm”."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Lue myös /usr/share/doc/krb5-kdc/README.KDC ja paketista krb5-doc löytyvä "
+"ylläpito-opas."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Luodaanko Kerberos KDC -asetukset automaattisesti?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Kerberos-avainten jakokeskuksen (Kerberos Key Distribution Center, KDC) "
+"hakemistossa /etc/krb5kdc olevat asetustiedostot voidaan luoda "
+"automaattisesti."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Oletuksena mallitiedosto kopioidaan tähän hakemistoon ja siihen lisätään "
+"paikalliset parametrit."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Ylläpitäjät, joilla on jo järjestelmä Kerberos-asetustensa hallitsemiseen, "
+"saattavat haluta poistaa käytöstä tämän asetusten automaattisen muokkaamisen."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Tulisiko KDC-tietokanta poistaa?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Tämän paketin siivoaminen ei oletuksena poista hakemistossa /var/lib/krb5kdc/"
+"principal olevaa KDC-tietokantaa, koska tätä tietokantaa ei voida palauttaa "
+"kun se kerran on poistettu."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Valitse tämä vaihtoehto, jos KDC-tietokanta halutaan poistaa nyt. Tällöin "
+"poistetaan kaikki KDC:n käyttäjätunnukset ja salasanat."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Ajetaanko Kerberos V5 -ylläpitotaustaohjelmaa (kadmind)?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind palvelee pyyntöjä lisätä, muuttaa tai poistaa käyttäjiä Kerberos-"
+#~ "tietokannasta."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Salasanojen vaihtoon käytetty ohjelma kpasswd vaatii tämän. Normaaleissa "
+#~ "asennuksissa taustaohjelmaa tulisi ajaa isäntä-KDC:llä."
diff --git a/debian/po/fr.po b/debian/po/fr.po
new file mode 100644
index 000000000..8ad1ae38f
--- /dev/null
+++ b/debian/po/fr.po
@@ -0,0 +1,197 @@
+# Translation of krb5 debconf templates to French
+# Copyright (C) 2005-2009 Debian French l10n team <debian-l10n-french@lists.debian.org>
+# This file is distributed under the same license as the krb5 package.
+#
+# Translators:
+# Christian Perrier <bubulle@debian.org>, 2005, 2008, 2009, 2011.
+msgid ""
+msgstr ""
+"Project-Id-Version: \n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2011-06-17 19:57+0200\n"
+"Last-Translator: Christian Perrier <bubulle@debian.org>\n"
+"Language-Team: French <debian-l10n-french@lists.debian.org>\n"
+"Language: fr\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+"X-Generator: Lokalize 1.2\n"
+"Plural-Forms: nplurals=2; plural=(n > 1);\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Configuration d'un royaume (« Realm ») Kerberos"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Ce paquet contient les outils d'administration utiles pour un serveur maître "
+"Kerberos."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Cependant, la simple installation de ce paquet ne suffit pas pour mettre en "
+"service automatiquement un royaume Kerberos. Pour créer le royaume, veuillez "
+"utiliser la commande « krb5_newrealm »."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Vous pouvez aussi consulter le fichier /usr/share/doc/krb5-kdc/README.KDC et "
+"le guide d'administration fourni dans le paquet krb5-doc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr ""
+"Faut-il créer la configuration du centre de distribution de clés Kerberos "
+"automatiquement ?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Les fichiers de configuration du centre de distribution de clés Kerberos "
+"(KDC : Key Distribution Center), situés dans /etc/krb5kdc, peuvent être "
+"créés automatiquement."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Par défaut, des fichiers d'exemples comportant des paramètres locaux seront "
+"placés dans ce répertoire."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Les administrateurs qui utilisent déjà une infrastructure de gestion de la "
+"configuration de Kerberos souhaiteront probablement désactiver toute "
+"modification automatique de la configuration."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Faut-il supprimer la base de données KDC ?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Par défaut, la suppression complète de ce paquet ne supprimera pas la base "
+"de données KDC dans /var/lib/krb5kdc/principal car cette base de données ne "
+"peut pas être récupérée une fois supprimée."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Choisissez cette option si vous souhaitez supprimer la base de données KDC "
+"maintenant, ce qui supprimera tous les comptes des utilisateurs ainsi que "
+"les mots de passe, sur le ecntre de distribution de clés Kerberos (KDC)."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Faut-il lancer le démon d'administration de Kerberos v5 (kadmind) ?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind répond aux requêtes d'ajout, modification et suppression des "
+#~ "enregistrements dans la base de données de Kerberos."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Il est également indispensable pour que le programme kpasswd puisse "
+#~ "changer les mots de passe. Habituellement, ce démon doit être "
+#~ "opérationnel sur le centre de distribution de clés Kerberos (KDC)."
+
+#~ msgid "Kerberos V4 compatibility mode to use:"
+#~ msgstr "Mode de compatibilité avec Kerberos v4 à utiliser :"
+
+#~ msgid ""
+#~ "By default, Kerberos V4 requests are allowed from principals that do not "
+#~ "require preauthentication (\"nopreauth\"). This allows Kerberos V4 "
+#~ "services to exist while requiring most users to use Kerberos V5 clients "
+#~ "to get their initial tickets. These tickets can then be converted to "
+#~ "Kerberos V4 tickets."
+#~ msgstr ""
+#~ "Par défaut, les requêtes Kerberos v4 sont autorisées pour les "
+#~ "enregistrements (« principals ») qui n'ont pas besoin de pré-"
+#~ "authentification (« nopreauth »). Cela permet que les services Kerberos "
+#~ "v4 fonctionnent mais la majorité des utilisateurs devront utiliser des "
+#~ "clients Kerberos v5 pour obtenir leurs tickets initiaux. Ces tickets "
+#~ "pourront ensuite être convertis en tickets Kerberos v4."
+
+#~ msgid ""
+#~ "Alternatively, the mode can be set to \"full\", allowing Kerberos V4 "
+#~ "clients to get initial tickets even when preauthentication would normally "
+#~ "be required; to \"disable\", returning protocol version errors to all "
+#~ "Kerberos V4 clients; or to \"none\", which tells the KDC to not respond "
+#~ "to Kerberos V4 requests at all."
+#~ msgstr ""
+#~ "Ce mode peut également être configuré comme complet (« full »), ce qui "
+#~ "permet aux clients Kerberos v4 d'obtenir leurs tickets initiaux même "
+#~ "lorsque la pré-authentification est requise. Un autre réglage possible "
+#~ "est de le désactiver (« disable ») ce qui renvoie une erreur de version "
+#~ "de protocole à tous les clients Kerberos v4, ou de désactiver totalement "
+#~ "les réponses aux requêtes Kerberos v4 (« none »)."
+
+#~ msgid "Run a Kerberos V5 to Kerberos V4 ticket conversion daemon?"
+#~ msgstr ""
+#~ "Faut-il lancer un démon de conversion des tickets Kerberos v5 en Kerberos "
+#~ "v4 ?"
+
+#~ msgid ""
+#~ "The krb524d daemon converts Kerberos V5 tickets into Kerberos V4 tickets "
+#~ "for programs, such as krb524init, that obtain Kerberos V4 tickets for "
+#~ "compatibility with old applications."
+#~ msgstr ""
+#~ "Krb524d est un démon qui permet de convertir les tickets Kerberos v5 en "
+#~ "tickets Kerberos v4 pour les programmes tels que krb524init, qui "
+#~ "obtiennent des tickets Kerberos v4 pour préserver la compatibilité avec "
+#~ "d'anciennes applications."
+
+#~ msgid ""
+#~ "It is recommended to enable that daemon if Kerberos V4 is enabled, "
+#~ "especially when Kerberos V4 compatibility is set to \"nopreauth\"."
+#~ msgstr ""
+#~ "Ce démon est indispensable lorsque Kerberos4 est activé, notamment si le "
+#~ "mode de compatibilié est « pas de pré-authentification » (nopreauth)."
diff --git a/debian/po/gl.po b/debian/po/gl.po
new file mode 100644
index 000000000..e26a18751
--- /dev/null
+++ b/debian/po/gl.po
@@ -0,0 +1,272 @@
+# Galician translation of krb5's debconf templates.
+# This file is distributed under the same license as the krb5 package.
+#
+# Jacobo Tarrio <jtarrio@debian.org>, 2006, 2007.
+# marce villarino <mvillarino@users.sourceforge.net>, 2009.
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2009-03-12 17:14-0700\n"
+"Last-Translator: marce villarino <mvillarino@users.sourceforge.net>\n"
+"Language-Team: Galician <proxecto@trasno.ent>\n"
+"Language: gl\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+"X-Generator: Lokalize 0.2\n"
+"Plural-Forms: nplurals=2; plural=n != 1;\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Configuración dun reino Kerberos"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Este paquete contén as ferramentas administrativas precisas para que "
+"funcione o servidor mestre de Kerberos."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Porén, ao instalar este paquete non se configura automaticamente un reino "
+"Kerberos. Isto pódese facer despois executando a orde «krb5_newrealm»."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Consulte tamén o ficheiro /usr/share/doc/krb5-kdc/README.KDC e a guía do "
+"administrador que hai no paquete krb5-doc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Desexa crear automaticamente a configuración do KDC de Kerberos?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Pódense crear automaticamente os ficheiros de configuración do Centro de "
+"Distribución de Chaves de Kerberos (KDC) en /etc/krb5kdc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Por omisión hase copiar un modelo de exemplo neste directorio preenchendo os "
+"parámetros locais."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Os administradores que xa teñan unha infraestrutura para xestionar a "
+"configuración de Kerberos poden ter que desactivar estas modificacións de "
+"configuración automáticas."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Desexa eliminar a base de datos do KDC?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Por omisión, ao eliminar este paquete non se ha borrar a base de datos do "
+"KDC de /var/lib/krb5kdc/principal, xa que esta base de datos non se pode "
+"recuperar despois de borrala."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Escolla esta opción se quere borrar a base de datos do KDC agora, eliminando "
+"todas as contas de usuario e contrasinais do KDC."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr ""
+#~ "Desexa executar o servizo de administración de Kerberos V5 (kadmind)?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind serve peticións para engadir/modificar/eliminar principais na "
+#~ "base de datos Kerberos."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Precisa del o programa kpasswd, que se emprega para cambiar os "
+#~ "contrasinais. Coas configuracións estándar, este servizo debería estar a "
+#~ "funcionar no KDC mestre."
+
+#~ msgid "Kerberos V4 compatibility mode to use:"
+#~ msgstr "Modo de compatibilidade con Kerberos V4 a empregar:"
+
+#~ msgid ""
+#~ "By default, Kerberos V4 requests are allowed from principals that do not "
+#~ "require preauthentication (\"nopreauth\"). This allows Kerberos V4 "
+#~ "services to exist while requiring most users to use Kerberos V5 clients "
+#~ "to get their initial tickets. These tickets can then be converted to "
+#~ "Kerberos V4 tickets."
+#~ msgstr ""
+#~ "Por defecto admítense as peticións Kerberos V4 desde os principais que "
+#~ "non precisan de preautenticación (\"nopreauth\"). Isto permite que os "
+#~ "servizos Kerberos V4 sigan a existir mentres se require que a maioría dos "
+#~ "usuarios empreguen clientes Kerberos V5 para obter os seus tiquets "
+#~ "iniciais. Eses tiquets logo pódense converter en tiquets Kerberos V4."
+
+#~ msgid ""
+#~ "Alternatively, the mode can be set to \"full\", allowing Kerberos V4 "
+#~ "clients to get initial tickets even when preauthentication would normally "
+#~ "be required; to \"disable\", returning protocol version errors to all "
+#~ "Kerberos V4 clients; or to \"none\", which tells the KDC to not respond "
+#~ "to Kerberos V4 requests at all."
+#~ msgstr ""
+#~ "De xeito alternativo, pode cambiarse ao modo \"full\" (completo), o que "
+#~ "permite que os clientes Kerberos V4 obteñan tiquets iniciais incluso "
+#~ "cando se precisaría normalmente de preautenticación; ao modo \"disable"
+#~ "\" (desactivado), o que fai que se devolvan erros de versión do protocolo "
+#~ "aos clientes Kerberos V4, ou a \"none\" (ningún), o que indica ao KDC que "
+#~ "non resposte en absoluto ás peticións Kerberos V4."
+
+#~ msgid "Run a Kerberos V5 to Kerberos V4 ticket conversion daemon?"
+#~ msgstr ""
+#~ "¿Executar un servizo de conversións de tiquets Kerberos V5 a Kerberos V4?"
+
+#~ msgid ""
+#~ "The krb524d daemon converts Kerberos V5 tickets into Kerberos V4 tickets "
+#~ "for programs, such as krb524init, that obtain Kerberos V4 tickets for "
+#~ "compatibility with old applications."
+#~ msgstr ""
+#~ "O servizo krb524d convirte os tiquets Kerberos V5 a tiquets Kerberos V4 "
+#~ "para os programas, tales coma krb524init, que obteñen tiquets Kerberos V4 "
+#~ "por compatibilidade coas aplicacións antigas."
+
+#~ msgid ""
+#~ "It is recommended to enable that daemon if Kerberos V4 is enabled, "
+#~ "especially when Kerberos V4 compatibility is set to \"nopreauth\"."
+#~ msgstr ""
+#~ "Recoméndase activar este servizo se se activa Kerberos V4, especialmente "
+#~ "se se establece a compatibilidade Kerberos V4 a \"nopreauth\"."
+
+#~ msgid "Should the data be purged as well as the package files?"
+#~ msgstr "¿Deben purgarse os datos cos ficheiros dos paquetes?"
+
+#~ msgid "disable"
+#~ msgstr "desactivado"
+
+#~ msgid "full"
+#~ msgstr "completo"
+
+#~ msgid "nopreauth"
+#~ msgstr "nopreauth"
+
+#~ msgid "none"
+#~ msgstr "ningún"
+
+#~ msgid ""
+#~ "This package contains the administrative tools necessary to run on the "
+#~ "Kerberos master server. However, installing this package does not "
+#~ "automatically set up a Kerberos realm. Doing so requires entering "
+#~ "passwords and as such is not well-suited for package installation. To "
+#~ "create the realm, run the krb5_newrealm command. You may also wish to "
+#~ "read /usr/share/doc/krb5-kdc/README.KDC and the administration guide "
+#~ "found in the krb5-doc package."
+#~ msgstr ""
+#~ "Este paquete contén as ferramentas administrativas necesarias para "
+#~ "executar no servidor mestre de Kerberos. Nembargantes, a instalación "
+#~ "deste paquete non configura automaticamente un reino Kerberos. Para "
+#~ "facelo hai que introducir contrasinais, e por iso non se axusta ben á "
+#~ "instalación do paquete. Para crear o reini execute o programa "
+#~ "krb5_newrealm. Tamén é importante que lea o ficheiro /usr/sare/doc/krb5-"
+#~ "kdc/README.KDC e a guía administrativa que se atopa no paquete krb5-doc."
+
+#~ msgid ""
+#~ "Don't forget to set up DNS information so your clients can find your KDC "
+#~ "and admin servers. Doing so is documented in the administration guide."
+#~ msgstr ""
+#~ "Non esqueza configurar a información do DNS para que os clientes poidan "
+#~ "atopar o KDC e o servidor administrativo. O xeito de o facer documéntase "
+#~ "na guía de administración."
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database. It also must be running for the kpasswd program to be used to "
+#~ "change passwords. Normally, this daemon runs on the master KDC."
+#~ msgstr ""
+#~ "Kadmind serve peticións para engadir/modificar/eliminar principais na "
+#~ "base de datos Kerberos. Tamén ten que estar a funcionar para que o "
+#~ "programa kpasswd o empregue para cambiar contrasinais. Normalmente este "
+#~ "servizo funciona no KDC mestre."
+
+#~ msgid ""
+#~ "Many sites will wish to have this script automatically create Kerberos "
+#~ "KDC configuration files in /etc/krb5kdc. By default an example template "
+#~ "will be copied into this directory with local parameters filled in. Some "
+#~ "sites who already have infrastructure to manage their own Kerberos "
+#~ "configuration will wish to disable any automatic configuration changes."
+#~ msgstr ""
+#~ "En moitos sitios se ha querer que este script cree automaticamente os "
+#~ "ficheiros de configuración do KDC de Kerberos en /etc/krb5kdc. Por "
+#~ "defecto hase copiar un patrón de exemplo neste directorio cos parámetros "
+#~ "locais introducidos. Os sitios que xa teñan a infraestructura para "
+#~ "xestionar a súa propia configuración de Kerberos poden ter que desactivar "
+#~ "os cambios automáticos na configuración."
+
+#~ msgid "disable, full, nopreauth, none"
+#~ msgstr "desactivado, completo, nopreauth, ningún"
+
+#~ msgid "Run a krb524d?"
+#~ msgstr "¿Executar krb524d?"
+
+#~ msgid ""
+#~ "Krb524d is a daemon that converts Kerberos5 tickets into Kerberos4 "
+#~ "tickets for the krb524init program. If you have Kerberos4 enabled at "
+#~ "all, then you probably want to run this program. Especially when "
+#~ "Kerberos4 compatibility is set to nopreauth, krb524d is important if you "
+#~ "have any Kerberos4 services."
+#~ msgstr ""
+#~ "Krb524d é un servizo que convirte os tiquets Kerberos5 en tiquets "
+#~ "Kerberos4 para o programa krb524init. Se ten Kerberos4 activado é "
+#~ "probable que queira executar este programa. Krb524d é importante se ten "
+#~ "servizos Kerberos4, especialmente se a compatibilidade con Kerberos4 é "
+#~ "nopreauth."
diff --git a/debian/po/it.po b/debian/po/it.po
new file mode 100644
index 000000000..f3e8340c2
--- /dev/null
+++ b/debian/po/it.po
@@ -0,0 +1,137 @@
+# Italian (it) translation of debconf templates for krb5
+# Copyright (C) 2008 Software in the Public Interest
+# This file is distributed under the same license as the krb5 package.
+# Luca Monducci <luca.mo@tiscali.it>, 2008-2009.
+#
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5 1.6.dfsg.3 italian debconf templates\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2009-03-10 21:41+0100\n"
+"Last-Translator: Luca Monducci <luca.mo@tiscali.it>\n"
+"Language-Team: Italian <debian-l10n-italian@lists.debian.org>\n"
+"Language: it\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Impostazione di un Realm Kerberos"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Questo pacchetto contiene gli strumenti d'amministrazione necessari per "
+"l'esecuzione del server principale Kerberos."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Comunque l'installazione di questo pacchetto non comporta la configurazione "
+"automatica di un realm Kerberos, che può essere fatta in seguito usando il "
+"comando \"krb5_newrealm\"."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Leggere anche il file /usr/share/doc/krb5-kdc/README.KDC e la guida per "
+"l'amministrazione, entrambi contenuti nel pacchetto krb5-doc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Creare automaticamente la configurazione del KDC Kerberos?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"I file di configurazione del KDC (Key Distribution Center) Kerberos, in /etc/"
+"krb5kdc, possono essere creati automaticamente."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Un modello d'esempio verrà copiato all'interno di quella directory con la "
+"parte relativa ai parametri locali già compilata."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Gli amministratori che hanno già un'infrastruttura per la gestione della "
+"configurazione di Kerberos potrebbero voler disabilitare le modifiche "
+"automatiche della configurazione."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Eliminare il database del KDC?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Normalmente la rimozione di questo pacchetto non elimina il database del KDC "
+"in /var/lib/krb5kdc/principal poiché questo database non può essere "
+"ripristinato una volta cancellato."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Scegliere questa opzione se si desidera eliminare adesso il database del "
+"KDC, perdendo tutti gli account e le password degli utenti nel KDC."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Attivare il demone di amministrazione Kerberos V5 (kadmind)?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmin evade le richieste di inserimento/modifica/rimozione dei principal "
+#~ "nel database Kerberos."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Questo servizio è necessario per il programma kpasswd, usato per cambiare "
+#~ "le password. Con la configurazione standard, questo demone viene eseguito "
+#~ "sul KDC principale."
diff --git a/debian/po/ja.po b/debian/po/ja.po
new file mode 100644
index 000000000..3fe87a42b
--- /dev/null
+++ b/debian/po/ja.po
@@ -0,0 +1,135 @@
+# SOME DESCRIPTIVE TITLE.
+# Copyright (C) YEAR THE PACKAGE'S COPYRIGHT HOLDER
+# This file is distributed under the same license as the PACKAGE package.
+# FIRST AUTHOR <EMAIL@ADDRESS>, YEAR.
+#
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5 1.4.4-7\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2009-03-05 23:36+0900\n"
+"Last-Translator: TANAKA, Atushi <atanaka@hotcake.halfmoon.jp>\n"
+"Language-Team: Japanese <debian-japanese@lists.debian.org>\n"
+"Language: ja\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Kerberos レルムの設定"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"このパッケージは Kerberos のマスターサーバーを稼働させるのに必要な管理用の道"
+"具を含みます。"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"ただし、このパッケージをインストールするだけで自動的にKerberos のレルムが設定"
+"されるわけではありません。\"krb5_newrealm\" コマンドを実行することで、これを"
+"あとで行なえます。"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"/usr/share/doc/krb5-kdc/README.KDC と krb5-doc パッケージにある管理案内も読ん"
+"でください。"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Kerberos KDC の設定を自動的に作成しますか?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Kerberos Key Distribution Center (KDC) の /etc/krb5kdc にある設定ファイルは自"
+"動的に作成させることができます。"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"デフォルトでは、テンプレートがこのディレクトリにコピーされ、ローカルなパラ"
+"メーターの値が与えられます。"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Kerberos の設定を管理するインフラが既にある場合、自動的に設定を変更させないこ"
+"とを望むかもしれません。"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "KDC データベースを消去すべきですか?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"デフォルトでは、このパッケージを削除しても /var/lib/krb5kdc/principal の KDC "
+"データベースは消去されません。というのも、このデータベースは一旦削除されると"
+"復活不能だからです。"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"もし、KDC データベースをすぐ消去し、KDC の全てのユーザのアカウントとパスワー"
+"ドを削除したい場合はこのオプションを選んでください。"
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Kerberos5 管理デーモン (kadmind) を起動しますか?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "kadmind は Kerberos データベースのプリンシパルの追加/変更/消去の要求に応じ"
+#~ "ます。"
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "これは、パスワードの変更で使われる、kpasswd プログラムで必要とされます。普"
+#~ "通の設定では、このデーモンはマスター KDC で稼働させるべきです。"
diff --git a/debian/po/nl.po b/debian/po/nl.po
new file mode 100644
index 000000000..5df7abdbd
--- /dev/null
+++ b/debian/po/nl.po
@@ -0,0 +1,138 @@
+# Dutch krb5 po-debconf translation,
+# Copyright (C) 2011 THE PACKAGE'S COPYRIGHT HOLDER
+# This file is distributed under the same license as the krb5 package.
+# Vincent Zweije <zweije@xs4all.nl>, 2008.
+# Vincent Zweije <vincent@zweije.nl>, 2011.
+#
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5 1.9+dfsg-1\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2011-05-22 17:40+0000\n"
+"Last-Translator: Vincent Zweije <vincent@zweije.nl>\n"
+"Language-Team: Debian-Dutch <debian-l10n-dutch@lists.debian.org>\n"
+"Language: \n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=utf-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Aanmaken van een Kerberos autoriteitsgebied (realm)"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Dit pakket bevat de administratieve hulpmiddelen die nodig zijn om de "
+"Kerberos hoofd-server te draaien."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"De installatie van dit pakket maakt echter niet automatisch een Kerberos "
+"autoriteitsgebied (realm) aan. Dit kan later worden gedaan door het "
+"programma \"krb5_newrealm\" uit te voeren."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Lees alstublieft ook het bestand /usr/share/doc/krb5-kdc/README.KDC en de "
+"administratiehandleiding in pakket krb5-doc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Kerberos KDC configuratie aanmaken met debconf?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"De configuratiebestanden van het Kerberos sleuteldistributiecentrum (Key "
+"Distribution Center, KDC), in /etc/krb5kdc, kunnen automatisch worden "
+"aangemaakt."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Standaard zal een sjabloon naar deze map worden gekopieerd, waarin de locale "
+"parameters al zijn ingevuld."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Beheerders die reeds infrastructuur hebben om hun Kerberos configuratie te "
+"beheren kunnen deze automatische configuratiewijzigingen uitschakelen."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Dient de KDC database te worden verwijderd?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Standaard zal het wissen (purge) van dit pakket de KDC database in /var/lib/"
+"krb5kdc/principal niet verwijderen, aangezien deze database niet kan worden "
+"hersteld als deze is verwijderd."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Accepteer deze optie indien u de KDC database nu wilt verwijderen, waarbij "
+"alle gebruikers en wachtwoorden verloren gaan."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "De Kerberos-V5 administratie-achtergronddienst (kadmind) starten?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind handelt aanvragen af om principals in de Kerberos database toe te "
+#~ "voegen, te wijzigen of te verwijderen."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Het is vereist voor het programma kpasswd, dat wordt gebruikt voor het "
+#~ "wijzigen van wachtwoorden. Gewoonlijk werkt deze achtergronddienst op de "
+#~ "hoofd-KDC."
diff --git a/debian/po/pl.po b/debian/po/pl.po
new file mode 100644
index 000000000..8b8e8994a
--- /dev/null
+++ b/debian/po/pl.po
@@ -0,0 +1,137 @@
+# Translation of krb5 debconf templates to Polish.
+# Copyright (C) 2009
+# This file is distributed under the same license as the krb5 package.
+#
+# Michał Kułach <michal.kulach@gmail.com>, 2012.
+msgid ""
+msgstr ""
+"Project-Id-Version: \n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2012-02-03 01:06+0100\n"
+"Last-Translator: Michał Kułach <michal.kulach@gmail.com>\n"
+"Language-Team: Polish <debian-l10n-polish@lists.debian.org>\n"
+"Language: pl\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+"X-Generator: Lokalize 1.2\n"
+"Plural-Forms: nplurals=3; plural=(n==1 ? 0 : n%10>=2 && n%10<=4 && (n%100<10 "
+"|| n%100>=20) ? 1 : 2);\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Konfigurowanie Kerberos Realm"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Pakiet zawiera narzędzia administracyjne potrzebne do działania głównego "
+"serwera Kerberos."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Zainstalowanie tego pakietu nie skonfiguruje jednak tzw. realm (dziedziny, "
+"domeny) systemu Kerberos w sposób automatyczny. Można to uczynić później, "
+"poleceniem \"krb5_newrealm\"."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Proszę również zapoznać się z plikiem /usr/share/doc/krb5-kdc/README.KDC "
+"oraz z przewodnikiem administracyjnym z pakietu krb5-doc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Utworzyć konfigurację Kerberos KDC automatycznie?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Pliki konfiguracyjne Kerberos Key Distribution Center (KDC), w /etc/krb5dc, "
+"mogą zostać utworzone automatycznie."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Domyślnie, przykładowy szablon zostanie skopiowany do tego katalogu i "
+"wypełniony lokalnymi parametrami."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Administratorzy, którzy posiadają infrastrukturę do zarządzania swoją "
+"konfiguracją Kerberos, mogą chcieć wyłączyć automatyczną zmianę konfiguracji."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Czy baza danych KDC ma zostać usunięta?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Domyślnie, usunięcie tego pakietu nie usunie bazy danych KDC z /var/lib/"
+"krb5kdc/principal, ponieważ nie może ona zostać odzyskana po usunięciu."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Proszę wybrać \"tak\" aby skasować bazę danych KDC teraz, usuwając wszystkie "
+"konta i hasła użytkowników z KDC."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Uruchomić demona administracyjnego Kerberos V5 (kadmind)?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind obsługuje żądania dodania/zmodyfikowania/usunięcia tzw. principal "
+#~ "(użytkowników) w bazie danych Kerberos."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Jest wymagany przez program kpasswd, używany do zmiany haseł. W "
+#~ "standardowej konfiguracji demon powinien działać na głównym KDC."
diff --git a/debian/po/pt.po b/debian/po/pt.po
new file mode 100644
index 000000000..79564ec38
--- /dev/null
+++ b/debian/po/pt.po
@@ -0,0 +1,271 @@
+# Portuguese translation for krb5's debconf messages
+# Copyright (C) 2007 Miguel Figueiredo <elmig@debianpt.org>
+# This file is distributed under the same license as the krb5 package.
+# Miguel Figueiredo <elmig@debianpt.org>, 2007-2009.
+#
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5 1.4.4-6\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2009-03-09 19:50+0000\n"
+"Last-Translator: Miguel Figueiredo <elmig@debianpt.org>\n"
+"Language-Team: Portuguese <traduz@debianpt.org>\n"
+"Language: pt\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Configurar um Reino Kerberos"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Este pacote contém as ferramentas administrativas necessárias para correr o "
+"servidor mestre Kerberos."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"No entanto, instalar este pacote não configura automaticamente um reino "
+"Kerberos. Isto pode ser feito posteriormente ao correr o comando "
+"\"krb5_newrealm\"."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Por favor leia o ficheiro /usr/share/doc/krb5-kdc/README.KDC e o guia de "
+"administração que se encontra no pacote krb5-doc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Criar automaticamente a configuração do KDC Kerberos?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Os ficheiros de configuração do Kerberos Key Distribution Center (KDC), em /"
+"etc/krb5kdc, podem ser criados automaticamente."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Por pré-definição, será copiado um exemplo de modelo para este directório "
+"com os parâmetros locais preenchidos."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Os administradores que já tenham uma infraestrutura para gerir a sua "
+"configuração do Kerberos podem desejar desabilitar estas mudanças de "
+"configuração automática."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Deve a base de dados KDC ser apagada?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Por pré-definição, remover este pacote não irá apagar a base de dados do KDC "
+"em /var/lib/krb5kdc/principal já que a base de dados não pode ser recuperada "
+"depois de apagada."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Escolha esta opção se deseja apagar agora a base de dados KDC, apagando "
+"todas as contas e palavras-passe de utilizadores no KDC."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Correr o daemon de administração (kadmind) do Kerberos V5?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "O Kadmind serve pedidos para acrescentar/modificar/remover conteúdos na "
+#~ "base de dados do Kerberos."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Isto é necessário para o programa kpasswd, utilizado para alterar "
+#~ "palavras-passe. Com as configurações standard, este daemon deve correr "
+#~ "no KDC mestre."
+
+#~ msgid "Kerberos V4 compatibility mode to use:"
+#~ msgstr "Modo de compatibilidade Kerberos V4 a utilizar:"
+
+#~ msgid ""
+#~ "By default, Kerberos V4 requests are allowed from principals that do not "
+#~ "require preauthentication (\"nopreauth\"). This allows Kerberos V4 "
+#~ "services to exist while requiring most users to use Kerberos V5 clients "
+#~ "to get their initial tickets. These tickets can then be converted to "
+#~ "Kerberos V4 tickets."
+#~ msgstr ""
+#~ "Por pré-definição, os pedidos Kerberos V4 são permitidos a partir de "
+#~ "conteúdos que não necessitem de pré-autenticação (\"nopreauth\"). Isto "
+#~ "permite que existam serviços Kerberos V4 enquanto que requer que a "
+#~ "maioria dos utilizadores utilizem clientes Kerberos V5 para obter os seus "
+#~ "tickets iniciais. Estes tickets podem então ser convertidos para tickets "
+#~ "Kerberos V4."
+
+#~ msgid ""
+#~ "Alternatively, the mode can be set to \"full\", allowing Kerberos V4 "
+#~ "clients to get initial tickets even when preauthentication would normally "
+#~ "be required; to \"disable\", returning protocol version errors to all "
+#~ "Kerberos V4 clients; or to \"none\", which tells the KDC to not respond "
+#~ "to Kerberos V4 requests at all."
+#~ msgstr ""
+#~ "Alternativamente, o modo pode ser definido para \"full\", permitindo a "
+#~ "clientes Kerberos V4 obter os tickets iniciais mesmo quando a pré-"
+#~ "autenticação seria normalmente necessária; para \"disable\", retornando "
+#~ "erros de versão de protocolo para todos os clientes Kerberos V4; ou para "
+#~ "\"none\", que diz ao KDC para não responder a nenhum pedido Kerberos V4."
+
+#~ msgid "Run a Kerberos V5 to Kerberos V4 ticket conversion daemon?"
+#~ msgstr ""
+#~ "Correr um daemon de conversão de tickets de Kerberos V5 para Kerberos V4?"
+
+#~ msgid ""
+#~ "The krb524d daemon converts Kerberos V5 tickets into Kerberos V4 tickets "
+#~ "for programs, such as krb524init, that obtain Kerberos V4 tickets for "
+#~ "compatibility with old applications."
+#~ msgstr ""
+#~ "O daemon krb524d converte tickets Kerberos V5 para tickets Kerberos V4 "
+#~ "para programas, tais como o krb524init, que obtém tickets Kerberos V4 "
+#~ "para compatibilidade com aplicativos antigos."
+
+#~ msgid ""
+#~ "It is recommended to enable that daemon if Kerberos V4 is enabled, "
+#~ "especially when Kerberos V4 compatibility is set to \"nopreauth\"."
+#~ msgstr ""
+#~ "É recomendado habilitar este daemon se o Kerberos V4 estiver habilitado, "
+#~ "especialmente quando a compatibilidade Kerberos V4 estiver definida para "
+#~ "\"nopreauth\"."
+
+#~ msgid "Should the data be purged as well as the package files?"
+#~ msgstr "Devem os dados ser purgados assim como os ficheiros do pacote?"
+
+#~ msgid "disable"
+#~ msgstr "desabilitar"
+
+#~ msgid "full"
+#~ msgstr "total"
+
+#~ msgid "nopreauth"
+#~ msgstr "nopreauth"
+
+#~ msgid "none"
+#~ msgstr "nenhum"
+
+#~ msgid ""
+#~ "This package contains the administrative tools necessary to run on the "
+#~ "Kerberos master server. However, installing this package does not "
+#~ "automatically set up a Kerberos realm. Doing so requires entering "
+#~ "passwords and as such is not well-suited for package installation. To "
+#~ "create the realm, run the krb5_newrealm command. You may also wish to "
+#~ "read /usr/share/doc/krb5-kdc/README.KDC and the administration guide "
+#~ "found in the krb5-doc package."
+#~ msgstr ""
+#~ "Este pacote contém ferramentas administrativas necessárias para correr no "
+#~ "servidor master de Kerberos. No entanto, instalar este pacote não "
+#~ "configura automaticamente um reino Kerberos. Fazê-lo necessita que sejam "
+#~ "introduzidas palavras-chaves e tal não é indicado para a instalação de "
+#~ "pacotes. Para criar o reino, corra o comando krb5_newrealm. Também "
+#~ "poderá querer ler /usr/share/doc/krb5-kdc/README.KDC e o guia de "
+#~ "administração que se encontra no pacote krb5-doc."
+
+#~ msgid ""
+#~ "Don't forget to set up DNS information so your clients can find your KDC "
+#~ "and admin servers. Doing so is documented in the administration guide."
+#~ msgstr ""
+#~ "Não se esqueça de configurar a informação de DNS para que os seus "
+#~ "clientes possam encontrar os servidores de administração e de KDC. Como "
+#~ "o fazer está documentado no guia de administração."
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database. It also must be running for the kpasswd program to be used to "
+#~ "change passwords. Normally, this daemon runs on the master KDC."
+#~ msgstr ""
+#~ "O kadmind serve pedidos para acrescentar/modificar/remover principais na "
+#~ "base de dados Kerberos. Terá que estar a correr para que o programa "
+#~ "kpasswd possa ser usado para alterar palavras-chave. Normalmente este "
+#~ "daemon corre no KDC master."
+
+#~ msgid ""
+#~ "Many sites will wish to have this script automatically create Kerberos "
+#~ "KDC configuration files in /etc/krb5kdc. By default an example template "
+#~ "will be copied into this directory with local parameters filled in. Some "
+#~ "sites who already have infrastructure to manage their own Kerberos "
+#~ "configuration will wish to disable any automatic configuration changes."
+#~ msgstr ""
+#~ "Muitos sites irão querer ter este script a criar automaticamente os "
+#~ "ficheiros de configuração Kerberos KDC em /etc/krb5kdc. Por omissão, "
+#~ "será copiado um modelo de exemplo para este directório com os parâmetros "
+#~ "locais preenchidos. Alguns sites que já têm infra-estrutura para gerir a "
+#~ "sua própria configuração Kerberos irão querer desabilitar as alterações "
+#~ "automáticas de configuração."
+
+#~ msgid "disable, full, nopreauth, none"
+#~ msgstr "disable, full, nopreauth, none"
+
+#~ msgid "Run a krb524d?"
+#~ msgstr "Correr um krb524d?"
+
+#~ msgid ""
+#~ "Krb524d is a daemon that converts Kerberos5 tickets into Kerberos4 "
+#~ "tickets for the krb524init program. If you have Kerberos4 enabled at "
+#~ "all, then you probably want to run this program. Especially when "
+#~ "Kerberos4 compatibility is set to nopreauth, krb524d is important if you "
+#~ "have any Kerberos4 services."
+#~ msgstr ""
+#~ "Krb524d é um daemon que converte tickets Kerberos5 para tickets Kerberos4 "
+#~ "para o programa krb524init. Se tem o Kerberos4 habilitado, então "
+#~ "provavelmente quererá correr este programa. Especialmente quando a "
+#~ "compatibilidade Kerberos4 está definida para nopreauth, krb524d é "
+#~ "importante se tem quaisquer serviços Kerberos4."
diff --git a/debian/po/pt_BR.po b/debian/po/pt_BR.po
new file mode 100644
index 000000000..2a67b8c1c
--- /dev/null
+++ b/debian/po/pt_BR.po
@@ -0,0 +1,139 @@
+# krb5 Brazilian Portuguese translation
+# Copyright (C) 2008 THE krb5'S COPYRIGHT HOLDER
+# This file is distributed under the same license as the krb5 package.
+# Eder L. Marques <eder@edermarques.net>, 2008, 2009.
+# Fernando Ike de Oliveira (fike) <fike@midstorm.org>. 2013.
+#
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2013-08-04 13:54-0300\n"
+"Last-Translator: Fernando Ike de Oliveira (fike) <fike@midstorm.org>\n"
+"Language-Team: Brazilian Portuguese <debian-l10n-portuguese@lists.debian."
+"org>\n"
+"Language: pt_BR\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Configurando um Realm Kerberos"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Este pacote contém as ferramentas administrativas necessárias para executar "
+"o servidor mestre Kerberos."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Contudo, instalar este pacote não configura automaticamente um realm "
+"Kerberos. Isto pode ser feito posteriormente executando o comando "
+"\"krb5_newrealm\"."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Por favor, leia também o arquivo /usr/share/doc/krb5-kdc/README.KDC e o guia "
+"de administração encontrado no pacote krb5-doc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Criar a configuração do Kerberos KDC automaticamente?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Os arquivos de configuração do Centro de Distribuição de Chaves Kerberos "
+"(KDC -- \"Kerberos Key Distribution Center\"), em /etc/krb5kdc, podem ser "
+"criados automaticamente."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Por padrão, um modelo de exemplo será copiado para este diretório com os "
+"parâmetros locais preenchidos."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Administradores que já possuem infraestrutura para administrar suas "
+"configurações Kerberos podem desejar desabilitar estas mudanças automáticas "
+"de configuração."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "O banco de dados do KDC deve ser excluído?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Por padrão, remover este pacote não excluirá o banco de dados do KDC em /var/"
+"lib/krb5kdc/principal visto que este banco de dados não pode ser recuperado "
+"uma vez excluído."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Escolha esta opção se você deseja excluir o banco de dados do KDC agora, "
+"excluindo todas as contas de usuários e senhas do KDC."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Executar o daemon de administração do Kerberos V5 (kadmind)?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "O kadmind atende requisições para adicionar/modificar/remover \"principals"
+#~ "\" no banco de dados do Kerberos."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Ele é necessário para o programa kpasswd, usado para alterar senhas. Com "
+#~ "configurações padrão, este daemon deveria ser executado no KDC mestre."
diff --git a/debian/po/ro.po b/debian/po/ro.po
new file mode 100644
index 000000000..70132be1e
--- /dev/null
+++ b/debian/po/ro.po
@@ -0,0 +1,264 @@
+# translation of ro.po to Romanian
+# Romanian translation of krb5.
+# Copyright (C) 2006 THE krb5'S COPYRIGHT HOLDER
+# This file is distributed under the same license as the krb5 package.
+#
+# Stan Ioan-Eugen <stan.ieugen@gmail.com>, 2006.
+# Eddy Petrișor <eddy.petrisor@gmail.com>, 2008, 2009.
+msgid ""
+msgstr ""
+"Project-Id-Version: ro\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2009-03-12 01:34+0200\n"
+"Last-Translator: Eddy Petrișor <eddy.petrisor@gmail.com>\n"
+"Language-Team: Romanian <debian-l10n-romanian@lists.debian.org>\n"
+"Language: ro\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+"X-Generator: KBabel 1.11.4\n"
+"Plural-Forms: nplurals=3; plural=n==1 ? 0 : (n==0 || (n%100 > 0 && n%100 < "
+"20)) ? 1 : 2;\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Se configurează un Domeniu Kerberos"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Acest pachet conține uneltele administrative necesare pentru a rula serverul "
+"principal Kerberos."
+
+# XRO: realm e „tărâm” sau „domeniu”?
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Totuși, prin instalarea acestui pachet nu se configurează automat un domeniu "
+"Kerberos. Aceasta se poate face mai târziu rulând comanda „krb5_newrealm”."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Citiți, de asemenea, fișierul /usr/share/doc/krb5-kdc/README.KDC și ghidul "
+"de administrare din pachetul krb5-doc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Se crează automat configurația Kerberos KDC?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Fișierele de configurare ale centrului de distribuție de chei Kerberos "
+"(KDC), din /etc/krb5kdc, pot fi create automat."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"În mod implicit, un șablon-exemplu cu parametrii locali completați în el, va "
+"fi copiat în acest director."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Administratorii care dețin deja o infrastructură de management a "
+"configurației Kerberos, probabil că vor prefera să dezactiveze schimbările "
+"automate ale configurației."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Se șterge baza de date KDC?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"În mod implicit, dacă se șterge acest pachet, nu se șterge și baza de date "
+"KDC din /var/lib/krb5kdc/principal deoarece, odată ștearsă, nu poate fi "
+"recuperată."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Alegeți această opțiune, dacă doriți să ștergeți baza de date KDC acum, "
+"ștergând astfel toate conturile utilizatorilor și toate parolele din KDC."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Se rulează demonul de administrare Kerberos V5 (kadmind)?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind servește cereri de adăugare/modificare/ștergere de directori în "
+#~ "baza de date Kerberos."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Este necesar programului kpasswd, program folosit pentru schimbarea "
+#~ "parolelor. În configurațiile standard, acest serviciu ar trebui să ruleze "
+#~ "pe KDC-ul principal."
+
+#~ msgid "Kerberos V4 compatibility mode to use:"
+#~ msgstr "Modul de compatibilitate Kerberos V4 folosit:"
+
+#~ msgid ""
+#~ "By default, Kerberos V4 requests are allowed from principals that do not "
+#~ "require preauthentication (\"nopreauth\"). This allows Kerberos V4 "
+#~ "services to exist while requiring most users to use Kerberos V5 clients "
+#~ "to get their initial tickets. These tickets can then be converted to "
+#~ "Kerberos V4 tickets."
+#~ msgstr ""
+#~ "Implicit, cererile Kerberos4 sunt permise de la directori care nu "
+#~ "necesită preautentificare („nopreauth”). Acest lucru permite existența "
+#~ "serviciilor Kerberos4 în timp ce utilizatorii trebuie să folosească "
+#~ "clienți Kerberos5 pentru a obține tichete inițiale. Aceste tichete pot fi "
+#~ "convertite în tichete pentru Kerberos V4."
+
+#~ msgid ""
+#~ "Alternatively, the mode can be set to \"full\", allowing Kerberos V4 "
+#~ "clients to get initial tickets even when preauthentication would normally "
+#~ "be required; to \"disable\", returning protocol version errors to all "
+#~ "Kerberos V4 clients; or to \"none\", which tells the KDC to not respond "
+#~ "to Kerberos V4 requests at all."
+#~ msgstr ""
+#~ "Există și posibilitatea ca modul selectat să fie unul din următoarele: "
+#~ "„full”, astfel permițând clienților Kerberos V4 să obțină tichetele "
+#~ "inițiale chiar și atunci când, în mod normal, ar fi necesară "
+#~ "preautentificarea; „disable” face ca toți clienții Kerberos V4 să "
+#~ "primească erori de versiune de protocol; „none” va instrui KDC-ul să nu "
+#~ "răspundă deloc clienților Kerberos V4."
+
+#~ msgid "Run a Kerberos V5 to Kerberos V4 ticket conversion daemon?"
+#~ msgstr ""
+#~ "Se rulează un serviciu de conversie a tichetelor Kerberos V5 în tichete "
+#~ "Kerberos V4?"
+
+#~ msgid ""
+#~ "The krb524d daemon converts Kerberos V5 tickets into Kerberos V4 tickets "
+#~ "for programs, such as krb524init, that obtain Kerberos V4 tickets for "
+#~ "compatibility with old applications."
+#~ msgstr ""
+#~ "Serviciul krb524d convertește tichete Kerberos V5 în tichete Kerberos V4 "
+#~ "pentru programe precum krb524init, acestea obținând tichete Kerberos V4 "
+#~ "pentru compatibilitate cu aplicațiile vechi."
+
+#~ msgid ""
+#~ "It is recommended to enable that daemon if Kerberos V4 is enabled, "
+#~ "especially when Kerberos V4 compatibility is set to \"nopreauth\"."
+#~ msgstr ""
+#~ "Se recomandă activarea acestui serviciu, în condițiile în care Kerberos "
+#~ "V4 este activ, mai ales când modul de compatibilitate cu Kerberos V4 este "
+#~ "configurat ca fiind „nopreauth”."
+
+#~ msgid "Should the data be purged as well as the package files?"
+#~ msgstr "Să se șteargă atât datele cât și fișierele pachetului?"
+
+#~ msgid ""
+#~ "This package contains the administrative tools necessary to run on the "
+#~ "Kerberos master server. However, installing this package does not "
+#~ "automatically set up a Kerberos realm. Doing so requires entering "
+#~ "passwords and as such is not well-suited for package installation. To "
+#~ "create the realm, run the krb5_newrealm command. You may also wish to "
+#~ "read /usr/share/doc/krb5-kdc/README.KDC and the administration guide "
+#~ "found in the krb5-doc package."
+#~ msgstr ""
+#~ "Acest pachet conține uneltele de administrare necesare rulării pe un "
+#~ "server master Kerberos. Totuși, instalând acest pachet nu se "
+#~ "configurează automat un domeniu Kerberos. Un asemenea lucru necesită "
+#~ "introducerea de parole operație care nu este potrivită la instalarea "
+#~ "pachetului. Pentru a crea domeniul, executați comanda krb5_newrealm. "
+#~ "Veți dori probabil să citiți și /usr/share/doc/krb5-kdc/README.KDC și "
+#~ "ghidul de administrare din pachetul krb5-doc."
+
+#~ msgid ""
+#~ "Don't forget to set up DNS information so your clients can find your KDC "
+#~ "and admin servers. Doing so is documented in the administration guide."
+#~ msgstr ""
+#~ "Nu uitați să configurați informațiile pentru DNS astfel încât clienții să "
+#~ "poată gasi serverele și KDC-ul dumneavoastră. Acest lucru este "
+#~ "documentat în ghidul de administrare."
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database. It also must be running for the kpasswd program to be used to "
+#~ "change passwords. Normally, this daemon runs on the master KDC."
+#~ msgstr ""
+#~ "Kadmind rezolvă cereri de adăugare/modificare/îndepărtare a directorilor "
+#~ "din baza de date Kerberos. Acesta trebuie să ruleze și pentru ca "
+#~ "programul kpasswd să poată fi folosit pentru a schimba parolele. În mod "
+#~ "normal, acest demon ruleaza pe serverul master KDC."
+
+#~ msgid ""
+#~ "Many sites will wish to have this script automatically create Kerberos "
+#~ "KDC configuration files in /etc/krb5kdc. By default an example template "
+#~ "will be copied into this directory with local parameters filled in. Some "
+#~ "sites who already have infrastructure to manage their own Kerberos "
+#~ "configuration will wish to disable any automatic configuration changes."
+#~ msgstr ""
+#~ "Multe situri vor dori ca acest script să creeze automat fișierele de "
+#~ "configurare Kerberos KDC în /etc/krb5kdc. Implicit un șablon va fi "
+#~ "copiat în acest director, cu parametrii locali completați. Unele situri "
+#~ "care au deja o infrastructură pentru a administra configurațiile Kerberos "
+#~ "vor dori să dezactiveze orice modificare automată a configurației."
+
+#~ msgid "disable, full, nopreauth, none"
+#~ msgstr "dezactivat, complet, fără preautentificare, nici unul"
+
+#~ msgid "Run a krb524d?"
+#~ msgstr "Se rulează krb524d?"
+
+#~ msgid ""
+#~ "Krb524d is a daemon that converts Kerberos5 tickets into Kerberos4 "
+#~ "tickets for the krb524init program. If you have Kerberos4 enabled at "
+#~ "all, then you probably want to run this program. Especially when "
+#~ "Kerberos4 compatibility is set to nopreauth, krb524d is important if you "
+#~ "have any Kerberos4 services."
+#~ msgstr ""
+#~ "Krb524d este un demon care convertește tichetele Kerberos5 în tichete "
+#~ "Kerberos4 pentru programul krb524init. Dacă aveți activat Kerberos4 "
+#~ "atunci probabil că veți dori să rulați acest program. Krb524 este "
+#~ "important dacă aveți servicii Kerberos4, în special dacă modulu de "
+#~ "compatibilitate Kerberos4 este fără preautentificare."
diff --git a/debian/po/ru.po b/debian/po/ru.po
new file mode 100644
index 000000000..efcd3a110
--- /dev/null
+++ b/debian/po/ru.po
@@ -0,0 +1,205 @@
+# Translation of krb5 to Russian
+# This file is distributed under the same license as the PACKAGE package.
+# Copyright (C) YEAR THE PACKAGE'S COPYRIGHT HOLDER.
+#
+# Yuri Kozlov <kozlov.y@gmail.com>, 2006, 2007.
+# Alyoshin Sergey <alyoshin.s@gmail.com>, 2007, 2008, 2009.
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5_1.6.dfsg.4~beta1-10\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2009-03-09 00:11:57+0300\n"
+"Last-Translator: Alyoshin Sergey <alyoshin.s@gmail.com>\n"
+"Language-Team: Russian <debian-l10n-russian@lists.debian.org>\n"
+"Language: ru\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+"X-Generator: KBabel 1.11.4\n"
+"Plural-Forms: nplurals=3; plural=(n%10==1 && n%100!=11 ? 0 : n%10>=2 && n"
+"%10<=4 && (n%100<10 || n%100>=20) ? 1 : 2);\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Настройка области Kerberos"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Этот пакет содержит управляющие инструменты, требующиеся для работы мастер-"
+"сервера Kerberos."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Однако при установке пакета не выполняется автоматическая настройка области "
+"Kerberos. Это может быть сделано позже с помощью команды \"krb5_newrealm\"."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Пожалуйста, прочтите также файл /usr/share/doc/krb5-kdc/README.KDC и "
+"руководство администратора из пакета krb5-doc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Создать конфигурацию Kerberos KDC автоматически?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Конфигурационные файлы центра распределения ключей Kerberos (KDC) в "
+"каталоге /etc/krb5kdc могут быть созданы автоматически."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"По умолчанию в этот каталог будет скопирован образец шаблона с заполненными "
+"локальными параметрами."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Администраторы, у которых уже есть инфраструктура, обслуживаемая их "
+"конфигурацией Kerberos, возможно, не захотят выполнять автоматическое "
+"изменение конфигурации."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Удалить базу данных KDC?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"По умолчанию, удаление данного пакета не приводит к удалению базы данных KDC "
+"в /var/lib/krb5kdc/principal, так как эта база данных не может быть "
+"восстановлена после удаления."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Выберите этот параметр, если хотите удалить базу данных KDC сейчас, при этом "
+"будут удалены все пользовательские учётные записи и пароли в KDC."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Запускать службу администрирования Kerberos V5 (kadmind)?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind обслуживает запросы на добавление, изменение и/или удаление "
+#~ "принципалов в базе данных Kerberos."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Он требуется программе kpasswd, используемой для изменения паролей. При "
+#~ "стандартной установке эта служба должна работать на главном KDC."
+
+#~ msgid "Kerberos V4 compatibility mode to use:"
+#~ msgstr "Используемый режим совместимости с Kerberos V4:"
+
+#~ msgid ""
+#~ "By default, Kerberos V4 requests are allowed from principals that do not "
+#~ "require preauthentication (\"nopreauth\"). This allows Kerberos V4 "
+#~ "services to exist while requiring most users to use Kerberos V5 clients "
+#~ "to get their initial tickets. These tickets can then be converted to "
+#~ "Kerberos V4 tickets."
+#~ msgstr ""
+#~ "По умолчанию, запросы Kerberos V4 разрешены от принципалов, для которых "
+#~ "не требуется предварительная аутентификация (\"nopreauth\", \"без "
+#~ "предварительной аутентификации\"). Это позволяет существовать сервисам "
+#~ "Kerberos V4, но требует от большинства пользователей использования "
+#~ "клиента Kerberos V5 для получения начальных мандатов. Затем эти мандаты "
+#~ "могут быть преобразованы в мандаты Kerberos V4."
+
+#~ msgid ""
+#~ "Alternatively, the mode can be set to \"full\", allowing Kerberos V4 "
+#~ "clients to get initial tickets even when preauthentication would normally "
+#~ "be required; to \"disable\", returning protocol version errors to all "
+#~ "Kerberos V4 clients; or to \"none\", which tells the KDC to not respond "
+#~ "to Kerberos V4 requests at all."
+#~ msgstr ""
+#~ "Кроме того, могут быть установлены режимы: \"full\" (\"полный\"), который "
+#~ "позволяет клиентам Kerberos V4 получить начальные мандаты, даже если "
+#~ "обычно требуется предварительная аутентификация; \"disable\" (\"отключён"
+#~ "\"), при котором всем клиентам Kerberos V4 возвращаются ошибки версии "
+#~ "протокола; \"none\" (\"никакой\"), при котором KDC вообще не отвечает на "
+#~ "запросы Kerberos V4."
+
+#~ msgid "Run a Kerberos V5 to Kerberos V4 ticket conversion daemon?"
+#~ msgstr "Запустить демон преобразования мандатов Kerberos V5 в Kerberos V4?"
+
+#~ msgid ""
+#~ "The krb524d daemon converts Kerberos V5 tickets into Kerberos V4 tickets "
+#~ "for programs, such as krb524init, that obtain Kerberos V4 tickets for "
+#~ "compatibility with old applications."
+#~ msgstr ""
+#~ "Демон krb524d преобразует мандаты Kerberos V5 в мандаты Kerberos V4 для "
+#~ "таких программ как krb524init, которая получает мандаты Kerberos V4 для "
+#~ "совместимости со старыми приложениями."
+
+#~ msgid ""
+#~ "It is recommended to enable that daemon if Kerberos V4 is enabled, "
+#~ "especially when Kerberos V4 compatibility is set to \"nopreauth\"."
+#~ msgstr ""
+#~ "Рекомендуется включить этот демон, если работает Kerberos V4, особенно "
+#~ "если режим совместимости Kerberos V4 установлен в \"nopreauth\" (\"без "
+#~ "предварительной аутентификации\")."
+
+#~ msgid "Should the data be purged as well as the package files?"
+#~ msgstr "Вычищать данные при удалении файлов пакета?"
+
+#~ msgid "disable"
+#~ msgstr "отключён"
+
+#~ msgid "full"
+#~ msgstr "полный"
+
+#~ msgid "nopreauth"
+#~ msgstr "без предварительной аутентификации"
+
+#~ msgid "none"
+#~ msgstr "никакой"
diff --git a/debian/po/sv.po b/debian/po/sv.po
new file mode 100644
index 000000000..019ae78fe
--- /dev/null
+++ b/debian/po/sv.po
@@ -0,0 +1,201 @@
+# translation of krb5_1.6.dfsg.3-2_sv.po to swedish
+# Copyright (C) YEAR THE PACKAGE'S COPYRIGHT HOLDER
+# This file is distributed under the same license as the PACKAGE package.
+#
+# Martin Bagge <martin.bagge@bthstudent.se>, 2008.
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5_1.6.dfsg.3-2_sv\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2009-03-05 15:55+0100\n"
+"Last-Translator: Martin Bagge <brother@bsnet.se>\n"
+"Language-Team: swedish <debian-l10n-swedish@lists.debian.org>\n"
+"Language: \n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+"X-Generator: KBabel 1.11.4\n"
+"X-Poedit-Language: swedish\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Ställer in ett Kerberos realm "
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Detta paket innehåller administrationsverktygen för att köra en huvudserver "
+"av Kerberos."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Att bara installera paketet ger dock inte automatiskt en fix och färdig "
+"Kerberos realm. Detta kan göras vid ett senare tillfälle genom att köra "
+"\"krb5_newrealm\"."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Läs också /usr/share/doc/krb5-kdc/README.KDC och administrationsguiden i "
+"paketet 'krb5-doc'."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Vill du skapa Kerberos KDC-konfigurationen automatiskt?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Konfigurationsfiler för Kerberos Key Distribution Center (KDC) kan skapas "
+"automatiskt i /etc/krb5kdc."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Standardutförandet är att kopiera lokala inställningar till en exempelfil "
+"kompieras som läggs i denna katalog."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Administratörer som redan har infrastruktur för att ta hand om Kerberos "
+"konfigurationsfiler kan stänga av denna automatiska körning."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Vill du radera KDC-databasen?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"I standardläget så tas bara paketfilerna bort och KDC-databasen i /var/lib/"
+"krb5kdc/principal lämnas kvar då den inte kan återskapas om den tas bort."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Välj detta alternativ om du vill ta bortKDC-databasen när paketet är "
+"borttaget. Alla användare och lösenord i KDC kommer då att tas bort."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Vill du köra administrationstjänsten för Kerberos V5(kadmind)?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind tar emot förfrågningar om att lägga till/ändra/ta bort innehåll i "
+#~ "Kerberosdatabasen."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "kpasswd (används för att byta lösenord) behöver den. I standardutförandet "
+#~ "så ska den köras på huvud-KDC."
+
+#~ msgid "Kerberos V4 compatibility mode to use:"
+#~ msgstr "Kompabilitetsläge för Kerberos v4-anslutningar:"
+
+#~ msgid ""
+#~ "By default, Kerberos V4 requests are allowed from principals that do not "
+#~ "require preauthentication (\"nopreauth\"). This allows Kerberos V4 "
+#~ "services to exist while requiring most users to use Kerberos V5 clients "
+#~ "to get their initial tickets. These tickets can then be converted to "
+#~ "Kerberos V4 tickets."
+#~ msgstr ""
+#~ "Standardutförandet är att tillåta Kerberos v4-klienter som inte kräver "
+#~ "förautentisiering (\"nopreauth\"). Då kan en Kerberos v4-tjänster finnas "
+#~ "kvar men man kräver att de flesta användarna har en Kerberos v5-klient "
+#~ "som hämtar deras första biljett (eng: ticket), dessa kan sedan "
+#~ "konverteras till Kerberos v4."
+
+#~ msgid ""
+#~ "Alternatively, the mode can be set to \"full\", allowing Kerberos V4 "
+#~ "clients to get initial tickets even when preauthentication would normally "
+#~ "be required; to \"disable\", returning protocol version errors to all "
+#~ "Kerberos V4 clients; or to \"none\", which tells the KDC to not respond "
+#~ "to Kerberos V4 requests at all."
+#~ msgstr ""
+#~ "Du kan ange läget som \"full\"och därmed tillåta Kerberos v4-klienter att "
+#~ "skaffa sina biljetter även om förautentisiering skulle varit i bruk. "
+#~ "Eller vidare så kan läget ställas till \"avaktivera\", då sänds "
+#~ "felmeddelanden till Kerbers v4-klienterna, eller slutligen \"ingen\" som "
+#~ "anger att KDC inte ska svara alls på förfrågningar från Kerberos v4-"
+#~ "klienter."
+
+#~ msgid "Run a Kerberos V5 to Kerberos V4 ticket conversion daemon?"
+#~ msgstr ""
+#~ "Vill du köra en tjänst som konverterar mellan Kerberos v5 och Kerberos v4?"
+
+#~ msgid ""
+#~ "The krb524d daemon converts Kerberos V5 tickets into Kerberos V4 tickets "
+#~ "for programs, such as krb524init, that obtain Kerberos V4 tickets for "
+#~ "compatibility with old applications."
+#~ msgstr ""
+#~ "Tjänsten krb524 konverterar Kerberos v5-biljetter till Kerberos v4-"
+#~ "biljetter för äldre program som inte kan läsa Kerberos v5-biljetter."
+
+#~ msgid ""
+#~ "It is recommended to enable that daemon if Kerberos V4 is enabled, "
+#~ "especially when Kerberos V4 compatibility is set to \"nopreauth\"."
+#~ msgstr ""
+#~ "Du bör aktivera tjänsten om Kerberos v4 är aktiverat, särskilt om "
+#~ "Kerberos v4-kompabilitet är satt till \"utan förautentisiering\"."
+
+#~ msgid "disable"
+#~ msgstr "avaktivera"
+
+#~ msgid "full"
+#~ msgstr "full"
+
+#, fuzzy
+#~ msgid "nopreauth"
+#~ msgstr "utan förautentisiering (eng: nopreauth)"
+
+#~ msgid "none"
+#~ msgstr "ingen"
+
+#~ msgid "Should the data be purged as well as the package files?"
+#~ msgstr "Vill du göra dig av med både datafiler och paketfiler?"
diff --git a/debian/po/templates.pot b/debian/po/templates.pot
new file mode 100644
index 000000000..d1791c80a
--- /dev/null
+++ b/debian/po/templates.pot
@@ -0,0 +1,101 @@
+# SOME DESCRIPTIVE TITLE.
+# Copyright (C) YEAR THE PACKAGE'S COPYRIGHT HOLDER
+# This file is distributed under the same license as the PACKAGE package.
+# FIRST AUTHOR <EMAIL@ADDRESS>, YEAR.
+#
+#, fuzzy
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: YEAR-MO-DA HO:MI+ZONE\n"
+"Last-Translator: FULL NAME <EMAIL@ADDRESS>\n"
+"Language-Team: LANGUAGE <LL@li.org>\n"
+"Language: \n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=CHARSET\n"
+"Content-Transfer-Encoding: 8bit\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr ""
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr ""
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr ""
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
diff --git a/debian/po/tr.po b/debian/po/tr.po
new file mode 100644
index 000000000..513b58f3e
--- /dev/null
+++ b/debian/po/tr.po
@@ -0,0 +1,136 @@
+# SOME DESCRIPTIVE TITLE.
+# Copyright (C) YEAR THE PACKAGE'S COPYRIGHT HOLDER
+# This file is distributed under the same license as the krb5 package.
+# Atila KOÇ <akoc@artielektronik.com.tr>, 2012.
+#
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2012-02-07 22:37+0200\n"
+"Last-Translator: Atila KOÇ <akoc@artielektronik.com.tr>\n"
+"Language-Team: Turkish <debian-l10n-turkish@lists.debian.org>\n"
+"Language: tr\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Bir Kerberos Bölgesi kuruluyor"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Bu paket Kerberos ana sunucusunu işletmek için gerekli yönetimsel araçları "
+"barındırır."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Öte yandan, bu paketi yüklemek kendiliğinden bir Kerberos bölgesi kurmaz. Bu "
+"işlem \"krb5_newrealm\" komutu ile sonradan yapılabilir."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Lütfen krb5-doc paketinde yer alan yönetim kılavuzunu ve /usr/share/doc/krb5-"
+"kdc/README.KDC dosyasını okuyunuz."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Kerberos KDC yapılandırması kendiliğinden yaratılsın mı?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"/etc/krb5kdc dizininde yer alan Kerberos Anahtar Dağıtım Merkezi (KDC) "
+"yapılandırma dosyaları kendiliğinden yaratılabilir."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Öntanımlı olarak, yerel değerleri doldurulmuş halde örnek bir şablon bu "
+"dizine kaydedilecektir."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Kerberos yapılandırmalarını yönetmek için altyapıları hazır olan "
+"yöneticiler, kendiliğinden yapılacak bu yapılandırma değişikliklerini "
+"atlayabilirler."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "KDC veritabanı silinsin mi?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Öntanımlı olarak bu paketin kaldırılması /var/lib/krb5kdc/principal "
+"dizinindeki veritabanını kaldırmayacaktır. Çünkü bu veritabanı bir kez "
+"silindi mi bir daha kurtarılamaz."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Bu seçeneği KDC veritabanını şimdi silmek istiyorsanız seçin, bu durumda "
+"KDC'de yer alan tüm kullanıcı hesapları ve şifreler de silinecektir."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Kerberos V5 yönetimi artalan süreci (kadmind) çalıştırılsın mı?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind Kerberos veritabanına yönelik özlük ekleme/düzenleme/kaldırma "
+#~ "isteklerini yanıtlar."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Bunlara ek olarak kpasswd programının şifreleri değiştirebilmesi için de "
+#~ "gereklidir. Sıradan kurulumlarda, bu artalan süreci ana KDC üzerinde "
+#~ "çalışmalıdır."
diff --git a/debian/po/vi.po b/debian/po/vi.po
new file mode 100644
index 000000000..38ba54183
--- /dev/null
+++ b/debian/po/vi.po
@@ -0,0 +1,141 @@
+# Vietnamese Translation for krb5.
+# Copyright © 2010 Free Software Foundation, Inc.
+# Clytie Siddall <clytie@riverland.net.au>, 2005-2010.
+#
+msgid ""
+msgstr ""
+"Project-Id-Version: krb5 1.8.3+dfsg-2\n"
+"Report-Msgid-Bugs-To: krb5@packages.debian.org\n"
+"POT-Creation-Date: 2014-10-20 17:18-0400\n"
+"PO-Revision-Date: 2010-10-27 15:10+1030\n"
+"Last-Translator: Clytie Siddall <clytie@riverland.net.au>\n"
+"Language-Team: Vietnamese <vi-VN@googlegroups.com>\n"
+"Language: vi\n"
+"MIME-Version: 1.0\n"
+"Content-Type: text/plain; charset=UTF-8\n"
+"Content-Transfer-Encoding: 8bit\n"
+"Plural-Forms: nplurals=1; plural=0;\n"
+"X-Generator: LocFactoryEditor 1.8\n"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid "Setting up a Kerberos Realm"
+msgstr "Thiết lập một Địa hạt Kerberos"
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"This package contains the administrative tools required to run the Kerberos "
+"master server."
+msgstr ""
+"Gói này chứa các công cụ quản trị cần thiết để chạy trình phục vụ chủ "
+"Kerberos."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"However, installing this package does not automatically set up a Kerberos "
+"realm. This can be done later by running the \"krb5_newrealm\" command."
+msgstr ""
+"Tuy nhiên, việc cài đặt gói này không phải tự động thiết lập một địa hạt "
+"(realm) Kerberos. Có thể làm đó về sau, bằng cách chạy câu lệnh « "
+"krb5_newrealm »."
+
+#. Type: note
+#. Description
+#: ../krb5-admin-server.templates:2001
+msgid ""
+"Please also read the /usr/share/doc/krb5-kdc/README.KDC file and the "
+"administration guide found in the krb5-doc package."
+msgstr ""
+"Xem thêm tập tin Đọc Đi « /usr/share/doc/krb5-kdc/README.KDC » và sổ tay "
+"quản trị (administration guide) nằm trong gói tài liệu « krb5-doc »."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid "Create the Kerberos KDC configuration automatically?"
+msgstr "Tự động tạo cấu hình KDC Kerberos không?"
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"The Kerberos Key Distribution Center (KDC) configuration files, in /etc/"
+"krb5kdc, may be created automatically."
+msgstr ""
+"Những tập tin cấu hình Trung tâm Phân phối Khoá Kerberos (KDC), trong thư "
+"mục « /etc/krb5kdc », cũng có thể được tự động tạo."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"By default, an example template will be copied into this directory with "
+"local parameters filled in."
+msgstr ""
+"Mặc định là một mẫu thí dụ sẽ được sao chép vào thư mục này với các tham số "
+"cục bộ được điền sẵn."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:2001
+msgid ""
+"Administrators who already have infrastructure to manage their Kerberos "
+"configuration may wish to disable these automatic configuration changes."
+msgstr ""
+"Quản trị đã có nền tảng để quản lý cấu hình Kerberos thì có thể muốn tắt các "
+"thay đổi cấu hình tự động này."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid "Should the KDC database be deleted?"
+msgstr "Có nên xoá cơ sở dữ liệu KDC không?"
+
+# By default, purging this package will not delete the KDC database in /var/
+# lib/krb5kdc/principal since this database cannot be recovered once it is
+# deleted. If you wish to delete your KDC database when this package is
+# purged, knowing that purging this package will then mean deleting all of
+# the user accounts and passwords in the KDC, enable this option.
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"By default, removing this package will not delete the KDC database in /var/"
+"lib/krb5kdc/principal since this database cannot be recovered once it is "
+"deleted."
+msgstr ""
+"Mặc định là việc gỡ bỏ gói này sẽ không xoá cơ sở dữ liệu KDC trong « /var/"
+"lib/krb5kdc/principal », vì một khi xoá cơ sở dữ liệu này, không thể phục "
+"hồi lại."
+
+#. Type: boolean
+#. Description
+#: ../krb5-kdc.templates:3001
+msgid ""
+"Choose this option if you wish to delete the KDC database now, deleting all "
+"of the user accounts and passwords in the KDC."
+msgstr ""
+"Hãy bật tùy chọn này nếu bạn muốn xoá cơ sở dữ liệu KDC ngay bây giờ, thì "
+"cũng xoá mọi tài khoản và mật khẩu của người dùng trong KDC."
+
+#~ msgid "Run the Kerberos V5 administration daemon (kadmind)?"
+#~ msgstr "Chạy trình nền quản trị phiên bản 5 Kerberos (kadmind) không?"
+
+#~ msgid ""
+#~ "Kadmind serves requests to add/modify/remove principals in the Kerberos "
+#~ "database."
+#~ msgstr ""
+#~ "Kadmind phục vụ yêu cầu để thêm/sửa đổi/gỡ bỏ điều tiền gốc trong cơ sở "
+#~ "dữ liệu Kerberos."
+
+#~ msgid ""
+#~ "It is required by the kpasswd program, used to change passwords. With "
+#~ "standard setups, this daemon should run on the master KDC."
+#~ msgstr ""
+#~ "Nó bị chương trình kpasswd cần thiết để thay đổi mật khẩu. Đối với thiết "
+#~ "lập tiêu chuẩn, trình nền này nên chạy trên KDC chủ."
diff --git a/debian/rules b/debian/rules
new file mode 100755
index 000000000..9eda8dc79
--- /dev/null
+++ b/debian/rules
@@ -0,0 +1,226 @@
+#!/usr/bin/make -f
+# Based on sample debian/rules that uses debhelper.
+# GNU copyright 1997 by Joey Hess.
+
+# Uncomment this to turn on verbose mode.
+#export DH_VERBOSE=1
+
+# This has to be exported to make some magic below work.
+export DH_OPTIONS
+
+SHELL=/bin/bash
+export SHELL
+
+# Tell Autoconf the correct system types. Needed for cross builds.
+DEB_HOST_GNU_TYPE ?= $(shell dpkg-architecture -qDEB_HOST_GNU_TYPE)
+DEB_BUILD_GNU_TYPE ?= $(shell dpkg-architecture -qDEB_BUILD_GNU_TYPE)
+DEB_HOST_MULTIARCH ?= $(shell dpkg-architecture -qDEB_HOST_MULTIARCH)
+ifeq ($(DEB_BUILD_GNU_TYPE),$(DEB_HOST_GNU_TYPE))
+ SYSTEM = --build $(DEB_HOST_GNU_TYPE)
+ CACHE =
+else
+ SYSTEM = --build $(DEB_BUILD_GNU_TYPE) --host $(DEB_HOST_GNU_TYPE)
+ CACHE = --cache-file=$(DEB_HOST_GNU_TYPE).cache
+endif
+
+export DEB_HOST_MULTIARCH
+
+CCOPTS=-g
+ifneq (,$(findstring noopt,$(DEB_BUILD_OPTIONS)))
+ CCOPTS +=-O0
+else
+ CCOPTS +=-O2
+endif
+
+ifneq (,$(filter i486-linux-gnu x86_64-linux-gnu,$(DEB_HOST_GNU_TYPE)))
+ CCOPTS +=-D_FORTIFY_SOURCE=2 -fstack-protector
+ endif
+FLAGS=$(shell if res=`dpkg-buildflags --export=configure `; then echo $$res; else echo CFLAGS="'$(CCOPTS)'"; fi)
+
+ifneq (,$(filter parallel=%,$(DEB_BUILD_OPTIONS)))
+ NUMJOBS = -j$(patsubst parallel=%,%,$(filter parallel=%,$(DEB_BUILD_OPTIONS)))
+endif
+
+# The flags to pass to dh_install specifying the upstream files to exclude.
+# We use --fail-missing to be sure we catch any new upstream files, so be
+# sure to update this list if upstream adds any more files we don't want.
+EXCLUDE = -Xtmac.doc -Xexamples/krb5 -Xgnats/mit -Xkrb5-send-pr \
+ -Xsserver -Xsim_server -Xuuserver \
+ -Xsclient -Xsim_client -Xuuclient -Xpreauth/test.so
+
+LIB_PACKAGES = libkrb5-3 libgssapi-krb5-2 libkadm5clnt-mit11 libkadm5srv-mit11 libkdb5-9 libgssrpc4 \
+ libkrb5support0 libk5crypto3 libkrad0
+
+ifneq (,$(filter stage1,$(DEB_BUILD_PROFILES)))
+KRB5_SKIP_LDAP= 1
+endif
+
+ifeq (,$(KRB5_SKIP_LDAP))
+CONFIGURE_LDAP= --with-ldap
+else
+CONFIGURE_LDAP= --without-ldap
+endif
+
+# We touch each configure and Autoconf-related file so that we do not attempt
+# to use Autoconf. The cache is used by the Embdebian project for cross
+# compiles.
+configure: configure-stamp
+configure-stamp:
+ dh_testdir
+ mkdir -p build
+ find src -name configure -print | xargs touch
+ find src \( -name \*hin -o -name \*.h.in -o -name \*.stmp \) -print \
+ | xargs touch
+ [ ! -f $(DEB_HOST_GNU_TYPE).cache ] \
+ || cp $(DEB_HOST_GNU_TYPE).cache build/
+ cd build && $(FLAGS) ../src/configure \
+ --prefix=/usr --localstatedir=/etc --mandir=/usr/share/man \
+ --with-system-et --with-system-ss --disable-rpath \
+ --enable-shared $(CONFIGURE_LDAP) --without-tcl \
+ --with-system-verto \
+ --libdir=\$${prefix}/lib/$(DEB_HOST_MULTIARCH) \
+ --sysconfdir=/etc \
+ $(SYSTEM) $(CACHE)
+ touch configure-stamp
+
+# Build the documentation in a separate directory, since otherwise we'll
+# overwrite the info pages provided upstream and then debian/rules clean won't
+# get back to a virgin copy of the package.
+build: build-arch build-indep
+
+build-arch: build-stamp
+
+build-indep: build-indep-stamp
+
+build-stamp: configure-stamp
+ cd build && $(MAKE) $(NUMJOBS) all
+ touch build-stamp
+
+build-indep-stamp: build-stamp
+ifeq (,$(findstring nodoc,$(DEB_BUILD_OPTIONS)))
+ cd build/doc && make PYTHON=python substhtml substpdf
+ ln -sf /usr/share/javascript/jquery/jquery.js build/doc/html_subst/_static/jquery.js
+ ln -sf /usr/share/javascript/underscore/underscore.js build/doc/html_subst/_static/underscore.js
+ ln -sf /usr/share/javascript/sphinxdoc/1.0/doctools.js build/doc/html_subst/_static/doctools.js
+ ln -sf /usr/share/javascript/sphinxdoc/1.0/searchtools.js build/doc/html_subst/_static/searchtools.js
+ touch build-indep-stamp
+endif
+
+clean:
+ dh_testdir
+ -rm -rf build doc/tools/*.pyc doc/version.py
+ dh_clean build-stamp configure-stamp build-indep-stamp
+
+install: DH_OPTIONS=
+install: build-arch
+ dh_testdir
+ dh_testroot
+ dh_prep
+ set -e; for file in krb5-kdc.dirs krb5-multidev.dirs krb5-multidev.links \
+ krb5-multidev.install libkrb5-3.dirs libkrb5-dev.dirs; \
+ do \
+ sed -e"s,\$${DEB_HOST_MULTIARCH},${DEB_HOST_MULTIARCH},g" \
+ debian/$${file}.in > debian/$$file; \
+ done
+ dh_installdirs
+
+ cd build && $(MAKE) install DESTDIR=`pwd`/../debian/tmp
+ install -d $(CURDIR)/debian/tmp/usr/lib/$(DEB_HOST_MULTIARCH)/krb5 $(CURDIR)/debian/tmp/etc/insserv/overrides
+ifeq (,$(KRB5_SKIP_LDAP))
+ install -m644 debian/krb5-kdc-ldap.insserv-override debian/tmp/etc/insserv/overrides/krb5-kdc
+ mv $(CURDIR)/debian/tmp/usr/lib/$(DEB_HOST_MULTIARCH)/libkdb_ldap* \
+ $(CURDIR)/debian/tmp/usr/lib/$(DEB_HOST_MULTIARCH)/krb5/
+ rm -f $(CURDIR)/debian/tmp/usr/lib/$(DEB_HOST_MULTIARCH)/krb5/libkdb_ldap*.so
+else
+ rm -f $(CURDIR)/debian/tmp/usr/share/man/man8/kdb5_ldap_util.8
+endif
+ mv $(CURDIR)/debian/tmp/usr/bin/krb5-config \
+ $(CURDIR)/debian/tmp/usr/bin/krb5-config.mit
+ mv $(CURDIR)/debian/tmp/usr/share/man/man1/krb5-config.1 \
+ $(CURDIR)/debian/tmp/usr/share/man/man1/krb5-config.mit.1
+
+ install -m644 src/util/ac_check_krb5.m4 \
+ debian/libkrb5-dev/usr/share/aclocal
+
+ dh_install --fail-missing $(EXCLUDE)
+ set -e ; find debian/krb5-multidev/usr/lib/$(DEB_HOST_MULTIARCH)/mit-krb5 -type l -name \*.so -print |\
+ while read linkname; do \
+ ln -s -f ../`readlink $$linkname` \
+ $$linkname; \
+ done
+ rm debian/krb5-multidev/usr/include/mit-krb5/krad.h debian/krb5-multidev/usr/lib/*/mit-krb5/libkrad.so
+ for dir in include lib/$(DEB_HOST_MULTIARCH) lib/$(DEB_HOST_MULTIARCH)/pkgconfig; do \
+ (cd debian/krb5-multidev/usr/$$dir/mit-krb5 && \
+ find . -type d -print ) | (cd debian/libkrb5-dev/usr/$$dir && \
+ xargs mkdir -p); \
+ (cd debian/krb5-multidev/usr/$$dir/mit-krb5 && find . \( -type f -o -type l \) -print ) | \
+ (cd debian/libkrb5-dev/usr/$$dir && xargs -I+ ln -s /usr/$$dir/mit-krb5/+ +) ; \
+ done
+ # however we will handle libkadm5{srv,clnt.so} in dh_link
+# because they actually point to the current level not one level up
+ rm -f debian/krb5-multidev/usr/lib/$(DEB_HOST_MULTIARCH)/mit-krb5/libkadm5{clnt,srv}.so
+
+
+ docbook-to-man debian/krb5_newrealm.sgml \
+ > debian/krb5-admin-server/usr/share/man/man8/krb5_newrealm.8
+ install -o root -g root -m 755 debian/krb5_newrealm \
+ debian/krb5-admin-server/usr/sbin
+ install -o root -g root -m 644 debian/kdc.conf \
+ debian/krb5-kdc/usr/share/krb5-kdc/kdc.conf.template
+ ln -s /usr/share/krb5-kdc/kdc.conf.template \
+ debian/krb5-kdc/usr/share/doc/krb5-kdc/examples/kdc.conf
+
+# Build architecture-independent files here.
+# Pass -i to all debhelper commands in this target to reduce clutter.
+binary-indep: DH_OPTIONS=-i
+binary-indep: build-indep install
+ dh_testdir
+ dh_testroot
+ dh_installchangelogs
+ dh_installdocs
+ dh_installinfo
+ dh_link
+ dh_compress
+ dh_fixperms
+ dh_installdeb
+ dh_gencontrol
+ dh_md5sums
+ dh_builddeb
+
+# Build architecture-dependent files here.
+# Pass -a to all debhelper commands in this target to reduce clutter. Strip
+# library packages separately and save the debug information for the
+# libkrb5-dbg package. This method strips the libraries in those packages
+# twice, but that should be harmless and all other ways of doing this seem
+# uglier.
+binary-arch: DH_OPTIONS=-a
+binary-arch: build-arch install
+ dh_testdir
+ dh_testroot
+ dh_installchangelogs
+ dh_installdocs
+ dh_installdebconf
+ DH_OPTIONS= dh_installinit -pkrb5-kdc --error-handler=init_error -- defaults 18 18
+ DH_OPTIONS= dh_installinit -pkrb5-kpropd -- defaults 18 18
+ DH_OPTIONS= dh_installinit -pkrb5-admin-server -- defaults 18 18
+ dh_systemd_enable
+ dh_lintian
+ set -e ; for pkg in $(LIB_PACKAGES) ; do \
+ DH_OPTIONS="" dh_strip -p$$pkg --dbg-package=libkrb5-dbg; \
+ DH_OPTIONS="" dh_makeshlibs -p$$pkg -Xusr/lib/$(DEB_HOST_MULTIARCH)/krb5/plugins -- -c4 ; \
+ done
+ dh_strip
+ dh_link
+ dh_compress
+ dh_fixperms
+ chmod u+s debian/krb5-user/usr/bin/ksu
+ chmod 700 debian/krb5-kdc/var/lib/krb5kdc
+ chmod 700 debian/krb5-kdc/etc/krb5kdc
+ dh_installdeb
+ dh_shlibdeps
+ dh_gencontrol
+ dh_md5sums
+ dh_builddeb
+
+binary: binary-indep binary-arch
+.PHONY: build clean configure binary-indep binary-arch binary install
diff --git a/debian/slapd-before-kdc.conf b/debian/slapd-before-kdc.conf
new file mode 100644
index 000000000..717cec2b5
--- /dev/null
+++ b/debian/slapd-before-kdc.conf
@@ -0,0 +1,2 @@
+[Unit]
+After=slapd.service
diff --git a/debian/source/format b/debian/source/format
new file mode 100644
index 000000000..163aaf8d8
--- /dev/null
+++ b/debian/source/format
@@ -0,0 +1 @@
+3.0 (quilt)
diff --git a/debian/source/include-binaries b/debian/source/include-binaries
new file mode 100644
index 000000000..a61050820
--- /dev/null
+++ b/debian/source/include-binaries
@@ -0,0 +1 @@
+debian/upstream/signing-key.pgp
diff --git a/debian/source/lintian-overrides b/debian/source/lintian-overrides
new file mode 100644
index 000000000..00307cb51
--- /dev/null
+++ b/debian/source/lintian-overrides
@@ -0,0 +1,7 @@
+krb5 source: license-problem-non-free-RFC doc/html/mitK5license.html
+krb5 source: license-problem-non-free-RFC-BCP78 debian/copyright
+krb5 source: license-problem-non-free-RFC-BCP78 NOTICE
+# Written by upstream with no external authors
+krb5 source: license-problem-non-free-RFC-BCP78src/lib/gssapi/krb5/3des.txt
+
+
diff --git a/debian/tests/control b/debian/tests/control
new file mode 100644
index 000000000..42ae6803e
--- /dev/null
+++ b/debian/tests/control
@@ -0,0 +1,7 @@
+Tests: kinit
+Depends: @
+Restrictions: isolation-container, needs-root, allow-stderr
+
+Tests: slapd-gssapi
+Depends: @, slapd, ldap-utils, libsasl2-modules-gssapi-mit
+Restrictions: isolation-container, needs-root, allow-stderr
diff --git a/debian/tests/kinit b/debian/tests/kinit
new file mode 100644
index 000000000..5c5075fdb
--- /dev/null
+++ b/debian/tests/kinit
@@ -0,0 +1,27 @@
+#!/bin/sh
+
+set -ex
+
+. debian/tests/util
+
+TEST_REALM="EXAMPLE.INTERNAL"
+MYHOSTNAME="krb5-dep8.internal"
+adjust_hostname "${MYHOSTNAME}"
+
+create_realm "${TEST_REALM}" "${MYHOSTNAME}"
+
+# create a random-enough principal
+principal="testuser$$"
+kadmin.local -q "addprinc -pw secret ${principal}"
+
+# get a ticket
+echo secret | kinit ${principal}
+
+# did we really get a ticket?
+klist | grep krbtgt/${TEST_REALM}@${TEST_REALM}
+
+# destroy it
+kdestroy
+
+# delete the principal
+kadmin.local -q "delprinc -force ${principal}"
diff --git a/debian/tests/slapd-gssapi b/debian/tests/slapd-gssapi
new file mode 100644
index 000000000..1b28606a1
--- /dev/null
+++ b/debian/tests/slapd-gssapi
@@ -0,0 +1,52 @@
+#!/bin/sh
+
+set -ex
+
+. debian/tests/util
+
+TEST_REALM="EXAMPLE.INTERNAL"
+MYHOSTNAME="krb5-dep8.internal"
+adjust_hostname "${MYHOSTNAME}"
+
+create_realm "${TEST_REALM}" "${MYHOSTNAME}"
+
+# restart slapd
+systemctl restart slapd.service
+
+# create a random-enough principal
+principal="testuser$$"
+kadmin.local -q "addprinc -pw secret ${principal}"
+
+# create an ldap service principal
+kadmin.local -q "addprinc -randkey ldap/${MYHOSTNAME}"
+
+# extract the key into the system keytab
+kadmin.local -q "ktadd -k /etc/krb5.keytab ldap/${MYHOSTNAME}"
+
+# make sure the user under which the service runs can read that keytab
+chown root:openldap /etc/krb5.keytab
+chmod 0640 /etc/krb5.keytab
+
+# Prepare some LDAP defaults
+# The LDAP base doesn't matter for this test
+cat > /etc/ldap/ldap.conf <<EOF
+BASE dc=example,dc=internal
+URI ldap://${MYHOSTNAME}/
+SASL_REALM ${TEST_REALM}
+# Do not perform reverse DNS lookups to canonicalize SASL host names.
+SASL_NOCANON yes
+EOF
+
+# moment of truth
+# first, authenticate ourselves
+echo secret | kinit ${principal}
+klist | grep krbtgt/${TEST_REALM}@${TEST_REALM}
+
+# now let's see if ldap thinks we are authenticated with gssapi
+ldapwhoami -Y GSSAPI -Q | grep -E "^dn:uid=${principal},cn=gssapi,cn=auth"
+
+# and we should have an ldap ticket
+klist | grep ldap/${MYHOSTNAME}@${TEST_REALM}
+
+# remove tickets
+kdestroy
diff --git a/debian/tests/util b/debian/tests/util
new file mode 100644
index 000000000..4dbf0298d
--- /dev/null
+++ b/debian/tests/util
@@ -0,0 +1,68 @@
+#!/bin/sh
+
+# Copyright 2018 Canonical Ltd.
+# This code is licensed under the same terms as MIT Kerberos.
+
+set -ex
+
+adjust_hostname() {
+ local myhostname="$1"
+
+ echo "${myhostname}" > /etc/hostname
+ hostname "${myhostname}"
+ if ! grep -qE "${myhostname}" /etc/hosts; then
+ # just so it's resolvable
+ echo "127.0.1.10 ${myhostname}" >> /etc/hosts
+ fi
+}
+
+create_realm() {
+ local realm_name="$1"
+ local kerberos_server="$2"
+
+ # start fresh
+ rm -rf /var/lib/krb5kdc/*
+ rm -rf /etc/krb5kdc/*
+ rm -f /etc/krb5.keytab
+
+ # setup some defaults
+ cat > /etc/krb5kdc/kdc.conf <<EOF
+[kdcdefaults]
+ kdc_ports = 750,88
+[realms]
+ ${realm_name} = {
+ database_name = /var/lib/krb5kdc/principal
+ admin_keytab = FILE:/etc/krb5kdc/kadm5.keytab
+ acl_file = /etc/krb5kdc/kadm5.acl
+ key_stash_file = /etc/krb5kdc/stash
+ kdc_ports = 750,88
+ max_life = 10h 0m 0s
+ max_renewable_life = 7d 0h 0m 0s
+ master_key_type = des3-hmac-sha1
+ #supported_enctypes = aes256-cts:normal aes128-cts:normal
+ default_principal_flags = +preauth
+ }
+EOF
+
+ cat > /etc/krb5.conf <<EOF
+[libdefaults]
+ default_realm = ${realm_name}
+ kdc_timesync = 1
+ ccache_type = 4
+ forwardable = true
+ proxiable = true
+ fcc-mit-ticketflags = true
+[realms]
+ ${realm_name} = {
+ kdc = ${kerberos_server}
+ admin_server = ${kerberos_server}
+ }
+EOF
+ echo "# */admin *" > /etc/krb5kdc/kadm5.acl
+
+ # create the realm
+ kdb5_util create -s -P secretpassword
+
+ # restart services
+ systemctl restart krb5-kdc.service krb5-admin-server.service
+}
diff --git a/debian/upstream/signing-key.pgp b/debian/upstream/signing-key.pgp
new file mode 100644
index 000000000..b14ac7e8d
--- /dev/null
+++ b/debian/upstream/signing-key.pgp
Binary files differ
diff --git a/debian/watch b/debian/watch
new file mode 100644
index 000000000..1d0ea5912
--- /dev/null
+++ b/debian/watch
@@ -0,0 +1,5 @@
+# debian/watch -- Rules for uscan to find new upstream versions.
+
+version=3
+#opts=dversionmangle=s/\+dfsg// \
+opts=pgpsigurlmangle=s/$/.asc/ http://web.mit.edu/kerberos/dist/ krb5/[\d.]+/krb5-([\d.]+).tar.gz$