1*4882a593SmuzhiyunSUMMARY = "A network authentication protocol" 2*4882a593SmuzhiyunDESCRIPTION = "Kerberos is a system for authenticating users and services on a network. \ 3*4882a593Smuzhiyun Kerberos is a trusted third-party service. That means that there is a \ 4*4882a593Smuzhiyun third party (the Kerberos server) that is trusted by all the entities on \ 5*4882a593Smuzhiyun the network (users and services, usually called "principals"). \ 6*4882a593Smuzhiyun . \ 7*4882a593Smuzhiyun This is the MIT reference implementation of Kerberos V5. \ 8*4882a593Smuzhiyun . \ 9*4882a593Smuzhiyun This package contains the Kerberos key server (KDC). The KDC manages all \ 10*4882a593Smuzhiyun authentication credentials for a Kerberos realm, holds the master keys \ 11*4882a593Smuzhiyun for the realm, and responds to authentication requests. This package \ 12*4882a593Smuzhiyun should be installed on both master and slave KDCs." 13*4882a593Smuzhiyun 14*4882a593SmuzhiyunHOMEPAGE = "http://web.mit.edu/Kerberos/" 15*4882a593SmuzhiyunSECTION = "console/network" 16*4882a593SmuzhiyunLICENSE = "MIT" 17*4882a593SmuzhiyunLIC_FILES_CHKSUM = "file://${S}/../NOTICE;md5=dd4d0ad4c5e98abb58aa0d312f276791" 18*4882a593SmuzhiyunDEPENDS = "bison-native ncurses util-linux e2fsprogs e2fsprogs-native openssl" 19*4882a593Smuzhiyun 20*4882a593Smuzhiyuninherit autotools-brokensep binconfig perlnative systemd update-rc.d 21*4882a593Smuzhiyun 22*4882a593SmuzhiyunSHRT_VER = "${@oe.utils.trim_version("${PV}", 2)}" 23*4882a593SmuzhiyunSRC_URI = "http://web.mit.edu/kerberos/dist/${BPN}/${SHRT_VER}/${BP}.tar.gz \ 24*4882a593Smuzhiyun file://0001-aclocal-Add-parameter-to-disable-keyutils-detection.patch \ 25*4882a593Smuzhiyun file://debian-suppress-usr-lib-in-krb5-config.patch;striplevel=2 \ 26*4882a593Smuzhiyun file://crosscompile_nm.patch \ 27*4882a593Smuzhiyun file://etc/init.d/krb5-kdc \ 28*4882a593Smuzhiyun file://etc/init.d/krb5-admin-server \ 29*4882a593Smuzhiyun file://etc/default/krb5-kdc \ 30*4882a593Smuzhiyun file://etc/default/krb5-admin-server \ 31*4882a593Smuzhiyun file://krb5-kdc.service \ 32*4882a593Smuzhiyun file://krb5-admin-server.service \ 33*4882a593Smuzhiyun file://CVE-2021-36222.patch;striplevel=2 \ 34*4882a593Smuzhiyun file://CVE-2021-37750.patch;striplevel=2 \ 35*4882a593Smuzhiyun file://CVE-2022-42898.patch;striplevel=2 \ 36*4882a593Smuzhiyun" 37*4882a593SmuzhiyunSRC_URI[md5sum] = "aa4337fffa3b61f22dbd0167f708818f" 38*4882a593SmuzhiyunSRC_URI[sha256sum] = "1a4bba94df92f6d39a197a10687653e8bfbc9a2076e129f6eb92766974f86134" 39*4882a593Smuzhiyun 40*4882a593SmuzhiyunCVE_PRODUCT = "kerberos" 41*4882a593SmuzhiyunCVE_VERSION = "5-${PV}" 42*4882a593Smuzhiyun 43*4882a593SmuzhiyunS = "${WORKDIR}/${BP}/src" 44*4882a593Smuzhiyun 45*4882a593SmuzhiyunPACKAGECONFIG ??= "pkinit" 46*4882a593SmuzhiyunPACKAGECONFIG[libedit] = "--with-libedit,--without-libedit,libedit" 47*4882a593SmuzhiyunPACKAGECONFIG[openssl] = "--with-crypto-impl=openssl,,openssl" 48*4882a593SmuzhiyunPACKAGECONFIG[keyutils] = "--enable-keyutils,--disable-keyutils,keyutils" 49*4882a593SmuzhiyunPACKAGECONFIG[ldap] = "--with-ldap,--without-ldap,openldap" 50*4882a593SmuzhiyunPACKAGECONFIG[readline] = "--with-readline,--without-readline,readline" 51*4882a593SmuzhiyunPACKAGECONFIG[pkinit] = "--enable-pkinit, --disable-pkinit" 52*4882a593Smuzhiyun 53*4882a593SmuzhiyunEXTRA_OECONF += " --without-tcl --with-system-et --disable-rpath" 54*4882a593SmuzhiyunCACHED_CONFIGUREVARS += "krb5_cv_attr_constructor_destructor=yes ac_cv_func_regcomp=yes \ 55*4882a593Smuzhiyun ac_cv_printf_positional=yes ac_cv_file__etc_environment=yes \ 56*4882a593Smuzhiyun ac_cv_file__etc_TIMEZONE=no" 57*4882a593Smuzhiyun 58*4882a593SmuzhiyunCFLAGS:append = " -fPIC -DDESTRUCTOR_ATTR_WORKS=1 -I${STAGING_INCDIR}/et" 59*4882a593SmuzhiyunCFLAGS:append:riscv64 = " -D_REENTRANT -pthread" 60*4882a593SmuzhiyunLDFLAGS:append = " -pthread" 61*4882a593Smuzhiyun 62*4882a593Smuzhiyundo_configure() { 63*4882a593Smuzhiyun gnu-configize --force 64*4882a593Smuzhiyun autoreconf 65*4882a593Smuzhiyun oe_runconf 66*4882a593Smuzhiyun} 67*4882a593Smuzhiyun 68*4882a593Smuzhiyundo_install:append() { 69*4882a593Smuzhiyun rm -rf ${D}/${localstatedir}/run 70*4882a593Smuzhiyun rm -f ${D}${bindir}/sclient 71*4882a593Smuzhiyun rm -f ${D}${bindir}/sim_client 72*4882a593Smuzhiyun rm -f ${D}${bindir}/uuclient 73*4882a593Smuzhiyun rm -f ${D}${sbindir}/krb5-send-pr 74*4882a593Smuzhiyun rm -f ${D}${sbindir}/sim_server 75*4882a593Smuzhiyun rm -f ${D}${sbindir}/sserver 76*4882a593Smuzhiyun rm -f ${D}${sbindir}/uuserver 77*4882a593Smuzhiyun 78*4882a593Smuzhiyun if ${@bb.utils.contains('DISTRO_FEATURES', 'sysvinit', 'true', 'false', d)}; then 79*4882a593Smuzhiyun mkdir -p ${D}/${sysconfdir}/init.d ${D}/${sysconfdir}/default 80*4882a593Smuzhiyun install -m 0755 ${WORKDIR}/etc/init.d/* ${D}/${sysconfdir}/init.d 81*4882a593Smuzhiyun install -m 0644 ${WORKDIR}/etc/default/* ${D}/${sysconfdir}/default 82*4882a593Smuzhiyun 83*4882a593Smuzhiyun mkdir -p ${D}/${sysconfdir}/default/volatiles 84*4882a593Smuzhiyun echo "d root root 0755 ${localstatedir}/run/krb5kdc none" \ 85*4882a593Smuzhiyun > ${D}${sysconfdir}/default/volatiles/87_krb5 86*4882a593Smuzhiyun 87*4882a593Smuzhiyun echo "RUN_KADMIND=true" >> ${D}/${sysconfdir}/default/krb5-admin-server 88*4882a593Smuzhiyun fi 89*4882a593Smuzhiyun if ${@bb.utils.contains('DISTRO_FEATURES', 'systemd', 'true', 'false', d)}; then 90*4882a593Smuzhiyun install -d ${D}${sysconfdir}/tmpfiles.d 91*4882a593Smuzhiyun echo "d /run/krb5kdc - - - -" \ 92*4882a593Smuzhiyun > ${D}${sysconfdir}/tmpfiles.d/krb5.conf 93*4882a593Smuzhiyun 94*4882a593Smuzhiyun mkdir -p ${D}/${sysconfdir}/default 95*4882a593Smuzhiyun install -m 0644 ${WORKDIR}/etc/default/* ${D}/${sysconfdir}/default 96*4882a593Smuzhiyun 97*4882a593Smuzhiyun install -d ${D}${systemd_system_unitdir} 98*4882a593Smuzhiyun install -m 0644 ${WORKDIR}/krb5-admin-server.service ${D}${systemd_system_unitdir} 99*4882a593Smuzhiyun install -m 0644 ${WORKDIR}/krb5-kdc.service ${D}${systemd_system_unitdir} 100*4882a593Smuzhiyun fi 101*4882a593Smuzhiyun 102*4882a593Smuzhiyun sed -e 's@[^ ]*-ffile-prefix-map=[^ "]*@@g' \ 103*4882a593Smuzhiyun -e 's@[^ ]*-fdebug-prefix-map=[^ "]*@@g' \ 104*4882a593Smuzhiyun -e 's@[^ ]*-fmacro-prefix-map=[^ "]*@@g' \ 105*4882a593Smuzhiyun -i ${D}${bindir}/krb5-config 106*4882a593Smuzhiyun} 107*4882a593Smuzhiyun 108*4882a593SmuzhiyunPACKAGES =+ "${PN}-admin-server \ 109*4882a593Smuzhiyun ${PN}-gss-samples \ 110*4882a593Smuzhiyun ${PN}-k5tls \ 111*4882a593Smuzhiyun ${PN}-kdc \ 112*4882a593Smuzhiyun ${PN}-kdc-ldap \ 113*4882a593Smuzhiyun ${PN}-kpropd \ 114*4882a593Smuzhiyun ${PN}-otp \ 115*4882a593Smuzhiyun ${PN}-pkinit \ 116*4882a593Smuzhiyun ${PN}-spake \ 117*4882a593Smuzhiyun ${PN}-user \ 118*4882a593Smuzhiyun libgssapi-krb5 \ 119*4882a593Smuzhiyun libgssrpc \ 120*4882a593Smuzhiyun libk5crypto \ 121*4882a593Smuzhiyun libkadm5clnt-mit \ 122*4882a593Smuzhiyun libkadm5srv-mit \ 123*4882a593Smuzhiyun libkdb5 \ 124*4882a593Smuzhiyun libkrad \ 125*4882a593Smuzhiyun libkrb5 \ 126*4882a593Smuzhiyun libkrb5support \ 127*4882a593Smuzhiyun libverto" 128*4882a593Smuzhiyun 129*4882a593SmuzhiyunFILES:${PN} = "${libdir}/krb5/plugins/preauth/test.so" 130*4882a593SmuzhiyunFILES:${PN}-doc += "${datadir}/examples" 131*4882a593SmuzhiyunFILES:${PN}-dbg += "${libdir}/krb5/plugins/*/.debug" 132*4882a593Smuzhiyun 133*4882a593SmuzhiyunFILES:${PN}-admin-server = "${sbindir}/kadmin.local \ 134*4882a593Smuzhiyun ${sbindir}/kadmind \ 135*4882a593Smuzhiyun ${sbindir}/kprop \ 136*4882a593Smuzhiyun ${sysconfdir}/default/krb5-admin-server \ 137*4882a593Smuzhiyun ${sysconfdir}/init.d/krb5-admin-server \ 138*4882a593Smuzhiyun ${systemd_system_unitdir}/krb5-admin-server.service" 139*4882a593Smuzhiyun 140*4882a593SmuzhiyunFILES:${PN}-gss-samples = "${bindir}/gss-client \ 141*4882a593Smuzhiyun ${sbindir}/gss-server" 142*4882a593Smuzhiyun 143*4882a593SmuzhiyunFILES:${PN}-k5tls = "${libdir}/krb5/plugins/tls/k5tls.so" 144*4882a593Smuzhiyun 145*4882a593SmuzhiyunFILES:${PN}-kdc = "${libdir}/krb5/plugins/kdb/db2.so \ 146*4882a593Smuzhiyun ${localstatedir}/krb5kdc \ 147*4882a593Smuzhiyun ${sbindir}/kdb5_util \ 148*4882a593Smuzhiyun ${sbindir}/kproplog \ 149*4882a593Smuzhiyun ${sbindir}/krb5kdc \ 150*4882a593Smuzhiyun ${sysconfdir}/default/krb5-kdc \ 151*4882a593Smuzhiyun ${sysconfdir}/default/volatiles/87_krb5 \ 152*4882a593Smuzhiyun ${sysconfdir}/init.d/krb5-kdc \ 153*4882a593Smuzhiyun ${sysconfdir}/tmpfiles.d/krb5.conf \ 154*4882a593Smuzhiyun ${systemd_system_unitdir}/krb5-kdc.service" 155*4882a593Smuzhiyun 156*4882a593SmuzhiyunFILES:${PN}-kdc-ldap = "${libdir}/krb5/libkdb_ldap${SOLIBS} \ 157*4882a593Smuzhiyun ${libdir}/krb5/plugins/kdb/kldap.so \ 158*4882a593Smuzhiyun ${sbindir}/kdb5_ldap_util" 159*4882a593Smuzhiyun 160*4882a593SmuzhiyunFILES:${PN}-kpropd = "${sbindir}/kpropd" 161*4882a593SmuzhiyunFILES:${PN}-otp = "${libdir}/krb5/plugins/preauth/otp.so" 162*4882a593SmuzhiyunFILES:${PN}-pkinit = "${libdir}/krb5/plugins/preauth/pkinit.so" 163*4882a593SmuzhiyunFILES:${PN}-spake = "${libdir}/krb5/plugins/preauth/spake.so" 164*4882a593SmuzhiyunFILES:${PN}-user = "${bindir}/k*" 165*4882a593Smuzhiyun 166*4882a593SmuzhiyunFILES:libgssapi-krb5 = "${libdir}/libgssapi_krb5${SOLIBS}" 167*4882a593SmuzhiyunFILES:libgssrpc = "${libdir}/libgssrpc${SOLIBS}" 168*4882a593SmuzhiyunFILES:libk5crypto = "${libdir}/libk5crypto${SOLIBS}" 169*4882a593SmuzhiyunFILES:libkadm5clnt-mit = "${libdir}/libkadm5clnt_mit${SOLIBS}" 170*4882a593SmuzhiyunFILES:libkadm5srv-mit = "${libdir}/libkadm5srv_mit${SOLIBS}" 171*4882a593SmuzhiyunFILES:libkdb5 = "${libdir}/libkdb5${SOLIBS}" 172*4882a593SmuzhiyunFILES:libkrad = "${libdir}/libkrad${SOLIBS}" 173*4882a593SmuzhiyunFILES:libkrb5 = "${libdir}/libkrb5${SOLIBS} \ 174*4882a593Smuzhiyun ${libdir}/krb5/plugins/authdata \ 175*4882a593Smuzhiyun ${libdir}/krb5/plugins/libkrb5" 176*4882a593SmuzhiyunFILES:libkrb5support = "${libdir}/libkrb5support${SOLIBS}" 177*4882a593SmuzhiyunFILES:libverto = "${libdir}/libverto${SOLIBS}" 178*4882a593Smuzhiyun 179*4882a593SmuzhiyunRDEPENDS:${PN}-kadmin-server = "${PN}-kdc" 180*4882a593SmuzhiyunRDEPENDS:${PN}-kpropd = "${PN}-kdc" 181*4882a593Smuzhiyun 182*4882a593SmuzhiyunINITSCRIPT_PACKAGES = "${PN}-admin-server ${PN}-kdc" 183*4882a593SmuzhiyunINITSCRIPT_NAME:${PN}-admin-server = "krb5-admin-server" 184*4882a593SmuzhiyunINITSCRIPT_NAME:${PN}-kdc = "krb5-kdc" 185*4882a593Smuzhiyun 186*4882a593SmuzhiyunSYSTEMD_PACKAGES = "${PN}-admin-server ${PN}-kdc" 187*4882a593SmuzhiyunSYSTEMD_SERVICE:${PN}-admin-server = "krb5-admin-server.service" 188*4882a593SmuzhiyunSYSTEMD_SERVICE:${PN}-kdc = "krb5-kdc.service" 189*4882a593Smuzhiyun 190*4882a593Smuzhiyunpkg_postinst:${PN}-kdc () { 191*4882a593Smuzhiyun if [ -z "$D" ]; then 192*4882a593Smuzhiyun if command -v systemd-tmpfiles >/dev/null; then 193*4882a593Smuzhiyun systemd-tmpfiles --create ${sysconfdir}/tmpfiles.d/krb5.conf 194*4882a593Smuzhiyun elif [ -e ${sysconfdir}/init.d/populate-volatile.sh ]; then 195*4882a593Smuzhiyun ${sysconfdir}/init.d/populate-volatile.sh update 196*4882a593Smuzhiyun fi 197*4882a593Smuzhiyun fi 198*4882a593Smuzhiyun} 199*4882a593Smuzhiyun 200*4882a593SmuzhiyunBBCLASSEXTEND = "native nativesdk" 201