aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--NEWS10
1 files changed, 5 insertions, 5 deletions
diff --git a/NEWS b/NEWS
index d8c4e00..24326f3 100644
--- a/NEWS
+++ b/NEWS
@@ -2,6 +2,11 @@
wallet 0.6 (unreleased)
+ SECURITY: If -f is used and the output file name with ".new" appended
+ already exists, unlink it first and then create it safely rather than
+ truncating it. This is much safer when creating files in a
+ world-writable directory.
+
The wallet client can now get the server, port, principal, and remctl
type from krb5.conf as well as from compile-time defaults and
command-line options.
@@ -14,11 +19,6 @@ wallet 0.6 (unreleased)
keytab keys into that file rather than moving aside the old keytab and
creating a new keytab with only the new keys.
- If -f is used and the output file name with ".new" appended already
- exists, unlink it first and then create it safely rather than
- truncating it. This is much safer when creating files in a
- world-writable directory.
-
Support enforcing a naming policy for wallet objects via a Perl
function in the wallet server configuration file.