Bug#613167: marked as done (kerberized nfs4 mounting)

Bug#613167: fixed in debian-edu-config 2.12.16
regarding kerberized nfs4 mounting
package: debian-edu-config
severity: wishlist


to ease maintainance (no more adding of workstations to be able to access home 
shares) and to improve security, it would be desirable to use kerberized nfs4 

This bug is for tracking this issue, ie by documenting the needed steps.

It's a wishlist feature and we can certainly release squeeze without. (It 
needs some time to implement and test properly.)


Source: debian-edu-config
Source-Version: 2.12.16
Done: Mike Gabriel <sunweaver@debian.org>

Date: Fri, 04 Feb 2022 13:06:25 +0100
Source: debian-edu-config
Architecture: source
Version: 2.12.16
Distribution: unstable
Urgency: medium
Maintainer: Debian Edu Developers <debian-edu@lists.debian.org>
Changed-By: Mike Gabriel <sunweaver@debian.org>
Closes: 613167 815042 971780 1003560 1003727 1004605 1004949
 debian-edu-config (2.12.16) unstable; urgency=medium
   [ Wolfgang Schweer ]
   * etc/exim4/exim-ldap-server-v4.conf: Accept incoming mail from internal
     network sent to root@<mynetwork-names>. (Closes: #1003727).
   [ Mike Gabriel ]
   * share/glib-2.0/schemas/31_debian-edu+mate.gschema.override: Add various
     long-term-used MATE settings overrides (some from Ubuntu MATE).
   * MATE screensaver: Offer "logout user" button on screensaver dialog after
     40min of inactivity and allow other users to salvage a workstation from
     an idle user (session).
   * share/debian-edu-config/tools/setup-freeradius-server: Fix integer
     comparison in run-by-root check. Script was not executable fully (not even
     as root).
   * etc/apache2/mods-available/debian-edu-userdir.conf:
     - White-space cleanup (tabs and spaces mixed).
     - CVE-2021-20001: Disable built-in PHP engine.
     - Add warning to not re-enable PHP interpretation in user dirs (with
       reference to our README).
   * README.public_html_with_PHP-CGI+suExec.md:
     - Provide documentation on how to enable suExec support in Apache2 userdirs
       (i.e. ~/public_html).
   * debian/NEWS:
     + Add file, inform about PHP being disabled in Apache2 user directories.
   * debian/debian-edu-config.fetch-ldap-cert: Drop retrieval of
     Debian-Edu_rootCA from this script. This now is the task of the
     fetch-rootca-cert script. (Closes: #971780).
   * debian/debian-edu-config.fetch-rootca-cert: Ensure proper symlinking of
     Debian-Edu_rootCA.crt in /usr/local/share/ca-certificates/ to
     Debian-Edu_rootCA.crt in /etc/ssl/ca-certificates. Forced symlinking is
     required, because earlier versions of the fetch-ldap-cert init script put
     Debian-Edu_rootCA.crt into /etc/ssl/ca-certificates/ as a file. Forced
     symlinking replaces files by the wanted symlink. The -n option (no-
     dereference) is required to make sure we don't follow any already existing
     symlink. (This relates to #971780).
   * Support krb5i on Diskless Workstations (aka LTSP FAT Clients):
     - ldap-bootstrap/netgroup.ldif: Add diskless-workstation-hosts NIS netgroup
       during LDAP bootstrap.
     - debian/debian-edu-config.{postinst,postrm}: Create non-privileged
       debian-edu system user account on Debian Edu mainserver (for distribution
       of host keytabs to diskless workstations aka LTSP fat clients).
     - share/debian-edu-config/tools/: Add new update-dlw-krb5-keytabs script and
       call it (with delay) from gosa-modify-host and gosa-remove-host hook
     - (Closes: #613167).
   * debian/control:
     + Add D: adduser.
   * share/debian-edu-config/tools/update-proxy-from-wpad:
     - Fix typo (wrong protocol) in APT proxy config creation.
     - Create a Debian Edu specific proxy configuration in /etc/apt/apt.conf.d/
       named 03debian-edu-config rather than meddling with /etc/apt/apt.conf
       directly. Clean up any earlier meddling from apt.conf, as well. (Closes:
   * share/debian-edu-config/tools/setup-roaming: Assure libsss-sudo is installed
     on Roaming Workstation. (Closes: #1004605).
   * share/debian-edu-config/tools/gosa-remove: Capture removals of GOsa² user
     templates and ignore them. (Closes: #815042).
   * ldap-schemas/: Update schema files from Debian's latest GOsa² list of
     schemas. (Closes: #1004949).
   * debian/debian-edu-config.postinst:
     + Replace calling 'service' by calling 'invoke-rc.d'. Thanks, lintian.
   * debian/debian-edu-config.lintian-overrides:
     + Adjust line number references in lintian overrides.
