| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211 |
- ##
- ## kerberos.spec -- OpenPKG RPM Package Specification
- ## Copyright (c) 2000-2005 OpenPKG Foundation e.V. <http://openpkg.net/>
- ## Copyright (c) 2000-2005 Ralf S. Engelschall <http://engelschall.com/>
- ##
- ## Permission to use, copy, modify, and distribute this software for
- ## any purpose with or without fee is hereby granted, provided that
- ## the above copyright notice and this permission notice appear in all
- ## copies.
- ##
- ## THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESSED OR IMPLIED
- ## WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF
- ## MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
- ## IN NO EVENT SHALL THE AUTHORS AND COPYRIGHT HOLDERS AND THEIR
- ## CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
- ## SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
- ## LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
- ## USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
- ## ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
- ## OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
- ## OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
- ## SUCH DAMAGE.
- ##
- # FIXME: rse: missing run-command support for kprop/kpropd based master/slave replication
- # package version
- %define V_major 1.4
- %define V_minor 3
- # package information
- Name: kerberos
- Summary: Kerberos Network Authentication System
- URL: http://web.mit.edu/kerberos/
- Vendor: MIT
- Packager: OpenPKG
- Distribution: OpenPKG
- Class: BASE
- Group: Cryptography
- License: MIT subject to US EAR
- Version: %{V_major}.%{V_minor}
- Release: 20051225
- # package options
- %option with_fsl yes
- # list of sources
- Source0: http://web.mit.edu/kerberos/dist/krb5/%{V_major}/krb5-%{version}-signed.tar
- Source1: rc.kerberos
- Source2: fsl.kerberos
- Source3: krb5.conf
- Source4: kdc.conf
- Source5: kerberos-setup.sh
- Patch0: kerberos.patch
- # build information
- Prefix: %{l_prefix}
- BuildRoot: %{l_buildroot}
- BuildPreReq: OpenPKG, openpkg >= 20040130, flex, bison, make, sed, perl
- PreReq: OpenPKG, openpkg >= 20040130
- %if "%{with_fsl}" == "yes"
- BuildPreReq: fsl >= 1.2.0
- PreReq: fsl >= 1.2.0
- %endif
- AutoReq: no
- AutoReqProv: no
- %description
- Kerberos is a network authentication protocol. It is designed to
- provide strong authentication for client/server applications by
- using secret-key cryptography. This is the free implementation of
- this protocol, as available from the Massachusetts Institute of
- Technology (MIT). Kerberos is available in many commercial products
- as well.
- %track
- prog kerberos = {
- version = %{version}
- url = http://web.mit.edu/kerberos/dist/
- regex = krb5-(__VER__)-signed\.tar
- }
- %prep
- %setup -q -T -c -n krb5-%{version}
- %{l_tar} xf %{SOURCE krb5-%{version}-signed.tar}
- %{l_gzip} -d -c krb5-%{version}.tar.gz | (cd .. && %{l_tar} xf -) || exit $?
- %patch -p0
- %{l_shtool} subst \
- -e 's;/etc/krb5\.conf:@SYSCONFDIR/krb5.conf;@SYSCONFDIR/kerberos/krb5.conf;g' \
- -e 's;FILE:/etc/krb5\.keytab;FILE:@SYSCONFDIR/kerberos/krb5.keytab;g' \
- -e 's;@LOCALSTATEDIR/krb5kdc;@LOCALSTATEDIR/kerberos;g' \
- -e 's;DEFAULT_KDC_PROFILE."@LOCALSTATEDIR;DEFAULT_KDC_PROFILE "@SYSCONFDIR;g' \
- src/include/krb5/stock/osconf.h
- %build
- # build toolkit
- cd src
- CC="%{l_cc}" \
- CFLAGS="%{l_cflags -O}" \
- LDFLAGS="%{l_fsl_ldflags}" \
- LIBS="%{l_fsl_libs}" \
- ./configure \
- --prefix=%{l_prefix} \
- --includedir=%{l_prefix}/include/kerberos \
- --libdir=%{l_prefix}/lib/kerberos \
- --enable-dns-for-realm \
- --without-tcl \
- --without-krb4 \
- --enable-static \
- --disable-shared
- %{l_make} %{l_mflags}
- %install
- # install toolkit
- rm -rf $RPM_BUILD_ROOT
- %{l_shtool} mkdir -f -p -m 755 \
- $RPM_BUILD_ROOT%{l_prefix}/var/kerberos
- ( cd src
- %{l_make} %{l_mflags} install DESTDIR=$RPM_BUILD_ROOT
- ) || exit $?
- # create additional directories
- %{l_shtool} mkdir -p -m 755 \
- $RPM_BUILD_ROOT%{l_prefix}/var/kerberos/log \
- $RPM_BUILD_ROOT%{l_prefix}/var/kerberos/run \
- $RPM_BUILD_ROOT%{l_prefix}/var/kerberos/db \
- $RPM_BUILD_ROOT%{l_prefix}/share/kerberos \
- $RPM_BUILD_ROOT%{l_prefix}/etc/kerberos \
- $RPM_BUILD_ROOT%{l_prefix}/etc/rc.d \
- $RPM_BUILD_ROOT%{l_prefix}/etc/fsl
- # strip down installation
- rm -rf $RPM_BUILD_ROOT%{l_prefix}/share/gnats
- rm -rf $RPM_BUILD_ROOT%{l_prefix}/share/examples
- strip $RPM_BUILD_ROOT%{l_prefix}/bin/* >/dev/null 2>&1 || true
- strip $RPM_BUILD_ROOT%{l_prefix}/sbin/* >/dev/null 2>&1 || true
- # install setup script
- %{l_shtool} install -c -m 755 %{l_value -s -a} \
- %{SOURCE kerberos-setup.sh} \
- $RPM_BUILD_ROOT%{l_prefix}/sbin/kerberos-setup
- # install run-command script
- %{l_shtool} install -c -m 755 %{l_value -s -a} \
- %{SOURCE rc.kerberos} \
- $RPM_BUILD_ROOT%{l_prefix}/etc/rc.d/
- # install default configuration files
- %{l_shtool} install -c -m 644 %{l_value -s -a} \
- %{SOURCE krb5.conf} %{SOURCE kdc.conf} \
- $RPM_BUILD_ROOT%{l_prefix}/etc/kerberos/
- # install OSSP fsl configuration
- %{l_shtool} install -c -m 644 %{l_value -s -a} \
- %{SOURCE fsl.kerberos} \
- $RPM_BUILD_ROOT%{l_prefix}/etc/fsl/
- # install documentation
- %{l_shtool} install -c -m 644 %{l_value -s -a} \
- doc/install-guide.ps doc/admin-guide.ps doc/user-guide.ps \
- $RPM_BUILD_ROOT%{l_prefix}/share/kerberos/
- # determine installation files
- %{l_rpmtool} files -v -ofiles -r$RPM_BUILD_ROOT \
- %{l_files_std} \
- '%not %dir %{l_prefix}/etc/fsl' \
- '%config %{l_prefix}/etc/fsl/fsl.kerberos' \
- '%config %{l_prefix}/etc/kerberos/*.conf' \
- '%doc %{l_prefix}/share/kerberos/*.ps' \
- '%attr(4755,%{l_susr},%{l_mgrp}) %{l_prefix}/bin/ksu'
- %files -f files
- %clean
- rm -rf $RPM_BUILD_ROOT
- %pre
- # before upgrade, save status and stop service
- [ $1 -eq 2 ] || exit 0
- eval `%{l_rc} kerberos status 2>/dev/null | tee %{l_tmpfile}`
- %{l_rc} kerberos stop 2>/dev/null
- exit 0
- %post
- # initial hints
- if [ $1 -eq 1 ]; then
- # display information about next steps
- ( echo "Before you can use Kerberos you have to choose the"
- echo "Kerberos realm (e.g. EXAMPLE.COM) and initialize the"
- echo "Kerberos database with the command:"
- echo " \$ $RPM_INSTALL_PREFIX/sbin/kerberos-setup <realm> <domain>"
- echo "where <domain> is the primary DNS zone of this setup and"
- echo "<realm> by convention the upper-case version of <domain>."
- ) | %{l_rpmtool} msg -b -t notice
- fi
- # after upgrade, restore status
- [ $1 -eq 2 ] || exit 0
- eval `cat %{l_tmpfile}`; rm -f %{l_tmpfile}
- [ ".$kerberos_active" = .yes ] && %{l_rc} kerberos start
- exit 0
- %preun
- # before erase, stop service and remove log files
- [ $1 -eq 0 ] || exit 0
- %{l_rc} kerberos stop 2>/dev/null
- rm -f $RPM_INSTALL_PREFIX/var/kerberos/log/*.log >/dev/null 2>&1 || true
- rm -f $RPM_INSTALL_PREFIX/var/kerberos/run/*.pid >/dev/null 2>&1 || true
- rm -f $RPM_INSTALL_PREFIX/var/kerberos/db/* >/dev/null 2>&1 || true
- exit 0
|