apache2-mod_auth_openidc-2.3.8-lp151.2.6.1<>,4|^p/=„5U4蘠|e1I3(W >\H5Ƅ OJڎW_vFX, WWJJfר֍#˪6 fCa(wHf\+uADwnt+s}GCK/-_&U]Ζōs؈PMyh2m3C=\D ] R+_ S` JnjF207?6 =L_8OfS;Hpcm!RUS29'xۨHQ#>>|?ld! - n' @d     PX(89:F G8H@IHXLYT\x]^bced eflu,v4wxy z  &hCapache2-mod_auth_openidc2.3.8lp151.2.6.1Apache2.x module for an OpenID Connect enabled Identity ProviderThis module enables an Apache 2.x web server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server.^parmbuild02openSUSE Leap 15.1openSUSEApache-2.0http://bugs.opensuse.orgProductivity/Networking/Web/Servershttps://github.com/zmartzone/mod_auth_openidc/linuxaarch64A^p^p6900275957c30ce30d373d96ca23ca4066c5751f40a3ee382ceb425ec8ba2f24rootrootrootrootapache2-mod_auth_openidc-2.3.8-lp151.2.6.1.src.rpmapache2-mod_auth_openidcapache2-mod_auth_openidc(aarch-64)@@@@@@@@@@@    apache_mmn_20120211ld-linux-aarch64.so.1()(64bit)ld-linux-aarch64.so.1(GLIBC_2.17)(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.17)(64bit)libcjose.so.0()(64bit)libcrypto.so.1.1()(64bit)libcrypto.so.1.1(OPENSSL_1_1_0)(64bit)libcurl.so.4()(64bit)libhiredis.so.0.13()(64bit)libjansson.so.4()(64bit)libpcre.so.1()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)suse_maintenance_mmn_03.0.4-14.6.0-14.0-15.2-14.14.1^_@]{@[v[GZZ1@Kristyna Streitova Kristyna Streitova kstreitova@suse.comkstreitova@suse.comvcizek@suse.comchristof.hanke@mpcdf.mpg.de- add apache2-mod_auth_openidc-2.3.8-CVE-2019-20479.patch to fix open redirect issue that exists in URLs with a slash and backslash at the beginning [bsc#1164459], [CVE-2019-20479]- add apache2-mod_auth_openidc-2.3.8-CVE-2019-14857.patch to fix open redirect issue that exists in URLs with trailing slashes [bsc#1153666], [CVE-2019-14857]- submission to SLE15SP1 because of fate#324447 - build with hiredis only for openSUSE where hiredis is available - add a version for jansson BuildRequires- update to 2.3.8 - changes in 2.3.8 * fix return result FALSE when JWT payload parsing fails * add LGTM code quality badges * fix 3 LGTM alerts * improve auto-detection of XMLHttpRequests via Accept header * initialize test_proto_authorization_request properly * add sanity check on provider->auth_request_method * allow usage with LibreSSL * don't return content with 503 since it will turn the HTTP status code into a 200 * add option to set an upper limit to the number of concurrent state cookies via OIDCStateMaxNumberOfCookies * make the default maximum number of parallel state cookies 7 instead of unlimited * fix using access token as endpoint auth method in introspection calls * fix reading access_token form POST parameters when combined with `AuthType auth-openidc` - changes in 2.3.7 * abort when string length for remote user name substitution is larger than 255 characters * fix Redis concurrency issue when used with multiple vhosts * add support for authorization server metadata with OIDCOAuthServerMetadataURL as in RFC 8414 * refactor session object creation * clear session cookie and contents if cache corruption is detected * use apr_pstrdup when setting r->user * reserve 255 characters in remote username substition instead of 50 - changes in 2.3.6 * add check to detect session cache corruption for server-based caches and cached static metadata * avoid using pipelining for Redis * send Basic header in OAuth www-authenticate response if that's the only accepted method; thanks @puiterwijk * refactor Redis cache backend to solve issues on AUTH errors: a) memory leak and b) redisGetReply lagging behind * adjust copyright year/org * fix buffer overflow in shm cache key set strcpy * turn missing session_state from warning into a debug statement * fix missing "return" on error return from the OP * explicitly set encryption kid so we're compatible with cjose >= 0.6.0 - changes in 2.3.5 * fix encoding of preserved POST data * avoid buffer overflow in shm cache key construction * compile with with Libressl- update to 2.3.4 - requested in fate#323817- initial packagingarmbuild02 15844574722.3.8-lp151.2.6.12.3.8-lp151.2.6.1apache2mod_auth_openidc.so/usr/lib64//usr/lib64/apache2/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:12125/openSUSE_Leap_15.1_Update_ports/b47f787fdae79a7460ac948bf717ed52-apache2-mod_auth_openidc.openSUSE_Leap_15.1_Updatedrpmxz5aarch64-suse-linuxdirectoryELF 64-bit LSB shared object, ARM aarch64, version 1 (SYSV), dynamically linked, BuildID[sha1]=87984f9a45aacc5ba6ef82b504c945fb0faafe64, stripped RRRRRR RR R RR9aXutf-8de4a594155a225993a5ddac945893d1eb6385ef5e4a8744d6b1193d68e665f3b? 7zXZ !t/55]"k%"5okw@_/.PS8;oͩz.> f֞8GD˅笜QY'myła"c Wr<"YZ5JڠM&#;B'Hy_PRMz%޹YZ t1K*+zb0Afu5Xz=kӬ3e"7B8T wfs +vGrv)!Syh yXzQm3PAwP!4hכ8ǍNV:Cv]=6gYݍGBTQ 7`E%4.^4B>oD9 &=6&}1 6ުӯ<Hr(ޟzrZ ɫ4wyf]S8ncL㐎YdzMA|8jgA.x-?G x_ F͙!n_C~K#QeV[70@IAQOx<'ſ-KzaӤ}UB %LKJ2Q9uH[1d鹭F#G΁4&"勖E0  $@fiԇxccJ?ENbQ`U- ۊ4} a:DZbW3]7S v{CE6Ѧ|*-@o4Aw${DƯ{4;o쟟Zd\f8WLآ͸h5Y\MeX 1ONo$e6f,x%g8m+y8!ݽ_sqW^x)T(G_f]'֤+h6C m%hVùoX6͖)iw dJ}-sNJJZg {l5Z*R UCc}m%;${gɹ*N_('wr7",Ms?+K[ ă+005=KaĆ$Rf$qYy'/#Bj<8t00HQa /.E 6xaV VLoݥ P `&MR( M2z팋kMRͤWN _xKܭQtoj*O=O.&ʠ{>ʕ*Ms6̢ѼG{G8l7\ xGg DSU1S=ۜg5ѯ^2b20/4LYO ib3É}j챑"9{{ +eT!=V9@yuJQZ"!2YBy89|c:aG%(mSaϜn\Fص D{0!#Khc9Rt4[ŧny&u'#+ܛ4$ 9Zʥٍܴ*(38=tsw)suޔj"i|SN!"P)nxoH.F˭qf k/ 癔 DJDʎI' 4|'f %2Hf[<Y(@"8ȯ~u?*C֯%rhjcl20 $R*{Ԭup+k!e'+C+cY#mZKg/ h C=Ύ)A Z``?@L0ܙ3:[ +/҈Y؍v'ңBiԍ}Nק]r;6@[v@f;NrKkMI+NN\F腥 pԢ{`E\ ##CccN$m B)-o`-txNݙYͶ4G"rS. lw5B,0`Ԃa "p1"Ulmͺ{ˠ4qT;ehx_z9f˄ƈ{wÌпM)k[NP B(U!k$śE 8AS"44EIzFshePFyh WX}7 d>DicܝebD5mY$w%TF8 $@ mĻ!ҬbE)"NM8EwGGҷhI&9=/m#.ee}@A<}KMGJm~ ^WѼ5j ;%@\ձQڍZ9e&p5;1Iʨ ppjX{v}:+aTuGQkPlV=' RX#%zr N\_m;Ö4oJjd]ˆH܋9:F1j竎\&ʙl'B*HFN`-2=:7频ߐ@oAP]ˡ(4ĉ:&̔&_xG]|e 'k?cҝd`}jƾX? Klv/>% a x]J g *u`T_"B:(/5[ض%؟a;d GH>9:"a9Xʪ/^a F 2ִl ᓑIi+pKN f3FX`&]V^ut{:>u-hYt)ZuWʝ_GbZܝI5/_#w~`ơ3TOEs QWU0&X>lI|5ni#?yv"%94jy_ ,O29XE}g|sg@}>,Y ^c6yw K9m> x?tƜ;I"§Ơ 7 5"N ֎P ﶹp=~kd77cé Xwy o4v3y$; ;cp*~ĉP@c5Cum&"vLRŒX[e @[tB2R&낳[&r\$#Aj6%|/~ (bp )w{$Oh^֦KxQӆtR/Z7ܚ,.k0o1@i܃)">G4 TK|6iu*9@,YY _int2Kk8v~{B}Td,it`Չ LCq:ԭWPG ]2!*P]S*e[Yp&zS4uQGAjb^ JG^**928l&#jς7$ьyw[PŨZ-r~$ER Sk*&|K KP m.V`ypj$[#ӄiGIgǖiZ=Mbx@&ݔl7,.<BS'Yow$L]oKғOp.Ĕc))j9_r8XH"»:9`LHwݞ*Tc졃Q N/ g;R:Ș`}.|~b{xxKZ7ĒhdZkmSl g"#9AC}`ڌltA s4ZUk_KҺTN0n|h$䈊G_Y"[}&"늵*ϲRBrsiGCSD׊voJQP^.ALٮUYѠV_O<82Ug&yNؗ:}bus+SzLDsKg4=7Tv.-ʧad L;"c~G;˘% D2jc=}B=s|4L4ݼtI߄}[wo7Y'YZܨ!W C"jW{Ӿ9/В[^ĥG+ #>xR1qz[_2˿oc{SUH_3(ZuMTöNOSvТl}?xc$Z2 ѡgXZO?_^.Qvo1