apache2-mod_auth_openidc-2.3.8-lp151.2.6.1<>,:X^pf/=„@"Px[ MmQ N]hwb$4b;@ 0F[4l .Q њ#P.>&9Ĵ!<؋¢\@ ҄-YBxSkaC_׋^s~6@j, |ֆ b`ea})O=7q<ŎN=JWFPV GeHt9%,>z4IFrGvv'N|Zx>>?d! - n' @d     LT(89:FTGhHpIxX|Y\]^bcd7e<f?lAuTv\wxy z8HLRCapache2-mod_auth_openidc2.3.8lp151.2.6.1Apache2.x module for an OpenID Connect enabled Identity ProviderThis module enables an Apache 2.x web server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server.^pfcloud108openSUSE Leap 15.1openSUSEApache-2.0http://bugs.opensuse.orgProductivity/Networking/Web/Servershttps://github.com/zmartzone/mod_auth_openidc/linuxx86_64A^pe^pe7eaee877d6cf387d4ae332eeef53f29369429a50ad8dc880835f3e87889e4d00rootrootrootrootapache2-mod_auth_openidc-2.3.8-lp151.2.6.1.src.rpmapache2-mod_auth_openidcapache2-mod_auth_openidc(x86-64)@@@@@@@@@@@@@    apache_mmn_20120211libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcjose.so.0()(64bit)libcrypto.so.1.1()(64bit)libcrypto.so.1.1(OPENSSL_1_1_0)(64bit)libcurl.so.4()(64bit)libhiredis.so.0.13()(64bit)libjansson.so.4()(64bit)libpcre.so.1()(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)suse_maintenance_mmn_03.0.4-14.6.0-14.0-15.2-14.14.1^_@]{@[v[GZZ1@Kristyna Streitova Kristyna Streitova kstreitova@suse.comkstreitova@suse.comvcizek@suse.comchristof.hanke@mpcdf.mpg.de- add apache2-mod_auth_openidc-2.3.8-CVE-2019-20479.patch to fix open redirect issue that exists in URLs with a slash and backslash at the beginning [bsc#1164459], [CVE-2019-20479]- add apache2-mod_auth_openidc-2.3.8-CVE-2019-14857.patch to fix open redirect issue that exists in URLs with trailing slashes [bsc#1153666], [CVE-2019-14857]- submission to SLE15SP1 because of fate#324447 - build with hiredis only for openSUSE where hiredis is available - add a version for jansson BuildRequires- update to 2.3.8 - changes in 2.3.8 * fix return result FALSE when JWT payload parsing fails * add LGTM code quality badges * fix 3 LGTM alerts * improve auto-detection of XMLHttpRequests via Accept header * initialize test_proto_authorization_request properly * add sanity check on provider->auth_request_method * allow usage with LibreSSL * don't return content with 503 since it will turn the HTTP status code into a 200 * add option to set an upper limit to the number of concurrent state cookies via OIDCStateMaxNumberOfCookies * make the default maximum number of parallel state cookies 7 instead of unlimited * fix using access token as endpoint auth method in introspection calls * fix reading access_token form POST parameters when combined with `AuthType auth-openidc` - changes in 2.3.7 * abort when string length for remote user name substitution is larger than 255 characters * fix Redis concurrency issue when used with multiple vhosts * add support for authorization server metadata with OIDCOAuthServerMetadataURL as in RFC 8414 * refactor session object creation * clear session cookie and contents if cache corruption is detected * use apr_pstrdup when setting r->user * reserve 255 characters in remote username substition instead of 50 - changes in 2.3.6 * add check to detect session cache corruption for server-based caches and cached static metadata * avoid using pipelining for Redis * send Basic header in OAuth www-authenticate response if that's the only accepted method; thanks @puiterwijk * refactor Redis cache backend to solve issues on AUTH errors: a) memory leak and b) redisGetReply lagging behind * adjust copyright year/org * fix buffer overflow in shm cache key set strcpy * turn missing session_state from warning into a debug statement * fix missing "return" on error return from the OP * explicitly set encryption kid so we're compatible with cjose >= 0.6.0 - changes in 2.3.5 * fix encoding of preserved POST data * avoid buffer overflow in shm cache key construction * compile with with Libressl- update to 2.3.4 - requested in fate#323817- initial packagingcloud108 15844573182.3.8-lp151.2.6.12.3.8-lp151.2.6.1apache2mod_auth_openidc.so/usr/lib64//usr/lib64/apache2/-fmessage-length=0 -grecord-gcc-switches -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector-strong -funwind-tables -fasynchronous-unwind-tables -fstack-clash-protection -gobs://build.opensuse.org/openSUSE:Maintenance:12125/openSUSE_Leap_15.1_Update/b47f787fdae79a7460ac948bf717ed52-apache2-mod_auth_openidc.openSUSE_Leap_15.1_Updatedrpmxz5x86_64-suse-linuxdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=85e563849b753387bf2512827ffc4ab0a641cf50, stripped RRRRRR R RR RR R R R^c,u^څutf-8940e2fbbb196f0ba7602ca367a86229a2edbc96795179a09ecd2d558a657f58a? 7zXZ !t/?e"e]"k%"5okw@_/.PS8;oͩz.> 1}W2oũCLS²I$Gsǒ$TOB ]ô5nu_Œk,ll H)L WO%_kbu괝QL ~D4ٳi*tb(EXqNFHץ׳r{쭈ѩpi};'SЀ-5N2,&|.2G6"wvHB_?n l4eoHk[L{'Zy|cMww*d^q-3)#ՓsnBG%w^"wtR)BuAc)1ôɞ4S/5,4[~5sLrJ;#[3/횗nM w9iT|$V n >.FY|N ʖ!FoIF:vP&ʔ*ATwj_Φ+mGdJ2ei7 T9s l}&[R&$X L4rڕ2sQSLw2ꪡ(Q *|3:ǯpԄ8v4HFѲmtpo)?4!mHCw0dW1C\2^LeFV`L#}Xwy[2| >_)g_^Mf?cʚ;Ӵ%lb#dl{5ThҸѤlW_C#|v79Hr(,Lcv,@,KH#qۯw^ x uIb\K|:|Ɩ?Ǔ|fc6/ٻ+BĔ\~gYFtyh.L&am}:I't`sF'r_Q[V7V8:5j5}$4?[N\P?9ZH5 v="V^?=Tz454 } f*r']iBkm1'fd@ U4Eu?ה'ŲΛYي bqh 3-œ!3 1m-A~kJM<{pY5^;9!i㾸8U-yEz~t@2rX q PNbSyOU}}F@W[!D0-pP`4Ɏ:g' 5;#LrV L1'_D UKÁrx~Pˎ6 /Ջ_/!›:z$7߱H%3^*pt!:bƠ<̔Xs@fBbw!W: gێܠ*Ŷ.`)XݔmQ& [gDw^ "dS4:+Bs 9[v)*$M*H~YcnY4dmʆWcoSHHmN';.j[꒒f46쇆KOҧ?kyi d>Aa @"!Vҥ|BFAat}(* 0uqXj單C~S(f )^@kOkJXX`ƶ4B*H_ܿn;&FzL99_5u&]CQ\{޲v*\{?c؅v?_VoSlɀlSq M6ÓW\QY q阥ގUs'nKզ׾q<2rHEԦ]d]5k{𘓈s{o uҨ:w ӥ*g79dB b~mFX(yvF *8W K>XG7pD$=rnjEs"c9';o(,&U*TYڼr2pgy:4!SίO1Ao/QeV :@i@AG>SF$F؆!^5X``< .]'G~~2oS>l_e<~|]YY 6ᵢŀxW (+w.PGUGsG`n|K5_|>&2ym'V Ð`ƍ㖣uBi G sU2ו^id+XE",'`L]JH%yz@a썐McPGLVrK:X f;dgDžaj H^Cc?aQ_z*>`HosakNJ[!bl/ YūjRٖeSA5j$S;XƁ#}\~0J1CABp+IUKTa/Uc@E> ?]~)/*aXP`zKyc qYJ#/C!:Ɠ4,1$h\[]٦4<)]]zɯED VF]"4Έ[it#az.7^G!{?Z> Z( >ya,q,aOPR {^ٵ+959<־-Qɍ@kݒ@ 7&FL4Slh3VYϬ~Cj\Zz 0@ E\:x Ӵ)%౿ǹJ- hTp|P}"]BuXr[}DS7V3=3v4P |НL.Gk,""+>a<~Ӳ9?&㥨Z[y_[)?<*u?/?@W Ə9$ FN\% swOaC=- x, %9}u&,"DEߖ!=$vORڗ>S·2!Sov> ks,su sIo18t壯ֺ;C I/CXTO!Kc;A 7IaG#\y#L<ÿn iw rlM} Ssla*^BHB[Jcw,,GXVIcnuzDh1Z^ ^㿲q6<_=26e|ͳCW~cp6[TQpYS S;҃Ւ[;E+x[{U|@ l_;n/tT6 f`+7fJ'^#E].&J ѽpL>1y؟l(7&њXرcHQ.^oSß1%hsS\5 AJIQ#q;J7 a}yx:jjpE/?ohICe$ml4 Uo[oF4Tb:(QU揺g hfH, G}$e0"H nʆ brnI|]%Uo 1xNq>:S%ψ 91PF[ ^uVIVS"4v|IMI) HcV'ؽ.B!J oyycx?1Ic ZNSaG6^''WM>+H򩳱įTg__Ʀئi.N2{-r{\AJ: j+fR_ǸEy FķX`uN!#7ETmCҙyRv&>bv8F9ЊK胍A1swɽ.aTw~z= ( /"7MU.@ ۫L2G°WMje>XRBCqdlXŷAveC79_s+jBTRcA-X6f8p _г20Ȋ^v"`aʺ6zzM #6{Lrd(Vkg cU7fF@1ZD*G  S)jY@z ie J?xa*u2t >->Ixʔ:xB_5b/AFxXb hwc*&,λP/0"nGƯZ3jۓb)0[mfUWmb8qvHMͭ}6H{M-gLtF\k[iz*+oӕ8;ԝBm>5A0l@"3fn%>o=W.; z!Xiʁ4u"^8rH`ZI .6U#b]~KՁ 6Ws?T{V(Y  _4ІdQ3O8umm[cNbDso|v] Ʃb4HH)I(-0unp sg+">~f(i ۇ We[AE "9Z L2#Jn+}82i;+妉'Ck/25F¨hT;c\t3YJt @2 5Knc)]3j&#u08Ɋ~z޺\-ĦkE& ^㌏ {U]mS sau`pN,pݗ^`=}7gO48݂ :zWDŽ- w`jM *,ndlB*u{?|CF1 !q,:¬VDw@,k%'aWZ4/H_G!gpC_$]q必&}UG5\ެT5k/u"}uI|Wt$볷pht[EɵlP8,r:O"֧,7kZdc_vၨ~CzE,#ae '{d/{r!h[hF?Z73@^exhNLJZdT֕O߃ͲE(l8rmzlP Z.`I-=ΚP%rjebއ U8l|2&Hd5 g63>(K,wi 2oy];_w]ʮ1ٕa=UYRH篮mTEHɻm$q#\%e$|l}&$ț4'--ewmn@T3cPq S5By>uX?,V}ڋ3Xór߱W3JAJۖ,ܫ!>+7|^ɿ/\=£I@lŰ면eYhyJYL.\Wՠʠ)CXٹ{ \;ԕ(j;1o7TmLv`K,dHAR6}FysssF=YuX(LS}~xE6>i PjTU,IS;^p.h0#rbF.E~TĶ YZ