From a939781428d8cb2db2c6f4c7eba5d20a57e616bf Mon Sep 17 00:00:00 2001 From: Jonathan Lent <jlent@stanford.edu> Date: Wed, 24 Jun 2015 07:27:07 -0700 Subject: [PATCH] Staging for 004.048 release --- NEWS | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/NEWS b/NEWS index 59789f9..5ef87bf 100644 --- a/NEWS +++ b/NEWS @@ -1,7 +1,10 @@ -unreleased (??) +release/004.048 (2015-06-24) [newsyslog] Change permissions of /var/log/btmp to '600' in RHEL - systems so that sshd stops complaining (jlent) + systems so that sshd stops complaining. This is because RHEL builds + of openssh are paranoid about the frequency that passwords are + mistakenly entered as usernames. If the utmp group is compromised, + there could be enough context to get real account credentials (jlent) [dns] Make dns_cache a class-level parameter, so that it can be set in Hiera (as base::dns::dns_cache) (akkornel) -- GitLab