File: shibboleth.spec

package info (click to toggle)
shibboleth-sp2 2.6.0%2Bdfsg1-4%2Bdeb9u1
  • links: PTS, VCS
  • area: main
  • in suites: stretch
  • size: 7,896 kB
  • sloc: cpp: 39,404; sh: 11,726; makefile: 866; xml: 371; ansic: 35
file content (614 lines) | stat: -rw-r--r-- 20,473 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
Name:		shibboleth
Version:	2.6.0
Release:	1
Summary:	Open source system for attribute-based Web SSO
Group:		Productivity/Networking/Security
Vendor:		Shibboleth Consortium
License:	Apache-2.0
URL:		http://shibboleth.net/
Source:		%{name}-sp-%{version}.tar.bz2
BuildRoot:	%{_tmppath}/%{name}-sp-%{version}-root
Obsoletes:	shibboleth-sp = 2.5.0
Requires:	openssl
%if 0%{?rhel} >= 6 || 0%{?centos_version} >= 600 || 0%{?amzn} >= 1
PreReq:		xmltooling-schemas%{?_isa} >= 1.6.0, opensaml-schemas%{?_isa} >= 2.6.0
%else
PreReq:		xmltooling-schemas >= 1.6.0, opensaml-schemas >= 2.6.0
%endif
%if 0%{?suse_version} > 1030 && 0%{?suse_version} < 1130
PreReq:		%{insserv_prereq} %{fillup_prereq}
BuildRequires:	libxerces-c-devel >= 3.1
%else
%if 0%{?rhel} >= 7 || 0%{?centos_version} >= 700
BuildRequires:	systemd-devel, pkgconfig
BuildRequires:	xerces-c-devel >= 3.1
%else
BuildRequires:	libxerces-c-devel >= 3.1
%endif
%endif
BuildRequires:	libxml-security-c-devel >= 1.7.3
BuildRequires:	libxmltooling-devel >= 1.6.0
BuildRequires:	libsaml-devel >= 2.6.0
%{?_with_log4cpp:BuildRequires: liblog4cpp-devel >= 1.0}
%{!?_with_log4cpp:BuildRequires: liblog4shib-devel >= 1.0.4}
%if 0%{?rhel} >= 6 || 0%{?centos_version} >= 600 || 0%{?amzn} >= 1
Requires:	libcurl-openssl%{?_isa} >= 7.21.7
BuildRequires:	chrpath
%endif
%if 0%{?suse_version} > 1300
BuildRequires:	libtool
%endif
BuildRequires:  gcc-c++, zlib-devel, boost-devel >= 1.32.0
%{!?_without_gssapi:BuildRequires: krb5-devel}
%{!?_without_doxygen:BuildRequires: doxygen}
%{!?_without_odbc:BuildRequires:unixODBC-devel}
%{?_with_fastcgi:BuildRequires: fcgi-devel}
%if 0%{?centos_version} >= 600
BuildRequires:	libmemcached-devel
%endif
%{?_with_memcached:BuildRequires: libmemcached-devel}
%if "%{_vendor}" == "redhat" || "%{_vendor}" == "amazon"
%if 0%{?rhel} >= 6 || 0%{?centos_version} >= 600 || 0%{?amzn} >= 1
%{!?_without_builtinapache:BuildRequires: httpd-devel%{?_isa}}
%else
%{!?_without_builtinapache:BuildRequires: httpd-devel}
%endif
BuildRequires: redhat-rpm-config
Requires(pre): shadow-utils
Requires(post): chkconfig
Requires(preun): chkconfig, initscripts
%endif
%if "%{_vendor}" == "suse"
Requires(pre): pwdutils
%{!?_without_builtinapache:BuildRequires: apache2-devel}
%{?systemd_requires}
%if 0%{?suse_version} >= 1210
BuildRequires: systemd-rpm-macros, systemd-devel, pkgconfig
%endif
%endif

%{!?_tmpfilesdir:%global _tmpfilesdir /usr/lib/tmpfiles.d}

%define runuser shibd
%if "%{_vendor}" == "suse"
%define pkgdocdir %{_docdir}/shibboleth
%else
%define pkgdocdir %{_docdir}/shibboleth-%{version}
%endif

%description
Shibboleth is a Web Single Sign-On implementations based on OpenSAML
that supports multiple protocols, federated identity, and the extensible
exchange of rich attributes subject to privacy controls.

This package contains the Shibboleth Service Provider runtime libraries,
daemon, default plugins, and Apache module(s).

%package devel
Summary:	Shibboleth Development Headers
Group:		Development/Libraries/C and C++
Requires:	%{name} = %{version}-%{release}
Obsoletes:	shibboleth-sp-devel = 2.5.0
%if 0%{?rhel} >= 7 || 0%{?centos_version} >= 700
Requires:	xerces-c-devel >= 3.1
%else
Requires:	libxerces-c-devel >= 3.1
%endif
Requires: 	libxml-security-c-devel >= 1.7.3
Requires: 	libxmltooling-devel >= 1.6.0
Requires: 	libsaml-devel >= 2.6.0
%{?_with_log4cpp:Requires: liblog4cpp-devel >= 1.0}
%{!?_with_log4cpp:Requires: liblog4shib-devel >= 1.0.4}

%description devel
Shibboleth is a Web Single Sign-On implementations based on OpenSAML
that supports multiple protocols, federated identity, and the extensible
exchange of rich attributes subject to privacy controls.

This package includes files needed for development with Shibboleth.

%prep
%setup -n %{name}-sp-%{version}

%build
%if 0%{?suse_version} >= 1210
	%configure %{?_without_odbc:--disable-odbc} %{?_without_adfs:--disable-adfs} %{?_with_fastcgi} %{!?_without_gssapi:--with-gssapi} %{!?_without_systemd:--enable-systemd} %{?shib_options}
%else
%if 0%{?rhel} >= 7 || 0%{?centos_version} >= 700
	%configure %{?_without_odbc:--disable-odbc} %{?_without_adfs:--disable-adfs} %{?_with_fastcgi} %{!?_without_gssapi:--with-gssapi} %{!?_without_memcached:--with-memcached} %{!?_without_systemd:--enable-systemd} %{?shib_options}
%else
%if 0%{?centos_version} >= 600
	%configure %{?_without_odbc:--disable-odbc} %{?_without_adfs:--disable-adfs} %{?_with_fastcgi} %{!?_without_gssapi:--with-gssapi} %{!?_without_memcached:--with-memcached} %{?shib_options}
%else
	%configure %{?_without_odbc:--disable-odbc} %{?_without_adfs:--disable-adfs} %{?_with_fastcgi} %{!?_without_gssapi:--with-gssapi} %{?_with_memcached} %{?shib_options}
%endif
%endif
%endif
%{__make} pkgdocdir=%{pkgdocdir}

%install
%{__make} install NOKEYGEN=1 DESTDIR=$RPM_BUILD_ROOT pkgdocdir=%{pkgdocdir}

%if "%{_vendor}" == "suse"
	%{__sed} -i "s/\/var\/log\/httpd/\/var\/log\/apache2/g" \
		$RPM_BUILD_ROOT%{_sysconfdir}/shibboleth/native.logger
%endif

# Plug the SP into the built-in Apache on a recognized system.
touch rpm.filelist
APACHE_CONFIG="no"
if [ -f $RPM_BUILD_ROOT%{_libdir}/shibboleth/mod_shib_13.so ] ; then
	APACHE_CONFIG="apache.config"
fi
if [ -f $RPM_BUILD_ROOT%{_libdir}/shibboleth/mod_shib_20.so ] ; then
	APACHE_CONFIG="apache2.config"
fi
if [ -f $RPM_BUILD_ROOT%{_libdir}/shibboleth/mod_shib_22.so ] ; then
	APACHE_CONFIG="apache22.config"
fi
if [ -f $RPM_BUILD_ROOT%{_libdir}/shibboleth/mod_shib_24.so ] ; then
	APACHE_CONFIG="apache24.config"
fi
%{?_without_builtinapache:APACHE_CONFIG="no"}
if [ "$APACHE_CONFIG" != "no" ] ; then
	APACHE_CONFD="no"
	if [ -d %{_sysconfdir}/httpd/conf.d ] ; then
		APACHE_CONFD="%{_sysconfdir}/httpd/conf.d"
	fi
	if [ -d %{_sysconfdir}/apache2/conf.d ] ; then
		APACHE_CONFD="%{_sysconfdir}/apache2/conf.d"
	fi
	if [ "$APACHE_CONFD" != "no" ] ; then
		%{__mkdir} -p $RPM_BUILD_ROOT$APACHE_CONFD
		%{__cp} -p $RPM_BUILD_ROOT%{_sysconfdir}/shibboleth/$APACHE_CONFIG $RPM_BUILD_ROOT$APACHE_CONFD/shib.conf 
		echo "%config(noreplace) $APACHE_CONFD/shib.conf" >> rpm.filelist
	fi
fi

# Establish location of systemd file, if any.
SYSTEMD_SHIBD="no"
%if 0%{?suse_version} >= 1210 || 0%{?rhel} >= 7 || 0%{?centos_version} >= 700
	%{__mkdir} -p $RPM_BUILD_ROOT%{_unitdir}
	echo "%attr(0444,-,-) %{_unitdir}/shibd.service" >> rpm.filelist
	SYSTEMD_SHIBD="$RPM_BUILD_ROOT%{_unitdir}/shibd.service"

	# Get run directory created at boot time.
	%{__mkdir} -p $RPM_BUILD_ROOT%{_tmpfilesdir}
	echo "%attr(0444,-,-) %{_tmpfilesdir}/%{name}.conf" >> rpm.filelist
	cat > $RPM_BUILD_ROOT%{_tmpfilesdir}/%{name}.conf <<EOF
d /run/%{name} 755 %{runuser} %{runuser} -
EOF
%endif

# Otherwise, establish location of sysconfig file, if any.
SYSCONFIG_SHIBD="no"
if [ "$SYSTEMD_SHIBD" == "no" ] ; then
%if "%{_vendor}" == "redhat" || "%{_vendor}" == "amazon"
	%{__mkdir} -p $RPM_BUILD_ROOT%{_sysconfdir}/sysconfig
	echo "%config(noreplace) %{_sysconfdir}/sysconfig/shibd" >> rpm.filelist
	SYSCONFIG_SHIBD="$RPM_BUILD_ROOT%{_sysconfdir}/sysconfig/shibd"
%endif
%if "%{_vendor}" == "suse"
	%{__mkdir} -p $RPM_BUILD_ROOT%{_localstatedir}/adm/fillup-templates
	echo "%{_localstatedir}/adm/fillup-templates/sysconfig.shibd" >> rpm.filelist
	SYSCONFIG_SHIBD="$RPM_BUILD_ROOT%{_localstatedir}/adm/fillup-templates/sysconfig.shibd"
%endif
fi

if [ "$SYSTEMD_SHIBD" != "no" ] ; then
	# Populate the systemd file
	cat > $SYSTEMD_SHIBD <<EOF
[Unit]
Description=Shibboleth Service Provider Daemon
After=network.target
Before=httpd.service

[Service]
Type=notify
NotifyAccess=main
User=%{runuser}
%if 0%{?rhel} >= 6 || 0%{?centos_version} >= 600 || 0%{?amzn} >= 1
Environment=LD_LIBRARY_PATH=/opt/shibboleth/%{_lib}
%endif
ExecStart=%{_sbindir}/shibd -f -F
StandardInput=null
StandardOutput=null
StandardError=journal
TimeoutStopSec=5s
TimeoutStartSec=150s
Restart=on-failure
RestartSec=30s

[Install]
WantedBy=multi-user.target
EOF
elif [ "$SYSCONFIG_SHIBD" != "no" ] ; then
	# Populate the sysconfig file.
	cat > $SYSCONFIG_SHIBD <<EOF
# Shibboleth SP init script customization

# User account for shibd
SHIBD_USER=%{runuser}

# Umask for shibd
# SHIBD_UMASK=022

# Wait period (secs) for configuration (and metadata) to load
SHIBD_WAIT=30
EOF
	%if 0%{?rhel} >= 6 || 0%{?centos_version} >= 600 || 0%{?amzn} >= 1
		cat >> $SYSCONFIG_SHIBD <<EOF

# Override OS-supplied libcurl
export LD_LIBRARY_PATH=/opt/shibboleth/%{_lib}
EOF
	%endif
fi

%if 0%{?rhel} >= 6 || 0%{?centos_version} >= 600 || 0%{?amzn} >= 1
	# Strip existing rpath to libcurl.
	chrpath -d $RPM_BUILD_ROOT%{_sbindir}/shibd
	chrpath -d $RPM_BUILD_ROOT%{_bindir}/mdquery
	chrpath -d $RPM_BUILD_ROOT%{_bindir}/resolvertest
%endif

%if "%{_vendor}" == "redhat" || "%{_vendor}" == "amazon" || "%{_vendor}" == "suse"
if [ "$SYSTEMD_SHIBD" == "no" ] ; then
	# %{_initddir} not yet in RHEL5, use deprecated %{_initrddir}
	install -d -m 0755 $RPM_BUILD_ROOT%{_initrddir}
	install -m 0755 $RPM_BUILD_ROOT%{_sysconfdir}/shibboleth/shibd-%{_vendor} $RPM_BUILD_ROOT%{_initrddir}/shibd
%if "%{_vendor}" == "suse"
	install -d -m 0755 $RPM_BUILD_ROOT/%{_sbindir}
	%{__ln_s} -f %{_initrddir}/shibd $RPM_BUILD_ROOT%{_sbindir}/rcshibd
%endif
fi
%endif

%check
%{__make} check

%clean
[ "$RPM_BUILD_ROOT" != "/" ] && %{__rm} -rf $RPM_BUILD_ROOT

%pre
getent group %{runuser} >/dev/null || groupadd -r %{runuser}
getent passwd %{runuser} >/dev/null || useradd -r -g %{runuser} \
	-d  %{_localstatedir}/run/shibboleth -s /sbin/nologin -c "Shibboleth SP daemon" %{runuser}
%if 0%{?suse_version} >= 1210
	%service_add_pre shibd.service
%endif
exit 0

%post
%ifnos solaris2.8 solaris2.9 solaris2.10 solaris2.11
/sbin/ldconfig
%endif

# Key generation or ownership fix
cd %{_sysconfdir}/shibboleth
if [ -f sp-key.pem ] ; then
	%{__chown} %{runuser}:%{runuser} sp-key.pem sp-cert.pem 2>/dev/null || :
else
	/bin/sh ./keygen.sh -b -u %{runuser} -g %{runuser}
fi

# Fix ownership of log files (even on new installs, if they're left from an older one).
%{__chown} %{runuser}:%{runuser} %{_localstatedir}/log/shibboleth/* 2>/dev/null || :

%if "%{_vendor}" == "redhat" || "%{_vendor}" == "amazon"
	if [ $1 -gt 1 ] ; then
		# On Red Hat with shib.conf installed, clean up old Alias commands
		# by pointing them at new version-independent /usr/share/share tree.
		# Any Aliases we didn't create we assume are custom files.
		# This is to accomodate making shib.conf a noreplace config file.
		# We can't do this for SUSE, because they disallow changes to
		# packaged files in scriplets.
		APACHE_CONF="no"
		if [ -f %{_sysconfdir}/httpd/conf.d/shib.conf ] ; then
			APACHE_CONF="%{_sysconfdir}/httpd/conf.d/shib.conf"
		fi
		if [ "$APACHE_CONF" != "no" ] ; then
			%{__sed} -i "s/\/usr\/share\/doc\/shibboleth\(\-\(.\)\{1,\}\)\{0,1\}\/main\.css/\/usr\/share\/shibboleth\/main.css/g" \
				$APACHE_CONF
			%{__sed} -i "s/\/usr\/share\/doc\/shibboleth\(\-\(.\)\{1,\}\)\{0,1\}\/logo\.jpg/\/usr\/share\/shibboleth\/logo.jpg/g" \
				$APACHE_CONF
		fi
	fi

%if 0%{?rhel} >= 7 || 0%{?centos_version} >= 700
	# Initial prep for systemd
	%systemd_post shibd.service
	if [ $1 -gt 1 ] ; then
		systemctl daemon-reload
	fi
%else
	# Add the proper /etc/rc*.d links for the script
	/sbin/chkconfig --add shibd
%endif
%endif
%if "%{_vendor}" == "suse"
%if 0%{?suse_version} >= 1210
	%service_add_post shibd.service
	systemd-tmpfiles --create %{_tmpfilesdir}/%{name}.conf
%else
	# This adds the proper /etc/rc*.d links for the script
	# and populates the sysconfig/shibd file.
	cd /
	%{fillup_only -n shibd}
	%insserv_force_if_yast shibd
%endif
%endif

%preun
# On final removal, stop shibd and remove service, restart Apache if running.
%if "%{_vendor}" == "redhat" || "%{_vendor}" == "amazon"
%if 0%{?rhel} >= 7 || 0%{?centos_version} >= 700
	%systemd_preun shibd.service
%else
	if [ $1 -eq 0 ] ; then
		/sbin/service shibd stop >/dev/null 2>&1
		/sbin/chkconfig --del shibd
	fi
%endif
	if [ $1 -eq 0 ] ; then
		%{!?_without_builtinapache:/sbin/service httpd status 1>/dev/null && /sbin/service httpd restart 1>/dev/null}
	fi
%endif
%if "%{_vendor}" == "suse"
%if 0%{?suse_version} >= 1210
        %service_del_preun shibd.service
%else
	%stop_on_removal shibd
%endif
	if [ $1 -eq 0 ] ; then
		%{!?_without_builtinapache:/sbin/service apache2 status 1>/dev/null && /sbin/service apache2 restart 1>/dev/null}
	fi
%endif
exit 0

%postun
%ifnos solaris2.8 solaris2.9 solaris2.10 solaris2.11
/sbin/ldconfig
%endif
%if "%{_vendor}" == "redhat" || "%{_vendor}" == "amazon"
	# On upgrade, restart components if they're already running.
%if 0%{?rhel} >= 7 || 0%{?centos_version} >= 700
	%systemd_postun_with_restart shibd.service
%else
	if [ $1 -ge 1 ] ; then
		/sbin/service shibd status 1>/dev/null && /sbin/service shibd restart 1>/dev/null
	fi
%endif
	if [ $1 -ge 1 ] ; then
		%{!?_without_builtinapache:/sbin/service httpd status 1>/dev/null && /sbin/service httpd restart 1>/dev/null}
		exit 0
	fi
%endif
%if "%{_vendor}" == "suse"
%if 0%{?suse_version} >= 1210
	%service_del_postun shibd.service
%else
	cd / 
	%restart_on_update shibd
	%{insserv_cleanup}
%endif
	%{!?_without_builtinapache:%restart_on_update apache2}
%endif

%posttrans
# One-time extra restart of shibd and Apache to work around
# SUSE bug that breaks old %restart_on_update macro.
# If we remove, upgrades from pre-systemd to post-systemd
# will stop doing the final restart.
%if "%{_vendor}" == "suse" && 0%{?suse_version} >= 1210
	/usr/bin/systemctl try-restart shibd >/dev/null 2>&1 || :
	/usr/bin/systemctl try-restart apache2 >/dev/null 2>&1 || :
%endif
exit 0

%files -f rpm.filelist
%defattr(-,root,root,-)
%{_sbindir}/shibd
%{_bindir}/mdquery
%{_bindir}/resolvertest
%{_libdir}/libshibsp.so.*
%{_libdir}/libshibsp-lite.so.*
%dir %{_libdir}/shibboleth
%{_libdir}/shibboleth/*
%attr(0750,%{runuser},%{runuser}) %dir %{_localstatedir}/log/shibboleth
%if "%{_vendor}" == "redhat" || "%{_vendor}" == "amazon" || "%{_vendor}" == "suse"
%if "%{_vendor}" == "redhat" || "%{_vendor}" == "amazon"
%attr(0750,apache,apache) %dir %{_localstatedir}/log/shibboleth-www
%endif
%if "%{_vendor}" == "suse"
%attr(0750,wwwrun,www) %dir %{_localstatedir}/log/shibboleth-www
%endif
%else
%attr(0750,-,-) %dir %{_localstatedir}/log/shibboleth-www
%endif
%if 0%{?suse_version} < 1300
%attr(0755,%{runuser},%{runuser}) %dir %{_localstatedir}/run/shibboleth
%endif
%attr(0755,%{runuser},%{runuser}) %dir %{_localstatedir}/cache/shibboleth
%dir %{_datadir}/xml/shibboleth
%{_datadir}/xml/shibboleth/*
%dir %{_datadir}/shibboleth
%{_datadir}/shibboleth/*
%dir %{_sysconfdir}/shibboleth
%config(noreplace) %{_sysconfdir}/shibboleth/*.xml
%config(noreplace) %{_sysconfdir}/shibboleth/*.html
%config(noreplace) %{_sysconfdir}/shibboleth/*.logger
%if "%{_vendor}" == "redhat"
%if 0%{?rhel} >= 7 || 0%{?centos_version} >= 700
%else
%config %{_initrddir}/shibd
%endif
%endif
%if "%{_vendor}" == "amazon"
%config %{_initrddir}/shibd
%endif
%if "%{_vendor}" == "suse" && 0%{?suse_version} < 1210
%config %{_initrddir}/shibd
%{_sbindir}/rcshibd
%endif
%if 0%{?suse_version} >= 1210 || 0%{?rhel} >= 7 || 0%{?centos_version} >= 700
%{_tmpfilesdir}/%{name}.conf
%endif
%{_sysconfdir}/shibboleth/*.dist
%{_sysconfdir}/shibboleth/apache*.config
%{_sysconfdir}/shibboleth/shibd-*
%attr(0755,root,root) %{_sysconfdir}/shibboleth/keygen.sh
%attr(0755,root,root) %{_sysconfdir}/shibboleth/metagen.sh
%doc %{pkgdocdir}
%exclude %{pkgdocdir}/api

%files devel
%defattr(-,root,root,-)
%{_includedir}/*
%{_libdir}/libshibsp.so
%{_libdir}/libshibsp-lite.so
%doc %{pkgdocdir}/api

%changelog
* Tue May 03 2016 Scott Cantor <cantor.2@osu.edu> - 2.6.0-1
- Bump opensaml dependency version
- Bump max wait time for shibd systemd unit file

* Thu Jul 23 2015 Scott Cantor <cantor.2@osu.edu> - 2.5.5-2
- Fix use of /var/run/shibboleth on newer tmpfs platforms

* Thu Jul 2 2015 Scott Cantor <cantor.2@osu.edu> - 2.5.5-1
- Revamp with systemd support for RH/CentOS 7+ and SUSE 12.1+

* Mon Mar 9 2015 Scott Cantor <cantor.2@osu.edu> - 2.5.4-1
- Add Amazon VM support
- Add a separate native logging directory
- Remove hard-coded init.d usage
- Switch to bz2 sources to prevent future issues with SuSE

* Mon Nov 17 2014 Scott Cantor <cantor.2@osu.edu> - 2.5.3-2
- Add libtool dep for OpenSUSE 13
- Remove /var/run/shibboleth for OpenSUSE 13

* Tue May 13 2014 Ian Young <ian@iay.org.uk> - 2.5.3-1.2
- Update package dependencies for RHEL/CentOS 7
- Fix bogus dates in changelog

* Sat Jun 8 2013   Scott Cantor  <cantor.2@osu.edu>  - 2.5.2-1
- Add --with-gssapi using MIT K5 by default

* Tue Sep 25 2012  Scott Cantor  <cantor.2@osu.edu>  - 2.5.1-1
- Merge back various changes used in released packages
- Prep for 2.5.1 by pulling extra restart out

* Tue Aug 7 2012  Scott Cantor  <cantor.2@osu.edu>  - 2.5.0-2
- Changed package name back to shibboleth because of upgrade bugs
- Put back extra restart for this release only.

* Thu Mar 1 2012  Scott Cantor  <cantor.2@osu.edu>  - 2.5.0-1
- Move logo and stylesheet to version-independent tree
- Make shib.conf noreplace
- Post-fixup of Alias commands in older shib.conf
- Changes to run shibd as non-root shibboleth user
- Move init customizations to /etc/sysconfig/shibd
- Copy shibd restart for Red Hat to postun
- Add boost-devel dependency
- Build memcache plugin on RH6
- Add cachedir to install
- Add Apache 2.4 to install

* Sun Jun 26 2011  Scott Cantor  <cantor.2@osu.edu>  - 2.4.3-1
- Log files shouldn't be world readable.
- Explicit requirement for libcurl-openssl on RHEL6
- Uncomment LD_LIBRARY_PATH in init script for RHEL6 
- Remove rpath from binaries for RHEL6

* Fri Dec 25 2009  Scott Cantor  <cantor.2@osu.edu>  - 2.4-1
- Update dependencies.

* Mon Nov 23 2009 Scott Cantor  <cantor.2@osu.edu>  - 2.3.1-1
- Reset revision for 2.3.1 release

* Wed Aug 19 2009 Scott Cantor  <cantor.2@osu.edu>  - 2.2.1-2
- SuSE init script changes
- Restart Apache on removal, not just upgrade
- Fix scriptlet exit values when Apache is stopped

* Mon Aug 10 2009 Scott Cantor  <cantor.2@osu.edu>  - 2.2.1-1
- Doc handling changes
- SuSE init script

* Tue Aug 4 2009 Scott Cantor  <cantor.2@osu.edu>  - 2.2.1-1
- Initial version for 2.2.1, with shibd/httpd restart on upgrade

* Thu Jun 25 2009 Scott Cantor  <cantor.2@osu.edu>  - 2.2-3
- Add additional cleanup to posttrans fix

* Tue Jun 23 2009 Scott Cantor  <cantor.2@osu.edu>  - 2.2-2
- Reverse without_builtinapache macro test
- Fix init script handling on Red Hat to handle upgrades

* Wed Dec 3 2008  Scott Cantor  <cantor.2@osu.edu>  - 2.2-1
- Bump minor version.
- Make keygen.sh executable.
- Fixing SUSE Xerces dependency name.
- Optionally package shib.conf.

* Tue Jun 10 2008  Scott Cantor  <cantor.2@osu.edu>  - 2.1-1
- Change shib.conf handling to treat as config file.

* Mon Mar 17 2008  Scott Cantor  <cantor.2@osu.edu>  - 2.0-6
- Official release.

* Fri Jan 18 2008  Scott Cantor  <cantor.2@osu.edu>  - 2.0-5
- Release candidate 1.

* Sun Oct 21 2007 Scott Cantor  <cantor.2@osu.edu>  - 2.0-4
- libexec -> lib/shibboleth changes
- Added doc subpackage

* Thu Aug 16 2007 Scott Cantor  <cantor.2@osu.edu>  - 2.0-3
- First public beta.

* Fri Jul 13 2007 Scott Cantor	<cantor.2@osu.edu>  - 2.0-2
- Second alpha release.

* Sun Jun 10 2007 Scott Cantor	<cantor.2@osu.edu>  - 2.0-1
- First alpha release.

* Mon Oct 2 2006 Scott Cantor	<cantor.2@osu.edu>  - 1.3-11
- Applied fix for secadv 20061002
- Fix for metadata loader loop

* Thu Jun 15 2006 Scott Cantor  <cantor.2@osu.edu>  - 1.3-10
- Applied fix for sec 20060615

* Sat Apr 15 2006 Scott Cantor  <cantor.2@osu.edu>  - 1.3-9
- Misc. patches, SuSE, Apache 2.2, gcc 4.1, and 64-bit support

* Mon Jan 9 2006 Scott Cantor  <cantor.2@osu.edu>  - 1.3-8
- Applied new fix for secadv 20060109

* Tue Nov 8 2005 Scott Cantor  <cantor.2@osu.edu>  - 1.3-7
- Applied new fix for secadv 20050901 plus rollup

* Fri Sep 23 2005 Scott Cantor  <cantor.2@osu.edu>  - 1.3-6
- Minor patches and default config changes
- pidfile patch
- Fix shib.conf creation
- Integrated init.d script
- Prevent replacement of config files

* Thu Sep 1 2005  Scott Cantor  <cantor.2@osu.edu>  - 1.3-5
- Applied fix for secadv 20050901 plus rollup of NSAPI fixes

* Sun Apr 24 2005  Scott Cantor  <cantor.2@osu.edu>  - 1.3-1
- Updated test programs and location of schemas.
- move siterefresh to to sbindir

* Fri Apr  1 2005  Derek Atkins  <derek@ihtfp.com>  - 1.3-1
- Add selinux-targeted-policy package
- move shar to sbindir

* Tue Oct 19 2004  Derek Atkins  <derek@ihtfp.com>  - 1.2-1
- Create SPEC file based on various versions in existence.