X-Git-Url: https://git.tld-linux.org/?a=blobdiff_plain;f=libvirt-sasl.patch;h=8fbad42ab31b1a09aba0a47c5a2a5ba7639f56f1;hb=f08e2de848020f421ff12e52ee56c58506abe1f6;hp=d9f1675c6ccb66c3d5fd6feb9b4bb4c13be97191;hpb=dd619b7ec6ce3f6e0ccaaf63698d61d39a66398f;p=packages%2Flibvirt.git diff --git a/libvirt-sasl.patch b/libvirt-sasl.patch index d9f1675..8fbad42 100644 --- a/libvirt-sasl.patch +++ b/libvirt-sasl.patch @@ -1,7 +1,7 @@ -diff -urp libvirt-1.3.2.orig/daemon/libvirtd.conf libvirt-1.3.2/daemon/libvirtd.conf ---- libvirt-1.3.2.orig/daemon/libvirtd.conf 2016-01-10 01:57:37.000000000 +0000 -+++ libvirt-1.3.2/daemon/libvirtd.conf 2016-03-18 06:57:24.113768000 +0000 -@@ -128,7 +128,7 @@ +diff -urp libvirt-4.0.0.orig/daemon/libvirtd.conf libvirt-4.0.0/daemon/libvirtd.conf +--- libvirt-4.0.0.orig/daemon/libvirtd.conf 2018-01-24 11:43:38.147588228 +0000 ++++ libvirt-4.0.0/daemon/libvirtd.conf 2018-01-24 11:44:02.010586806 +0000 +@@ -123,7 +123,7 @@ # the network providing auth (eg, TLS/x509 certificates) # # - sasl: use SASL infrastructure. The actual auth scheme is then @@ -10,7 +10,7 @@ diff -urp libvirt-1.3.2.orig/daemon/libvirtd.conf libvirt-1.3.2/daemon/libvirtd. # socket only GSSAPI & DIGEST-MD5 mechanisms will be used. # For non-TCP or TLS sockets, any scheme is allowed. # -@@ -159,7 +159,7 @@ +@@ -154,7 +154,7 @@ # If you don't enable SASL, then all TCP traffic is cleartext. # Don't do this outside of a dev/test scenario. For real world # use, always enable SASL and use the GSSAPI or DIGEST-MD5 @@ -19,10 +19,10 @@ diff -urp libvirt-1.3.2.orig/daemon/libvirtd.conf libvirt-1.3.2/daemon/libvirtd. #auth_tcp = "sasl" # Change the authentication scheme for TLS sockets. -diff -urp libvirt-1.3.2.orig/daemon/Makefile.am libvirt-1.3.2/daemon/Makefile.am ---- libvirt-1.3.2.orig/daemon/Makefile.am 2016-02-24 01:55:16.000000000 +0000 -+++ libvirt-1.3.2/daemon/Makefile.am 2016-03-18 06:57:24.114768000 +0000 -@@ -521,13 +521,13 @@ $(srcdir)/libvirtd.8.in: libvirtd.pod.in +diff -urp libvirt-4.0.0.orig/daemon/Makefile.am libvirt-4.0.0/daemon/Makefile.am +--- libvirt-4.0.0.orig/daemon/Makefile.am 2018-01-24 11:43:38.146588228 +0000 ++++ libvirt-4.0.0/daemon/Makefile.am 2018-01-24 11:44:02.010586806 +0000 +@@ -477,13 +477,13 @@ POD2MAN = pod2man -c "Virtualization Sup # the WITH_LIBVIRTD conditional if WITH_SASL install-data-sasl: @@ -40,10 +40,10 @@ diff -urp libvirt-1.3.2.orig/daemon/Makefile.am libvirt-1.3.2/daemon/Makefile.am else ! WITH_SASL install-data-sasl: uninstall-data-sasl: -diff -urp libvirt-1.3.2.orig/daemon/Makefile.in libvirt-1.3.2/daemon/Makefile.in ---- libvirt-1.3.2.orig/daemon/Makefile.in 2016-03-01 03:19:22.000000000 +0000 -+++ libvirt-1.3.2/daemon/Makefile.in 2016-03-18 12:16:33.415768000 +0000 -@@ -2832,13 +2832,13 @@ $(srcdir)/libvirtd.8.in: libvirtd.pod.in +diff -urp libvirt-4.0.0.orig/daemon/Makefile.in libvirt-4.0.0/daemon/Makefile.in +--- libvirt-4.0.0.orig/daemon/Makefile.in 2018-01-24 11:43:38.146588228 +0000 ++++ libvirt-4.0.0/daemon/Makefile.in 2018-01-24 11:44:02.010586806 +0000 +@@ -2941,13 +2941,13 @@ admin_dispatch.h: $(top_srcdir)/src/rpc/ # This is needed for clients too, so can't wrap in # the WITH_LIBVIRTD conditional @WITH_SASL_TRUE@install-data-sasl: @@ -61,58 +61,58 @@ diff -urp libvirt-1.3.2.orig/daemon/Makefile.in libvirt-1.3.2/daemon/Makefile.in @WITH_SASL_FALSE@install-data-sasl: @WITH_SASL_FALSE@uninstall-data-sasl: -diff -urp libvirt-1.3.2.orig/docs/auth.html libvirt-1.3.2/docs/auth.html ---- libvirt-1.3.2.orig/docs/auth.html 2016-02-24 01:58:13.000000000 +0000 -+++ libvirt-1.3.2/docs/auth.html 2016-03-18 06:57:24.115768000 +0000 -@@ -400,7 +400,7 @@ again: - The plain TCP socket of the libvirt daemon defaults to using SASL for authentication. - The SASL mechanism configured by default is DIGEST-MD5, which provides a basic - username+password style authentication. To enable Kerberos single-sign-on instead, --the libvirt SASL configuration file must be changed. This is /etc/sasl2/libvirt.conf. -+the libvirt SASL configuration file must be changed. This is /etc/sasl/libvirt.conf. - The mech_list parameter must first be changed to gssapi - instead of the default digest-md5, and keytab should be set to - /etc/libvirt/krb5.tab . If SASL is enabled on the UNIX -diff -urp libvirt-1.3.2.orig/docs/auth.html.in libvirt-1.3.2/docs/auth.html.in ---- libvirt-1.3.2.orig/docs/auth.html.in 2015-01-23 11:44:53.000000000 +0000 -+++ libvirt-1.3.2/docs/auth.html.in 2016-03-18 06:57:24.116768000 +0000 -@@ -234,7 +234,7 @@ again: - The plain TCP socket of the libvirt daemon defaults to using SASL for authentication. - The SASL mechanism configured by default is DIGEST-MD5, which provides a basic - username+password style authentication. To enable Kerberos single-sign-on instead, --the libvirt SASL configuration file must be changed. This is /etc/sasl2/libvirt.conf. -+the libvirt SASL configuration file must be changed. This is /etc/sasl/libvirt.conf. - The mech_list parameter must first be changed to gssapi - instead of the default digest-md5, and keytab should be set to - /etc/libvirt/krb5.tab . If SASL is enabled on the UNIX -diff -urp libvirt-1.3.2.orig/libvirt.spec libvirt-1.3.2/libvirt.spec ---- libvirt-1.3.2.orig/libvirt.spec 2016-03-01 03:20:27.000000000 +0000 -+++ libvirt-1.3.2/libvirt.spec 2016-03-18 06:57:24.118768000 +0000 -@@ -2316,7 +2316,7 @@ exit 0 - %dir %attr(0755, root, root) %{_localstatedir}/lib/libvirt/ +diff -urp libvirt-4.0.0.orig/docs/auth.html libvirt-4.0.0/docs/auth.html +--- libvirt-4.0.0.orig/docs/auth.html 2018-01-24 11:43:38.029588235 +0000 ++++ libvirt-4.0.0/docs/auth.html 2018-01-24 11:44:02.011586806 +0000 +@@ -338,7 +338,7 @@ to turn on SASL auth in these listeners. +

+ Since the libvirt SASL config file defaults to using GSSAPI (Kerberos), a + config change is rquired to enable plain password auth. This is done by +-editting /etc/sasl2/libvirt.conf to set the mech_list ++editting /etc/sasl/libvirt.conf to set the mech_list + parameter to scram-sha-1. +

+

+diff -urp libvirt-4.0.0.orig/docs/auth.html.in libvirt-4.0.0/docs/auth.html.in +--- libvirt-4.0.0.orig/docs/auth.html.in 2018-01-24 11:43:38.033588235 +0000 ++++ libvirt-4.0.0/docs/auth.html.in 2018-01-24 11:44:02.011586806 +0000 +@@ -267,7 +267,7 @@ to turn on SASL auth in these listeners. +

+ Since the libvirt SASL config file defaults to using GSSAPI (Kerberos), a + config change is rquired to enable plain password auth. This is done by +-editting /etc/sasl2/libvirt.conf to set the mech_list ++editting /etc/sasl/libvirt.conf to set the mech_list + parameter to scram-sha-1. +

+

+diff -urp libvirt-4.0.0.orig/libvirt.spec libvirt-4.0.0/libvirt.spec +--- libvirt-4.0.0.orig/libvirt.spec 2018-01-24 11:43:38.090588232 +0000 ++++ libvirt-4.0.0/libvirt.spec 2018-01-24 11:44:02.011586806 +0000 +@@ -2106,7 +2106,7 @@ exit 0 + + %{_datadir}/libvirt/test-screenshot.png - %if %{with_sasl} -%config(noreplace) %{_sysconfdir}/sasl2/libvirt.conf +%config(noreplace) %{_sysconfdir}/sasl/libvirt.conf - %endif - %if %{with_wireshark} -diff -urp libvirt-1.3.2.orig/libvirt.spec.in libvirt-1.3.2/libvirt.spec.in ---- libvirt-1.3.2.orig/libvirt.spec.in 2016-03-01 03:18:39.000000000 +0000 -+++ libvirt-1.3.2/libvirt.spec.in 2016-03-18 06:57:24.119768000 +0000 -@@ -2316,7 +2316,7 @@ exit 0 - %dir %attr(0755, root, root) %{_localstatedir}/lib/libvirt/ + %files admin + %{_mandir}/man1/virt-admin.1* +diff -urp libvirt-4.0.0.orig/libvirt.spec.in libvirt-4.0.0/libvirt.spec.in +--- libvirt-4.0.0.orig/libvirt.spec.in 2018-01-24 11:43:38.089588232 +0000 ++++ libvirt-4.0.0/libvirt.spec.in 2018-01-24 11:44:02.011586806 +0000 +@@ -2106,7 +2106,7 @@ exit 0 + + %{_datadir}/libvirt/test-screenshot.png - %if %{with_sasl} -%config(noreplace) %{_sysconfdir}/sasl2/libvirt.conf +%config(noreplace) %{_sysconfdir}/sasl/libvirt.conf - %endif - %if %{with_wireshark} -diff -urp libvirt-1.3.2.orig/src/qemu/qemu.conf libvirt-1.3.2/src/qemu/qemu.conf ---- libvirt-1.3.2.orig/src/qemu/qemu.conf 2015-11-27 12:43:23.000000000 +0000 -+++ libvirt-1.3.2/src/qemu/qemu.conf 2016-03-18 12:16:11.751768000 +0000 -@@ -74,18 +74,18 @@ + %files admin + %{_mandir}/man1/virt-admin.1* +diff -urp libvirt-4.0.0.orig/src/qemu/qemu.conf libvirt-4.0.0/src/qemu/qemu.conf +--- libvirt-4.0.0.orig/src/qemu/qemu.conf 2018-01-24 11:43:38.123588230 +0000 ++++ libvirt-4.0.0/src/qemu/qemu.conf 2018-01-24 11:44:02.012586806 +0000 +@@ -129,18 +129,18 @@ # Examples include vinagre, virt-viewer and virt-manager # itself. UltraVNC, RealVNC, TightVNC do not support this # @@ -134,7 +134,7 @@ diff -urp libvirt-1.3.2.orig/src/qemu/qemu.conf libvirt-1.3.2/src/qemu/qemu.conf # QEMU implements an extension for providing audio over a VNC connection, -@@ -143,17 +143,17 @@ +@@ -205,17 +205,17 @@ # Enable use of SASL encryption on the SPICE server. This requires # a SPICE client which supports the SASL protocol extension. # @@ -153,12 +153,12 @@ diff -urp libvirt-1.3.2.orig/src/qemu/qemu.conf libvirt-1.3.2/src/qemu/qemu.conf -#spice_sasl_dir = "/some/directory/sasl2" +#spice_sasl_dir = "/some/directory/sasl" - - # By default, if no graphical front end is configured, libvirt will disable -diff -urp libvirt-1.3.2.orig/src/qemu/test_libvirtd_qemu.aug.in libvirt-1.3.2/src/qemu/test_libvirtd_qemu.aug.in ---- libvirt-1.3.2.orig/src/qemu/test_libvirtd_qemu.aug.in 2015-11-27 12:43:23.000000000 +0000 -+++ libvirt-1.3.2/src/qemu/test_libvirtd_qemu.aug.in 2016-03-18 12:16:00.319768000 +0000 -@@ -9,14 +9,14 @@ module Test_libvirtd_qemu = + # Enable use of TLS encryption on the chardev TCP transports. + # +diff -urp libvirt-4.0.0.orig/src/qemu/test_libvirtd_qemu.aug.in libvirt-4.0.0/src/qemu/test_libvirtd_qemu.aug.in +--- libvirt-4.0.0.orig/src/qemu/test_libvirtd_qemu.aug.in 2018-01-24 11:43:38.123588230 +0000 ++++ libvirt-4.0.0/src/qemu/test_libvirtd_qemu.aug.in 2018-01-24 11:44:02.012586806 +0000 +@@ -12,7 +12,7 @@ module Test_libvirtd_qemu = { "vnc_tls_x509_verify" = "1" } { "vnc_password" = "XYZ12345" } { "vnc_sasl" = "1" } @@ -167,59 +167,18 @@ diff -urp libvirt-1.3.2.orig/src/qemu/test_libvirtd_qemu.aug.in libvirt-1.3.2/sr { "vnc_allow_host_audio" = "0" } { "spice_listen" = "0.0.0.0" } { "spice_tls" = "1" } - { "spice_tls_x509_cert_dir" = "/etc/pki/libvirt-spice" } +@@ -20,7 +20,7 @@ module Test_libvirtd_qemu = + { "spice_auto_unix_socket" = "1" } { "spice_password" = "XYZ12345" } { "spice_sasl" = "1" } -{ "spice_sasl_dir" = "/some/directory/sasl2" } +{ "spice_sasl_dir" = "/some/directory/sasl" } - { "nographics_allow_host_audio" = "1" } - { "remote_display_port_min" = "5900" } - { "remote_display_port_max" = "65535" } -diff -urp libvirt-1.3.2.orig/tests/confdata/libvirtd.conf libvirt-1.3.2/tests/confdata/libvirtd.conf ---- libvirt-1.3.2.orig/tests/confdata/libvirtd.conf 2015-06-28 03:29:13.000000000 +0000 -+++ libvirt-1.3.2/tests/confdata/libvirtd.conf 2016-03-18 06:57:24.120768000 +0000 -@@ -108,7 +108,7 @@ unix_sock_admin_perms = "0700" - # the network providing auth (eg, TLS/x509 certificates) - # - # - sasl: use SASL infrastructure. The actual auth scheme is then --# controlled from /etc/sasl2/libvirt.conf. For the TCP -+# controlled from /etc/sasl/libvirt.conf. For the TCP - # socket only GSSAPI & DIGEST-MD5 mechanisms will be used. - # For non-TCP or TLS sockets, any scheme is allowed. - # -@@ -139,7 +139,7 @@ auth_unix_rw = "none" - # If you don't enable SASL, then all TCP traffic is cleartext. - # Don't do this outside of a dev/test scenario. For real world - # use, always enable SASL and use the GSSAPI or DIGEST-MD5 --# mechanism in /etc/sasl2/libvirt.conf -+# mechanism in /etc/sasl/libvirt.conf - auth_tcp = "sasl" - - # Change the authentication scheme for TLS sockets. -diff -urp libvirt-1.3.2.orig/tests/confdata/libvirtd.out libvirt-1.3.2/tests/confdata/libvirtd.out ---- libvirt-1.3.2.orig/tests/confdata/libvirtd.out 2015-06-28 03:29:13.000000000 +0000 -+++ libvirt-1.3.2/tests/confdata/libvirtd.out 2016-03-18 06:57:24.121768000 +0000 -@@ -87,7 +87,7 @@ unix_sock_admin_perms = "0700" - # the network providing auth (eg, TLS/x509 certificates) - # - # - sasl: use SASL infrastructure. The actual auth scheme is then --# controlled from /etc/sasl2/libvirt.conf. For the TCP -+# controlled from /etc/sasl/libvirt.conf. For the TCP - # socket only GSSAPI & DIGEST-MD5 mechanisms will be used. - # For non-TCP or TLS sockets, any scheme is allowed. - # -@@ -116,7 +116,7 @@ auth_unix_rw = "none" - # If you don't enable SASL, then all TCP traffic is cleartext. - # Don't do this outside of a dev/test scenario. For real world - # use, always enable SASL and use the GSSAPI or DIGEST-MD5 --# mechanism in /etc/sasl2/libvirt.conf -+# mechanism in /etc/sasl/libvirt.conf - auth_tcp = "sasl" - # Change the authentication scheme for TLS sockets. - # -diff -urp libvirt-1.3.2.orig/tests/qemuargv2xmldata/qemuargv2xml-graphics-vnc-sasl.args libvirt-1.3.2/tests/qemuargv2xmldata/qemuargv2xml-graphics-vnc-sasl.args ---- libvirt-1.3.2.orig/tests/qemuargv2xmldata/qemuargv2xml-graphics-vnc-sasl.args 2016-02-16 14:25:07.000000000 +0000 -+++ libvirt-1.3.2/tests/qemuargv2xmldata/qemuargv2xml-graphics-vnc-sasl.args 2016-03-18 12:15:39.783768000 +0000 + { "chardev_tls" = "1" } + { "chardev_tls_x509_cert_dir" = "/etc/pki/libvirt-chardev" } + { "chardev_tls_x509_verify" = "1" } +diff -urp libvirt-4.0.0.orig/tests/qemuargv2xmldata/graphics-vnc-sasl.args libvirt-4.0.0/tests/qemuargv2xmldata/graphics-vnc-sasl.args +--- libvirt-4.0.0.orig/tests/qemuargv2xmldata/graphics-vnc-sasl.args 2018-01-24 11:43:39.724588134 +0000 ++++ libvirt-4.0.0/tests/qemuargv2xmldata/graphics-vnc-sasl.args 2018-01-24 11:57:36.684538248 +0000 @@ -3,7 +3,7 @@ PATH=/bin \ HOME=/home/test \ USER=test \ @@ -227,11 +186,11 @@ diff -urp libvirt-1.3.2.orig/tests/qemuargv2xmldata/qemuargv2xml-graphics-vnc-sa -SASL_CONF_PATH=/root/.sasl2 \ +SASL_CONF_PATH=/root/.sasl \ QEMU_AUDIO_DRV=none \ - /usr/bin/qemu \ + /usr/bin/qemu-system-i686 \ -name QEMUGuest1 \ -diff -urp libvirt-1.3.2.orig/tests/qemuargv2xmldata/qemuargv2xml-graphics-vnc-tls.args libvirt-1.3.2/tests/qemuargv2xmldata/qemuargv2xml-graphics-vnc-tls.args ---- libvirt-1.3.2.orig/tests/qemuargv2xmldata/qemuargv2xml-graphics-vnc-tls.args 2016-02-16 14:25:07.000000000 +0000 -+++ libvirt-1.3.2/tests/qemuargv2xmldata/qemuargv2xml-graphics-vnc-tls.args 2016-03-18 12:15:42.431768000 +0000 +diff -urp libvirt-4.0.0.orig/tests/qemuargv2xmldata/graphics-vnc-tls.args libvirt-4.0.0/tests/qemuargv2xmldata/graphics-vnc-tls.args +--- libvirt-4.0.0.orig/tests/qemuargv2xmldata/graphics-vnc-tls.args 2018-01-24 11:43:39.724588134 +0000 ++++ libvirt-4.0.0/tests/qemuargv2xmldata/graphics-vnc-tls.args 2018-01-24 11:57:57.508537006 +0000 @@ -3,7 +3,7 @@ PATH=/bin \ HOME=/home/test \ USER=test \ @@ -239,11 +198,11 @@ diff -urp libvirt-1.3.2.orig/tests/qemuargv2xmldata/qemuargv2xml-graphics-vnc-tl -SASL_CONF_PATH=/root/.sasl2 \ +SASL_CONF_PATH=/root/.sasl \ QEMU_AUDIO_DRV=none \ - /usr/bin/qemu \ + /usr/bin/qemu-system-i686 \ -name QEMUGuest1 \ -diff -urp libvirt-1.3.2.orig/tests/qemuxml2argvdata/qemuxml2argv-graphics-spice-sasl.args libvirt-1.3.2/tests/qemuxml2argvdata/qemuxml2argv-graphics-spice-sasl.args ---- libvirt-1.3.2.orig/tests/qemuxml2argvdata/qemuxml2argv-graphics-spice-sasl.args 2016-01-10 01:57:37.000000000 +0000 -+++ libvirt-1.3.2/tests/qemuxml2argvdata/qemuxml2argv-graphics-spice-sasl.args 2016-03-18 12:13:04.244768000 +0000 +diff -urp libvirt-4.0.0.orig/tests/qemuxml2argvdata/graphics-spice-sasl.args libvirt-4.0.0/tests/qemuxml2argvdata/graphics-spice-sasl.args +--- libvirt-4.0.0.orig/tests/qemuxml2argvdata/graphics-spice-sasl.args 2018-01-24 11:43:39.747588133 +0000 ++++ libvirt-4.0.0/tests/qemuxml2argvdata/graphics-spice-sasl.args 2018-01-24 11:58:03.869536627 +0000 @@ -3,7 +3,7 @@ PATH=/bin \ HOME=/home/test \ USER=test \ @@ -251,11 +210,11 @@ diff -urp libvirt-1.3.2.orig/tests/qemuxml2argvdata/qemuxml2argv-graphics-spice- -SASL_CONF_PATH=/root/.sasl2 \ +SASL_CONF_PATH=/root/.sasl \ QEMU_AUDIO_DRV=spice \ - /usr/bin/qemu \ + /usr/bin/qemu-system-i686 \ -name QEMUGuest1 \ -diff -urp libvirt-1.3.2.orig/tests/qemuxml2argvdata/qemuxml2argv-graphics-vnc-sasl.args libvirt-1.3.2/tests/qemuxml2argvdata/qemuxml2argv-graphics-vnc-sasl.args ---- libvirt-1.3.2.orig/tests/qemuxml2argvdata/qemuxml2argv-graphics-vnc-sasl.args 2016-02-16 14:25:07.000000000 +0000 -+++ libvirt-1.3.2/tests/qemuxml2argvdata/qemuxml2argv-graphics-vnc-sasl.args 2016-03-18 12:12:18.798768000 +0000 +diff -urp libvirt-4.0.0.orig/tests/qemuxml2argvdata/graphics-vnc-sasl.args libvirt-4.0.0/tests/qemuxml2argvdata/graphics-vnc-sasl.args +--- libvirt-4.0.0.orig/tests/qemuxml2argvdata/graphics-vnc-sasl.args 2018-01-24 11:43:39.747588133 +0000 ++++ libvirt-4.0.0/tests/qemuxml2argvdata/graphics-vnc-sasl.args 2018-01-24 11:58:00.876536806 +0000 @@ -3,7 +3,7 @@ PATH=/bin \ HOME=/home/test \ USER=test \ @@ -263,11 +222,11 @@ diff -urp libvirt-1.3.2.orig/tests/qemuxml2argvdata/qemuxml2argv-graphics-vnc-sa -SASL_CONF_PATH=/root/.sasl2 \ +SASL_CONF_PATH=/root/.sasl \ QEMU_AUDIO_DRV=none \ - /usr/bin/qemu \ + /usr/bin/qemu-system-i686 \ -name QEMUGuest1 \ -diff -urp libvirt-1.3.2.orig/tests/qemuxml2argvdata/qemuxml2argv-graphics-vnc-tls.args libvirt-1.3.2/tests/qemuxml2argvdata/qemuxml2argv-graphics-vnc-tls.args ---- libvirt-1.3.2.orig/tests/qemuxml2argvdata/qemuxml2argv-graphics-vnc-tls.args 2016-02-16 14:25:07.000000000 +0000 -+++ libvirt-1.3.2/tests/qemuxml2argvdata/qemuxml2argv-graphics-vnc-tls.args 2016-03-18 12:12:35.964768000 +0000 +diff -urp libvirt-4.0.0.orig/tests/qemuxml2argvdata/graphics-vnc-tls.args libvirt-4.0.0/tests/qemuxml2argvdata/graphics-vnc-tls.args +--- libvirt-4.0.0.orig/tests/qemuxml2argvdata/graphics-vnc-tls.args 2018-01-24 11:43:39.747588133 +0000 ++++ libvirt-4.0.0/tests/qemuxml2argvdata/graphics-vnc-tls.args 2018-01-24 11:58:06.308536482 +0000 @@ -3,7 +3,7 @@ PATH=/bin \ HOME=/home/test \ USER=test \ @@ -275,26 +234,68 @@ diff -urp libvirt-1.3.2.orig/tests/qemuxml2argvdata/qemuxml2argv-graphics-vnc-tl -SASL_CONF_PATH=/root/.sasl2 \ +SASL_CONF_PATH=/root/.sasl \ QEMU_AUDIO_DRV=none \ - /usr/bin/qemu \ + /usr/bin/qemu-system-i686 \ -name QEMUGuest1 \ -diff -urp libvirt-1.3.2.orig/tests/qemuxml2argvtest.c libvirt-1.3.2/tests/qemuxml2argvtest.c ---- libvirt-1.3.2.orig/tests/qemuxml2argvtest.c 2016-02-27 03:16:01.000000000 +0000 -+++ libvirt-1.3.2/tests/qemuxml2argvtest.c 2016-03-18 12:11:24.793768000 +0000 -@@ -921,7 +921,7 @@ mymain(void) +diff -urp libvirt-4.0.0.orig/tests/qemuxml2argvtest.c libvirt-4.0.0/tests/qemuxml2argvtest.c +--- libvirt-4.0.0.orig/tests/qemuxml2argvtest.c 2018-01-24 11:43:38.900588183 +0000 ++++ libvirt-4.0.0/tests/qemuxml2argvtest.c 2018-01-24 11:44:07.107586502 +0000 +@@ -1092,7 +1092,7 @@ mymain(void) driver.config->vncSASL = 1; VIR_FREE(driver.config->vncSASLdir); - ignore_value(VIR_STRDUP(driver.config->vncSASLdir, "/root/.sasl2")); + ignore_value(VIR_STRDUP(driver.config->vncSASLdir, "/root/.sasl")); - DO_TEST("graphics-vnc-sasl", QEMU_CAPS_VNC); + DO_TEST("graphics-vnc-sasl", QEMU_CAPS_VNC, QEMU_CAPS_DEVICE_CIRRUS_VGA); driver.config->vncTLS = 1; driver.config->vncTLSx509verify = 1; -@@ -941,7 +941,7 @@ mymain(void) - QEMU_CAPS_DEVICE_QXL, - QEMU_CAPS_SPICE_FILE_XFER_DISABLE); +@@ -1116,7 +1116,7 @@ mymain(void) + DO_TEST("graphics-spice-no-args", + QEMU_CAPS_SPICE, QEMU_CAPS_DEVICE_CIRRUS_VGA); driver.config->spiceSASL = 1; - ignore_value(VIR_STRDUP(driver.config->spiceSASLdir, "/root/.sasl2")); + ignore_value(VIR_STRDUP(driver.config->spiceSASLdir, "/root/.sasl")); DO_TEST("graphics-spice-sasl", - QEMU_CAPS_VGA_QXL, QEMU_CAPS_SPICE, + QEMU_CAPS_DEVICE_QXL); +diff -urp libvirt-4.0.0.orig/tests/virconfdata/libvirtd.conf libvirt-4.0.0/tests/virconfdata/libvirtd.conf +--- libvirt-4.0.0.orig/tests/virconfdata/libvirtd.conf 2018-01-24 11:43:38.873588185 +0000 ++++ libvirt-4.0.0/tests/virconfdata/libvirtd.conf 2018-01-24 11:44:07.107586502 +0000 +@@ -108,7 +108,7 @@ unix_sock_admin_perms = "0700" + # the network providing auth (eg, TLS/x509 certificates) + # + # - sasl: use SASL infrastructure. The actual auth scheme is then +-# controlled from /etc/sasl2/libvirt.conf. For the TCP ++# controlled from /etc/sasl/libvirt.conf. For the TCP + # socket only GSSAPI & DIGEST-MD5 mechanisms will be used. + # For non-TCP or TLS sockets, any scheme is allowed. + # +@@ -139,7 +139,7 @@ auth_unix_rw = "none" + # If you don't enable SASL, then all TCP traffic is cleartext. + # Don't do this outside of a dev/test scenario. For real world + # use, always enable SASL and use the GSSAPI or DIGEST-MD5 +-# mechanism in /etc/sasl2/libvirt.conf ++# mechanism in /etc/sasl/libvirt.conf + auth_tcp = "sasl" + + # Change the authentication scheme for TLS sockets. +diff -urp libvirt-4.0.0.orig/tests/virconfdata/libvirtd.out libvirt-4.0.0/tests/virconfdata/libvirtd.out +--- libvirt-4.0.0.orig/tests/virconfdata/libvirtd.out 2018-01-24 11:43:38.873588185 +0000 ++++ libvirt-4.0.0/tests/virconfdata/libvirtd.out 2018-01-24 11:44:07.108586502 +0000 +@@ -87,7 +87,7 @@ unix_sock_admin_perms = "0700" + # the network providing auth (eg, TLS/x509 certificates) + # + # - sasl: use SASL infrastructure. The actual auth scheme is then +-# controlled from /etc/sasl2/libvirt.conf. For the TCP ++# controlled from /etc/sasl/libvirt.conf. For the TCP + # socket only GSSAPI & DIGEST-MD5 mechanisms will be used. + # For non-TCP or TLS sockets, any scheme is allowed. + # +@@ -116,7 +116,7 @@ auth_unix_rw = "none" + # If you don't enable SASL, then all TCP traffic is cleartext. + # Don't do this outside of a dev/test scenario. For real world + # use, always enable SASL and use the GSSAPI or DIGEST-MD5 +-# mechanism in /etc/sasl2/libvirt.conf ++# mechanism in /etc/sasl/libvirt.conf + auth_tcp = "sasl" + # Change the authentication scheme for TLS sockets. + #