libapache2-webauth - Transitional package for WebAuth Apache modules

Property Value
Distribution Debian 8 (Jessie)
Repository Debian Main amd64
Package name libapache2-webauth
Package version 4.6.1
Package release 1
Package architecture all
Package type deb
Installed size 88 B
Download size 56.59 KB
Official Mirror
WebAuth is a cookie-based web authentication system built on top of
Kerberos.  It relies on a central authentication server that handles all
user authentication for a domain and creates user authentication
credentials for any web server that needs strong authentication.
This package is a transitional package to ease upgrades to the correct
Apache module package naming scheme.  It can be safely removed.


Package Version Architecture Repository
libapache2-webauth_4.6.1-1_all.deb 4.6.1 all Debian Main
libapache2-webauth - - -


Name Value
libapache2-mod-webauth -
libapache2-mod-webauthldap -


Type URL
Binary Package libapache2-webauth_4.6.1-1_all.deb
Source Package webauth

Install Howto

  1. Update the package index:
    # sudo apt-get update
  2. Install libapache2-webauth deb package:
    # sudo apt-get install libapache2-webauth




2014-07-23 - Russ Allbery <>
webauth (4.6.1-1) unstable; urgency=medium
* New upstream release.
- Fix legacy support for AuthType StanfordAuth.
- New mod_webkdc configuration directive, WebKdcFastArmorCache, that
tells the WebKDC to always use FAST armor when obtaining initial
credentials using a password.
- Fix parsing of the WebKdcKerberosFactors directive.
- New webauth_krb5_set_fast_armor_path API.
- Show expiring password warning in WebLogin after any POST.
- Translate KRB5_KDC_UNREACH into a user rejected error instead of an
internal failure.
- Translate an EINVAL error to an incorrect password error code.
- Verify the username field on multifactor authentication to avoid
warnings from later in the code.
- Allow newlines, CRs, and tabs in XML from the WebKDC to the WebLogin
server, fixing display of some user message elements.
- Force display of the confirmation page if authorization identity
switching is permitted.
- Diagnose empty RT and ST parameters to WebLogin.
- Add new factors mp (mobile push) and v (voice).
- Warn in the mod_webauth documentation that all members of a
load-balanced pool accepting credential delegation must use the same
Kerberos identity.
* Enable tests controlled with AUTOMATED_TESTING.
* Rename packages and change library symbols for upstream SONAME bump
and symbol versioning changes.
2014-07-02 - Russ Allbery <>
webauth (4.6.0-4) unstable; urgency=medium
* Use an executable debian/libwebauth-perl.install file and some Perl
code in debian/rules to pull the correct Perl arch-specific vendor
module path from Perl during the build.  Should fix builds with Perl
5.20.  Thanks, Niko Tyni and gregor herrmann.  (Closes: #752903)
2014-04-13 - Russ Allbery <>
webauth (4.6.0-3) unstable; urgency=medium
* Handle ownership change of the mod_webauth keyring in the
libapache2-webauth transition package as well, since that's the
package that will see the versioned upgrade.
* Tighten dependency of libwebkdc-perl on libwebauth-perl to ensure that
the remctl password change API is available.
* Refresh debian/copyright with current upstream LICENSE file.
* Remove now-unneeded Lintian override for the upstream signing key.
* Add a Lintian override for the dual-licensed protocol specification.
2014-03-19 - Russ Allbery <>
webauth (4.6.0-2) unstable; urgency=medium
* Change ownership of the mod_webauth keyring to www-data on upgrade
from prior versions if it was owned by root.  Versions prior to 4.6.0
created the keyring during Apache configuration parsing before Apache
dropped privileges, but keyring handling is now done by the Apache
child processes.  Without this change, WebAuth actions would fail
because the keyring could not be initialized.

