Skip to content

chore(release): prepare for publishing - #754

Merged
Benoît Cortier (CBenoit) merged 2 commits into
masterfrom
release-plz/2026-09-25T15-24-44Z
Sep 29, 2026
Merged

Benoît Cortier (CBenoit) merged 2 commits into
masterfrom
release-plz/2026-09-25T15-24-44Z

Conversation

@devolutionsbot

@devolutionsbot devolutionsbot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

🤖 New release

  • sspi: 0.22.0 -> 0.22.1 (✓ API compatible changes)
  • kdc: 0.1.0 -> 0.1.1 (✓ API compatible changes)
Changelog

sspi

[0.22.1] - 2026-09-29

Bug Fixes

  • Preserve RC4 sealing state across mechListMIC (#753) (5b2b137e13)

    CredSSP can wrap pubKeyAuth after the initiator sends its mechListMIC
    but before it verifies the acceptor's MIC. Resetting both NTLM RC4
    handles during verification loses the advanced send state and breaks the
    next wrapped message.

    Snapshot and restore only the sealing handle used for each MIC,
    including when verification fails. Remove the obsolete reset helper and
    add regression coverage for both directions, the CredSSP ordering, and
    invalid signatures. Sequence numbers remain unchanged.

  • Recover from KDC clock skew during AS exchange (#757) (24c9c52352)

    • When a KDC rejects encrypted AS pre-authentication with
      KRB_AP_ERR_SKEW, derive a per-context time offset from the error's
      stime/susec and retry once. Propagate a second skew error or any
      other error without additional retries.
    • Apply the offset to password, keytab, and smart-card
      pre-authentication timestamps and to subsequent TGS, AP, and
      password-change authenticators. Existing public generator calls still
      use local time unless invoked through the corrected client context.
    • Fix the built-in KDC's skew check so timestamps slightly ahead of
      or behind its clock are accepted within max_time_skew.

Please Sort

kdc

[0.1.1] - 2026-09-29

Bug Fixes

  • Recover from KDC clock skew during AS exchange (#757) (24c9c52352)

    • When a KDC rejects encrypted AS pre-authentication with
      KRB_AP_ERR_SKEW, derive a per-context time offset from the error's
      stime/susec and retry once. Propagate a second skew error or any
      other error without additional retries.
    • Apply the offset to password, keytab, and smart-card
      pre-authentication timestamps and to subsequent TGS, AP, and
      password-change authenticators. Existing public generator calls still
      use local time unless invoked through the corrected client context.
    • Fix the built-in KDC's skew check so timestamps slightly ahead of
      or behind its clock are accepted within max_time_skew.


This PR was generated with release-plz.

Copilot AI balanced review requested due to automatic review settings September 25, 2026 15:24

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The release metadata is consistent and the dependency refresh matches the repository’s release-plz configuration.

Review effort: Balanced
Findings: None

What changed in this PR

Prepares the sspi 0.22.1 bug-fix release addressing NTLM RC4 sealing-state preservation.

Changes:

  • Bumps sspi from 0.22.0 to 0.22.1.
  • Adds the release changelog.
  • Refreshes locked transitive dependencies as configured by release-plz.
File Description
CHANGELOG.md Documents the RC4 sealing-state fix.
Cargo.toml Updates the crate version.
Cargo.lock Synchronizes the version and dependency lock state.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@devolutionsbot
devolutionsbot force-pushed the release-plz/2026-09-25T15-24-44Z branch 2 times, most recently from 6f27a0a to d5ecc26 Compare September 28, 2026 03:10
@devolutionsbot
devolutionsbot force-pushed the release-plz/2026-09-25T15-24-44Z branch from d5ecc26 to b524021 Compare September 29, 2026 05:30
Rewrite the newly generated release sections so each entry describes the user-visible change for that crate: keep the NTLM RC4 sealing-state fix and the Kerberos clock-skew recovery in the sspi notes, restrict the kdc notes to the PA-ENC-TIMESTAMP skew check, and drop the NuGet musl packaging entry, which does not affect the sspi crate.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@CBenoit
Benoît Cortier (CBenoit) merged commit b1cad7b into master Sep 29, 2026
68 checks passed
@CBenoit
Benoît Cortier (CBenoit) deleted the release-plz/2026-09-25T15-24-44Z branch September 29, 2026 09:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

3 participants