- 
    Wed Aug 17 2016 Matus Honek <mhonek@redhat.com> - 2.4.40-13
    - fix: Bad log levels in check_password module
- fix: We can't search expected entries from LDAP server
- fix: OpenLDAP ciphersuite parsing doesn't match OpenSSL ciphers man page
  + Add TLS_DHE_DSS_WITH_AES_256_GCM_SHA384 to list of ciphers
  + Add DH cipher string parsing option
  + Correct handling kECDH ciphers with aRSA or aECDSA 
- 
    Fri Jul 01 2016 Matus Honek <mhonek@redhat.com> - 2.4.40-12
    - fix: slapd crash in do_search (#1316450)
- fix: Setting olcTLSProtocolMin does not change supported protocols (#1249093) 
- 
    Mon May 30 2016 Matus Honek <mhonek@redhat.com> - 2.4.40-11
    - fix: correct inconsistent slapd.d directory permissions (#1255433) 
- 
    Mon May 30 2016 Matus Honek <mhonek@redhat.com> - 2.4.40-10
    - fix: slapd fails to start on boot (#1315958)
- fix: id_query option is not available after rebasing openldap to 2.4.39 (#1311832)
- Include sha2 module (#1292568)
- Compile AllOp together with other overlays (#990893)
- Missing mutex unlock in accesslog overlay (#1261003)
- ITS#8337 fix missing olcDbChecksum config attr (#1292590)
- ITS#8003 fix off-by-one in LDIF length (#1292619) 
- 
    Mon Feb 22 2016 Matúš Honěk <mhonek@redhat.com> - 2.4.40-9
    - fix: nslcd segfaults due to incorrect mutex initialization (#1294385) 
- 
    Wed Sep 23 2015 Matúš Honěk <mhonek@redhat.com> - 2.4.40-8
    - NSS does not support string ordering (#1231522)
- implement and correct order of parsing attributes (#1231522)
- add multi_mask and multi_strength to correctly handle sets of attributes (#1231522)
- add new cipher suites and correct AES-GCM attributes (#1245279)
- correct DEFAULT ciphers handling to exclude eNULL cipher suites (#1245279) 
- 
    Mon Sep 14 2015 Matúš Honěk <mhonek@redhat.com> - 2.4.40-7
    - Merge two MozNSS cipher suite definition patches into one. (#1245279)
- Use what NSS considers default for DEFAULT cipher string. (#1245279)
- Remove unnecesary defaults from ciphers' definitions (#1245279) 
- 
    Tue Sep 01 2015 Matúš Honěk <mhonek@redhat.com> - 2.4.40-6
    - fix: OpenLDAP shared library destructor triggers memory leaks in NSPR (#1249977) 
- 
    Fri Jul 24 2015 Matúš Honěk <mhonek@redhat.com> - 2.4.40-5
    - enhancement: support TLS 1.1 and later (#1231522,#1160467)
- fix: openldap ciphersuite parsing code handles masks incorrectly (#1231522)
- fix the patch in commit da1b5c (fix: OpenLDAP crash in NSS shutdown handling) (#1231228) 
- 
    Mon Jun 29 2015 Matúš Honěk <mhonek@redhat.com> - 2.4.40-4
    - fix: rpm -V complains (#1230263) -- make the previous fix do what was intended