Changelog for
sssd-common-1.12.2-58.el7.i686.rpm :
* Tue Feb 03 2015 Jakub Hrozek
- 1.12.2-57- Run the restart in sssd-common posttrans- Explicitly require libwbclient- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade
* Fri Jan 30 2015 Jakub Hrozek - 1.12.2-56- Resolves: rhbz#1187113 - sssd deamon was not running after RHEL 7.1 upgrade
* Fri Jan 30 2015 Jakub Hrozek - 1.12.2-55- Fix endianess bug in fill_id()- Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares
* Fri Jan 30 2015 Jakub Hrozek - 1.12.2-54- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view
* Fri Jan 30 2015 Jakub Hrozek - 1.12.2-53- Resolves: rhbz#1187192 - IPA initgroups don\'t work correctly in non-default view
* Tue Jan 27 2015 Jakub Hrozek - 1.12.2-52- Resolves: rhbz#1184982 - Need to set different umask in selinux_child
* Tue Jan 27 2015 Jakub Hrozek - 1.12.2-51- Bump the release number- Related: rhbz#1184140 - Users saved throug extop don\'t have the originalMemberOf attribute
* Tue Jan 27 2015 Jakub Hrozek - 1.12.2-50- Add a patch dependency- Related: rhbz#1184140 - Users saved throug extop don\'t have the originalMemberOf attribute
* Tue Jan 27 2015 Jakub Hrozek - 1.12.2-49- Process ghost members only once- Fix processing of universal groups with members from different domains- Related: rhbz#1168904 - gid is overridden by uid in default trust view
* Tue Jan 27 2015 Jakub Hrozek - 1.12.2-48- Related: rhbz#1184140 - Users saved throug extop don\'t have the originalMemberOf attribute
* Fri Jan 23 2015 Jakub Hrozek - 1.12.2-47- Resolves: rhbz#1185188 - Uncached SIDs cannot be resolved
* Fri Jan 23 2015 Jakub Hrozek - 1.12.2-46- Handle GID override in MPG domains- Handle views with mixed-case domains- Related: rhbz#1168904 - gid is overridden by uid in default trust view
* Wed Jan 21 2015 Jakub Hrozek - 1.12.2-45- Open socket to the PAC responder in krb5_child before dropping root- Related: rhbz#1184140 - Users saved throug extop don\'t have the originalMemberOf attribute
* Tue Jan 20 2015 Jakub Hrozek - 1.12.2-44- Resolves: rhbz#1184140 - Users saved throug extop don\'t have the originalMemberOf attribute
* Mon Jan 19 2015 Jakub Hrozek - 1.12.2-43- Resolves: rhbz#1182183 - pam_sss(sshd:auth): authentication failure with user from AD
* Wed Jan 14 2015 Jakub Hrozek - 1.12.2-42- Resolves: rhbz#889206 - On clock skew sssd returns system error
* Wed Jan 14 2015 Jakub Hrozek - 1.12.2-41- Related: rhbz#1168904 - gid is overridden by uid in default trust view
* Tue Jan 13 2015 Jakub Hrozek - 1.12.2-40- Resolves: rhbz#1177140 - gpo_child fails if \"log level\" is enabled in smb.conf- Related: rhbz#1168904 - gid is overridden by uid in default trust view
* Fri Dec 19 2014 Sumit Bose - 1.12.2-39- Resolves: rhbz#1175408 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1175705 - sssd-libwbclient conflicts with Samba\'s and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package
* Wed Dec 17 2014 Sumit Bose - 1.12.2-38- Resolves: rhbz#1171215 - Crash in function get_object_from_cache- Resolves: rhbz#1171383 - getent fails for posix group with AD users after login- Resolves: rhbz#1171382 - getent of AD universal group fails after group users login- Resolves: rhbz#1170300 - Access is not rejected for disabled domain- Resolves: rhbz#1162486 - Error processing external groups with getgrnam/getgrgid in the server mode- Resolves: rhbz#1168904 - gid is overridden by uid in default trust view
* Wed Dec 17 2014 Sumit Bose - 1.12.2-37- Resolves: rhbz#1169459 - sssd-ad: The man page description to enable GPO HBAC Policies are unclear- Related: rhbz#1113783 - sssd should run under unprivileged user
* Mon Dec 15 2014 Jakub Hrozek - 1.12.2-35- Rebuild to add several forgotten Patch entries- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users- Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=
* Sun Dec 14 2014 Jakub Hrozek - 1.12.2-35- Remove Coverity warnings in krb5_child code- Related: rhbz#1113783 - sssd should run under unprivileged user
* Sat Dec 13 2014 Jakub Hrozek - 1.12.2-34- Resolves: rhbz#1173482 - MAN: Document that only user names are checked for pam_trusted_users- Resolves: rhbz#1167324 - pam_sss domains option: User auth should fail when domains=
* Sat Dec 13 2014 Jakub Hrozek - 1.12.2-33- Don\'t error out on chpass with OTPs- Related: rhbz#1109756 - Rebase SSSD to 1.12
* Mon Dec 08 2014 Jakub Hrozek - 1.12.2-32- Resolves: rhbz#1124320 - [FJ7.0 Bug]: getgrent returns error because sss is written in nsswitch.conf as default.
* Mon Dec 08 2014 Jakub Hrozek - 1.12.2-31- Resolves: rhbz#1169739 - selinuxusermap rule does not apply to trusted AD users- Enable running unit tests without cmocka- Related: rhbz#1113783 - sssd should run under unprivileged user
* Wed Dec 03 2014 Jakub Hrozek - 1.12.2-30- krb5_child and ldap_child do not call Kerberos calls as root- Related: rhbz#1113783 - sssd should run under unprivileged user
* Wed Dec 03 2014 Jakub Hrozek - 1.12.2-29- Resolves: rhbz#1168735 - The Kerberos provider is not properly views-aware
* Wed Nov 26 2014 Jakub Hrozek - 1.12.2-28- Fix typo in libwbclient-devel alternatives invocation- Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares
* Wed Nov 26 2014 Jakub Hrozek - 1.12.2-27- Resolves: rhbz#1166727 - pam_sss domains option: Untrusted users from the same domain are allowed to auth.
* Tue Nov 25 2014 Jakub Hrozek - 1.12.2-26- Handle migrating clients between views- Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution
* Tue Nov 25 2014 Jakub Hrozek - 1.12.2-25- Use alternatives for libwbclient- Related: rhbz#1109331 - [RFE] Allow SSSD to be used with smbd shares
* Tue Nov 25 2014 Jakub Hrozek - 1.12.2-24- Resolves: rhbz#1165794 - sssd does not work with custom value of option re_expression
* Tue Nov 25 2014 Jakub Hrozek - 1.12.2-23- Add an option that describes where to put generated krb5 files to- Related: rhbz#1135043 - [RFE] Implement localauth plugin for MIT krb5 1.12
* Tue Nov 25 2014 Jakub Hrozek - 1.12.2-22- Handle IPA group names returned from the extop plugin- Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution
* Tue Nov 25 2014 Jakub Hrozek - 1.12.2-21- Resolves: rhbz#1165792 - automount segfaults in sss_nss_check_header
* Thu Nov 20 2014 Jakub Hrozek - 1.12.2-20- Resolves: rhbz#1163742 - \"debug_timestamps = false\" and \"debug_microseconds = true\" do not work after enabling journald with sssd.
* Thu Nov 20 2014 Jakub Hrozek - 1.12.2-19- Resolves: rhbz#1153593 - Manpage description of case_sensitive=preserving is incomplete
* Thu Nov 20 2014 Jakub Hrozek - 1.12.2-18- Support views for IPA users- Related: rhbz#891984 - [RFE] ID Views: Support migration from the sync solution to the trust solution
* Thu Nov 20 2014 Jakub Hrozek - 1.12.2-17- Update man page to clarify TGs should be disabled with a custom search base- Related: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases
* Wed Nov 19 2014 Jakub Hrozek - 1.12.2-16- Use upstreamed patches for the rootless sssd- Related: rhbz#1113783 - sssd should run under unprivileged user
* Wed Nov 19 2014 Jakub Hrozek - 1.12.2-15- Resolves: rhbz#1153603 - Proxy Provider: Fails to lookup case sensitive users and groups with case_sensitive=preserving
* Wed Nov 19 2014 Jakub Hrozek - 1.12.2-14- Resolves: rhbz#1161741 - TokenGroups for LDAP provider breaks in corner cases
* Wed Nov 19 2014 Jakub Hrozek - 1.12.2-13- Resolves: rhbz#1162480 - dereferencing failure against openldap server
* Wed Nov 12 2014 Jakub Hrozek - 1.12.2-12- Move adding the user from pretrans to pre, copy adding the user to sssd-krb5-common and sssd-ipa as well in order to work around yum ordering issue- Related: rhbz#1113783 - sssd should run under unprivileged user
* Tue Nov 11 2014 Jakub Hrozek - 1.12.2-11- Resolves: rhbz#1113783 - sssd should run under unprivileged user
* Fri Nov 07 2014 Jakub Hrozek - 1.12.2-10- Fix two regressions in the new selinux_child process- Related: rhbz#1113783 - sssd should run under unprivileged user- Resolves: rhbz#1132365 - Remove password from the PAM stack if OTP is used
* Wed Nov 05 2014 Jakub Hrozek - 1.12.2-9- Include the ldap_child and selinux_child patches for rootless sssd- Related: rhbz#1113783 - sssd should run under unprivileged user
* Wed Nov 05 2014 Jakub Hrozek - 1.12.2-8- Support overriding SSH public keys with views- Support extended attributes via the extop plugin- Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1137010 - disable midpoint refresh for netgroups if ptask refresh is enabled
* Thu Oct 30 2014 Jakub Hrozek - 1.12.2-7- Resolves: rhbz#1153518 - service lookups returned in lowercase with case_sensitive=preserving- Resolves: rhbz#1158809 - Enumeration shows only a single group multiple times
* Wed Oct 22 2014 Jakub Hrozek - 1.12.2-6- Include the responder and packaging patches for rootless sssd- Related: rhbz#1113783 - sssd should run under unprivileged user
* Wed Oct 22 2014 Jakub Hrozek - 1.12.2-5- Amend the sssd-ldap man page with info about lockout setup- Related: rhbz#1109756 - Rebase SSSD to 1.12- Resolves: rhbz#1137014 - Shell fallback mechanism in SSSD - Resolves: rhbz#790854 - 4 functions with reference leaks within sssd (src/python/pyhbac.c)
* Wed Oct 22 2014 Jakub Hrozek - 1.12.2-4- Fix regressions caused by views patches when SSSD is connected to a pre-4.0 IPA server- Related: rhbz#1109756 - Rebase SSSD to 1.12
* Wed Oct 22 2014 Jakub Hrozek - 1.12.2-3- Add the low-level server changes for running as unprivileged user- Package the libsss_semange library needed for SELinux label changes- Related: rhbz#1113783 - sssd should run under unprivileged user - Resolves: rhbz#1113784 - sssd should audit selinux user map changes
* Wed Oct 22 2014 Jakub Hrozek - 1.12.2-2- Use libsemanage for SELinux label changes- Resolves: rhbz#1113784 - sssd should audit selinux user map changes
* Mon Oct 20 2014 Jakub Hrozek - 1.12.2-1- Rebase SSSD to 1.12.2- Related: rhbz#1109756 - Rebase SSSD to 1.12
* Thu Oct 09 2014 Jakub Hrozek - 1.12.1-2- Sync with upstream- Related: rhbz#1109756 - Rebase SSSD to 1.12
* Thu Sep 11 2014 Jakub Hrozek - 1.12.1-1- Rebuild against ding-libs with fixed SONAME- Related: rhbz#1109756 - Rebase SSSD to 1.12
* Tue Sep 09 2014 Jakub Hrozek - 1.12.1-1- Rebase SSSD to 1.12.1- Related: rhbz#1109756 - Rebase SSSD to 1.12
* Fri Sep 05 2014 Jakub Hrozek - 1.12.0-3- Require ldb 2.1.17- Related: rhbz#1133914 - Rebase libldb to version 1.1.17 or newer
* Fri Aug 08 2014 Jakub Hrozek - 1.12.0-2- Fix fully qualified IFP lookups- Related: rhbz#1109756 - Rebase SSSD to 1.12
* Thu Jul 24 2014 Jakub Hrozek - 1.12.0-1- Rebase SSSD to 1.12.0- Related: rhbz#1109756 - Rebase SSSD to 1.12
* Wed May 21 2014 Jakub Hrozek - 1.11.2-70- Squash in upstream review comments about the PAC patch- Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder
* Tue May 13 2014 Jakub Hrozek - 1.11.2-69- Backport a patch to allow krb5-utils-test to run as root- Related: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder
* Tue May 13 2014 Jakub Hrozek - 1.11.2-68- Resolves: rhbz#1097286 - Expanding home directory fails when the request comes from the PAC responder
* Tue May 13 2014 Jakub Hrozek - 1.11.2-67- Fix a DEBUG message, backport two related fixes- Related: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain
* Tue May 13 2014 Jakub Hrozek - 1.11.2-66- Resolves: rhbz#1090653 - segfault in sssd_be when second domain tree users are queried while joined to child domain
* Wed Apr 02 2014 Jakub Hrozek - 1.11.2-65- Resolves: rhbz#1082191 - RHEL7 IPA selinuxusermap hbac rule not always matching
* Wed Apr 02 2014 Jakub Hrozek - 1.11.2-64- Resolves: rhbz#1077328 - other subdomains are unavailable when joined to a subdomain in the ad forest
* Wed Mar 26 2014 Sumit Bose - 1.11.2-63- Resolves: rhbz#1078877 - Valgrind: Invalid read of int while processing netgroup
* Wed Mar 26 2014 Sumit Bose - 1.11.2-62- Resolves: rhbz#1075092 - Password change w/ OTP generates error on success
* Fri Mar 21 2014 Jakub Hrozek - 1.11.2-61- Resolves: rhbz#1078840 - Error during password change
* Thu Mar 13 2014 Jakub Hrozek - 1.11.2-60- Resolves: rhbz#1075663 - SSSD should create the SELinux mapping file with format expected by pam_selinux
* Wed Mar 12 2014 Jakub Hrozek - 1.11.2-59- Related: rhbz#1075621 - Add another Kerberos error code to trigger IPA password migration
* Tue Mar 11 2014 Jakub Hrozek - 1.11.2-58- Related: rhbz#1073635 - IPA SELinux code looks for the host in the wrong sysdb subdir when a trusted user logs in
* Tue Mar 11 2014 Jakub Hrozek - 1.11.2-57- Related: rhbz#1066096 - not retrieving homedirs of AD users with posix attributes
* Mon Mar 10 2014 Jakub Hrozek - 1.11.2-56- Related: rhbz#1072995 - AD group inconsistency when using AD provider in sssd-1.11-40
* Mon Mar 10 2014 Jakub Hrozek - 1.11.2-55- Resolves: rhbz#1073631 - sssd fails to handle expired passwords when OTP is used
* Tue Mar 04 2014 Jakub Hrozek - 1.11.2-54- Resolves: rhbz#1072067 - SSSD Does not cache SELinux map from FreeIPA correctly
* Tue Mar 04 2014 Jakub Hrozek - 1.11.2-53- Resolves: rhbz#1071903 - ipa-server-mode: Use lower-case user name component in home dir path
* Tue Mar 04 2014 Jakub Hrozek - 1.11.2-52- Resolves: rhbz#1068725 - Evaluate usage of sudo LDAP provider together with the AD provider
* Wed Feb 26 2014 Jakub Hrozek - 1.11.2-51- Fix idmap documentation- Bump idmap version info- Related: rhbz#1067361 - Check IPA idranges before saving them to the cache
* Wed Feb 26 2014 Jakub Hrozek - 1.11.2-50- Pull some follow up man page fixes from upstream- Related: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes- Related: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example
* Wed Feb 26 2014 Jakub Hrozek - 1.11.2-49- Resolves: rhbz#1060389 - Document that `sssd` cache needs to be cleared manually, if ID mapping configuration changes
* Wed Feb 26 2014 Jakub Hrozek - 1.11.2-48- Resolves: rhbz#1064908 - MAN: Remove misleading memberof example from ldap_access_filter example
* Wed Feb 26 2014 Jakub Hrozek - 1.11.2-47- Resolves: rhbz#1068723 - Setting int option to 0 yields the default value
* Wed Feb 26 2014 Jakub Hrozek - 1.11.2-46- Resolves: rhbz#1067361 - Check IPA idranges before saving them to the cache
* Wed Feb 26 2014 Jakub Hrozek - 1.11.2-45- Resolves: rhbz#1067476 - SSSD pam module accepts usernames with leading spaces
* Wed Feb 26 2014 Jakub Hrozek - 1.11.2-44- Resolves: rhbz#1033069 - Configuring two different provider types might start two parallel enumeration tasks
* Mon Feb 17 2014 Jakub Hrozek - 1.11.2-43- Resolves: rhbz#1068640 - \'IPA: Don\'t call tevent_req_post outside _send\' should be added to RHEL7
* Mon Feb 17 2014 Jakub Hrozek - 1.11.2-42- Resolves: rhbz#1063977 - SSSD needs to enable FAST by default
* Mon Feb 17 2014 Jakub Hrozek - 1.11.2-41- Resolves: rhbz#1064582 - sss_cache does not reset the SYSDB_INITGR_EXPIRE attribute when expiring users
* Wed Feb 12 2014 Jakub Hrozek - 1.11.2-40- Resolves: rhbz#1033081 - Implement heuristics to detect if POSIX attributes have been replicated to the Global Catalog or not
* Wed Feb 12 2014 Jakub Hrozek - 1.11.2-39- Resolves: rhbz#872177 - [RFE] subdomain homedir template should be configurable/use flatname by default
* Wed Feb 12 2014 Jakub Hrozek - 1.11.2-38- Resolves: rhbz#1059753 - Warn with a user-friendly error message when permissions on sssd.conf are incorrect
* Wed Jan 29 2014 Jakub Hrozek - 1.11.2-37- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn\'t exclude uidNumber in filter
* Wed Jan 29 2014 Jakub Hrozek - 1.11.2-36- Resolves: rhbz#1059253 - Man page states default_shell option supersedes other shell options but in fact override_shell does.- Use the right domain for AD site resolution- Related: rhbz#743503 - [RFE] sssd should support DNS sites
* Wed Jan 29 2014 Jakub Hrozek - 1.11.2-35- Resolves: rhbz#1028039 - AD Enumeration reads data from LDAP while regular lookups connect to GC
* Wed Jan 29 2014 Jakub Hrozek - 1.11.2-34- Resolves: rhbz#877438 - sudoNotBefore/sudoNotAfter not supported by sssd sudoers plugin
* Fri Jan 24 2014 Daniel Mach - 1.11.2-33- Mass rebuild 2014-01-24
* Fri Jan 24 2014 Jakub Hrozek - 1.11.2-32- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn\'t match any configured idmap domain
* Fri Jan 24 2014 Jakub Hrozek - 1.11.2-31- Resolves: rhbz#1054899 - explicitly suggest krb5_auth_timeout in a loud DEBUG message in case Kerberos authentication times out
* Wed Jan 22 2014 Jakub Hrozek - 1.11.2-30- Resolves: rhbz#1037653 - Enabling ldap_id_mapping doesn\'t exclude uidNumber in filter
* Mon Jan 20 2014 Jakub Hrozek - 1.11.2-29- Resolves: rhbz#1051360 - [FJ7.0 Bug]: [REG] sssd_be crashes when ldap_search_base cannot be parsed.- Fix a typo in the man page- Related: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir
* Mon Jan 20 2014 Jakub Hrozek - 1.11.2-28- Resolves: rhbz#1054639 - sssd_be aborts a request if it doesn\'t match any configured idmap domain- Fix return value when searching for AD domain flat names- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\\user
* Wed Jan 15 2014 Jakub Hrozek - 1.11.2-27- Resolves: rhbz#1034920 - RHEL7 sssd not setting IPA AD trusted user homedir
* Wed Jan 15 2014 Jakub Hrozek - 1.11.2-26- Resolves: rhbz#1048102 - Access denied for users from gc domain when using format DOMAIN\\user
* Wed Jan 15 2014 Jakub Hrozek - 1.11.2-25- Resolves: rhbz#1053106 - sssd ad trusted sub domain do not inherit fallbacks and overrides settings
* Thu Jan 09 2014 Jakub Hrozek - 1.11.2-24- Resolves: rhbz#1051016 - FAST does not work in SSSD 1.11.2 in Fedora 20
* Thu Jan 09 2014 Jakub Hrozek - 1.11.2-23- Resolves: rhbz#1033133 - \"System Error\" when invalid ad_access_filter is used
* Thu Jan 09 2014 Jakub Hrozek - 1.11.2-22- Resolves: rhbz#1032983 - sssd_be crashes when ad_access_filter uses FOREST keyword.- Fix two memory leaks in the PAC responder (Related: rhbz#991065)
* Wed Jan 08 2014 Jakub Hrozek - 1.11.2-21- Resolves: rhbz#1048184 - Group lookup does not return member with multiple names after user lookup
* Wed Jan 08 2014 Jakub Hrozek - 1.11.2-20- Resolves: rhbz#1049533 - Group membership lookup issue
* Fri Dec 27 2013 Daniel Mach - 1.11.2-19- Mass rebuild 2013-12-27
* Thu Dec 19 2013 Jakub Hrozek - 1.11.2-18- Resolves: rhbz#894068 - sss_cache doesn\'t support subdomains
* Thu Dec 19 2013 Jakub Hrozek - 1.11.2-17- Re-initialize subdomains after provider startup- Related: rhbz#1038637 - If SSSD starts offline, subdomains list is never read
* Thu Dec 19 2013 Jakub Hrozek - 1.11.2-16- The AD provider is able to resolve group memberships for groups with Global and Universal scope- Related: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog
* Wed Dec 18 2013 Jakub Hrozek - 1.11.2-15- Resolves: rhbz#1033096 - tokenGroups do not work reliable with Global Catalog- Resolves: rhbz#1030483 - Individual group search returned multiple results in GC lookups
* Wed Dec 18 2013 Jakub Hrozek - 1.11.2-14- Resolves: rhbz#1040969 - sssd_nss grows memory footprint when netgroups are requested
* Thu Dec 12 2013 Jakub Hrozek - 1.11.2-13- Resolves: rhbz#1023409 - Valgrind sssd \"Syscall param socketcall.sendto(msg) points to uninitialised byte(s)\"
* Thu Dec 12 2013 Jakub Hrozek - 1.11.2-12- Resolves: rhbz#1037936 - sssd_be crashes occasionally
* Thu Dec 12 2013 Jakub Hrozek - 1.11.2-11- Resolves: rhbz#1038637 - If SSSD starts offline, subdomains list is never read
* Mon Dec 02 2013 Jakub Hrozek - 1.11.2-10- Resolves: rhbz#1029631 - sssd_be crashes on manually adding a cleartext password to ldap_default_authtok
* Mon Dec 02 2013 Jakub Hrozek - 1.11.2-9- Resolves: rhbz#1036758 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy
* Mon Dec 02 2013 Jakub Hrozek - 1.11.2-8- Resolves: rhbz#1034050 - Errors in domain log when saving user to sysdb
* Mon Dec 02 2013 Jakub Hrozek - 1.11.2-7- Resolves: rhbz#1036157 - sssd can\'t retrieve auto.master when using the \"default_domain_suffix\" option in
* Mon Dec 02 2013 Jakub Hrozek - 1.11.2-6- Resolves: rhbz#1028057 - Improve detection of the right domain when processing group with members from several domains
* Mon Dec 02 2013 Jakub Hrozek - 1.11.2-5- Resolves: rhbz#1033084 - sssd_be segfaults if empty grop is resolved using ad_matching_rule
* Mon Dec 02 2013 Jakub Hrozek - 1.11.2-4- Resolves: rhbz#1031562 - Incorrect mention of access_filter in sssd-ad manpage
* Mon Dec 02 2013 Jakub Hrozek - 1.11.2-3- Resolves: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes
* Mon Dec 02 2013 Jakub Hrozek - 1.11.2-2- Skip netgroups that don\'t provide well-formed triplets- Related: rhbz#991549 - sssd fails to retrieve netgroups with multiple CN attributes
* Wed Oct 30 2013 Jakub Hrozek - 1.11.2-1- New upstream release 1.11.2- Remove upstreamed patches- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Resolves: rhbz#991065
* Fri Sep 27 2013 Jakub Hrozek - 1.11.1-2- Resolves: rhbz#1019882 - RHEL7 ipa ad trusted user lookups failed with sssd_be crash- Resolves: rhbz#1002597 - ad: unable to resolve membership when user is from different domain than group
* Fri Sep 27 2013 Jakub Hrozek - 1.11.1-1- New upstream release 1.11.1- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Resolves: rhbz#991065 - Rebase SSSD to 1.11.0
* Thu Aug 29 2013 Jakub Hrozek - 1.11.0-1- New upstream release 1.11.0- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: rhbz#991065
* Fri Aug 02 2013 Jakub Hrozek - 1.11.0.1beta2- New upstream release 1.11 beta 2- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- Related: rhbz#991065
* Wed Jul 31 2013 Jakub Hrozek - 1.10.1-5- Resolves: #906427 - Do not use lib in specfile for the nss and pam libraries
* Wed Jul 31 2013 Jakub Hrozek - 1.10.1-4- Resolves: #983587 - sss_debuglevel did not increase verbosity in sssd_pac.log
* Wed Jul 31 2013 Jakub Hrozek - 1.10.1-3- Resolves: #983580 - Netgroups should ignore the \'use_fully_qualified_names\' setting
* Wed Jul 31 2013 Jakub Hrozek - 1.10.1-2- Apply several important fixes from upstream 1.10 branch- Related: #966757 - SSSD failover doesn\'t work if the first DNS server in resolv.conf is unavailable
* Thu Jul 18 2013 Jakub Hrozek - 1.10.1-1- New upstream release 1.10.1- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1
* Wed Jul 10 2013 Jakub Hrozek - 1.10.0-18- Remove libcmocka dependency
* Mon Jul 08 2013 Jakub Hrozek - 1.10.0-17- sssd-tools should require sssd-common, not sssd
* Tue Jul 02 2013 Stephen Gallagher - 1.10.0-16- Move sssd_pac to the sssd-ipa and sssd-ad subpackages- Trim out RHEL5-specific macros since we don\'t build on RHEL 5- Trim out macros for Fedora older than F18- Update libldb requirement to 1.1.16- Trim RPM changelog down to the last year
* Tue Jul 02 2013 Stephen Gallagher - 1.10.0-15- Move sssd_pac to the sssd-krb5 subpackage
* Mon Jul 01 2013 Stephen Gallagher - 1.10.0-14- Fix Obsoletes: to account for dist tag- Convert post and pre scripts to run on the sssd-common subpackage- Remove old conversion from SYSV
* Thu Jun 27 2013 Jakub Hrozek - 1.10.0-13- New upstream release 1.10- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0
* Mon Jun 17 2013 Dan HorĂ¡k - 1.10.0-12.beta2- the cmocka toolkit exists only on selected arches
* Sun Jun 16 2013 Jakub Hrozek - 1.10.0-11.beta2- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)
* Thu Jun 13 2013 Jakub Hrozek - 1.10.0-10.beta2- Only BuildRequire libcmocka on Fedora
* Thu Jun 13 2013 Jakub Hrozek - 1.10.0-9.beta2- Fix typo in Requires that prevented an upgrade (#973916)- Use a hardcoded version in Conflicts, not less-than-current
* Wed Jun 12 2013 Jakub Hrozek - 1.10.0-8.beta2- New upstream release 1.10 beta2- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2- BuildRequire libcmocka-devel in order to run all upstream tests during build- BuildRequire libnl3 instead of libnl1- No longer BuildRequire initscripts, we no longer use /sbin/service- Remove explicit krb5-libs >= 1.10 requires; this platform doensn\'t carry any older krb5-libs version
* Thu Jun 06 2013 Jakub Hrozek - 1.10.0-7.beta1- Enable hardened build for RHEL7
* Fri May 24 2013 Jakub Hrozek - 1.10.0-6.beta1- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later
* Tue May 14 2013 Jakub Hrozek - 1.10.0-5.beta1- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join- Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider- Resolves: rhbz#961251 - sssd does not create user\'s krb5 ccache dir/file parent directory when logging in
* Tue May 07 2013 Jakub Hrozek - 1.10.0-4.beta1- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs- Fix SSH integration with fully-qualified domains- Add the ability to dynamically discover the NetBIOS name
* Fri May 03 2013 Jakub Hrozek - 1.10.0-3.beta1- New upstream release 1.10 beta1- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1
* Wed Apr 17 2013 Jakub Hrozek - 1.10.0-2.alpha1- Add a patch to fix krb5 ccache creation issue with krb5 1.11
* Tue Apr 02 2013 Jakub Hrozek - 1.10.0-1.alpha1- New upstream release 1.10 alpha1- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1
* Fri Mar 01 2013 Stephen Gallagher - 1.9.4-9- Split internal helper libraries into a shared object- Significantly reduce disk-space usage
* Thu Feb 14 2013 Jakub Hrozek - 1.9.4-8- Fix the Kerberos password expiration warning (#912223)
* Thu Feb 14 2013 Jakub Hrozek - 1.9.4-7- Do not write out dots in the domain-realm mapping file (#905650)
* Mon Feb 11 2013 Jakub Hrozek - 1.9.4-6- Include upstream patch to build with krb5-1.11
* Thu Feb 07 2013 Jakub Hrozek - 1.9.4-5- Rebuild against new libldb
* Mon Feb 04 2013 Jakub Hrozek - 1.9.4-4- Fix build with new automake versions
* Wed Jan 30 2013 Jakub Hrozek - 1.9.4-3- Recreate Kerberos ccache directory if it\'s missing- Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist
* Tue Jan 29 2013 Jakub Hrozek - 1.9.4-2- Fix changelog dates to make F19 rpmbuild happy
* Mon Jan 28 2013 Jakub Hrozek - 1.9.4-1- New upstream release 1.9.4
* Thu Dec 06 2012 Jakub Hrozek - 1.9.3-1- New upstream release 1.9.3
* Tue Oct 30 2012 Jakub Hrozek - 1.9.2-5- Resolve groups from AD correctly
* Tue Oct 30 2012 Jakub Hrozek - 1.9.2-4- Check the validity of naming context
* Thu Oct 18 2012 Jakub Hrozek - 1.9.2-3- Move the sss_cache tool to the main package
* Sun Oct 14 2012 Jakub Hrozek - 1.9.2-2- Include the 1.9.2 tarball
* Sun Oct 14 2012 Jakub Hrozek - 1.9.2-1- New upstream release 1.9.2
* Sun Oct 07 2012 Jakub Hrozek - 1.9.1-1- New upstream release 1.9.1
* Wed Oct 03 2012 Jakub Hrozek - 1.9.0-24- require the latest libldb
* Tue Sep 25 2012 Jakub Hrozek - 1.9.0-24- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file
* Tue Sep 25 2012 Jakub Hrozek - 1.9.0-23- New upstream release 1.9.0
* Fri Sep 14 2012 Jakub Hrozek - 1.9.0-22.rc1- New upstream release 1.9.0 rc1
* Thu Sep 06 2012 Jakub Hrozek - 1.9.0-21.beta7- New upstream release 1.9.0 beta7- obsoletes patches #1-#3
* Mon Sep 03 2012 Jakub Hrozek - 1.9.0-20.beta6- Rebuild against libldb 1.12
* Tue Aug 28 2012 Jakub Hrozek - 1.9.0-19.beta6- Rebuild against libldb 1.11
* Fri Aug 24 2012 Jakub Hrozek - 1.9.0-18.beta6- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly- Resolves: rhbz#851304
* Mon Aug 20 2012 Jakub Hrozek - 1.9.0-17.beta6- Rebuild against libldb 1.10
* Fri Aug 17 2012 Jakub Hrozek - 1.9.0-16.beta6- Only create the SELinux login file if there are SELinux mappings on the IPA server
* Fri Aug 10 2012 Jakub Hrozek - 1.9.0-14.beta6- Don\'t discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)
* Thu Aug 02 2012 Jakub Hrozek - 1.9.0-13.beta6- New upstream release 1.9.0 beta 6- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6- A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value.- Fixes for the support for setting default SELinux user context from FreeIPA.- Fixed a regression introduced in beta 5 that broke LDAP SASL binds- The SSSD supports the concept of a Primary Server and a Back Up Server in failover- A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine- SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server.- Packaging changes to fix ldconfig usage in subpackages (#843995)- Rebuild against libldb 1.1.9
* Fri Jul 27 2012 Fedora Release Engineering - 1.9.0-13.beta5- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
* Thu Jul 19 2012 Jakub Hrozek - 1.9.0-12.beta5- New upstream release 1.9.0 beta 5- Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5- Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation- Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation- The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds
* Mon Jul 16 2012 Stephen Gallagher - 1.9.0-11.beta4- Fix broken ARM build- Add missing DP_OPTION_TERMINATOR in AD provider options
* Wed Jul 11 2012 Jakub Hrozek - 1.9.0-10.beta4- Own several directories create during make install (#839782)
* Wed Jul 11 2012 Jakub Hrozek - 1.9.0-9.beta4- New upstream release 1.9.0 beta 4- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4- Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers- SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules- The IPA authentication provider now supports subdomains- Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.
* Mon Jun 25 2012 Stephen Gallagher - 1.9.0-8.beta3- New upstream release 1.9.0 beta 3- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3- Add a new PAC responder for dealing with cross-realm Kerberos trusts- Terminate idle connections to the NSS and PAM responders
* Wed Jun 20 2012 Stephen Gallagher - 1.9.0-7.beta2- Switch unicode library from libunistring to Glib- Drop unnecessary explicit Requires on keyutils- Guarantee that versioned Requires include the correct architecture
* Mon Jun 18 2012 Stephen Gallagher - 1.9.0-6.beta2- Fix accidental disabling of the DIR cache support
* Fri Jun 15 2012 Stephen Gallagher - 1.9.0-5.beta2- New upstream release 1.9.0 beta 2- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2- Add support for the Kerberos DIR cache for storing multiple TGTs automatically- Major performance enhancement when storing large groups in the cache- Major performance enhancement when performing initgroups() against Active Directory- SSSDConfig data file default locations can now be set during configure for easier packaging
* Tue May 29 2012 Stephen Gallagher - 1.9.0-4.beta1- Fix regression in endianness patch
* Tue May 29 2012 Stephen Gallagher - 1.9.0-3.beta1- Rebuild SSSD against ding-libs 0.3.0beta1- Fix endianness bug in service map protocol
* Thu May 24 2012 Stephen Gallagher - 1.9.0-2.beta1- Fix several regressions since 1.5.x- Ensure that the RPM creates the /var/lib/sss/mc directory- Add support for Netscape password warning expiration control- Rebuild against libldb 1.1.6
* Fri May 11 2012 Stephen Gallagher - 1.9.0-1.beta1- New upstream release 1.9.0 beta 1- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1- Add native support for autofs to the IPA provider- Support for ID-mapping when connecting to Active Directory- Support for handling very large (> 1500 users) groups in Active Directory- Support for sub-domains (will be used for dealing with trust relationships)- Add a new fast in-memory cache to speed up lookups of cached data on repeated requests
* Thu May 03 2012 Stephen Gallagher - 1.8.3-11- New upstream release 1.8.3- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3- Numerous manpage and translation updates- LDAP: Handle situations where the RootDSE isn\'t available anonymously- LDAP: Fix regression for users using non-standard LDAP attributes for user information
* Mon Apr 09 2012 Stephen Gallagher - 1.8.2-10- New upstream release 1.8.2- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2- Several fixes to case-insensitive domain functions- Fix for GSSAPI binds when the keytab contains unrelated principals- Fixed several segfaults- Workarounds added for LDAP servers with unreadable RootDSE- SSH knownhostproxy will no longer enter an infinite loop preventing login- The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown- Assorted minor fixes for issues discovered by static analysis tools
* Mon Mar 26 2012 Stephen Gallagher - 1.8.1-9- Don\'t duplicate libsss_autofs.so in two packages- Set explicit package contents instead of globbing
* Wed Mar 21 2012 Stephen Gallagher - 1.8.1-8- Fix uninitialized value bug causing crashes throughout the code- Resolves: rhbz#804783 - [abrt] Segfault during LDAP \'services\' lookup
* Mon Mar 12 2012 Stephen Gallagher - 1.8.1-7- New upstream release 1.8.1- Resolve issue where we could enter an infinite loop trying to connect to an auth server- Fix serious issue with complex (3+ levels) nested groups- Fix netgroup support for case-insensitivity and aliases- Fix serious issue with lookup bundling resulting in requests never completing- IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate- Fix several regressions in the proxy provider- Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD- Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn\'t work
* Tue Feb 28 2012 Stephen Gallagher - 1.8.0-6- New upstream release 1.8.0- Support for the service map in NSS- Support for setting default SELinux user context from FreeIPA- Support for retrieving SSH user and host keys from LDAP (Experimental)- Support for caching autofs LDAP requests (Experimental)- Support for caching SUDO rules (Experimental)- Include the IPA AutoFS provider- Fixed several memory-corruption bugs- Fixed a regression in group enumeration since 1.7.0- Fixed a regression in the proxy provider- Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD- Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login- Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV)- Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc
* Wed Feb 22 2012 Stephen Gallagher - 1.8.0-5.beta3- Change default kerberos credential cache location to /run/user/
* Wed Feb 15 2012 Stephen Gallagher - 1.8.0-4.beta3- New upstream release 1.8.0 beta 3- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3- Fixed a regression in group enumeration since 1.7.0- Fixed several memory-corruption bugs- Finalized the ABI for the autofs support- Fixed a regression in the proxy provider
* Fri Feb 10 2012 Petr Pisar - 1.8.0-3.beta2- Rebuild against PCRE 8.30
* Mon Feb 06 2012 Stephen Gallagher - 1.8.0-1.beta2- New upstream release- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2- Fix two minor manpage bugs- Include the IPA AutoFS provider
* Mon Feb 06 2012 Stephen Gallagher - 1.8.0-1.beta1- New upstream release- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1- Support for the service map in NSS- Support for setting default SELinux user context from FreeIPA- Support for retrieving SSH user and host keys from LDAP (Experimental)- Support for caching autofs LDAP requests (Experimental)- Support for caching SUDO rules (Experimental)
* Wed Feb 01 2012 Stephen Gallagher - 1.7.0-5- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well
* Wed Feb 01 2012 Stephen Gallagher - 1.7.0-4- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.
* Wed Feb 01 2012 Stephen Gallagher - 1.7.0-3- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features
* Sat Jan 14 2012 Fedora Release Engineering - 1.7.0-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
* Thu Dec 22 2011 Stephen Gallagher - 1.7.0-1- New upstream release 1.7.0- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0- Support for case-insensitive domains- Support for multiple search bases in the LDAP provider- Support for the native FreeIPA netgroup implementation- Reliability improvements to the process monitor- New DEBUG facility with more consistent log levels- New tool to change debug log levels without restarting SSSD- SSSD will now disconnect from LDAP server when idle- FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains- Assorted performance improvements in the LDAP provider
* Mon Dec 19 2011 Stephen Gallagher - 1.6.4-1- New upstream release 1.6.4- Rolls up previous patches applied to the 1.6.3 tarball- Fixes a rare issue causing crashes in the failover logic- Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.
* Wed Dec 07 2011 Stephen Gallagher - 1.6.3-5- Rebuild against libldb 1.1.4
* Tue Nov 29 2011 Stephen Gallagher - 1.6.3-4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam()- Resolves: rhbz#758425 - LDAP failover not working if server refuses connections
* Thu Nov 24 2011 Jakub Hrozek - 1.6.3-3- Rebuild for libldb 1.1.3
* Thu Nov 10 2011 Stephen Gallagher - 1.6.3-2- Resolves: rhbz#752495 - Crash when apply settings
* Fri Nov 04 2011 Stephen Gallagher - 1.6.3-1- New upstream release 1.6.3- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3- Fixes a major cache performance issue introduced in 1.6.2- Fixes a potential infinite-loop with certain LDAP layouts
* Wed Oct 26 2011 Fedora Release Engineering - 1.6.2-5- Rebuilt for glibc bug#747377
* Sun Oct 23 2011 Stephen Gallagher - 1.6.2-4- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.
* Fri Oct 21 2011 Stephen Gallagher - 1.6.2-3- Add explicit requirement on selinux-policy version to address new SBUS symlinks.
* Wed Oct 19 2011 Stephen Gallagher - 1.6.2-2- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.
* Tue Oct 18 2011 Stephen Gallagher - 1.6.2-1- Improved handling of users and groups with multi-valued name attributes (aliases)- Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing- Improved process-hang detection and restarting- Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries)- Cleaned up the example configuration- New tool to change debug level on the fly
* Mon Aug 29 2011 Stephen Gallagher - 1.6.1-1- New upstream release 1.6.1- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1- Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep)- SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined- The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided.- Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory)- Three HBAC regressions have been fixed.- Fix for an infinite loop in the deref code
* Wed Aug 03 2011 Stephen Gallagher - 1.6.0-2- Build with _hardened_build macro
* Wed Aug 03 2011 Stephen Gallagher - 1.6.0-1- New upstream release 1.6.0- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0- Add host access control support for LDAP (similar to pam_host_attr)- Finer-grained control on principals used with Kerberos (such as for FAST or- validation)- Added a new tool sss_cache to allow selective expiring of cached entries- Added support for LDAP DEREF and ASQ controls- Added access control features for Novell Directory Server- FreeIPA dynamic DNS update now checks first to see if an update is needed- Complete rewrite of the HBAC library- New libraries: libipa_hbac and libipa_hbac-python
* Tue Jul 05 2011 Stephen Gallagher - 1.5.11-2- New upstream release 1.5.11- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11- Fix a serious regression that prevented SSSD from working with ldaps:// URIs- IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6- address being saved to the AAAA record
* Fri Jul 01 2011 Stephen Gallagher - 1.5.10-1- New upstream release 1.5.10- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10- Fixed a regression introduced in 1.5.9 that could result in blocking calls- to LDAP
* Thu Jun 30 2011 Stephen Gallagher - 1.5.9-1- New upstream release 1.5.9- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9- Support for overriding home directory, shell and primary GID locally- Properly honor TTL values from SRV record lookups- Support non-POSIX groups in nested group chains (for RFC2307bis LDAP- servers)- Properly escape IPv6 addresses in the failover code- Do not crash if inotify fails (e.g. resource exhaustion)- Don\'t add multiple TGT renewal callbacks (too many log messages)
* Fri May 27 2011 Stephen Gallagher - 1.5.8-1- New upstream release 1.5.8- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8- Support for the LDAP paging control- Support for multiple DNS servers for name resolution- Fixes for several group membership bugs- Fixes for rare crash bugs
* Mon May 23 2011 Stephen Gallagher - 1.5.7-3- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d- Make sure to properly convert to systemd if upgrading from newer- updates for Fedora 14
* Mon May 02 2011 Stephen Gallagher - 1.5.7-2- Fix segfault in TGT renewal
* Fri Apr 29 2011 Stephen Gallagher - 1.5.7-1- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites- cached password with predicatable filename
* Wed Apr 20 2011 Stephen Gallagher - 1.5.6.1-1- Re-add manpage translations
* Wed Apr 20 2011 Stephen Gallagher - 1.5.6-1- New upstream release 1.5.6- https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6- Fixed a serious memory leak in the memberOf plugin- Fixed a regression with the negative cache that caused it to be essentially- nonfunctional- Fixed an issue where the user\'s full name would sometimes be removed from- the cache- Fixed an issue with password changes in the kerberos provider not working- with kpasswd
* Wed Apr 20 2011 Stephen Gallagher - 1.5.5-5- Resolves: rhbz#697057 - kpasswd fails when using sssd and- kadmin server != kdc server- Upgrades from SysV should now maintain enabled/disabled status
* Mon Apr 18 2011 Stephen Gallagher - 1.5.5-4- Fix %postun