Changelog for
freeipa-client-4.6.1-8.65.x86_64.rpm :
* Tue Oct 17 2017 Rob Crittenden
- 4.6.1-3- Update workaround patch to prevent SELinux execmem AVC (#1491508)
* Mon Oct 16 2017 Alexander Bokovoy - 4.6.1-2- Another attempt at fix for bug #1491053
* Fri Sep 22 2017 Tomas Krizek - 4.6.1-1- Fixes #1491053 Firefox reports insecure TLS configuration when visiting FreeIPA web UI after standard server deployment
* Wed Sep 13 2017 Adam Williamson - 4.6.0-3- Fixes #1490762 Ipa-server-install update dse.ldif with wrong SELinux context- Fixes #1491056 FreeIPA enrolment via kickstart fails
* Wed Sep 06 2017 Adam Williamson - 4.6.0-2- Fixes #1488640 \"unknown command \'undefined\'\" error when changing password in web UI- BuildRequires diffstat (for the use in patch application)
* Mon Sep 04 2017 Tomas Krizek - 4.6.0-1- Rebase to upstream 4.6.0
* Wed Aug 02 2017 Fedora Release Engineering - 4.5.3-3- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
* Wed Jul 26 2017 Fedora Release Engineering - 4.5.3-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Fri Jul 21 2017 Tomas Krizek - 4.5.3-1- Update to upstream 4.5.3 - see https://www.freeipa.org/page/Releases/4.5.3
* Thu Jul 13 2017 Alexander Bokovoy - 4.5.2-4- Make sure tmpfiles.d snippet for replica is in place after install
* Mon Jul 10 2017 Alexander Bokovoy - 4.5.2-3- Fix build with Samba 4.7.0-RC1- Increase java stack for rhino calls to get around crashes on ppc64-le
* Tue Jun 20 2017 Tomas Krizek - 4.5.2-2- Patch: Fix IP address checks- Patch: python-netifaces fix
* Sun Jun 18 2017 Tomas Krizek - 4.5.2-1- Update to upstream 4.5.2 - see https://www.freeipa.org/page/Releases/4.5.2
* Thu May 25 2017 Tomas Krizek - 4.5.1-1- Update to upstream 4.5.1 - see https://www.freeipa.org/page/Releases/4.5.1- Fixes #1168266 UI drops \"Enknown Error\" when the ipa record in /etc/hosts changes
* Tue May 23 2017 Tomas Krizek - 4.4.4-2- Fixes #1448049 Subpackage freeipa-server-common has unmet dependencies on Rawhide- Fixes #1430247 FreeIPA server deployment runs ipa-custodia on Python 3, should use Python 2- Fixes #1446744 python2-ipaclient subpackage does not own /usr/lib/python2.7/site-packages/ipaclient/plugins- Fixes #1440525 surplus \'the\' in output of `ipa-adtrust-install`- Fixes #1411810 ipa-replica-install fails with 406 Client Error- Fixes #1405814 ipa plugins: ERROR an internal error occured
* Fri Mar 24 2017 Tomas Krizek - 4.4.4-1- Update to upstream 4.4.4 - see https://www.freeipa.org/page/Releases/4.4.4- Add upstream signature file for tarball
* Wed Mar 01 2017 Alexander Bokovoy - 4.4.3-8- Use different method to keep /usr/bin/ipa on Python 2- Fixes #1426847
* Mon Feb 27 2017 Tomas Krizek - 4.4.3-7- Fixes #1413137 CVE-2017-2590 ipa: Insufficient permission check for ca-del, ca-disable and ca-enable commands
* Mon Feb 27 2017 Alexander Bokovoy - 4.4.3-6- Rebuild to pick up system-python dependency change- Fixes #1426847 - Cannot upgrade freeipa-client on rawhide
* Wed Feb 15 2017 Tomas Krizek - 4.4.3-5- Fixes #1403352 - bind-dyndb-ldap: support new named.conf API in BIND 9.11- Fixes #1412739 - ipa-kdb: support DAL version 6.1
* Fri Feb 10 2017 Fedora Release Engineering - 4.4.3-4- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
* Sat Jan 21 2017 Igor Gnatenko - 4.4.3-3- Rebuild for xmlrpc-c
* Thu Dec 22 2016 Miro Hrončok - 4.4.3-2- Rebuild for Python 3.6
* Fri Dec 16 2016 Pavel Vomacka - 4.4.3-1- Update to upstream 4.4.3 - see http://www.freeipa.org/page/Releases/4.4.3
* Wed Dec 14 2016 Pavel Vomacka - 4.4.2-4- Fixes 1395311 - CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod- Fixes 1370493 - CVE-2016-7030 ipa: DoS attack against kerberized services by abusing password policy
* Tue Nov 29 2016 Petr Vobornik - 4.4.2-3- Fixes 1389866 krb5-server: ipadb_change_pwd(): kdb5_util killed by SIGSEGV
* Fri Oct 21 2016 Petr Vobornik - 4.4.2-2- Rebuild against krb5-1.15
* Thu Oct 13 2016 Petr Vobornik - 4.4.2-1- Update to upstream 4.4.2 - see http://www.freeipa.org/page/Releases/4.4.2
* Thu Sep 01 2016 Alexander Bokovoy - 4.4.1-1- Update to upstream 4.4.1 - see http://www.freeipa.org/page/Releases/4.4.1
* Fri Aug 19 2016 Petr Vobornik - 4.3.2-2- Fixes 1365669 - The ipa-server-upgrade command failed when named-pkcs11 does not happen to run during dnf upgrade- Fixes 1367883 - CVE-2016-5404 freeipa: ipa: Insufficient privileges check in certificate revocation- Fixes 1364338 - Freeipa cannot be build on fedora 25
* Fri Jul 22 2016 Petr Vobornik - 4.3.2-1- Update to upstream 4.3.2 - see http://www.freeipa.org/page/Releases/4.3.2
* Tue Jul 19 2016 Fedora Release Engineering - 4.3.1-2- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages
* Thu Mar 24 2016 Petr Vobornik - 4.3.1-1- Update to upstream 4.3.1 - see http://www.freeipa.org/page/Releases/4.3.1
* Thu Feb 04 2016 Petr Vobornik - 4.3.0-3- Fix build with Samba 4.4- Update SELinux requires to fix connection check during installation
* Wed Feb 03 2016 Fedora Release Engineering - 4.3.0-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
* Fri Dec 18 2015 Petr Vobornik - 4.3.0-1- Update to upstream 4.3.0 - see http://www.freeipa.org/page/Releases/4.3.0
* Mon Dec 07 2015 Petr Vobornik - 4.2.3-2- Workarounds for SELinux execmem violations in cryptography
* Mon Nov 02 2015 Petr Vobornik - 4.2.3-1- Update to upstream 4.2.3 - see http://www.freeipa.org/page/Releases/4.2.3- fix #1274905
* Wed Oct 21 2015 Alexander Bokovoy - 4.2.2-2- Depend on samba-common-tools for the trust-ad subpackage after samba package split- Rebuild against krb5 1.14 to fix bug #1273957
* Thu Oct 08 2015 Petr Vobornik - 4.2.2-1- Update to upstream 4.2.2 - see http://www.freeipa.org/page/Releases/4.2.2
* Mon Sep 07 2015 Petr Vobornik - 4.2.1-1- Update to upstream 4.2.1 - see http://www.freeipa.org/page/Releases/4.2.1
* Wed Jun 17 2015 Fedora Release Engineering - 4.1.4-5- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
* Tue May 12 2015 Alexander Bokovoy - 4.1.4-4- Fix typo in the patch to fix bug #1219834
* Mon May 11 2015 Alexander Bokovoy - 4.1.4-3- Fix FreeIPA trusts to AD feature with Samba 4.2 (#1219834)
* Mon Mar 30 2015 Petr Vobornik - 4.1.4-2- Replace mod_auth_kerb usage with mod_auth_gssapi
* Thu Mar 26 2015 Alexander Bokovoy - 4.1.4-1- Update to upstream 4.1.4 - see http://www.freeipa.org/page/Releases/4.1.4- fix CVE-2015-1827 (#1206047)- Require slapi-nis 0.54.2 and newer for CVE-2015-0283 fixes
* Tue Mar 17 2015 Petr Vobornik - 4.1.3-3- Timeout ipa-client install if ntp server is unreachable #4842- Skip time sync during client install when using --no-ntp #4842
* Wed Mar 04 2015 Petr Vobornik - 4.1.3-2- Add missing sssd python dependencies- https://bugzilla.redhat.com/show_bug.cgi?id=1197218
* Wed Feb 18 2015 Petr Vobornik - 4.1.3-1- Update to upstream 4.1.3 - see http://www.freeipa.org/page/Releases/4.1.3
* Mon Jan 19 2015 Alexander Bokovoy - 4.1.2-2- Fix broken build after Samba ABI change and rename of libpdb to libsamba-passdb- Use python-dateutil15 until we validate python-dateutil 2.x
* Tue Nov 25 2014 Petr Vobornik - 4.1.2-1- Update to upstream 4.1.2 - see http://www.freeipa.org/page/Releases/4.1.2- fix CVE-2014-7850
* Thu Nov 20 2014 Simo Sorce - 4.1.1-2- Patch blokers and feature freze exceptions- Resolves: bz1165674- Resolves: bz1165856 (CVE-2014-7850)- Fixes DNS install issue that prevents the server from working
* Thu Nov 06 2014 Petr Vobornik - 4.1.1-1- Update to upstream 4.1.1 - see http://www.freeipa.org/page/Releases/4.1.1- fix CVE-2014-7828
* Wed Oct 22 2014 Petr Vobornik - 4.1.0-2- fix armv7hl stack oversize build failure- fix https://fedorahosted.org/freeipa/ticket/4660
* Tue Oct 21 2014 Petr Vobornik - 4.1.0-1- Update to upstream 4.1.0 - see http://www.freeipa.org/page/Releases/4.1.0
* Fri Sep 12 2014 Petr Viktorin - 4.0.3-1- Update to upstream 4.0.3 - see http://www.freeipa.org/page/Releases/4.0.3
* Fri Sep 05 2014 Petr Viktorin - 4.0.2-1- Update to upstream 4.0.1 - see http://www.freeipa.org/page/Releases/4.0.2
* Tue Sep 02 2014 Pádraig Brady - 4.0.1-3- rebuild for libunistring soname bump
* Sat Aug 16 2014 Fedora Release Engineering - 4.0.1-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
* Fri Jul 25 2014 Martin Kosek 4.0.1-1- Update to upstream 4.0.1
* Mon Jul 07 2014 Petr Viktorin 4.0.0-1- Update to upstream 4.0.0- Remove the server-strict package
* Sat Jun 07 2014 Fedora Release Engineering - 3.3.5-4- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Wed May 21 2014 Petr Vobornik 3.3.5-3- Increase Java stack size for Web UI build on aarch64
* Wed Apr 16 2014 Peter Robinson 3.3.5-2- Add rhino as dependency to fix FTBFS
* Fri Mar 28 2014 Martin Kosek - 3.3.5-1- Update to upstream 3.3.5
* Tue Feb 11 2014 Martin Kosek - 3.3.4-3- Move ipa-otpd socket directory to /var/run/krb5kdc- Require krb5-server 1.11.5-3 supporting the new directory- ipa_lockout plugin did not work with users\'s without krbPwdPolicyReference
* Wed Jan 29 2014 Martin Kosek - 3.3.4-2- Fix hardened build
* Tue Jan 28 2014 Martin Kosek - 3.3.4-1- Update to upstream 3.3.4- Install CA anchor into standard location (#928478)- ipa-client-install part of ipa-server-install fails on reinstall (#1044994)- Remove mod_ssl workaround (RHEL bug #1029046)- Enable syncrepl plugin to support bind-dyndb-ldap 4.0
* Fri Jan 03 2014 Martin Kosek - 3.3.3-5- Build crashed with rhino exception on s390 architectures (#1040576)
* Thu Dec 12 2013 Martin Kosek - 3.3.3-4- Build crashed with rhino exception on PPC architectures (#1040576)
* Tue Dec 03 2013 Martin Kosek - 3.3.3-3- Fix -Werror=format-security errors (#1037070)
* Mon Nov 04 2013 Martin Kosek - 3.3.3-2- ipa-server-install crashed when freeipa-server-trust-ad subpackage was not installed
* Fri Nov 01 2013 Martin Kosek - 3.3.3-1- Update to upstream 3.3.3
* Fri Oct 04 2013 Martin Kosek - 3.3.2-1- Update to upstream 3.3.2
* Thu Aug 29 2013 Petr Viktorin - 3.3.1-1- Bring back Fedora-only changes
* Thu Aug 29 2013 Petr Viktorin - 3.3.1-0- Update to upstream 3.3.1
* Wed Aug 14 2013 Alexander Bokovoy - 3.3.0-2- Remove freeipa-systemd-upgrade as non-systemd installs are not supported anymore by Fedora project
* Wed Aug 07 2013 Martin Kosek - 3.3.0-1- Update to upstream 3.3.0
* Sat Aug 03 2013 Fedora Release Engineering - 3.2.2-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild
* Wed Jul 17 2013 Martin Kosek - 3.2.2-1- Update to upstream 3.2.2- Drop freeipa-server-selinux subpackage- Drop redundant directory /var/cache/ipa/sessions- Do not create /var/lib/ipa/pki-ca/publish, retain reference as ghost- Run ipa-upgradeconfig and server restart in posttrans to avoid inconsistency issues when there are still old parts of software (like entitlements plugin)
* Fri Jun 07 2013 Martin Kosek - 3.2.1-1- Update to upstream 3.2.1
* Tue May 14 2013 Rob Crittenden - 3.2.0-2- Add OTP patches- Add patch to set KRB5CCNAME for 389-ds-base
* Fri May 10 2013 Rob Crittenden - 3.2.0-1- Update to upstream 3.2.0 GA- ipa-client-install fails if /etc/ipa does not exist (#961483)- Certificate status is not visible in Service and Host page (#956718)- ipa-client-install removes needed options from ldap.conf (#953991)- Handle socket.gethostbyaddr() exceptions when verifying hostnames (#953957)- Add triggerin scriptlet to support OpenSSH 6.2 (#953617)- Require nss 3.14.3-12.0 to address certutil certificate import errors (#953485)- Require pki-ca 10.0.2-3 to pull in fix for sslget and mixed IPv4/6 environments. (#953464)- ipa-client-install removes \'sss\' from /etc/nsswitch.conf (#953453)- ipa-server-install --uninstall doesn\'t stop dirsrv instances (#953432)- Add requires for openldap-2.4.35-4 to pickup fixed SASL_NOCANON behavior for socket based connections (#960222)- Require libsss_nss_idmap-python- Add Conflicts on nss-pam-ldapd < 0.8.4. The mapping from uniqueMember to member is now done automatically and having it in the config file raises an error.- Add backup and restore tools, directory.- require at least systemd 38 which provides the journal (we no longer need to require syslog.target)- Update Requires on policycoreutils to 2.1.14-37- Update Requires on selinux-policy to 3.12.1-42- Update Requires on 389-ds-base to 1.3.1.0- Remove a Requires for java-atk-wrapper
* Tue Apr 23 2013 Rob Crittenden - 3.2.0-0.4.beta1- Remove release from krb5-server in strict sub-package to allow for rebuilds.
* Mon Apr 22 2013 Rob Crittenden - 3.2.0-0.3.beta1- Add a Requires for java-atk-wrapper until we can determine which package should be pulling it in, dogtag or tomcat.
* Tue Apr 16 2013 Rob Crittenden - 3.2.0-0.2.beta1- Update to upstream 3.2.0 Beta 1
* Tue Apr 02 2013 Martin Kosek - 3.2.0-0.1.pre1- Update to upstream 3.2.0 Prerelease 1- Use upstream reference spec file as a base for Fedora spec file
* Sat Mar 30 2013 Kevin Fenzi 3.1.2-4- Rebuild for broken deps- Fix 389-ds-base strict dep to be 1.3.0.5 and krb5-server 1.11.1
* Sat Feb 23 2013 Kevin Fenzi - 3.1.2-3- Rebuild for broken deps in rawhide- Fix 389-ds-base strict dep to be 1.3.0.3
* Wed Feb 13 2013 Fedora Release Engineering - 3.1.2-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
* Wed Jan 23 2013 Rob Crittenden - 3.1.2-1- Update to upstream 3.1.2- CVE-2012-4546: Incorrect CRLs publishing- CVE-2012-5484: MITM Attack during Join process- CVE-2013-0199: Cross-Realm Trust key leak- Updated strict dependencies to 389-ds-base = 1.3.0.2 and pki-ca = 10.0.1
* Thu Dec 20 2012 Martin Kosek - 3.1.0-2- Remove redundat Requires versions that are already in Fedora 17- Replace python-crypto Requires with m2crypto- Add missing Requires(post) for client and server-trust-ad subpackages- Restart httpd service when server-trust-ad subpackage is installed- Bump selinux-policy Requires to pick up PKI/LDAP port labeling fixes
* Mon Dec 10 2012 Rob Crittenden - 3.1.0-1- Updated to upstream 3.1.0 GA- Set minimum for sssd to 1.9.2- Set minimum for pki-ca to 10.0.0-1- Set minimum for 389-ds-base to 1.3.0- Set minimum for selinux-policy to 3.11.1-60- Remove unneeded dogtag package requires
* Tue Oct 23 2012 Martin Kosek - 3.0.0-3- Update Requires on krb5-server to 1.11
* Fri Oct 12 2012 Rob Crittenden - 3.0.0-2- Configure CA replication to use TLS instead of SSL
* Fri Oct 12 2012 Rob Crittenden - 3.0.0-1- Updated to upstream 3.0.0 GA- Set minimum for samba to 4.0.0-153.- Make sure server-trust-ad subpackage alternates winbind_krb5_locator.so plugin to /dev/null since they cannot be used when trusts are configured- Restrict krb5-server to 1.10.- Update BR for 389-ds-base to 1.3.0- Add directory /var/lib/ipa/pki-ca/publish for CRL published by pki-ca- Add Requires on zip for generating FF browser extension
* Fri Oct 05 2012 Rob Crittenden - 3.0.0-0.10- Updated to upstream 3.0.0 rc 2- Include new FF configuration extension- Set minimum Requires of selinux-policy to 3.11.1-33- Set minimum Requires dogtag to 10.0.0-0.43.b1- Add new optional strict sub-package to allow users to limit other package upgrades.
* Tue Oct 02 2012 Martin Kosek - 3.0.0-0.9- Require samba packages instead of obsoleted samba4 packages
* Fri Sep 21 2012 Rob Crittenden - 3.0.0-0.8- Updated to upstream 3.0.0 rc 1- Update BR for 389-ds-base to 1.2.11.14- Update BR for krb5 to 1.10- Update BR for samba4-devel to 4.0.0-139 (rc1)- Add BR for python-polib- Update BR and Requires on sssd to 1.9.0- Update Requires on policycoreutils to 2.1.12-5- Update Requires on 389-ds-base to 1.2.11.14- Update Requires on selinux-policy to 3.11.1-21- Update Requires on dogtag to 10.0.0-0.33.a1- Update Requires on certmonger to 0.60- Update Requires on tomcat to 7.0.29- Update minimum version of bind to 9.9.1-10.P3- Update minimum version of bind-dyndb-ldap to 1.1.0-0.16.rc1- Remove Requires on authconfig from python sub-package
* Wed Sep 05 2012 Rob Crittenden - 3.0.0-0.7- Rebuild against samba4 beta8
* Fri Aug 31 2012 Rob Crittenden - 3.0.0-0.6- Rebuild against samba4 beta7
* Wed Aug 22 2012 Alexander Bokovoy - 3.0.0-0.5- Adopt to samba4 beta6 (libsecurity -> libsamba-security)- Add dependency to samba4-winbind
* Fri Aug 17 2012 Rob Crittenden - 3.0.0-0.4- Updated to upstream 3.0.0 beta 2
* Mon Aug 06 2012 Martin Kosek - 3.0.0-0.3- Updated to current upstream state of 3.0.0 beta 2 development
* Mon Jul 23 2012 Alexander Bokovoy - 3.0.0-0.2- Rebuild against samba4 beta4
* Mon Jul 02 2012 Rob Crittenden - 3.0.0-0.1- Updated to upstream 3.0.0 beta 1
* Thu May 03 2012 Rob Crittenden - 2.2.0-1- Updated to upstream 2.2.0 GA- Update minimum n-v-r of certmonger to 0.53- Update minimum n-v-r of slapi-nis to 0.40- Add Requires in client to oddjob-mkhomedir and python-krbV- Update minimum selinux-policy to 3.10.0-110
* Mon Mar 19 2012 Rob Crittenden - 2.1.90-0.2- Update to upstream 2.2.0 beta 1 (2.1.90.rc1)- Set minimum n-v-r for pki-ca and pki-silent to 9.0.18.- Add Conflicts on mod_ssl- Update minimum n-v-r of 389-ds-base to 1.2.10.4- Update minimum n-v-r of sssd to 1.8.0- Update minimum n-v-r of slapi-nis to 0.38- Update minimum n-v-r of pki-
* to 9.0.18- Update conflicts on bind-dyndb-ldap to < 1.1.0-0.9.b1- Update conflicts on bind to < 9.9.0-1- Drop requires on krb5-server-ldap- Add patch to remove escaping arguments to pkisilent
* Mon Feb 06 2012 Rob Crittenden - 2.1.90-0.1- Update to upstream 2.2.0 alpha 1 (2.1.90.pre1)
* Wed Feb 01 2012 Alexander Bokovoy - 2.1.4-5- Force to use 389-ds 1.2.10-0.8.a7 or above- Improve upgrade script to handle systemd 389-ds change- Fix freeipa to work with python-ldap 2.4.6
* Wed Jan 11 2012 Martin Kosek - 2.1.4-4- Fix ipa-replica-install crashes- Fix ipa-server-install and ipa-dns-install logging- Set minimum version of pki-ca to 9.0.17 to fix sslget problem caused by FEDORA-2011-17400 update (#771357)
* Wed Dec 21 2011 Alexander Bokovoy - 2.1.4-3- Allow Web-based migration to work with tightened SE Linux policy (#769440)- Rebuild slapi plugins against re-enterant version of libldap
* Sun Dec 11 2011 Alexander Bokovoy - 2.1.4-2- Allow longer dirsrv startup with systemd: - IPAdmin class will wait until dirsrv instance is available up to 10 seconds - Helps with restarts during upgrade for ipa-ldap-updater- Fix pylint warnings from F16 and Rawhide
* Tue Dec 06 2011 Rob Crittenden - 2.1.4-1- Update to upstream 2.1.4 (CVE-2011-3636)
* Mon Dec 05 2011 Rob Crittenden - 2.1.3-8- Update SELinux policy to allow ipa_kpasswd to connect ldap and read /dev/urandom. (#759679)
* Wed Nov 30 2011 Alexander Bokovoy - 2.1.3-7- Fix wrong path in packaging freeipa-systemd-upgrade
* Wed Nov 30 2011 Alexander Bokovoy - 2.1.3-6- Introduce upgrade script to recover existing configuration after systemd migration as user has no means to recover FreeIPA from systemd migration- Upgrade script: - recovers symlinks in Dogtag instance install - recovers systemd configuration for FreeIPA\'s directory server instances - recovers freeipa.service - migrates directory server and KDC configs to use proper keytabs for systemd services
* Wed Oct 26 2011 Fedora Release Engineering - 2.1.3-5- Rebuilt for glibc bug#747377
* Wed Oct 19 2011 Alexander Bokovoy - 2.1.3-4- clean up spec- Depend on sssd >= 1.6.2 for better user experience
* Tue Oct 18 2011 Alexander Bokovoy - 2.1.3-3- Fix Fedora package changelog after merging systemd changes
* Tue Oct 18 2011 Alexander Bokovoy - 2.1.3-2- Fix postin scriplet for F-15/F-16
* Tue Oct 18 2011 Alexander Bokovoy - 2.1.3-1- 2.1.3
* Mon Oct 17 2011 Alexander Bokovoy - 2.1.2-1- Default to systemd for Fedora 16 and onwards
* Tue Aug 16 2011 Rob Crittenden - 2.1.0-1- Update to upstream 2.1.0
* Fri May 06 2011 Simo Sorce - 2.0.1-2- Fix bug #702633
* Mon May 02 2011 Rob Crittenden - 2.0.1-1- Update minimum selinux-policy to 3.9.16-18- Update minimum pki-ca and pki-selinux to 9.0.7- Update minimum 389-ds-base to 1.2.8.0-1- Update to upstream 2.0.1
* Thu Mar 24 2011 Rob Crittenden - 2.0.0-1- Update to upstream GA release- Automatically apply updates when the package is upgraded
* Fri Feb 25 2011 Rob Crittenden - 2.0.0-0.4.rc2- Update to upstream freeipa-2.0.0.rc2- Set minimum version of python-nss to 0.11 to make sure IPv6 support is in- Set minimum version of sssd to 1.5.1- Patch to include SuiteSpotGroup when setting up 389-ds instances- Move a lot of BuildRequires so this will build with ONLY_CLIENT enabled
* Tue Feb 15 2011 Rob Crittenden - 2.0.0-0.3.rc1- Set the N-V-R so rc1 is an update to beta2.
* Mon Feb 14 2011 Rob Crittenden - 2.0.0-0.1.rc1- Set minimum version of sssd to 1.5.1- Update to upstream freeipa-2.0.0.rc1- Move server-only binaries from admintools subpackage to server
* Tue Feb 08 2011 Fedora Release Engineering - 2.0.0-0.2.beta2- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Thu Feb 03 2011 Rob Crittenden - 2.0.0-0.1.beta2- Set min version of 389-ds-base to 1.2.8- Set min version of mod_nss 1.0.8-10- Set min version of selinux-policy to 3.9.7-27- Add dogtag themes to Requires- Update to upstream freeipa-2.0.0.pre2
* Thu Jan 27 2011 Rob Crittenden - 2.0.0-0.2.beta.git80e87e7- Remove unnecessary moving of v1 CA serial number file in post script- Add Obsoletes for server-selinxu subpackage- Using git snapshot 442d6ad30ce1156914e6245aa7502499e50ec0da
* Wed Jan 26 2011 Rob Crittenden - 2.0.0-0.1.beta.git80e87e7- Prepare spec file for release- Using git snapshot 80e87e75bd6ab56e3e20c49ece55bd4d52f1a503
* Tue Jan 25 2011 Rob Crittenden - 1.99-41- Re-arrange doc and defattr to clean up rpmlint warnings- Remove conditionals on older releases- Move some man pages into admintools subpackage- Remove some explicit Requires in client that aren\'t needed- Consistent use of buildroot vs RPM_BUILD_ROOT
* Wed Jan 19 2011 Adam Young - 1.99-40- Moved directory install/static to install/ui
* Thu Jan 13 2011 Simo Sorce - 1.99-39- Remove dependency on nss_ldap/nss-pam-ldapd- The official client is sssd and that\'s what we use by default.
* Thu Jan 13 2011 Simo Sorce - 1.99-38- Remove radius subpackages
* Thu Jan 13 2011 Rob Crittenden - 1.99-37- Set minimum pki-ca and pki-silent versions to 9.0.0
* Wed Jan 12 2011 Rob Crittenden - 1.99-36- Drop BuildRequires on mozldap-devel
* Mon Dec 13 2010 Rob Crittenden - 1.99-35- Add Requires on krb5-pkinit-openssl
* Fri Dec 10 2010 Jr Aquino - 1.99-34- Add ipa-host-net-manage script
* Tue Dec 07 2010 Simo Sorce - 1.99-33- Add ipa init script
* Fri Nov 19 2010 Rob Crittenden - 1.99-32- Set minimum level of 389-ds-base to 1.2.7 for enhanced memberof plugin
* Wed Nov 03 2010 Rob Crittenden - 1.99-31- remove ipa-fix-CVE-2008-3274
* Wed Oct 06 2010 Rob Crittenden - 1.99-30- Remove duplicate %files entries on share/ipa/static- Add python default encoding shared library
* Mon Sep 20 2010 Rob Crittenden - 1.99-29- Drop requires on python-configobj (not used any more)- Drop ipa-ldap-updater message, upgrades are done differently now
* Wed Sep 08 2010 Rob Crittenden - 1.99-28- Drop conflicts on mod_nss- Require nss-pam-ldapd on F-14 or higher instead of nss_ldap (#606847)- Drop a slew of conditionals on older Fedora releases (< 12)- Add a few conditionals against RHEL 6- Add Requires of nss-tools on ipa-client
* Fri Aug 13 2010 Rob Crittenden - 1.99-27- Set minimum version of certmonger to 0.26 (to pck up #621670)- Set minimum version of pki-silent to 1.3.4 (adds -key_algorithm)- Set minimum version of pki-ca to 1.3.6- Set minimum version of sssd to 1.2.1
* Tue Aug 10 2010 Rob Crittenden - 1.99-26- Add BuildRequires for authconfig
* Mon Jul 19 2010 Rob Crittenden - 1.99-25- Bump up minimum version of python-nss to pick up nss_is_initialize() API
* Thu Jun 24 2010 Adam Young - 1.99-24- Removed python-asset based webui
* Thu Jun 24 2010 Rob Crittenden - 1.99-23- Change Requires from fedora-ds-base to 389-ds-base- Set minimum level of 389-ds-base to 1.2.6 for the replication version plugin.
* Tue Jun 01 2010 Rob Crittenden - 1.99-22- Drop Requires of python-krbV on ipa-client
* Mon May 17 2010 Rob Crittenden - 1.99-21- Load ipa_dogtag.pp in post install
* Mon Apr 26 2010 Rob Crittenden - 1.99-20- Set minimum level of sssd to 1.1.1 to pull in required hbac fixes.
* Thu Mar 04 2010 Rob Crittenden - 1.99-19- No need to create /var/log/ipa_error.log since we aren\'t using TurboGears any more.
* Mon Mar 01 2010 Jason Gerard DeRose - 1.99-18- Fixed share/ipa/wsgi.py so .pyc, .pyo files are included
* Wed Feb 24 2010 Jason Gerard DeRose - 1.99-17- Added Require mod_wsgi, added share/ipa/wsgi.py
* Thu Feb 11 2010 Jason Gerard DeRose - 1.99-16- Require python-wehjit >= 0.2.2
* Wed Feb 03 2010 Rob Crittenden - 1.99-15- Add sssd and certmonger as a Requires on ipa-client
* Wed Jan 27 2010 Jason Gerard DeRose - 1.99-14- Require python-wehjit >= 0.2.0
* Fri Dec 04 2009 Rob Crittenden - 1.99-13- Add ipa-rmkeytab tool
* Tue Dec 01 2009 Rob Crittenden - 1.99-12- Set minimum of python-pyasn1 to 0.0.9a so we have support for the ASN.1 Any type
* Wed Nov 25 2009 Rob Crittenden - 1.99-11- Remove v1-style /etc/ipa/ipa.conf, replacing with /etc/ipa/default.conf
* Fri Nov 13 2009 Rob Crittenden - 1.99-10- Add bash completion script and own /etc/bash_completion.d in case it doesn\'t already exist
* Tue Nov 03 2009 Rob Crittenden - 1.99-9- Remove ipa_webgui, its functions rolled into ipa_httpd
* Mon Oct 12 2009 Jason Gerard DeRose - 1.99-8- Removed python-cherrypy from BuildRequires and Requires- Added Requires python-assets, python-wehjit
* Mon Aug 24 2009 Rob Crittenden - 1.99-7- Added httpd SELinux policy so CRLs can be read
* Thu May 21 2009 Rob Crittenden - 1.99-6- Move ipalib to ipa-python subpackage- Bump minimum version of slapi-nis to 0.15
* Wed May 06 2009 Rob Crittenden - 1.99-5- Set 0.14 as minimum version for slapi-nis
* Wed Apr 22 2009 Rob Crittenden - 1.99-4- Add Requires: python-nss to ipa-python sub-package
* Thu Mar 05 2009 Rob Crittenden - 1.99-3- Remove the IPA DNA plugin, use the DS one
* Wed Mar 04 2009 Rob Crittenden - 1.99-2- Build radius separately- Fix a few minor issues
* Tue Feb 03 2009 Rob Crittenden - 1.99-1- Replace TurboGears requirement with python-cherrypy
* Sat Jan 17 2009 Tomas Mraz - 1.2.1-3- rebuild with new openssl
* Fri Dec 19 2008 Dan Walsh - 1.2.1-2- Fix SELinux code
* Mon Dec 15 2008 Simo Sorce - 1.2.1-1- Fix breakage caused by python-kerberos update to 1.1
* Fri Dec 05 2008 Simo Sorce - 1.2.1-0- New upstream release 1.2.1
* Sat Nov 29 2008 Ignacio Vazquez-Abrams - 1.2.0-4- Rebuild for Python 2.6
* Fri Nov 14 2008 Simo Sorce - 1.2.0-3- Respin after the tarball has been re-released upstream New hash is 506c9c92dcaf9f227cba5030e999f177
* Thu Nov 13 2008 Simo Sorce - 1.2.0-2- Conditionally restart also dirsrv and httpd when upgrading
* Wed Oct 29 2008 Rob Crittenden - 1.2.0-1- Update to upstream version 1.2.0- Set fedora-ds-base minimum version to 1.1.3 for winsync header- Set the minimum version for SELinux policy- Remove references to Fedora 7
* Wed Jul 23 2008 Simo Sorce - 1.1.0-3- Fix for CVE-2008-3274- Fix segfault in ipa-kpasswd in case getifaddrs returns a NULL interface- Add fix for bug #453185- Rebuild against openldap libraries, mozldap ones do not work properly- TurboGears is currently broken in rawhide. Added patch to not build the UI locales and removed them from the ipa-server files section.
* Wed Jun 18 2008 Rob Crittenden - 1.1.0-2- Add call to /usr/sbin/upgradeconfig to post install
* Wed Jun 11 2008 Rob Crittenden - 1.1.0-1- Update to upstream version 1.1.0- Patch for indexing memberof attribute- Patch for indexing uidnumber and gidnumber- Patch to change DNA default values for replicas- Patch to fix uninitialized variable in ipa-getkeytab
* Fri May 16 2008 Rob Crittenden - 1.0.0-5- Set fedora-ds-base minimum version to 1.1.0.1-4 and mod_nss minimum version to 1.0.7-4 so we pick up the NSS fixes.- Add selinux-policy-base(post) to Requires (446496)
* Tue Apr 29 2008 Rob Crittenden - 1.0.0-4- Add missing entry for /var/cache/ipa/kpasswd (444624)- Added patch to fix permissions problems with the Apache NSS database.- Added patch to fix problem with DNS querying where the query could be returned as the answer.- Fix spec error where patch1 was in the wrong section
* Fri Apr 25 2008 Rob Crittenden - 1.0.0-3- Added patch to fix problem reported by ldapmodify
* Fri Apr 25 2008 Rob Crittenden - 1.0.0-2- Fix Requires for krb5-server that was missing for Fedora versions > 9- Remove quotes around test for fedora version to package egg-info
* Fri Apr 18 2008 Rob Crittenden - 1.0.0-1- Update to upstream version 1.0.0
* Tue Mar 18 2008 Rob Crittenden 0.99-12- Pull upstream changelog 722- Add Conflicts mod_ssl (435360)
* Fri Feb 29 2008 Rob Crittenden 0.99-11- Pull upstream changelog 698- Fix ownership of /var/log/ipa_error.log during install (435119)- Add pwpolicy command and man page
* Thu Feb 21 2008 Rob Crittenden 0.99-10- Pull upstream changelog 678- Add new subpackage, ipa-server-selinux- Add Requires: authconfig to ipa-python (bz #433747)- Package i18n files
* Mon Feb 18 2008 Rob Crittenden 0.99-9- Pull upstream changelog 641- Require minimum version of krb5-server on F-7 and F-8- Package some new files
* Thu Jan 31 2008 Rob Crittenden 0.99-8- Marked with wrong license. IPA is GPLv2.
* Tue Jan 29 2008 Rob Crittenden 0.99-7- Ensure that /etc/ipa exists before moving user-modifiable html files there- Put html files into /etc/ipa/html instead of /etc/ipa
* Tue Jan 29 2008 Rob Crittenden 0.99-6- Pull upstream changelog 608 which renamed several files
* Thu Jan 24 2008 Rob Crittenden 0.99-5- package the sessions dir /var/cache/ipa/sessions- Pull upstream changelog 597
* Thu Jan 24 2008 Rob Crittenden 0.99-4- Updated upstream pull (596) to fix bug in ipa_webgui that was causing the UI to not start.
* Thu Jan 24 2008 Rob Crittenden 0.99-3- Included LICENSE and README in all packages for documentation- Move user-modifiable content to /etc/ipa and linked back to /usr/share/ipa/html- Changed some references to /usr to the {_usr} macro and /etc to {_sysconfdir}- Added popt-devel to BuildRequires for Fedora 8 and higher and popt for Fedora 7- Package the egg-info for Fedora 9 and higher for ipa-python
* Tue Jan 22 2008 Rob Crittenden 0.99-2- Added auto
* BuildRequires
* Mon Jan 21 2008 Rob Crittenden 0.99-1- Unified spec file
* Thu Jan 17 2008 Rob Crittenden - 0.6.0-2- Fixed License in specfile- Include files from /usr/lib/python
*/site-packages/ipaserver
* Fri Dec 21 2007 Karl MacMillan - 0.6.0-1- Version bump for release
* Wed Nov 21 2007 Karl MacMillan - 0.5.0-1- Preverse mode on ipa-keytab-util- Version bump for relase and rpm name change
* Thu Nov 15 2007 Rob Crittenden - 0.4.1-2- Broke invididual Requires and BuildRequires onto separate lines and reordered them- Added python-tgexpandingformwidget as a dependency- Require at least fedora-ds-base 1.1
* Thu Nov 01 2007 Karl MacMillan - 0.4.1-1- Version bump for release
* Wed Oct 31 2007 Karl MacMillan - 0.4.0-6- Add dep for freeipa-admintools and acl
* Wed Oct 24 2007 Rob Crittenden - 0.4.0-5- Add dependency for python-krbV
* Fri Oct 19 2007 Rob Crittenden - 0.4.0-4- Require mod_nss-1.0.7-2 for mod_proxy fixes
* Thu Oct 18 2007 Karl MacMillan - 0.4.0-3- Convert to autotools-based build
* Tue Sep 25 2007 Karl MacMillan - 0.4.0-2
* Fri Sep 7 2007 Karl MacMillan - 0.3.0-1- Added support for libipa-dna-plugin
* Fri Aug 10 2007 Karl MacMillan - 0.2.0-1- Added support for ipa_kpasswd and ipa_pwd_extop
* Sun Aug 05 2007 Rob Crittenden - 0.1.0-3- Abstracted client class to work directly or over RPC
* Wed Aug 01 2007 Rob Crittenden - 0.1.0-2- Add mod_auth_kerb and cyrus-sasl-gssapi to Requires- Remove references to admin server in ipa-server-setupssl- Generate a client certificate for the XML-RPC server to connect to LDAP with- Create a keytab for Apache- Create an ldif with a test user- Provide a certmap.conf for doing SSL client authentication
* Fri Jul 27 2007 Karl MacMillan - 0.1.0-1- Initial rpm version