Changelog for
sssd-common-1.12.4-47.el6.x86_64.rpm :
Mon Jun 22 14:00:00 2015 Jakub Hrozek
- 1.12.4-47
- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from
ldap server
Mon Jun 8 14:00:00 2015 Jakub Hrozek - 1.12.4-46
- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task
- Resolves: rhbz#1227863 - ignore_group_members doesn\'t work for subdomains
Wed Jun 3 14:00:00 2015 Jakub Hrozek - 1.12.4-45
- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn\'t
return all groups on first attempt
Tue Jun 2 14:00:00 2015 Jakub Hrozek - 1.12.4-44
- Resolves: rhbz#1225614 - IPA enumeration provider crashes
Sun May 31 14:00:00 2015 Jakub Hrozek - 1.12.4-43
- Resolves: rhbz#1212610 - sssd ad groups work intermittently
Mon May 25 14:00:00 2015 Jakub Hrozek - 1.12.4-42
- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of
secondary groups
Mon May 25 14:00:00 2015 Jakub Hrozek - 1.12.4-41
- Resolves: rhbz#1221358 - SSSD doesn\'t work with ID mapping and disabled
subdomains
Fri May 15 14:00:00 2015 Jakub Hrozek - 1.12.4-40
- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD
users when using sssd-1.12.2-58.el7_1.6.x86_64
client in combination with
ipa-server-3.0.0-42.el6.x86_64 with AD Trust
Fri May 15 14:00:00 2015 Jakub Hrozek - 1.12.4-39
- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and
gets avc denial when ssh
Wed May 6 14:00:00 2015 Jakub Hrozek - 1.12.4-38
- Include several upstream fixes related to ID views
- Resolves: rhbz#1215195 - Override for IPA users with login does not list
user all groups
- Resolves: rhbz#1213947 - Group resolution is inconsistent with group
overrides
- Resolves: rhbz#1213822 - Overrides with --login work in second attempt
Thu Apr 30 14:00:00 2015 Jakub Hrozek - 1.12.4-37
- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix
and use_fully_qualified_names set
Thu Apr 30 14:00:00 2015 Jakub Hrozek - 1.12.4-36
- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad
src/providers/ad/ad_gpo.c:843
Wed Apr 29 14:00:00 2015 Jakub Hrozek - 1.12.4-35
- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers
group membership resolution
Tue Apr 28 14:00:00 2015 Jakub Hrozek - 1.12.4-34
- Resolves: rhbz#1170910 - SSSD should not fail authentication when only
allow rules are used
Mon Apr 27 14:00:00 2015 Jakub Hrozek - 1.12.4-33
- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name
does not work
- Resolves: rhbz#1213822 - Overrides with --login work in second attempt
Thu Apr 23 14:00:00 2015 Jakub Hrozek - 1.12.4-32
- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users
and filter_groups
Wed Apr 15 14:00:00 2015 Jakub Hrozek - 1.12.4-31
- Resolves: rhbz#1203642 - GPO access control looks for computer object
in user\'s domain only
Wed Apr 15 14:00:00 2015 Jakub Hrozek - 1.12.4-30
- Related: rhbz#1211728 - Only set the selinux context if the context
differs from the local one
Tue Apr 14 14:00:00 2015 Jakub Hrozek - 1.12.4-29
- Package the localauth plugin
- Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12
Tue Apr 14 14:00:00 2015 Jakub Hrozek - 1.12.4-28
- Resolves: rhbz#1207720 - id lookup resolves \"Domain Local\" group and
errors appear in domain log
Tue Apr 14 14:00:00 2015 Jakub Hrozek - 1.12.4-27
- BuildRequire the proper libkrb5 version for correct localauth plugin build
- Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12
Tue Apr 14 14:00:00 2015 Jakub Hrozek - 1.12.4-26
- Resolves: rhbz#1194367 - sssd_be dumping core
Fri Mar 27 13:00:00 2015 Jakub Hrozek - 1.12.4-25
- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in
manpage that unsupported time specification will
lead to sssd denying access
Fri Mar 27 13:00:00 2015 Jakub Hrozek - 1.12.4-24
- Resolves: rhbz#1205382 - Properly handle AD\'s binary objectGUID
Thu Mar 26 13:00:00 2015 Jakub Hrozek - 1.12.4-23
- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might
install with wrong user account (root)
Thu Mar 26 13:00:00 2015 Jakub Hrozek - 1.12.4-22
- Fix a typo in DEBUG message
- Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when
account naturally expires
Thu Mar 26 13:00:00 2015 Jakub Hrozek - 1.12.4-21
- Handle TTL=0 in SRV queries correctly
- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a
SRV query
Thu Mar 26 13:00:00 2015 Jakub Hrozek - 1.12.4-20
- Cherry-pick unit test changes from upstream to allow cherry-picking
sssd-1-12 patches
- Remove unused LDAP provider code to avoid static analyser warnings
- Related: rhbz#1168347 - Rebase sssd to 1.12.x
Thu Mar 26 13:00:00 2015 Jakub Hrozek - 1.12.4-19
- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code
Fri Mar 20 13:00:00 2015 Jakub Hrozek - 1.12.4-18
- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad
requires samba4
Fri Mar 20 13:00:00 2015 Jakub Hrozek - 1.12.4-17
- Resolves: rhbz#1203630 - SSSD doesn\'t own the GPO cache directory
Fri Mar 20 13:00:00 2015 Jakub Hrozek - 1.12.4-16
- Fix warning in SELinux code
- Handle setups with empty default and no SELinux maps
- Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security
context on client is staff_u
- Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD
trusted domain) client at
src/providers/ipa/ipa_s2n_exop.c:1605
- Resolves: rhbz#1201847 - SSSD downloads too much information when fetching
information about groups
Fri Mar 13 13:00:00 2015 Jakub Hrozek - 1.12.4-15
- Fix PAM responder initgroups cache for subdomain users
- Log extop failures better
- Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync
solution to the trust solution
Fri Mar 13 13:00:00 2015 Jakub Hrozek - 1.12.4-14
- Fix internal error codes broken when fixing rhbz#1036745
- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration
warning even if alternate authentication method
is used
Fri Mar 13 13:00:00 2015 Jakub Hrozek - 1.12.4-13
- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by
UPN and doesn\'t find anything
Fri Mar 13 13:00:00 2015 Jakub Hrozek - 1.12.4-12
- Fix Coverity warning in ldap_child
- Add better debugging
- Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error
Sun Mar 8 13:00:00 2015 Jakub Hrozek - 1.12.4-11
- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users,
groups or other cache objects
Fri Mar 6 13:00:00 2015 Jakub Hrozek - 1.12.4-10
- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when
account naturally expires
Fri Mar 6 13:00:00 2015 Jakub Hrozek - 1.12.4-9
- Initialize a pointer in ldap_child to NULL
- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error
Fri Mar 6 13:00:00 2015 Jakub Hrozek - 1.12.4-8
- Relax the ldb requirement
- Related: rhbz#1168347 - Rebase sssd to 1.12.x
Wed Mar 4 13:00:00 2015 Jakub Hrozek - 1.12.4-7
- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security
context on client is staff_u
Wed Mar 4 13:00:00 2015 Jakub Hrozek - 1.12.4-6
- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error
Wed Mar 4 13:00:00 2015 Jakub Hrozek - 1.12.4-5
- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a
SRV query
Tue Mar 3 13:00:00 2015 Jakub Hrozek - 1.12.4-4
- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a
SRV query
- Rebuild against latest krb5, add a versioned BuildRequires
- Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12
Tue Mar 3 13:00:00 2015 Jakub Hrozek - 1.12.4-3
- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration
warning even if alternate authentication method
is used
Wed Feb 18 13:00:00 2015 Jakub Hrozek - 1.12.4-2
- Do not mark the selinux_child helper as setuid, we don\'t support rootless
SSSD in 6.7
- Related: rhbz#1168347 - Rebase sssd to 1.12.x
Wed Feb 18 13:00:00 2015 Jakub Hrozek - 1.12.4-1
- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x
- The rebase resolves the following RHEL bugzillas
- Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about
domains parameter
- Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not
be fatal (backport fix from upstream)
- Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user
uid field
- Resolves: rhbz#1170910 - SSSD should not fail authentication when only
allow rules are used
- Resolves: rhbz#1168377 - [RFE] User\'s home directories and shells are
not taken from AD when there is an IPA trust with AD
- Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss
- Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync
solution to the trust solution
- Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option:
kerberos discovery is not using this option
- Resolves: rhbz#1148582 - inconsistent group information when multiple
ad domain sections are configured in sssd
- Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider
ad support
- Resolves: rhbz#1139878 - SSSD connection terminated after failing
anonymous bind to IBM Tivoli Directory Server
- Resolves: rhbz#1135838 - Man sssd-ldap shows parameter
ldap_purge_cache_timeout with \"Default: 10800
(12 hours)\"
- Resolves: rhbz#1135432 - Dereference code errors out when dereferencing
entries protected by ACIs
- Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012
R2\'s LDAP as AD
- Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header
- Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple
attributes
Tue Nov 18 13:00:00 2014 Jakub Hrozek - 1.11.6-33
- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn\'t return all group
memberships against an IPA server
Tue Nov 18 13:00:00 2014 Jakub Hrozek - 1.11.6-32
- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner
cases
Thu Sep 25 14:00:00 2014 Jakub Hrozek - 1.11.6-31
- Resolves: rhbz#1141814 - Password expiration policies are not being
enforced by SSSD
Mon Sep 15 14:00:00 2014 Jakub Hrozek - 1.11.6-30
- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found
Thu Sep 4 14:00:00 2014 Jakub Hrozek - 1.11.6-29
- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group
membership when encountering a non-POSIX group
Tue Aug 26 14:00:00 2014 Jakub Hrozek - 1.11.6-28
- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from
other AD domains
Tue Aug 26 14:00:00 2014 Jakub Hrozek - 1.11.6-27
- Resolves: rhbz#1127270 - sssd connect to ipa-server is long
Tue Aug 26 14:00:00 2014 Jakub Hrozek - 1.11.6-26
- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD,
POSIX attributes are used and primary group contains
the user as a member
Mon Aug 25 14:00:00 2014 Jakub Hrozek - 1.11.6-25
- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0)
is not prompted for password change
Fri Aug 22 14:00:00 2014 Jakub Hrozek - 1.11.6-24
- Resolves: rhbz#1132361 - use-after-free in dyndns code
Tue Aug 19 14:00:00 2014 Jakub Hrozek - 1.11.6-23
- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap
account lock to restrict access via ssh key
Tue Aug 19 14:00:00 2014 Jakub Hrozek - 1.11.6-22
- Use the correct sudo iterator
- Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk
Tue Aug 19 14:00:00 2014 Jakub Hrozek - 1.11.6-21
- Add notes about offline mode to sssd.conf
- Related: rhbz#1110226 - Requests queued during transition from offline
to online mode
Thu Aug 14 14:00:00 2014 Jakub Hrozek - 1.11.6-20
- Resolves: rhbz#1127278 - Auth fails when space in username is
replaced with character set by
override_default_whitespace
Thu Aug 14 14:00:00 2014 Jakub Hrozek - 1.11.6-19
- Resolves: rhbz#1127757 - sssd can\'t retrieve sudo rules when using the
\"default_domain_suffix\" option
Thu Aug 14 14:00:00 2014 Jakub Hrozek - 1.11.6-18
- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base
Thu Aug 14 14:00:00 2014 Jakub Hrozek - 1.11.6-17
- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade
Thu Aug 14 14:00:00 2014 Jakub Hrozek - 1.11.6-16
- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken
Thu Aug 14 14:00:00 2014 Jakub Hrozek - 1.11.6-15
- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk
Thu Jul 31 14:00:00 2014 Jakub Hrozek - 1.11.6-14
- Resolves: rhbz#1110226 - Requests queued during transition from offline
to online mode
Thu Jul 31 14:00:00 2014 Jakub Hrozek - 1.11.6-13
- Resolves: rhbz#1122873 - Failover does not always happen from SRV
to hostname resolution(via /etc/hosts)
- Remove spurious systemctl call on %postun
Mon Jul 28 14:00:00 2014 Jakub Hrozek - 1.11.6-12
- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with
specified character in LDAP group
Fri Jul 25 14:00:00 2014 Jakub Hrozek - 1.11.6-11
- Resolves: rhbz#1109188 - dereferencing control failure against openldap
server
Thu Jul 24 14:00:00 2014 Jakub Hrozek - 1.11.6-10
- Resolves: rhbz#1084532 - sssd_sudo process segfaults
Thu Jul 24 14:00:00 2014 Jakub Hrozek - 1.11.6-9
- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping
is off and tokengroups are enabled
Thu Jul 24 14:00:00 2014 Jakub Hrozek - 1.11.6-8
- Resolves: rhbz#1118541 - Floating point exception using ldap
Thu Jul 24 14:00:00 2014 Jakub Hrozek - 1.11.6-7
- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser
is not defined and no ldap_sudorule_runasuser mapping
has been defined in SSSD
Thu Jul 24 14:00:00 2014 Jakub Hrozek - 1.11.6-6
- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap
Thu Jul 24 14:00:00 2014 Jakub Hrozek - 1.11.6-5
- Fix potential NULL dereference in IFP code
- Related: rhbz#1110369 - sssd is started before messagebus, making
sssd-ifp fail
Wed Jul 16 14:00:00 2014 Jakub Hrozek - 1.11.6-4
- BuildRequire the latest libini_config
- Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6
Mon Jul 14 14:00:00 2014 Jakub Hrozek - 1.11.6-3
- Resolves: rhbz#1110369 - sssd is started before messagebus, making
sssd-ifp fail
Tue Jun 3 14:00:00 2014 Jakub Hrozek - 1.11.6-2
- Resolves: rhbz#1104145 - public key validator is too strict and does not
allow newlines anywhere in the public key string,
not even at the end
Tue Jun 3 14:00:00 2014 Jakub Hrozek - 1.11.6-1
- Rebase to 1.11.6
- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6
Thu May 29 14:00:00 2014 Jakub Hrozek - 1.11.5.1-4
- Rebuild against new ding-libs
- Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6
Wed May 14 14:00:00 2014 Jakub Hrozek - 1.11.5.1-3
- Backport the InfoPipe patches needed for Sat6 integration
- Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6
Mon May 12 14:00:00 2014 Jakub Hrozek - 1.11.5.1-2
- Resolves: #1085412 - SSSD Crashes when storage experiences high latency
Wed Apr 16 14:00:00 2014 Jakub Hrozek - 1.11.5.1-1
- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6
Mon Feb 24 13:00:00 2014 Jakub Hrozek - 1.9.2-134
Resolves: #1036168 - sssd can\'t retrieve auto.master when using the
\"default_domain_suffix\"
Mon Feb 24 13:00:00 2014 Jakub Hrozek - 1.9.2-133
- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces
Thu Dec 19 13:00:00 2013 Jakub Hrozek - 1.9.2-132
- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups
are requested
Tue Nov 19 13:00:00 2013 Jakub Hrozek - 1.9.2-131
- Allow combination of proxy id backend and LDAP auth backend
- Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using
id_provider = proxy
Tue Nov 19 13:00:00 2013 Jakub Hrozek - 1.9.2-130
- Inherit UID limits for subdomains
- Resolves: #1020905 - Creating system accounts on a IdM client takes up
to 10 minutes when AD trust is configured in the IdM.
Tue Oct 22 14:00:00 2013 Jakub Hrozek - 1.9.2-129
- Do not crash when LDAP disconnects while a search is still in progress
- Resolves: #1019979 - sssd_be segfault when authenticating against active
directory
Thu Sep 26 14:00:00 2013 Jakub Hrozek - 1.9.2-128
- More upstream fixes to prevent memcache crashes
- Related: #997406 - sssd_nss core dumps under load
Thu Sep 12 14:00:00 2013 Jakub Hrozek - 1.9.2-127
- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out
Tue Sep 3 14:00:00 2013 Jakub Hrozek - 1.9.2-126
- Make IPA SELinux provider aware of subdomain users
- A better version of already committed patch
- Resolves: #954342 - In IPA AD trust setup, the sssd logs throws
\'sysdb_search_user_by_name failed\' error when
AD user tries to login via ipa client.
Fri Aug 30 14:00:00 2013 Jakub Hrozek - 1.9.2-125
- Resolves: #997406 - sssd_nss core dumps under load
- Resolves: #984814 - sssd_nss terminated with segmentation fault
Fri Aug 30 14:00:00 2013 Jakub Hrozek - 1.9.2-124
- Resolves: #1002161 - large number of sudo rules results in error -
Unable to create response: Invalid argument
Mon Aug 19 14:00:00 2013 Jakub Hrozek - 1.9.2-123
- Silence restorecon on clean install
- Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for
/var/lib/sss/mc context
Sun Aug 11 14:00:00 2013 Jakub Hrozek - 1.9.2-122
- Make IPA SELinux provider aware of subdomain users
- Resolves: #954342 - In IPA AD trust setup, the sssd logs throws
\'sysdb_search_user_by_name failed\' error when
AD user tries to login via ipa client.
Sun Aug 11 14:00:00 2013 Jakub Hrozek - 1.9.2-121
- Print password complexity hint when password change fails with
constraint violation
- Related: #983028 - passwd returns \"Authentication token manipulation
error\" when entering wrong current password
Sun Aug 11 14:00:00 2013 Jakub Hrozek - 1.9.2-120
- Resolves: #983028 - passwd returns \"Authentication token manipulation
error\" when entering wrong current password
Sun Aug 11 14:00:00 2013 Jakub Hrozek - 1.9.2-119
- Resolves: #948830 - sssd do too many disk writes causing delay in
\"getent netgroup allmachines-netgroup\" nested netgroups.
Sun Aug 11 14:00:00 2013 Jakub Hrozek - 1.9.2-118
- Resolves: #984814 - sssd_nss terminated with segmentation fault
Fri Aug 9 14:00:00 2013 Jakub Hrozek - 1.9.2-117
- Resolves: #966757 - SSSD failover doesn\'t work if the first DNS server
in resolv.conf is unavailable
Fri Aug 9 14:00:00 2013 Jakub Hrozek - 1.9.2-116
- Resolves: #963235 - sssd_be crashing with nested ldap groups
Fri Aug 9 14:00:00 2013 Jakub Hrozek - 1.9.2-115
- Apply a forgotten dependency for patch #254
- Related: #916997 - getgrnam / getgrgid for large user groups
is too slow due to range retrieval functionality
- Add two fixes for better handling of faulty SRV processing
- Related: #954275 - sssd fails connect to IPA server during boot when
spanning tree is enabled in network router.
- Remove enumerate=true from example in man page
- Related: #988381 - clarify the disadvantages of enumeration in sssd.conf
Fri Aug 9 14:00:00 2013 Jakub Hrozek - 1.9.2-114
- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp
file for SELinux data failed
Fri Aug 9 14:00:00 2013 Jakub Hrozek - 1.9.2-113
- Resolves: #916997 - getgrnam / getgrgid for large user groups
is too slow due to range retrieval functionality
Fri Aug 9 14:00:00 2013 Jakub Hrozek - 1.9.2-112
- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors
when clearing cache
Fri Aug 9 14:00:00 2013 Jakub Hrozek - 1.9.2-111
- Resolves: #924113 - man sssd-sudo has wrong title
Fri Aug 9 14:00:00 2013 Jakub Hrozek - 1.9.2-110
- Resolves: #924397 - document what does access_provider=ad do
Fri Aug 9 14:00:00 2013 Jakub Hrozek - 1.9.2-109
- Use permissive control when adding ghost users
- Resolves: #928797 - cyclic group memberships may not work depending on
order of operations
Fri Aug 9 14:00:00 2013 Jakub Hrozek - 1.9.2-108
- Set correct state of SRV servers on resolving error
- Resolves: #954275 - sssd fails connect to IPA server during boot when
spanning tree is enabled in network router.
Fri Aug 9 14:00:00 2013 Jakub Hrozek - 1.9.2-107
- Resolves: #954323 - SSSD doesn\'t display warning for last grace login.
Fri Aug 9 14:00:00 2013 Jakub Hrozek - 1.9.2-106
- Format patch to configure sysv script differently
- RHEL-6 patch(1) apparently doesn\'t like the output of git format-patch
-M -C and doesn\'t properly copy files on renames
- Resolves: #971435 - Enhance sssd init script so that it would source a
configuration.
Thu Aug 8 14:00:00 2013 Jakub Hrozek - 1.9.2-105
- Resolves: #973345 - SSSD service randomly dies
Thu Aug 8 14:00:00 2013 Jakub Hrozek - 1.9.2-104
- Resolves: #971435 - Enhance sssd init script so that it would source
a configuration
Thu Aug 8 14:00:00 2013 Jakub Hrozek - 1.9.2-103
- Resolves: #961356 - SUDO is not working for users from trusted AD domain
Thu Aug 8 14:00:00 2013 Jakub Hrozek - 1.9.2-102
- Resolves: #970519 - [RFE] Add support for suppressing group members
Thu Aug 8 14:00:00 2013 Jakub Hrozek - 1.9.2-101
- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the
\"original value\"
Thu Aug 8 14:00:00 2013 Jakub Hrozek - 1.9.2-100
- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes
Thu Aug 8 14:00:00 2013 Jakub Hrozek - 1.9.2-99
- Clarify the min_id/max_id limits further
- Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero
Thu Aug 8 14:00:00 2013 Jakub Hrozek - 1.9.2-98
- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login
delays when client is under load
Thu Aug 8 14:00:00 2013 Jakub Hrozek - 1.9.2-97
- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table
in sssd_nss
Thu Aug 8 14:00:00 2013 Jakub Hrozek - 1.9.2-96
- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap
filter returns entries with multiple CNs
Thu Jul 25 14:00:00 2013 Jakub Hrozek - 1.9.2-95
- Mention that enumeration should be discouraged
- Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf
Thu Jul 25 14:00:00 2013 Jakub Hrozek - 1.9.2-94
- Call restorecon on memcache files to force the right context on upgrades
- Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for
/var/lib/sss/mc context
Wed Jul 24 14:00:00 2013 Jakub Hrozek - 1.9.2-93
- Resolves: #987479 - libsss_sudo should depend on sudo package with
sssd support
Fri Jul 19 14:00:00 2013 Jakub Hrozek - 1.9.2-92
- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck
Thu May 30 14:00:00 2013 Jakub Hrozek - 1.9.2-91
- Resolves: #967636 - SSSD frequently fails to return automount maps
from LDAP
Wed May 1 14:00:00 2013 Jakub Hrozek - 1.9.2-90
- Resolves: #953165 - Enabling enumeration causes sssd_be process to
utilize 100% of the CPU
Tue Apr 23 14:00:00 2013 Jakub Hrozek - 1.9.2-89
- Resolves: #906398 - sssd_be crashes sometimes
Mon Apr 15 14:00:00 2013 Jakub Hrozek - 1.9.2-88
- Resolves: #950874: Simple access control always denies uppercased users
in case insensitive domain
Wed Mar 20 13:00:00 2013 Jakub Hrozek - 1.9.2-87
- Resolves: #921454: Resolve local group members in LDAP groups
Tue Mar 5 13:00:00 2013 Jakub Hrozek - 1.9.2-86
- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended
ACL use when client to an AD provider
Fri Mar 1 13:00:00 2013 Jakub Hrozek - 1.9.2-85
- Fix pwd_expiration_warning=0
- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for
Kerberos
Fri Feb 22 13:00:00 2013 Jakub Hrozek - 1.9.2-84
- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for
Kerberos
Wed Jan 30 13:00:00 2013 Jakub Hrozek - 1.9.2-83
- Resolves: rhbz#872827 - Serious performance regression in sssd
Wed Jan 23 13:00:00 2013 Jakub Hrozek - 1.9.2-82
- Resolves: rhbz#888614 - Failure in memberof can lead to failed
database update
Wed Jan 23 13:00:00 2013 Jakub Hrozek - 1.9.2-81
- Resolves: rhbz#903078 - TOCTOU race conditions by copying
and removing directory trees
Wed Jan 23 13:00:00 2013 Jakub Hrozek - 1.9.2-80
- Resolves: rhbz#903078 - Out-of-bounds read flaws in
autofs and ssh services responders
Tue Jan 22 13:00:00 2013 Jakub Hrozek - 1.9.2-79
- Resolves: rhbz#902716 - Rule mismatch isn\'t noticed before smart refresh
on ppc64 and s390x
Tue Jan 22 13:00:00 2013 Jakub Hrozek - 1.9.2-78
- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning
value is higher than passwordWarning LDAP attribute.
Tue Jan 22 13:00:00 2013 Jakub Hrozek - 1.9.2-77
- Resolves: rhbz#902436 - possible segfault when backend callback is removed
Mon Jan 21 13:00:00 2013 Jakub Hrozek - 1.9.2-76
- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not
reflected in memory cache
Wed Jan 16 13:00:00 2013 Jakub Hrozek - 1.9.2-75
- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps
Wed Jan 16 13:00:00 2013 Jakub Hrozek - 1.9.2-74
- Resolves: rhbz894381 - memory cache is not updated after user is deleted
from ldb cache
Wed Jan 16 13:00:00 2013 Jakub Hrozek - 1.9.2-73
- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and
ppc64 platform
Tue Jan 15 13:00:00 2013 Jakub Hrozek - 1.9.2-72
- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups
outside the nesting limit
Tue Jan 15 13:00:00 2013 Jakub Hrozek - 1.9.2-71
- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not
reflected in memory cache
Tue Jan 15 13:00:00 2013 Jakub Hrozek - 1.9.2-70
- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache
Tue Jan 15 13:00:00 2013 Jakub Hrozek - 1.9.2-69
- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn\'t work
Wed Jan 9 13:00:00 2013 Jakub Hrozek - 1.9.2-68
- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group
memberships
Mon Jan 7 13:00:00 2013 Jakub Hrozek - 1.9.2-67
- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD
Users for commands like id and getent
Mon Jan 7 13:00:00 2013 Jakub Hrozek - 1.9.2-66
- Resolves: rhbz#874579 - sssd caching not working as expected for selinux
usermap contexts
Mon Jan 7 13:00:00 2013 Jakub Hrozek - 1.9.2-65
- Resolves: rhbz#892197 - Incorrect principal searched for in keytab
Mon Jan 7 13:00:00 2013 Jakub Hrozek - 1.9.2-64
- Resolves: rhbz#891356 - Smart refresh doesn\'t notice \"defaults\" addition
with OpenLDAP
Fri Jan 4 13:00:00 2013 Jakub Hrozek - 1.9.2-63
- Resolves: rhbz#878419 - sss_userdel doesn\'t remove entries from in-memory
cache
Fri Jan 4 13:00:00 2013 Jakub Hrozek - 1.9.2-62
- Resolves: rhbz#886848 - user id lookup fails for case sensitive users
using proxy provider
Fri Jan 4 13:00:00 2013 Jakub Hrozek - 1.9.2-61
- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn\'t work
Fri Jan 4 13:00:00 2013 Jakub Hrozek - 1.9.2-60
- Resolves: rhbz#874618 - sss_cache: fqdn not accepted
Thu Dec 20 13:00:00 2012 Jakub Hrozek - 1.9.2-59
- Resolves: rhbz#889182 - crash in memory cache
Thu Dec 20 13:00:00 2012 Jakub Hrozek - 1.9.2-58
- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable
tickets from cache
Thu Dec 20 13:00:00 2012 Jakub Hrozek - 1.9.2-57
- Resolves: rhbz#886091 - Disallow root SSH public key authentication
- Add default section to switch statement (Related: rhbz#884666)
Thu Dec 20 13:00:00 2012 Jakub Hrozek - 1.9.2-56
- Resolves: rhbz#886038 - sssd components seem to mishandle sighup
Thu Dec 20 13:00:00 2012 Jakub Hrozek - 1.9.2-55
- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function
Thu Dec 20 13:00:00 2012 Jakub Hrozek - 1.9.2-54
- Resolves: rhbz#888614 - Failure in memberof can lead to failed database
update
Thu Dec 20 13:00:00 2012 Jakub Hrozek - 1.9.2-53
- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the
enumeration is taking too long
Mon Dec 17 13:00:00 2012 Jakub Hrozek - 1.9.2-52
- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11
- Include more debugging during the sysdb upgrade
Mon Dec 17 13:00:00 2012 Jakub Hrozek - 1.9.2-51
- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal
Mon Dec 17 13:00:00 2012 Jakub Hrozek - 1.9.2-50
- Resolves: rhbz#870045 - always reread the master map from LDAP
- Resolves: rhbz#876531 - sss_cache does not work for automount maps
Mon Dec 17 13:00:00 2012 Jakub Hrozek - 1.9.2-49
- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule
another first full refresh
Mon Dec 17 13:00:00 2012 Jakub Hrozek - 1.9.2-48
- Resolves: rhbz#880956 - Primary server status is not always reset after
failover to backup server happened
- Silence a compilation warning in the memberof plugin (Related: rhbz#877974)
- Do not steal resolv result on error (Related: rhbz#882076)
Mon Dec 17 13:00:00 2012 Jakub Hrozek - 1.9.2-47
- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy
provider
Sat Dec 15 13:00:00 2012 Jakub Hrozek - 1.9.2-46
- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same
hostname
Fri Dec 14 13:00:00 2012 Jakub Hrozek - 1.9.2-45
- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd
failed. Timer expired
Fri Dec 14 13:00:00 2012 Jakub Hrozek - 1.9.2-44
- Resolves: rhbz#878419 - sss_userdel doesn\'t remove entries from in-memory
cache
Fri Dec 14 13:00:00 2012 Jakub Hrozek - 1.9.2-43
- Resolves: rhbz#880176 - memberUid required for primary groups to match
sudo rule
Fri Dec 14 13:00:00 2012 Jakub Hrozek - 1.9.2-42
- Resolves: rhbz#885105 - sudo denies access with disabled
ldap_sudo_use_host_filter
Tue Dec 11 13:00:00 2012 Jakub Hrozek - 1.9.2-41
- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly
Tue Dec 11 13:00:00 2012 Jakub Hrozek - 1.9.2-40
- Resolves: rhbz#880546 - krb5_kpasswd failover doesn\'t work
- Fix the error handler in sss_mc_create_file (Related: #789507)
Tue Dec 11 13:00:00 2012 Jakub Hrozek - 1.9.2-39
- Resolves: rhbz#882221 - Offline sudo denies access with expired
entry_cache_timeout
- Fix several bugs found by Coverity and clang:
- Check the return value of diff_gid_lists (Related: #869071)
- Move misplaced sysdb assignment (Related: #827606)
- Remove dead assignment (Related: #827606)
- Fix copy-n-paste error in the memberof plugin (Related: #877974)
Tue Dec 11 13:00:00 2012 Jakub Hrozek - 1.9.2-38
- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy
provider
- Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client
libraries (Related: #870060)
- Move sss_ssh_knownhosts documentation to the correct section
(Related: #870060)
Fri Dec 7 13:00:00 2012 Jakub Hrozek - 1.9.2-37
- Resolves: rhbz#884480 - user is not removed from group membership during
initgroups
- Fix incorrect synchronization in mmap cache (Related: #789507)
Fri Dec 7 13:00:00 2012 Jakub Hrozek - 1.9.2-36
- Resolves: rhbz#883336 - sssd crashes during start if id_provider is
not mentioned
Fri Dec 7 13:00:00 2012 Jakub Hrozek - 1.9.2-35
- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup
midpoint refresh to be always set to 10 seconds
Thu Dec 6 13:00:00 2012 Jakub Hrozek - 1.9.2-34
- Resolves: rhbz#877974 - updating top-level group does not reflect ghost
members correctly
- Resolves: rhbz#880159 - delete operation is not implemented for ghost users
Thu Dec 6 13:00:00 2012 Jakub Hrozek - 1.9.2-33
- Resolves: rhbz#881773 - mmap cache needs update after db changes
Thu Dec 6 13:00:00 2012 Jakub Hrozek - 1.9.2-32
- Resolves: rhbz#875677 - password expiry warning message doesn\'t appear
during auth
- Fix potential NULL dereference when skipping built-in AD groups
(Related: rhbz#874616)
- Add missing parameter to DEBUG message (Related: rhbz#829742)
Thu Dec 6 13:00:00 2012 Jakub Hrozek - 1.9.2-31
- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an
empty hostent during the DNS update
- Do not version libsss_sudo, it\'s not supposed to be linked against, but
dlopened (Related: rhbz#761573)
Wed Nov 28 13:00:00 2012 Jakub Hrozek - 1.9.2-30
- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations
Wed Nov 28 13:00:00 2012 Jakub Hrozek - 1.9.2-29
- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set
Wed Nov 28 13:00:00 2012 Jakub Hrozek - 1.9.2-28
- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code
skips a built-in group
Tue Nov 27 13:00:00 2012 Jakub Hrozek - 1.9.2-27
- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken
configurations
Tue Nov 27 13:00:00 2012 Jakub Hrozek - 1.9.2-26
- Resolves: rhbz#874673 - user id lookup fails using proxy provider
- Fix a possibly uninitialized variable in the LDAP provider
- Related: rhbz#877130
Wed Nov 21 13:00:00 2012 Jakub Hrozek - 1.9.2-25
- Resolves: rhbz#878262 - ipa password auth failing for user principal
name when shorter than IPA Realm name
- Resolves: rhbz#871843 - Nested groups are not retrieved appropriately
from cache
Tue Nov 20 13:00:00 2012 Jakub Hrozek - 1.9.2-24
- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password
Tue Nov 20 13:00:00 2012 Jakub Hrozek - 1.9.2-23
- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal
Tue Nov 20 13:00:00 2012 Jakub Hrozek - 1.9.2-22
- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart
after sbus failure
Mon Nov 19 13:00:00 2012 Jakub Hrozek - 1.9.2-21
- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn\'t expire
ldap connections
Mon Nov 19 13:00:00 2012 Jakub Hrozek - 1.9.2-20
- Related: rhbz#877126 - Bump the release tag
Mon Nov 19 13:00:00 2012 Jakub Hrozek - 1.9.2-20
- Resolves: rhbz#877126 - subdomains code does not save the proper
user/group name
Mon Nov 19 13:00:00 2012 Jakub Hrozek - 1.9.2-19
- Resolves: rhbz#877130 - LDAP provider fails to save empty groups
- Related: rhbz#869466 - check the return value of waitpid()
Mon Nov 19 13:00:00 2012 Jakub Hrozek - 1.9.2-18
- Resolves: rhbz#870039 - sss_cache says \'Wrong DB version\'
Mon Nov 19 13:00:00 2012 Jakub Hrozek - 1.9.2-17
- Resolves: rhbz#875740 - \"defaults\" entry ignored
Mon Nov 19 13:00:00 2012 Jakub Hrozek - 1.9.2-16
- Resolves: rhbz#875738 - offline authentication failure always returns
System Error
Sun Nov 18 13:00:00 2012 Jakub Hrozek - 1.9.2-15
- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11
Thu Nov 15 13:00:00 2012 Jakub Hrozek - 1.9.2-14
- Resolves: rhbz#870278 - ipa client setup should configure host properly
in a trust is in place
Wed Nov 14 13:00:00 2012 Jakub Hrozek - 1.9.2-13
- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment
Sun Nov 11 13:00:00 2012 Jakub Hrozek - 1.9.2-12
- Resolves: rhbz#870278 - ipa client setup should configure host properly
in a trust is in place
Sun Nov 11 13:00:00 2012 Jakub Hrozek - 1.9.2-11
- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule
Sun Nov 11 13:00:00 2012 Jakub Hrozek - 1.9.2-10
- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type
- Related: rhbz#867933 - invalidating the memcache with sss_cache doesn\'t work
if the sssd is not running
Sun Nov 11 13:00:00 2012 Jakub Hrozek - 1.9.2-9
- Resolves: rhbz#873988 - Man page issue to list \'force_timeout\' as an
option for the [sssd] section
Sun Nov 11 13:00:00 2012 Jakub Hrozek - 1.9.2-8
- Resolves: rhbz#873032 - Move sss_cache to the main subpackage
Tue Nov 6 13:00:00 2012 Jakub Hrozek - 1.9.2-7
- Resolves: rhbz#873032 - Move sss_cache to the main subpackage
- Resolves: rhbz#829740 - Init script reports complete before sssd is actually
working
- Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in
ldap_uri
- Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly
- Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn\'t work
if the sssd is not running
- Resolves: rhbz#872110 - User appears twice on looking up a nested group
Sun Nov 4 13:00:00 2012 Jakub Hrozek - 1.9.2-6
- Resolves: rhbz#871576 - sssd does not resolve group names from AD
- Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file
in the pam responder
- Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider
directive
Fri Nov 2 13:00:00 2012 Jakub Hrozek - 1.9.2-5
- Do not send SIGKILL to service right after sending SIGTERM
- Resolves: #771975
- Fix the initial sudo smart refresh
- Resolves: #869013
- Implement password authentication for users from trusted domains
- Resolves: #869071
- LDAP child crashed with a wrong keytab
- Resolves: #869150
- The sssd_nss process grows the memory consumption over time
- Resolves: #869443
Mon Oct 15 14:00:00 2012 Jakub Hrozek - 1.9.2-4
- BuildRequire selinux-policy so that selinux login support is built in
- Resolves: #867932
Mon Oct 15 14:00:00 2012 Jakub Hrozek - 1.9.2-3
- Do not segfault if namingContexts contain no values or multiple values
- Resolves: rhbz#866542
Mon Oct 15 14:00:00 2012 Jakub Hrozek - 1.9.2-2
- Fix the \"ca\" translation of the sssd-simple manual page
- Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4
Sun Oct 14 14:00:00 2012 Jakub Hrozek - 1.9.2-1
- New upstream release 1.9.2
Sun Oct 7 14:00:00 2012 Jakub Hrozek - 1.9.1-1
- Rebase to 1.9.1
Wed Oct 3 14:00:00 2012 Jakub Hrozek - 1.9.0-3
- Require the latest libldb
Tue Sep 25 14:00:00 2012 Jakub Hrozek - 1.9.0-2
- Rebase to 1.9.0
- Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4
Mon Sep 24 14:00:00 2012 Jakub Hrozek - 1.9.0-1.rc1
- Rebase to 1.9.0 RC1
- Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4
- Bump the selinux-policy version number to pull in required fixes
Thu Aug 9 14:00:00 2012 Jakub Hrozek - 1.8.0-33
- Resolves: rhbz#840089 - Update the shadowLastChange attribute
with days since the Epoch, not seconds
Tue May 29 14:00:00 2012 Stephen Gallagher - 1.8.0-32
- Fix protocol break for services map
- Related: rhbz#825028 - Service lookups by port number doesn\'t work on
s390x/ppc64 arches
Thu May 24 14:00:00 2012 Stephen Gallagher - 1.8.0-31
- Resolves: rhbz#825028 - Service lookups by port number doesn\'t work on
s390x/ppc64 arches
Thu May 24 14:00:00 2012 Stephen Gallagher - 1.8.0-30
- Resolves: rhbz#824616 - sssd_nss crashes when configured with
use_fully_qualified_names = true
Tue May 22 14:00:00 2012 Stephen Gallagher - 1.8.0-29
- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in
_tevent_schedule_immediate()
Wed May 16 14:00:00 2012 Stephen Gallagher - 1.8.0-28
- Resolves: rhbz#822236 - SSSD netgroups do not honor
entry_cache_nowait_percentage
Fri May 11 14:00:00 2012 Stephen Gallagher - 1.8.0-27
- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client
upgrade
- Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers
Thu May 10 14:00:00 2012 Stephen Gallagher - 1.8.0-26
- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names
- Resolves: rhbz#819063 - sssd fails to provide partial data till paged search
returns \"Size Limit Exceeded\"
- Resolves: rhbz#820585 - Group enumeration fails in proxy provider
Mon Apr 30 14:00:00 2012 Stephen Gallagher - 1.8.0-25
- Resolves: rhbz#816616 - group members are now lowercased in case insensitive
domains
Wed Apr 25 14:00:00 2012 Stephen Gallagher - 1.8.0-24
- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS
top level directory is chowned by a SSSD user
Fri Apr 20 14:00:00 2012 Stephen Gallagher - 1.8.0-23
- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding
- Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the
same user
- Resolves: rhbz#812281 - autofs client: map name length used as key length
- Related: rhbz#784870 - SSSD fails during autodetection of search bases for
new LDAP features
- Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes
Mon Apr 9 14:00:00 2012 Stephen Gallagher - 1.8.0-22
- Fix typo in patch for SSH umask
- Related: rhbz#808107 - Coverity revealed memory management defects
Mon Apr 9 14:00:00 2012 Stephen Gallagher - 1.8.0-21
- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm
- Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is
running
- Resolves: rhbz#808107 - Coverity revealed memory management defects
Fri Mar 30 14:00:00 2012 Stephen Gallagher - 1.8.0-20
- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with
case_sensitive=false
Fri Mar 30 14:00:00 2012 Stephen Gallagher - 1.8.0-18
- Resolves: rhbz#804057 - Initial service lookups having name with uppercase
alphabets doesn\'t work
- Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names
doesn\'t work when case_sensitive=false
- Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple
realms in a single keytab
- Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with
case_sensitive=false
- Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name
resolution times out
- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS
top level directory is chowned by a SSSD user
Fri Mar 16 13:00:00 2012 Stephen Gallagher - 1.8.0-17
- Related: rhbz#802207 - getent netgroup hangs when
\"use_fully_qualified_names = TRUE\" in sssd
- Resolves: rhbz#801719 - \"Error looking up public keys\" while ssh to replica
using IP address
- Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with
case_sensitive=false
- Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set
- Resolves: rhbz#805034 - accessing an undefined variable might cause crash
- Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login
Mon Mar 12 13:00:00 2012 Stephen Gallagher - 1.8.0-15
- Update translations
- Resolves: rhbz#802372 - Pick up latest translation files for SSSD
- Resolves: rhbz#802207 - getent netgroup hangs when
\"use_fully_qualified_names = TRUE\" in sssd
- Related: rhbz#801451 - Logging in with ssh pub key should consult
authentication authority policies
Fri Mar 9 13:00:00 2012 Stephen Gallagher - 1.8.0-12
- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search
requests
- Resolves: rhbz#801451 - Logging in with ssh pub key should consult
authentication authority policies
- Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials
- Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to
true
- Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn\'t work
- Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false
- Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam
can use
- Resolves: rhbz#799971 - sssd_be crashes on shutdown
- Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested
group structure
- Resolves: rhbz#801368 - Group lookups doesn\'t return members with proxy
provider configured
- Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd
is configured as proxy provider
Thu Mar 1 13:00:00 2012 Stephen Gallagher - 1.8.0-11
- Do not auto-upgrade debug levels
- Tool still available for manual use
- Reverts: rhbz#753763 - Provide logging configuration compatibility on
SSSD 1.5/1.6 upgrade
- Resolves: rhbz#798881 - Install-time warnings
- Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also
the dns_discovery_domain
- Resolves: rhbz#798655 - Password logins failing due to a process with high
UID
Wed Feb 29 13:00:00 2012 Stephen Gallagher - 1.8.0-10
- Fix explicit requires to use openldap instead of openldap-libs
- Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs
openldap >= openldap-2.4.23-20.el6.x86_64
Tue Feb 28 13:00:00 2012 Stephen Gallagher - 1.8.0-9
- Fix multilib-clean issue due to upgrade script
- Remove old copy from the spec file
- Related: rhbz#753763 - Provide logging configuration compatibility on
SSSD 1.5/1.6 upgrade
Tue Feb 28 13:00:00 2012 Stephen Gallagher - 1.8.0-8