SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

 
 
Changelog for ipa-client-4.6.8-5.sl7_9.17.x86_64.rpm :
Tue Jun 11 14:00:00 2024 Scientific Linux Auto Patch Process
- Added Source: ipa-spec-debrand.patch
--> remove TUV\'s Artwork
- Added Source: ipa-spec-fix-osrelease.patch
--> Force use of rhel as the ipaplatform
- Added Source: ipa.ini
--> Config file for automated patch script

Tue Jun 4 14:00:00 2024 Julien Rische - 4.6.8-5.el7_9.17
- Resolves: RHEL-29926 ipa: user can obtain a hash of the passwords of all domain users and perform offline brute force

Tue Nov 21 13:00:00 2023 Florence Blanc-Renaud - 4.6.8-5.el7_9.16
- Resolves: RHEL-12570 ipa: Invalid CSRF protection

Thu Aug 3 14:00:00 2023 Florence Blanc-Renaud - 4.6.8-5.el7_9.15
- Resolves: 2209636 libipa_otp_lasttoken plugin memory leak

Thu Mar 23 13:00:00 2023 Florence Blanc-Renaud - 4.6.8-5.el7_9.14
- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
- ipaserver: deepcopy objectclasses list from IPA config

Mon Mar 20 13:00:00 2023 Florence Blanc-Renaud - 4.6.8-5.el7_9.13
- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
- Defer creating the final krb5.conf on clients
- Move client certificate request after krb5.conf is created
- server install: remove error log about missing bkup file

Wed Oct 5 14:00:00 2022 Florence Blanc-Renaud - 4.6.8-5.el7_9.12
- Resolves: 2084223 - \'ipa idview-show idviewname\' & IPA WebUI takes longer time to return the results
- idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
- ipa otptoken-sync: return error when sync fails
- ipatests: add negative test for otptoken-sync
- ipatests: python2 does not support f-strings
- Fix otptoken_sync plugin

Tue May 10 14:00:00 2022 Florence Blanc-Renaud - 4.6.8-5.el7_9.11
- Resolves: 2082272 - [RFE] Require confirmation to change \"Default host group\" in IdM automember rules
- WebUI: Add confirmation dialog for changing default user/host group

Thu Dec 2 13:00:00 2021 Florence Blanc-Renaud - 4.6.8-5.el7_9.10
- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server
- Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
- SMB: switch IPA domain controller role

Wed Sep 8 14:00:00 2021 Florence Blanc-Renaud - 4.6.8-5.el7_9.9
- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
- extdom: return LDAP_NO_SUCH_OBJECT if domains differ

Tue Jun 22 14:00:00 2021 Florence Blanc-Renaud - 4.6.8-5.el7_9.7
- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
- CA less installation: non ASCII chars in CA subject
- ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
- Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server

Tue May 11 14:00:00 2021 Florence Blanc-Renaud - 4.6.8-5.el7_9.6
- Resolves: #1959349 - Need to bump pki + ds version

Tue Apr 6 14:00:00 2021 Florence Blanc-Renaud - 4.6.8-5.el7_9.5
- Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
- ipa-kdb: fix compiler warnings
- ipa-kdb: add missing prototypes
- ipa-kdb: reformat ipa_kdb_certauth
- ipa-kdb: mark test functions as static
- ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
- Resolves: #1835741 krb5kdc crashing on ipa server
- Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.

Fri Jan 29 13:00:00 2021 Florence Blanc-Renaud - 4.6.8-5.el7_9.4
- Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
- wgi/plugins.py: ignore empty plugin directories
- Resolves: #1895197 improve IPA PKI susbsystem detection by other means than a directory presence, use pki-server subsystem-find
- Improve PKI subsystem detection
- ipatests: add test for PKI subsystem detection
- ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
- Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
- Add more indices
- Resolves: #1884819 IdM Web UI shows users as disabled
- fix cert-find errors in CA-less deployment
- Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
- CAless installation: set the perms on KDC cert file
- ipatests: check KDC cert permissions in CA less install
- Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing
 
ICM