- Resolves: RHEL-165978 - Replication halt caused by an incorrect setting of "nsslapd-changelogmaxage"
- Resolves: RHEL-166003 - Crash in replica_config_add when manually configuring a replica with an incorrect nsds5ReplicaRoot.
- Resolves: RHEL-166004 - Possible memory leak when using the Retro Changelog plugin.
- Resolves: RHEL-168908 - ns-slapd fails to shutdown when deferred memberof update is in progress
- Resolves: RHEL-168964 - Web console doesn't show the sub suffix of ou=foo,ou=people,dc=example,dc=com. [rhel-9]
- Resolves: RHEL-168972 - Replica installation is failing with message MDB_BAD_VALSIZE: Unsupported size of key/DB name/data, or wrong DUPFIXED [rhel-9]
- Resolves: RHEL-169530 - Rebase 389-ds-base to 2.9.x
- Resolves: RHEL-170270 - DS 12 does not handle escape char in bind user [rhel-9]
- Resolves: RHEL-170275 - dnaSharedConfig: "dnaPortNum: 0" [rhel-9]
- Resolves: RHEL-170280 - Memory leaks in syncrepl plugin during persistent search operations [rhel-9]
- Resolves: RHEL-170287 - access log - suspicious wtime optime negative and large values in internal op [rhel-9]
- Resolves: RHEL-170477 - An online reinitialization with LMDB is terminating the receiving server [rhel-9]
- Resolves: RHEL-170480 - dsctl healthcheck DSMOLE0001 inaccurate recommendations when there is more than 1 LDAP backend [rhel-9]
- Resolves: RHEL-170651 - passwordbadwords attribute of the local password policy is not functioning [rhel-9]
- Resolves: RHEL-170732 - Memory leaks in IPA context on server restart [rhel-9]
- Resolves: RHEL-174525 - [RFE] Add OS-level thread names to all server threads [rhel-9]
- Resolves: RHEL-180717 - Online export is failing when using the option "-s" [rhel-9]
- Resolves: RHEL-117050 - Replication online reinitialization of a large database gets stalled. [rhel-9]
- Resolves: RHEL-123279 - The new ipahealthcheck test ipahealthcheck.ds.backends.BackendsCheck raises CRITICAL issue [rhel-9]
- Resolves: RHEL-140275 - ipa-healthcheck is complaining about missing or incorrectly configured system indexes. [rhel-9]
- Resolves: RHEL-142980 - Scalability issue of replication online initialization with large database [rhel-9]
- Resolves: RHEL-146899 - memory corruption in alias entry plugin [rhel-9]
- Resolves: RHEL-147212 - Access logs are not getting deleted as configured. [rhel-9]
- Resolves: RHEL-150907 - Remove memberof_del_dn_from_groups from MemberOf plugin [rhel-9]
- Resolves: RHEL-117050 - Replication online reinitialization of a large database gets stalled. [rhel-9]
- Resolves: RHEL-123244 - Attribute uniqueness is not enforced upon modrdn operation [rhel-9]
- Resolves: RHEL-123279 - The new ipahealthcheck test ipahealthcheck.ds.backends.BackendsCheck raises CRITICAL issue [rhel-9]
- Resolves: RHEL-140275 - ipa-healthcheck is complaining about missing or incorrectly configured system indexes. [rhel-9]
- Resolves: RHEL-142980 - Scalability issue of replication online initialization with large database [rhel-9]
- Resolves: RHEL-146899 - memory corruption in alias entry plugin [rhel-9]
- Resolves: RHEL-147212 - Access logs are not getting deleted as configured. [rhel-9]
- Resolves: RHEL-111229 - Error showing local password policy on web UI [rhel-9]
- Resolves: RHEL-112680 - Statistics about index lookup report a wrong duration [rhel-9]
- Resolves: RHEL-116426 - RetroCL plugin generates invalid LDIF [rhel-9]
- Resolves: RHEL-117050 - Replication online reinitialization of a large database gets stalled. [rhel-9]
- Resolves: RHEL-117748 - The numSubordinates value is not matching the number of direct children. [rhel-9]
- Resolves: RHEL-117771 - When deferred memberof update is enabled after the server crashed it should not launch memberof fixup task by default
- Resolves: RHEL-117782 - Ignore the memberOfDeferredUpdate setting when LMDB is used. [rhel-9]
- Resolves: RHEL-121170 - Units for changing MDB max size are not consistent across different tools [rhel-9]
- Resolves: RHEL-123231 - Improve the way to detect asynchronous operations in the access logs [rhel-9]
- Resolves: RHEL-123244 - Attribute uniqueness is not enforced upon modrdn operation [rhel-9]
- Resolves: RHEL-123258 - Typo in errors log after a Memberof fixup task. [rhel-9]
- Resolves: RHEL-123272 - LDAP high CPU usage while handling indexes with IDL scan limit at INT_MAX [rhel-9]
- Resolves: RHEL-123279 - The new ipahealthcheck test ipahealthcheck.ds.backends.BackendsCheck raises CRITICAL issue [rhel-9]
- Resolves: RHEL-123368 - IPA health check up script shows time skew is over 24 hours [rhel-9]
- Resolves: RHEL-123766 - 389-ds-base OpenScanHub Leaks Detected [rhel-9]
- Resolves: RHEL-123893 - Improve output dsctl dbverify when backend does not exist [rhel-9]
- Resolves: RHEL-123897 - [WebUI] Replication tab crashes after enabling replication as a consumer [rhel-9]
- Resolves: RHEL-123923 - Changelog trimming - add number of scanned entries to the log [rhel-9]
- Resolves: RHEL-126552 - RHDS 12.6 doesn't handle 'ldapsearch' filter with space char in DN name correctly [rhel-9]
- Resolves: RHEL-129559 - Online initialization of consumers fails with error -23 [rhel-9]
- Resolves: RHEL-129580 - Fix paged result search locking [rhel-9]
- Resolves: RHEL-138481 - Memory leak observed in ns-slapd with 389-ds-base-2.6.1-12 [rhel-9]
- Resolves: RHEL-139825 - Rebase 389-ds-base to 2.8.x
- Resolves: RHEL-140089 - Upgrading IDM to latest version: 389-ds-base and ipa-server breaks replication [rhel-9]
- Resolves: RHEL-104591 - RHDS12: Web console doesn't show Server Version [rhel-9]
- Resolves: RHEL-104593 - The numSubordinates value is not matching the number of direct children. [rhel-9]
- Resolves: RHEL-109034 - Allow Uniqueness plugin to search uniqueness attributes using custom matching rules [rhel-9]
- Resolves: RHEL-109885 - Wrong backend database name syntax causes "Red Hat Directory Server" => "Databases" menu blank in Cockpit [rhel-9]
- Resolves: RHEL-109889 - RootDN Access Control Plugin with wildcards for IP addresses fails with an error "Invalid IP address" [rhel-9]
- Resolves: RHEL-109892 - On RHDS 12.6 The user password policy for a user was created, but the pwdpolicysubentry attribute for this user incorrectly points to the People OU password policy instead of the specific user policy. [rhel-9]
- Resolves: RHEL-109897 - AddressSanitizer: leak in do_search [rhel-9]
- Resolves: RHEL-113981 - AddressSanitizer: memory leak in memberof_add_memberof_attr [rhel-9]
- Resolves: RHEL-104591 - RHDS12: Web console doesn't show Server Version [rhel-9]
- Resolves: RHEL-104593 - The numSubordinates value is not matching the number of direct children. [rhel-9]
- Resolves: RHEL-109034 - Allow Uniqueness plugin to search uniqueness attributes using custom matching rules [rhel-9]
- Resolves: RHEL-109885 - Wrong backend database name syntax causes "Red Hat Directory Server" => "Databases" menu blank in Cockpit [rhel-9]
- Resolves: RHEL-109889 - RootDN Access Control Plugin with wildcards for IP addresses fails with an error "Invalid IP address" [rhel-9]
- Resolves: RHEL-109892 - On RHDS 12.6 The user password policy for a user was created, but the pwdpolicysubentry attribute for this user incorrectly points to the People OU password policy instead of the specific user policy. [rhel-9]
- Resolves: RHEL-109897 - AddressSanitizer: leak in do_search [rhel-9]
- Resolves: RHEL-113981 - AddressSanitizer: memory leak in memberof_add_memberof_attr [rhel-9]
- Resolves: RHEL-89762 - dsidm Error: float() argument must be a string or a number, not 'NoneType' [rhel-9]
- Resolves: RHEL-92041 - Memory leak in roles_cache_create_object_from_entry
- Resolves: RHEL-95444 - ns-slapd[xxxx]: segfault at 10d7d0d0 ip 00007ff734050cdb sp 00007ff6de9f1430 error 6 in libslapd.so.0.1.0[7ff733ec0000+1b3000] [rhel-9]
- Resolves: RHEL-104821 - ipa-restore fails to restore SELinux contexts, causes ns-slapd AVC denials on /dev/shm after restore.
- Resolves: RHEL-107005 - Failure to get Server monitoring data when NDN cache is disabled. [rhel-9]
- Resolves: RHEL-107581 - segfault - error 4 in libpthread-2.28.so [rhel-9]
- Resolves: RHEL-107585 - ns-slapd crashed when we add nsslapd-referral [rhel-9]
- Resolves: RHEL-107586 - CWE-284 dirsrv log rotation creates files with world readable permission [rhel-9]
- Resolves: RHEL-107587 - CWE-532 Created user password hash available to see in audit log [rhel-9]
- Resolves: RHEL-107588 - CWE-778 Log doesn't show what user gets password changed by administrator [rhel-9]
- Resolves: RHEL-61347 - Directory Server is unavailable after a restart with nsslapd-readonly=on and consumes 100% CPU
- Resolves: RHEL-77983 - Defects found by OpenScanHub
- Resolves: RHEL-79673 - Improve the "result" field of ipa-healthcheck if replicas are busy
- Resolves: RHEL-80496 - Can't rename users member of automember rule [rhel-9]
- Resolves: RHEL-81141 - Healthcheck tool should warn admin about creating a substring index on membership attribute [rhel-9]
- Resolves: RHEL-89736 - dsconf backend replication monitor fails if replica id starts with 0 [rhel-9]
- Resolves: RHEL-89745 - ns-slapd crash in dbmdb_import_prepare_worker_entry() [rhel-9]
- Resolves: RHEL-89753 - Nested group does not receive memberOf attribute [rhel-9]
- Resolves: RHEL-89769 - Crash in __strlen_sse2 when using the nsRole filter rewriter. [rhel-9]
- Resolves: RHEL-89782 - RHDS12.2 NSMMReplicationPlugin - release_replica Unable to parse the response [rhel-9]
- Resolves: RHEL-95768 - Improve error message when bulk import connection is closed [rhel-9]
- Resolves: RHEL-101189 - lib389/replica.py is using unexisting datetime.UTC in python3.9
- Resolves: RHEL-18333 Can't rename users member of automember rule
- Resolves: RHEL-61341 After an initial failure, subsequent online backups will not work.
- Resolves: RHEL-63887 nsslapd-mdb-max-dbs autotuning doesn't work properly
- Resolves: RHEL-63891 dbscan crashes when showing statistics for MDB
- Resolves: RHEL-63998 dsconf should check for number of available named databases
- Resolves: RHEL-78344 During import of entries without nsUniqueId, a supplier generates duplicate nsUniqueId (LMDB only) [rhel-9]
- Resolves: RHEL-5151 - [RFE] defer memberof nested updates
- Resolves: RHEL-54148 - leaked_storage: Variable "childelems" going out of scope leaks the storage it points to.
- Resolves: RHEL-60135 - deadlock during cleanAllRuv
- Resolves: RHEL-61341 - After an initial failure, subsequent online backups will not work.
- Resolves: RHEL-61349 - Remove deprecated setting for HR time stamps in logs
- Resolves: RHEL-62875 - Passwords are not being updated to use the configured storage scheme ( nsslapd-enable-upgrade-hash is enabled ).
- Resolves: RHEL-64438 - VLV errors with RSNv3 and pruning enabled [rhel-9]
- Resolves: RHEL-64854 - cleanallruv consums CPU and is slow
- Resolves: RHEL-65506 - AddressSanitizer: double-free
- Resolves: RHEL-65512 - AddressSanitizer: heap-use-after-free in import_abort_all
- Resolves: RHEL-65561 - LeakSanitizer: detected memory leaks in dbmdb_public_db_op
- Resolves: RHEL-65662 - Replication issue between masters using cert based authentication
- Resolves: RHEL-65664 - LDAP unprotected search query during certificate based authentication
- Resolves: RHEL-65665 - Ambiguous warning about SELinux in dscreate for non-root user
- Resolves: RHEL-65741 - LeakSanitizer: memory leak in ldbm_entryrdn.c
- Resolves: RHEL-65776 - Wrong set of entries returned for some search filters [rhel-9]
- Resolves: RHEL-67004 - "dsconf config replace" should handle multivalued attributes.
- Resolves: RHEL-67005 - Online backup hangs sporadically.
- Resolves: RHEL-67008 - Some replication status data are reset upon a restart.
- Resolves: RHEL-67020 - 389DirectoryServer Process Stops When Setting up Sorted VLV Index
- Resolves: RHEL-67024 - Some nsslapd-haproxy-trusted-ip values are discarded upon a restart.
- Resolves: RHEL-69806 - ipahealthcheck.ds.replication displays WARNING '1 conflict entries found under the replication suffix'
- Resolves: RHEL-69826 - "Duplicated DN detected" errors when creating indexes or importing entries. [rhel-9]
- Resolves: RHEL-70127 - Crash in attrlist_find() when the Account Policy plugin is enabled. [rhel-9]
- Resolves: RHEL-70252 - Freelist ordering causes high wtime
- Resolves: RHEL-71218 - Sub suffix causes "id2entry - Could not open id2entry err 0" error when the Directory Server starts [rhel-9]
- Resolves: RHEL-74153 - backup/restore broken [rhel-9]
- Resolves: RHEL-74158 - If an entry RDN is identical to the suffix, then Entryrdn gets broken during a reindex [rhel-9]
- Resolves: RHEL-74163 - Crash during bind when acct policy plugin does not have "alwaysrecordlogin" set [rhel-9]
- Resolves: RHEL-74168 - On replica consumer, account policy plugin fails to manage the last login history [rhel-9]
- Resolves: RHEL-74174 - Replication broken after backup restore with freeipa configuration [rhel-9]
- Resolves: RHEL-74353 - nsslapd-haproxy-trusted-ip is not in schema [rhel-9]
- Resolves: RHEL-76019 - IPA LDAP error code T3 when no exceeded time limit from a paged search result [rhel-9]
- Resolves: RHEL-5108 - ns-slapd crash in referint_get_config
- Resolves: RHEL-5113 - nsslapd-numlisteners limit is not enforced
- Resolves: RHEL-5115 - `dscreate ds-root` accepts relative path
- Resolves: RHEL-5131 - ldif2db can be very slow
- Resolves: RHEL-5138 - Logconv.pl CSV file contains mismatched header and data columns
- Resolves: RHEL-14760 - ns-slapd crash in vlvIndex_delete
- Resolves: RHEL-17511 - nsslapd-idletimeout is ignored
- Resolves: RHEL-49454 - perf search result investigation for many large static groups and members
- Resolves: RHEL-49458 - subsuffix are not returned in one level scoped search
Resolves: RHEL-44324 - unauthenticated user can trigger a DoS by sending a specific extended search request
Resolves: RHEL-40946 - Malformed userPassword hash may cause Denial of Service
Resolves: RHEL-33087 - dsconf schema does not show inChain matching rule
Resolves: RHEL-28177 - Malformed userPassword may cause crash at do_modify in slapd/modify.c
Resolves: RHEL-25070 - nsslapd-haproxy-trusted-ip is not in schema
Resolves: RHEL-31777 - Rebase 389-ds-base.2.5.1 in RHEL 9.5
Resolves: RHEL-33348 - redhat-ds:11/389-ds-base: potential denial of service via specially crafted kerberos AS-REQ requ
Resolves: RHEL-15907 - Rebase 389-ds-base in RHEL 9.4
Resolves: RHEL-5142 - RFE Disable Transparent Huge Pages when using large caches
Resolves: RHEL-5130 - RFE Add PROXY protocol support to 389-ds-base via confiuration item - similar to Postfix
Resolves: RHEL-5133 - RFE Provide a history for 'LastLoginTime'
Resolves: RHEL-16984 - RFE inChain Matching Rule
Resolves: RHEL-15907 - Rebase 389-ds-base in RHEL 9.4
Resolves: RHEL-5142 - RFE Disable Transparent Huge Pages when using large caches
Resolves: RHEL-5130 - RFE Add PROXY protocol support to 389-ds-base via confiuration item - similar to Postfix
Resolves: RHEL-5133 - RFE Provide a history for 'LastLoginTime'
Resolves: RHEL-16984 - RFE inChain Matching Rule
Resolves: rhbz#2225532 - 389-ds-base FTBFS with rust-1.71.0
Resolves: rhbz#2218209 - useradd: invalid user ID '389:389': installing 389-ds-base in container fails to create the dirsrv user
Resolves: rhbz#2207691 - python3-lib389: Python tarfile extraction needs change to avoid a warning
Resolves: rhbz#2179278 - dirsrv failed to start after reboot because "dirsrv" did not have access on /run/dirsrv
Resolves: rhbz#2189954 - RFE Improve reponse time to filters containing 'nsrole'
Resolves: rhbz#2189946 - RFE support of slapi_memberof for plugins/core server
Resolves: rhbz#1974242 - Paged search impacts performance
Resolves: rhbz#2142636 - pam mutex lock causing high etimes, affecting red hat internal sso
Resolves: rhbz#2093981 - RFE - Create Security Audit Log
Resolves: rhbz#2132697 - [RFE] 389ds: run as non-root
Resolves: rhbz#2124660 - Retro changelog trimming uses maxage incorrectly
Resolves: rhbz#2114039 - Current pbkdf2 hardcoded parameters are no longer secure
Resolves: rhbz#2112998 - performance search rate: checking if an entry is a referral is expensive
Resolves: rhbz#2112361 - Supplier should do periodic update to avoid slow replication when a new direct update happen
Resolves: rhbz#2109891 - Migrate 389 to pcre2
Resolves: Bug 2061801 - rebase 389-ds-base to 2.1.3
Resolves: Bug 1872451 - RFE - run as non-root
Resolves: Bug 2052527 - RFE - Provide an option to abort an Auto Member rebuild task
Resolves: Bug 2057056 - Import may break the replication because changelog starting csn may not be created
Resolves: Bug 2057063 - Add support for recursively deleting subentries
Resolves: Bug 2062778 - sending crafted message could result in DoS
Resolves: Bug 2064781 - expired password was still allowed to access the database
Resolves: Bug 2100337 - dsconf backend export userroot fails ldap.DECODING_ERROR