- Resolves: RHEL-18041 - [RFE] When there are multiple backends cache auto-tune should adapt its tuning
- Resolves: RHEL-58682 - [RFE] modify entry cache eviction strategy to allow large groups to stay in the cache
- Resolves: RHEL-64019 - Units for changing MDB max size are not consistent across different tools
- Resolves: RHEL-83274 - Replication online reinitialization of a large database gets stalled.
- Resolves: RHEL-83852 - LDAP high CPU usage while handling indexes with IDL scan limit at INT_MAX
- Resolves: RHEL-86534 - [RFE] Support Dynamic Groups similar to OpenLDAP
- Resolves: RHEL-89601 - (&(cn:dn:=groups)) no longer returns results
- Resolves: RHEL-94025 - PAM Pass Through Authentication Plugin processes requests for accounts that do not meet the criteria specified in the `pamFilter` option.
- Resolves: RHEL-95395 - Getting "build_candidate_list - Database error 11" messages after migrating to LMDB.
- Resolves: RHEL-96196 - Duplicate/double local password policy entry display from redhat directory server webconsole
- Resolves: RHEL-99331 - [RFE] Need an option with dsconf to delete all the conflicts at once instead of deleting each conflict one after the other
- Resolves: RHEL-105578 - IPA health check up script shows time skew is over 24 hours
- Resolves: RHEL-106502 - Ignore the memberOfDeferredUpdate setting when LMDB is used.
- Resolves: RHEL-106559 - When deferred memberof update is enabled after the server crashed it should not launch memberof fixup task by default
- Resolves: RHEL-106849 - Abort the offline import if the root entry cannot be added.
- Resolves: RHEL-107003 - Improve output dsctl dbverify when backend does not exist
- Resolves: RHEL-109113 - [RFE] memberOf plugin - Add scope for specific groups
- Resolves: RHEL-111219 - Attribute uniqueness is not enforced upon modrdn operation
- Resolves: RHEL-113965 - RetroCL plugin generates invalid LDIF
- Resolves: RHEL-115179 - Several password related attributes are not replicating from the Replicas to the Masters
- Resolves: RHEL-115484 - ns-slapd crash in libdb, possible memory corruption
- Resolves: RHEL-116060 - Fix paged result search locking
- Resolves: RHEL-117124 - Missing access JSON logging for TLS/CLient auth
- Resolves: RHEL-117140 - Changelog trimming - add number of scanned entries to the log
- Resolves: RHEL-117520 - Typo in errors log after a Memberof fixup task.
- Resolves: RHEL-121208 - [RFE] Make nsslapd-haproxy-trusted-ip accept whole subnets
- Resolves: RHEL-122625 - ipa-healthcheck is complaining about missing or incorrectly configured system indexes.
- Resolves: RHEL-122674 - [WebUI] Replication tab crashes after enabling replication as a consumer
- Resolves: RHEL-123220 - Improve the way to detect asynchronous operations in the access logs
- Resolves: RHEL-123275 - The new ipahealthcheck test ipahealthcheck.ds.backends.BackendsCheck raises CRITICAL issue
- Resolves: RHEL-123663 - Online initialization of consumers fails with error -23
- Resolves: RHEL-123664 - RHDS 12.6 doesn't handle 'ldapsearch' filter with space char in DN name correctly
- Resolves: RHEL-123762 - 389-ds-base OpenScanHub Leaks Detected
- Resolves: RHEL-124694 - Access logs are not getting deleted as configured.
- Resolves: RHEL-126535 - memory corruption in alias entry plugin
- Resolves: RHEL-128906 - Scalability issue of replication online initialization with large database
- Resolves: RHEL-129675 - Can't locate CSN error seen in errors log when replicating after importing data from ldif files
- Resolves: RHEL-131129 - ns-slapd[2233]: segfault at 0 ip 00007f1f1d7cd7fc sp 00007f1e775fc070 error 4 in libjemalloc.so.2[7f1f1d738000+ac000] on 389-ds-base-2.6.1-11
- Resolves: RHEL-133795 - Memory leak observed in ns-slapd with 389-ds-base-2.6.1-12
- Resolves: RHEL-139826 - Rebase 389-ds-base to 3.2.x
- Resolves: RHEL-101783 - RHDS12: Web console doesn't show Server Version
- Resolves: RHEL-109018 - Allow Uniqueness plugin to search uniqueness attributes using custom matching rules
- Resolves: RHEL-111224 - Error showing local password policy on web UI
- Resolves: RHEL-112675 - Statistics about index lookup report a wrong duration
- Resolves: RHEL-112689 - Crash if repl keep alive entry can not be created
- Resolves: RHEL-112722 - Exception thrown by dsconf instance repl get_ruv
- Resolves: RHEL-113969 - AddressSanitizer: memory leak in memberof_add_memberof_attr
- Resolves: RHEL-79079 - Failure to get Server monitoring data when NDN cache is disabled.
- Resolves: RHEL-87352 - ns-slapd crashed when we add nsslapd-referral
- Resolves: RHEL-92054 - Memory leak in roles_cache_create_object_from_entry [rhel-10]
- Resolves: RHEL-107001 - ipa-restore fails to restore SELinux contexts, causes ns-slapd AVC denials on /dev/shm after restore. [rhel-10]
- Resolves: RHEL-107028 - CWE-284 dirsrv log rotation creates files with world readable permission
- Resolves: RHEL-107035 - CWE-532 Created user password hash available to see in audit log
- Resolves: RHEL-107037 - CWE-778 Log doesn't show what user gets password changed by administrator
- Resolves: RHEL-31959 - [RFE] add plugin origin or source in security's log msg info
- Resolves: RHEL-35241 - ns-slapd crashes in referral mode
- Resolves: RHEL-61327 - Incomplete messages about replication in the errors log.
- Resolves: RHEL-61353 - dbscan on replication changelog does not display MOD_TYPE
- Resolves: RHEL-62874 - dsidm: issue when renaming users
- Resolves: RHEL-65660 - DSIDM: Re-enabling user accounts that reached inactivity limit fails with error
- Resolves: RHEL-67003 - dsconf backend replication monitor fails if replica id starts with 0
- Resolves: RHEL-67006 - dsconf utility should let you configure the "uniqueness-exclude-subtrees" parameter of the Attribute Uniqueness plug-in
- Resolves: RHEL-67019 - Crash in __strlen_sse2 when using the nsRole filter rewriter.
- Resolves: RHEL-67022 - Password modify extended operation should skip password policy checks when executed by root DN
- Resolves: RHEL-70117 - Unify how group description can be added to a new group in WebUI and CLU
- Resolves: RHEL-74085 - Increased memory consumption caused by NDN cache
- Resolves: RHEL-74270 - [RFE] Implement "list-dn" option for dsidm tool in Directory Server
- Resolves: RHEL-76832 - Wrong backend database name syntax causes "Red Hat Directory Server" => "Databases" menu blank in Cockpit
- Resolves: RHEL-76837 - dsidm Error: float() argument must be a string or a number, not 'NoneType'
- Resolves: RHEL-76840 - Monitoring tab should use dsconf monitor
- Resolves: RHEL-77490 - Complete remove the parameter "nsslapd-subtree-rename-switch" from DS-12
- Resolves: RHEL-79080 - Json option does not work with "dsidm account get-by-dn" command
- Resolves: RHEL-80252 - [RFE] Structured (JSON) logging option for RHDS access and error logs
- Resolves: RHEL-80253 - RHDS hangs when having online backup running together with automember_rebuild task executing
- Resolves: RHEL-80497 - Can't rename users member of automember rule [rhel-10]
- Resolves: RHEL-81277 - logconv.py fails when specific timestamps are provided
- Resolves: RHEL-83850 - mdb database statistics don't work
- Resolves: RHEL-86279 - Cannot create a nested role using "dsidm role create-nested"
- Resolves: RHEL-86280 - Cannot create a filtered role using "dsidm role create-filtered"
- Resolves: RHEL-86313 - RootDN Access Control Plugin with wildcards for IP addresses fails with an error "Invalid IP address"
- Resolves: RHEL-86314 - dsidm failing with error "argument must be a string or a number"
- Resolves: RHEL-86315 - Dsidm get_dn option fails for organizational unit, service and posixgroup
- Resolves: RHEL-86316 - Dsidm uniquegroup members option does not work
- Resolves: RHEL-86321 - dsidm role rename-by-dn does not rename a role
- Resolves: RHEL-86322 - dsidm role subtree-status doesn't work
- Resolves: RHEL-86323 - dsidm role get-by-dn doesn't work properly with -j option
- Resolves: RHEL-86324 - Deleting a role with dsidm results in proper deletion message, but role is still present
- Resolves: RHEL-86785 - dscontainer: support loading custom schema
- Resolves: RHEL-86878 - segfault at 7ff2370010c8 ip 00007ff2339ba239 sp 00007fed321fe100 error 6 in liblmdb.so.0.0.0
- Resolves: RHEL-89748 - Nested group does not receive memberOf attribute
- Resolves: RHEL-89774 - Improve the "result" field of ipa-healthcheck if replicas are busy [rhel-10]
- Resolves: RHEL-89776 - RHDS12.2 NSMMReplicationPlugin - release_replica Unable to parse the response
- Resolves: RHEL-95441 - ns-slapd[xxxx]: segfault at 10d7d0d0 ip 00007ff734050cdb sp 00007ff6de9f1430 error 6 in libslapd.so.0.1.0[7ff733ec0000+1b3000]
- Resolves: RHEL-95761 - Improve error message when bulk import connection is closed
- Resolves: RHEL-97565 - On RHDS 12.6 The user password policy for a user was created, but the pwdpolicysubentry attribute for this user incorrectly points to the People OU password policy instead of the specific user policy.
- Resolves: RHEL-101926 - ipa-backup failed with error : 'No such file or directory: '/usr/sbin/dsctl'
- Resolves: RHEL-5141 - [RFE] For each request, a ldap client can assign an identifier to be added in the logs
- Resolves: RHEL-77948 - ns-slapd crashes with data directory ≥ 2 days old [rhel-10]
- Resolves: RHEL-78342 - During import of entries without nsUniqueId, a supplier generates duplicate nsUniqueId (LMDB only)
- Resolves: RHEL-1681 - [RFE] Log buffering for all log types
- Resolves: RHEL-5141 - [RFE] For each request, a ldap client can assign an identifier to be added in the logs
- Resolves: RHEL-38917 - dscreate interactive install shows a traceback when mdb is selected
- Resolves: RHEL-42485 - [RFE] pbkdf2 hardcoded parameters should be turned into configuration options
- Resolves: RHEL-59513 - [RFE] Port logconv.pl to python
- Resolves: RHEL-61253 - Make online import more robust
- Resolves: RHEL-69819 - "Duplicated DN detected" errors when creating indexes or importing entries. [rhel-10.0]
- Resolves: RHEL-70122 - Crash in attrlist_find() when the Account Policy plugin is enabled.
- Resolves: RHEL-74149 - backup/restore broken
- Resolves: RHEL-74154 - If an entry RDN is identical to the suffix, then Entryrdn gets broken during a reindex
- Resolves: RHEL-74159 - Crash during bind when acct policy plugin does not have "alwaysrecordlogin" set
- Resolves: RHEL-74164 - On replica consumer, account policy plugin fails to manage the last login history
- Resolves: RHEL-76020 - IPA LDAP error code T3 when no exceeded time limit from a paged search result [rhel-10]
- Resolves: RHEL-76838 - Unlocked and locked users having same error output
- Resolves: RHEL-76841 - Healthcheck tool should warn admin about creating a substring index on membership attribute
Resolves: RHEL-46801 - unauthenticated user can trigger a DoS by sending a specific extended search request
Resolves: RHEL-40940 - Malformed userPassword hash may cause Denial of Service
Resolves: RHEL-33336 - potential denial of service via specially crafted kerberos AS-REQ request
Issue 6043, 6044 - Enhance Rust and JS bundling and add SPDX licenses for both (#6045)
Issue 3555 - Remove audit-ci from dependencies (#6056)
Issue 6052 - Paged results test sets hostname to `localhost` on test collection
Issue 6051 - Drop unused pytest markers
Issue 6049 - lmdb - changelog is wrongly recreated by reindex task (#6050)
Issue 6047 - Add a check for tagged commits
Issue 6041 - dscreate ds-root - accepts relative path (#6042)
Switch default backend to lmdb and bump version to 3.0 (#6013)
Issue 6032 - Replication broken after backup restore (#6035)
Issue 6037 - Server crash at startup in vlvIndex_delete (#6038)
Issue 6034 - Change replica_id from str to int
Issue 6028 - vlv index keys inconsistencies (#6031)
Issue 5989 - RFE support of inChain Matching Rule (#5990)
Issue 6022 - lmdb inconsistency between vlv index and vlv cache names (#6026)
Issue 6015 - Fix typo remeber (#6014)
Issue 6016 - Pin upload/download artifacts action to v3
Issue 5939 - During an update, if the target entry is reverted in the entry cache, the server should not retry to lock it (#6007)
Issue 4673 - Update Rust crates
Issue 6004 - idletimeout may be ignored (#6005)
Issue 5954 - Disable Transparent Huge Pages
Issue 5997 - test_inactivty_and_expiration CI testcase is wrong (#5999)
Issue 5993 - Fix several race condition around CI tests (#5996)
Issue 5944 - Reversion of the entry cache should be limited to BETXN plugin failures (#5994)
Bump openssl from 0.10.55 to 0.10.60 in /src (#5995)
Issue 5980 - Improve instance startup failure handling (#5991)
Issue 5976 - Fix freeipa install regression with lmdb (#5977)
Issue 5984 - Crash when paged result search are abandoned - fix2 (#5987)
Issue 5984 - Crash when paged result search are abandoned (#5985)
Issue 5947 - CI test_vlv_recreation_reindex fails on LMDB (#5979)
Issue 5989 - RFE support of inChain Matching Rule (#5990)
Issue 5939 - During an update, if the target entry is reverted in the entry cache, the server should not retry to lock it (#6007)
Issue 5944 - Reversion of the entry cache should be limited to BETXN plugin failures (#5994)
Issue 5954 - Disable Transparent Huge Pages
Issue 5984 - Crash when paged result search are abandoned - fix2 (#5987)
Issue 5984 - Crash when paged result search are abandoned (#5985)
Issue 5971 - CLI - Fix password prompt for repl status (#5972)
Issue 5973 - Fix fedora cop RawHide builds (#5974)
Revert "Issue 5761 - Worker thread dynamic management (#5796)" (#5970)
Issue 5966 - CLI - Custom schema object is removed on a failed edit (#5967)
Issue 5786 - Update permissions for Release workflow
Issue 5960 - Subpackages should have more strict interdependencies
Issue 3555 - UI - Fix audit issue with npm - babel/traverse (#5959)
Issue 4843 - Fix dscreate create-template issue (#5950)
bugfix for --passwd-file not working on latest version (#5934)
Issue 5843 - dsconf / dscreate should be able to handle lmdb parameters (#5943)
Bump postcss from 8.4.24 to 8.4.31 in /src/cockpit/389-console (#5945)
Issue 5938 - Attribute Names changed to lowercase after adding the Attributes (#5940)
issue 5924 - ASAN server build crash when looping opening/closing connections (#5926)
Issue 1925 - Add a CI test (#5936)
Issue 5732 - Localizing Cockpit's 389ds Plugin using CockpitPoPlugin (#5764)
Issue 1870 - Add a CI test (#5929)
Issue 843 - Add a warning to slapi_valueset_add_value_ext (#5925)
Issue 5761 - Worker thread dynamic management (#5796)
Issue 1802 - Improve ldclt man page (#5928)
Issue 1456 - Add a CI test that verifies there is no issue (#5927)
Issue 1317 - Add a CI test (#5923)
Issue 1081 - CI - Add more tests for overwriting x-origin issue (#5815)
Issue 1115 - Add a CI test (#5913)
Issue 5848 - Fix condition and add a CI test (#5916)
Issue 5848 - Fix condition and add a CI test (#5916)
Issue 5914 - UI - server settings page validation improvements and db index fixes
Issue 5909 - Multi listener hang with 20k connections (#5917)
Issue 5902 - Fix previous commit regression (#5919)
pass instance correctly to ds_is_older (#5903)
Issue 5909 - Multi listener hang with 20k connections (#5910)
Issue 5722 - improve testcase (#5904)
Issue 5203 - outdated version in provided metadata for lib389
Bug Description:
issue 5890 part 2 - Need a tester for testing multiple listening thread feature (#5897)
Issue i5846 - Crash when lmdb import is aborted (#5881)
Issue 5894 - lmdb import error fails with Could not store the entry (#5895)
Issue 5890 - Need a tester for testing multiple listening thread feature (#5891)
Issue 5082 - slugify: ModuleNotFoundError when running test cases
Issue 4551 - Part 2 - Fix build warning of previous PR (#5888)
Issue 5834 - AccountPolicyPlugin erroring for some users (#5866)
Issue 5872 - part 2 - fix is_dbi regression (#5887)
Issue 4758 - Add tests for WebUI
Issue 5848 - dsconf should prevent setting the replicaID for hub and consumer roles (#5849)
Issue 5883 - Remove connection mutex contention risk on autobind (#5886)
Issue 5872 - `dbscan()` in lib389 can return bytes
Issue 5156 - RFE that implement slapi_memberof (#5694)
Issue 5734 - RFE - Exclude pwdFailureTime and ContextCSN (#5735)
Issue 5726 - ns-slapd crashing in ldbm_back_upgradednformat (#5727)
Issue 4758 - Add tests for WebUI
Issue 5718 - Memory leak in connection table (#5719)
Issue 5705 - Add config parameter to close client conns on failed bind (#5712)
Issue 4758 - Add tests for WebUI
Issue 5643 - Memory leak in entryrdn during delete (#5717)
Issue 5714 - UI - fix typo, db settings, log settings, and LDAP editor paginations
Issue 5701 - CLI - Fix referral mode setting (#5708)
Bump openssl from 0.10.45 to 0.10.48 in /src (#5709)
Issue 5710 - subtree search statistics for index lookup does not report ancestorid/entryrdn lookups (#5711)
Issue 5697 - Obsolete nsslapd-ldapimaprootdn attribute (#5698)
Issue 1081 - Stop schema replication from overwriting x-origin
Issue 4812 - Listener thread does not scale with a high num of established connections (#5706)
Issue 4812 - Listener thread does not scale with a high num of established connections (#5681)
Bump webpack from 5.75.0 to 5.76.0 in /src/cockpit/389-console (#5699)
Issue 5598 - (3rd) In 2.x, SRCH throughput drops by 10% because of handling of referral (#5692)
Issue 5598 - (2nd) In 2.x, SRCH throughput drops by 10% because of handling of referral (#5691)
Issue 5687 - UI - sensitive information disclosure
Issue 5661 - LMDB hangs while Rebuilding the replication changelog RUV (#5676)
Issue 5554 - Add more tests to security_basic_test suite
Issue 4583 - Update specfile to skip checks of ASAN builds
Issue 4758 - Add tests for WebUI
Issue 3604 - UI - Add support for Subject Alternative Names in CSR
Issue 5600 - buffer overflow when enabling sync repl plugin when dynamic plugins is enabled
Issue 5640 - Update logconv for new logging format
Issue 5162 - CI - fix error message for invalid pem file
Issue 5598 - In 2.x, SRCH throughput drops by 10% because of handling of referral (#5604)
Issue 5671 - covscan - clang warning (#5672)
Issue 5267 - CI - Fix issues with nsslapd-return-original-entrydn
Issue 5666 - CLI - Add timeout parameter for tasks
Issue 5567 - CLI - make ldifgen use the same default ldif name for all options
Issue 5647 - Fix unused variable warning from previous commit (#5670)
Issue 5162 - Lib389 - verify certificate type before adding
Issue 5642 - Build fails against setuptools 67.0.0
Issue 5630 - CLI - need to add logging filter for stdout
Issue 5646 - CLI/UI - do not hardcode password storage schemes
Issue 5640 - Update logconv for new logging format
issue 5647 - covscan: memory leak in audit log when adding entries (#5650)
Issue 5658 - CLI - unable to add attribute with matching rule
Issue 5653 - covscan - fix invalid dereference
Issue 5652 - Libasan crash in replication/cascading_test (#5659)
Issue 5628 - Handle graceful timeout in CI tests (#5657)
Issue 5648 - Covscan - Compiler warnings (#5651)
Issue 5630 - CLI - error messages should goto stderr
Issue 2435 - RFE - Raise IDL Scan Limit to INT_MAX (#5639)
Issue 5632 - CLI - improve error handling with db2ldif
Issue 5517 - Replication conflict CI test sometime fails (#5518)
Issue 5634 - Deprecated warning related to github action workflow code (#5635)
Issue 5637 - Covscan - fix Buffer Overflows (#5638)
Issue 5624 - RFE - UI - export certificates, and import text base64 encoded certificates
Bump tokio from 1.24.1 to 1.25.0 in /src (#5629)
Issue 4577 - Add LMDB pytest github action (#5627)
Issue 4293 - RFE - CLI - add dsrc options for setting user and group subtrees
Remove stale libevent(-devel) dependency
Issue 5578 - dscreate ds-root does not normaile paths (#5613)
Issue 5497 - boolean attributes should be case insensitive