Commit Graph

299 Commits

Author SHA1 Message Date
Kevin Fenzi
c7811c4ad8 Rebuild for broken deps
- Fix 389-ds-base strict dep to be 1.3.0.5 and krb5-server 1.11.1
2013-03-30 11:49:49 -06:00
Kevin Fenzi
e432b0144a Rebuild for broken deps in rawhide
- Fix 389-ds-base strict dep to be 1.3.0.3
2013-02-23 12:57:28 -07:00
Dennis Gilmore
e3032bd32c - Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild 2013-02-13 15:59:20 -06:00
Rob Crittenden
586582a2c2 Correct VERSION in the spec file 2013-01-23 17:28:20 -05:00
Rob Crittenden
ab5b2748dc Updated strict dependencies to 389-ds-base = 1.3.0.2 and pki-ca = 10.0.1 2013-01-23 17:16:53 -05:00
Rob Crittenden
3d64806b7a Update to upstream 3.1.2
- CVE-2012-4546: Incorrect CRLs publishing
- CVE-2012-5484: MITM Attack during Join process
- CVE-2013-0199: Cross-Realm Trust key leak
2013-01-23 17:13:20 -05:00
Martin Kosek
c6c1e1d976 Backport additional spec fixes from upstream
- Remove redundat Requires versions that are already in Fedora 17
- Replace python-crypto Requires with m2crypto
- Add missing Requires(post) for client and server-trust-ad subpackages
- Restart httpd service when server-trust-ad subpackage is installed
- Bump selinux-policy Requires to pick up PKI/LDAP port labeling fixes
2012-12-20 10:33:39 +01:00
Rob Crittenden
5e038ec750 Updated to upstream 3.1.0 GA
- Set minimum for sssd to 1.9.2
- Set minimum for pki-ca to 10.0.0-1
- Set minimum for 389-ds-base to 1.3.0
- Set minimum for selinux-policy to 3.11.1-60
- Remove unneeded dogtag package requires
2012-12-10 15:52:46 -05:00
Martin Kosek
0348a328fd Update Requires on krb5-server to 1.11 2012-11-23 14:49:15 +01:00
Rob Crittenden
e93bd136ff Configure CA replication to use TLS instead of SSL 2012-10-12 14:48:18 -04:00
Rob Crittenden
4de47b3304 Updated to upstream 3.0.0 GA
- Set minimum for samba to 4.0.0-153.
- Make sure server-trust-ad subpackage alternates winbind_krb5_locator.so
  plugin to /dev/null since they cannot be used when trusts are configured
- Restrict krb5-server to 1.10.
- Update minimum for 389-ds-base to 1.3.0
- Add directory /var/lib/ipa/pki-ca/publish for CRL published by pki-ca
- Add Requires on zip for generating FF browser extension
2012-10-12 12:02:17 -04:00
Rob Crittenden
8a8da0b567 - Updated to upstream 3.0.0 rc 2
- Include new FF configuration extension
2012-10-09 16:22:06 -04:00
Martin Kosek
53622bb0da Require samba packages instead of obsoleted samba4 packages 2012-10-02 08:36:19 +02:00
Rob Crittenden
23bbd3f9b4 Updated to upstream 3.0.0 rc 1
- Update BR for 389-ds-base to 1.2.11.14
- Update BR for krb5 to 1.10
- Update BR for samba4-devel to 4.0.0-139 (rc1)
- Add BR for python-polib
- Update Requires on policycoreutils to 2.1.12-5
- Update Requires on 389-ds-base to 1.2.11.14
- Update Requires on selinux-policy to 3.11.1-21
- Update Requires on dogtag to 10.0.0-0.33.a1
- Update Requires on certmonger to 0.60
- Update Requires on tomcat to 7.0.29
- Update minimum version of bind to 9.9.1-10.P3
- Update minimum version of bind-dyndb-ldap to 1.1.0-0.16.rc1
- Remove Requires on authconfig from python sub-package
2012-09-21 16:34:00 -04:00
Rob Crittenden
2d22c7100c Rebuild against samba4 beta8 2012-09-05 09:12:31 -04:00
Rob Crittenden
7caae3a676 Rebuild against samba4 beta7 2012-08-31 15:09:05 -04:00
Alexander Bokovoy
5c0f47e71d Adopt to samba4 beta6 and add samba4-winbind dependency to freeipa-server-trust-ad 2012-08-22 18:31:36 +03:00
Rob Crittenden
3c1392be1b Update to upstream 3.0.0 beta 2 2012-08-17 11:31:03 -04:00
Martin Kosek
3c91c125af Add missing 3.0.0 beta 2 development patches 2012-08-06 18:17:49 +02:00
Martin Kosek
23157c3804 Update to current upstream state of 3.0.0 beta 2 development 2012-08-06 17:16:15 +02:00
Alexander Bokovoy
10af3ccf36 Rebuild against samba4 beta4 2012-07-23 17:23:54 +03:00
Rob Crittenden
a0ca5be798 Update to upstream 3.0.0 beta 1 2012-07-02 15:55:25 -04:00
Rob Crittenden
b191f14e04 - Updated to upstream 2.2.0 GA
- Update minimum n-v-r of certmonger to 0.53
- Update minimum n-v-r of slapi-nis to 0.40
- Add Requires in client to oddjob-mkhomedir and python-krbV
- Update minimum selinux-policy to 3.10.0-110
2012-05-03 14:40:11 -04:00
Rob Crittenden
18a9ea07cd Update to 2.2.0 beta1, fix shell escaping to work with dogtag 9.0.18.
- Update to upstream 2.2.0 beta 1 (2.1.90.rc1)
- Set minimum n-v-r for pki-ca and pki-silent to 9.0.18.
- Add Conflicts on mod_ssl
- Update minimum n-v-r of 389-ds-base to 1.2.10.4
- Update minimum n-v-r of sssd to 1.8.0
- Update minimum n-v-r of slapi-nis to 0.38
- Update minimum n-v-r of pki-* to 9.0.18
- Update conflicts on bind-dyndb-ldap to < 1.1.0-0.9.b1
- Update conflicts on bind to < 9.9.0-1
- Drop requires on krb5-server-ldap
- Add patch to remove escaping arguments to pkisilent
2012-05-03 14:40:05 -04:00
Rob Crittenden
c3929a4ff3 Update to upstream 2.2.0 alpha 1 (2.1.90.pre1)
Remove unused patches, update tarball, sync spec to upstream spec

ipa_kpasswd has been dropped upstream
2012-02-06 14:51:43 -05:00
Alexander Bokovoy
fd3bdcaf1e - Force to use 389-ds 1.2.10-0.8.a7 or above
- Improve upgrade script to handle systemd 389-ds change
  - fixes FreeIPA tickets 2117 and 2300
- Fix freeipa to work with python-ldap 2.4.6
2012-02-01 21:25:07 +02:00
Martin Kosek
3d6f0d2911 Fix FreeIPA installation problems
This release fixes:
- ipa-replica-install crashes due to invalid Python calls
- ipa-server-install and ipa-dns-install may fail to produce log
- ipa-server-install crash due to sslget problem (#771357)
2012-01-11 11:34:54 +01:00
Alexander Bokovoy
0c5ab6443d Fix 769440
Rebuild SLAPI plugins against thread-safe ldap library as requirement of new 389-ds build
2011-12-21 14:49:37 +02:00
Alexander Bokovoy
e32f1a7067 Allow ipa-ldap-updater to wait for dirsrv service on systemd setups 2011-12-11 19:38:03 +02:00
Rob Crittenden
9cc2d9f70c Update to upstream 2.1.4 (CVE-2011-3636) 2011-12-06 12:09:19 -05:00
Rob Crittenden
44560406dd Update SELinux policy to allow ipa_kpasswd to connect ldap and
read /dev/urandom. (#759679)
2011-12-05 13:11:22 -05:00
Alexander Bokovoy
31a2cbeaa0 Update release 2011-11-30 15:36:42 +02:00
Alexander Bokovoy
ce4a13930d Fix wrong path in packaging freeipa-systemd-upgrade 2011-11-30 15:35:30 +02:00
Alexander Bokovoy
e95356d723 Introduce systemd upgrade script
As user has no means to recover existing FreeIPA install after
upgrading from SysV to systemd, introduce upgrade script.

The upgrade script does following:
    - restores symlinks in FreeIPA's Dogtag installation
    - converts FreeIPA directory server instances to systemd
    - converts FreeIPA directory server configuration to be compatible
      with systemd services
    - converts FreeIPA KDC configuration to be compatible
      with systemd services
    - re-enables FreeIPA

Script does nothing if FreeIPA is already active systemd service
2011-11-30 15:14:40 +02:00
Dennis Gilmore
3bfb4b3f41 - Rebuilt for glibc bug#747377 2011-10-26 18:45:58 -05:00
Alexander Bokovoy
70948ccd2a Upstream 2.1.3 release 2011-10-19 18:07:43 +03:00
Rob Crittenden
92a3878415 Update to 2.1.0 2011-08-16 17:20:37 -04:00
Simo Sorce
e3b0a5690f Fix bug #702633 2011-05-06 16:22:28 -04:00
Rob Crittenden
eed524353c - Update minimum selinux-policy to 3.9.16-18
- Update minimum pki-ca and pki-selinux to 9.0.7
- Update minimum 389-ds-base to 1.2.8.0-1
- Update to upstream 2.0.1
2011-05-02 13:33:13 -04:00
Rob Crittenden
f2186254fd - Update to upstream GA release
- Automatically apply updates when the package is upgraded
2011-03-24 17:57:00 -04:00
Rob Crittenden
2af185004b Remove tarball freeipa-2.0.0.rc2.tar.gz 2011-03-24 16:33:54 -04:00
Rob Crittenden
c6cab8a0d0 - Update to upstream freeipa-2.0.0.rc2
- Set minimum version of python-nss to 0.11 to make sure IPv6 support is in
- Set minimum version of sssd to 1.5.1
- Patch to include SuiteSpotGroup when setting up 389-ds instances
- Move a lot of BuildRequires so this will build with ONLY_CLIENT enabled
2011-02-25 18:12:29 -05:00
Rob Crittenden
8a46b7d6ae - Update to upstream freeipa-2.0.0.rc2
- Set minimum version of python-nss to 0.11 to make sure IPv6 support is in
- Set minimum version of sssd to 1.5.1
- Patch to include SuiteSpotGroup when setting up 389-ds instances
- Move a lot of BuildRequires so this will build with ONLY_CLIENT enable
2011-02-25 18:11:01 -05:00
Rob Crittenden
1127f3631f Fix the N-V-R so rc1 is an update to beta2 2011-02-15 09:45:55 -05:00
Rob Crittenden
68ba56c22b - Set minimum version of sssd to 1.5.1
- Update to upstream freeipa-2.0.0.rc1
- Move server-only binaries from admintools subpackage to server
2011-02-14 21:45:41 -05:00
Dennis Gilmore
34c9a74675 - Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild 2011-02-08 15:36:14 -06:00
Rob Crittenden
2bb258d1d1 Set min version of 389-ds-base to 1.2.8
Set min version of mod_nss 1.0.8-10
Set min version of selinux-policy to 3.9.7-27
Add dogtag themes to Requires
Update to upstream freeipa-2.0.0.pre2
2011-02-03 16:55:42 -05:00
Rob Crittenden
ce15e9e9d6 Initial import (#672986). 2011-01-27 23:33:55 -05:00
Fedora Release Engineering
f42e484d8e Initial setup of the repo 2011-01-28 02:15:10 +00:00