Commit Graph

337 Commits

Author SHA1 Message Date
François Cami
fc48683f41 Upstream release FreeIPA 4.9.3
Signed-off-by: François Cami <fcami@redhat.com>
2021-06-29 19:38:50 +02:00
Alexander Bokovoy
9eee394ae1 Rebuild for Python 3.10, second part
A rebuild is needed for picking up a new dependency for python3-wsgi

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2021-06-14 09:22:42 +03:00
Python Maint
4cd3eaa0f6 Rebuilt for Python 3.10 2021-06-04 20:04:44 +02:00
Alexander Bokovoy
f6e7b19cc5 FreeIPA 4.9.4
Fix missing creds breakage in 'ipa' tool post-release

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2021-06-04 15:50:17 +03:00
Alexander Bokovoy
bedd4a4587 Part 2 of the replication plugin rename fix
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2021-06-01 12:34:37 +03:00
Alexander Bokovoy
c999c986a6 Handle rename of replication plugin in 389-ds
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2021-06-01 10:55:29 +03:00
Alexander Bokovoy
df0fbfd556 Handle failures to resolve non-existing reverse zones during deployment with systemd-resolved
Resolves: rhbz#1948034

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2021-04-12 22:35:47 +03:00
Alexander Bokovoy
4b3503176e Upstream release FreeIPA 4.9.3
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2021-03-31 09:49:32 +03:00
Alexander Bokovoy
66db9529f8 Rebuild against 389-ds and PKI to fix https://github.com/389ds/389-ds-base/issues/4609
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2021-02-26 22:21:20 +02:00
Alexander Bokovoy
71a36c6ab9 Only use python-platform on RHEL 8
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2021-02-23 17:41:48 +02:00
Troy Dawson
4de77e9638 platform-python only on RHEL8 2021-02-19 21:28:16 +00:00
Alexander Bokovoy
f25a4e55eb Fix ipatests dependency to python3-pexpect
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2021-02-15 21:34:42 +02:00
Alexander Bokovoy
9c43e47a35 Update to FreeIPA 4.9.2
New upstream release.

Add RHEL/Fedora ELN-only branding patch.

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2021-02-15 21:02:25 +02:00
Alexander Bokovoy
179e81bf0a FreeIPA 4.9.1 release 2021-01-27 15:38:23 +02:00
Fedora Release Engineering
0b71cc63e9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2021-01-26 05:54:38 +00:00
Rob Crittenden
c4a47619fb Set client keytab location for 389ds
Resolves: RHBZ#1918075
2021-01-20 17:48:10 -05:00
Alexander Bokovoy
9ed0331cde FreeIPA 4.9.0 release
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2020-12-23 17:07:21 +02:00
Alexander Bokovoy
d10972a2bf Test a fix for rhbz#1902811 2020-12-16 08:11:09 +02:00
Alexander Bokovoy
d1d2d3bc50 Remove outdated patch reference for RHEL build 2020-12-16 07:51:20 +02:00
Alexander Bokovoy
dcdddd25b4 FreeIPA 4.9.0 release candidate 3 2020-12-10 18:41:26 +02:00
Alexander Bokovoy
b91bf7ae0f Apply 4.9.0rc2 fixes from upstream
Allow mod_auth_gssapi to create and access ccaches in /run/ipa/ccaches
Fixes: https://pagure.io/freeipa/issue/8613

upgrade: provide DOMAIN to the server upgrade dictionary
Fixes: https://pagure.io/freeipa/issue/8615
2020-12-09 20:07:18 +02:00
Alexander Bokovoy
3ad697a03a Correct selinux requirement
freeipa-selinux subpackage is used by both client and server but
requires freeipa-server subpackage unconditionally. This needs to be
removed.

Originally, upstream spec file did not have this bug. It was brought
in with unification of the specfiles.

Resolves: rhbz#1883005

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2020-12-04 22:21:50 +02:00
Alexander Bokovoy
ae7e82eec2 Update to FreeIPA 4.9.0 release candidate 2 2020-12-04 13:53:27 +02:00
Alexander Bokovoy
41b946dfeb Remove old freeipa-server requirement in selinux subpackage 2020-11-19 20:53:07 +02:00
Alexander Bokovoy
d0324d20d6 Update spec file 2020-11-19 20:45:31 +02:00
Alexander Bokovoy
5245a181b9 Fix client-only build
Upstream PR: https://github.com/freeipa/freeipa/pull/5273.patch
2020-11-18 13:05:01 +02:00
Alexander Bokovoy
792b04177b Remove obsolete patches 2020-11-18 12:08:02 +02:00
Alexander Bokovoy
a5238c00f7 Fix build directory location for release candidates 2020-11-18 12:00:47 +02:00
Alexander Bokovoy
0d298a885e FreeIPA 4.9.0 release candidate 1
- Update to new upstream release
- Unify most of Fedora/RHEL/Upstream spec files
2020-11-18 11:56:37 +02:00
Adam Williamson
f5ffc4abf3 Backport #5212 for deployment failures with 389-ds-base 1.4.4.6+ 2020-10-28 15:16:06 -07:00
Alexander Bokovoy
deafacd653 Handle better upgrade of sshd_config
Fixes: rhbz#1887928
2020-10-13 18:54:47 +03:00
Alexander Bokovoy
45879303cf Properly handle upgrade when systemd-resolved is enabled 2020-09-29 14:04:30 +03:00
Alexander Bokovoy
ede0ac6cb6 Fix permissions of systemd-resolved configuration file
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2020-09-28 15:38:44 +03:00
Alexander Bokovoy
649963736f Make selinux subpackage dependency in -common versioned 2020-09-27 18:11:56 +03:00
Alexander Bokovoy
cc0d18ca0a Fix dependency between freeipa-selinux and freeipa-common
We need to make sure freeipa-selinux subpackage pulls the same NVR set of
freeipa-* packages. We can achieve this with freeipa-common dependency.
Using freeipa-server was wrong as it pulled server packages into a
client-only deployment.

Rsolves: rhbz#1883005

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2020-09-27 18:05:53 +03:00
Alexander Bokovoy
dd627d4562 Support upgrade F32 to F33 with systemd-resolved 2020-09-26 16:41:34 +03:00
Alexander Bokovoy
90249d2730 Update changelog 2020-09-26 12:25:51 +03:00
Alexander Bokovoy
3c2acac7db Update to FreeIPA 4.8.10 2020-09-26 12:23:38 +03:00
Alexander Bokovoy
be9ba85ab6 Support older installations on upgrade 2020-08-21 15:34:04 +03:00
François Cami
8ac40118cb FreeIPA 4.8.7 upstream release 2020-08-20 19:24:07 +02:00
Alexander Bokovoy
9255ad4636 Make use of unshare+chroot in ipa-extdom-extop unittests to work against glibc 2.32 2020-08-03 12:36:19 +03:00
Fedora Release Engineering
3c3db56f45 - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-08-01 01:04:16 +00:00
Merlin Mathesius
05cc0230f3 Conditional fixes for ELN to set krb5-kdb version appropriately
Signed-off-by: Merlin Mathesius <mmathesi@redhat.com>
2020-07-30 08:23:26 -05:00
Fedora Release Engineering
043318b878 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-07-27 17:48:52 +00:00
Alexander Bokovoy
b7be92ba08 FreeIPA 4.8.7 upstream release 2020-06-10 23:45:00 +03:00
Miro Hrončok
21412083bf Rebuilt for Python 3.9 2020-05-26 02:45:52 +02:00
Alexander Bokovoy
c2ce1eaf19 FreeIPA 4.8.6 release 2020-03-27 09:35:21 +02:00
Alexander Bokovoy
307dce1d32 Roll up post-release fixes from upstream
Move freeipa-selinux to be a dependency of freeipa-common instead of
freeipa-server as client is also using some of the defined contexts.
2020-03-21 22:41:22 +02:00
Alexander Bokovoy
96a53ecb23 Do not build selinux policy subpackage for client-only build 2020-03-18 18:05:13 +02:00
Alexander Bokovoy
6147e44e8d Depend on selinux-policy-devel 3.14.6-9 for the build
https://github.com/fedora-selinux/selinux-policy/pull/333 is only fixed
in selinux-policy-devel-3.14.6-9.fc33.
2020-03-18 17:39:50 +02:00
Alexander Bokovoy
6803b54398 Upstream release FreeIPA 4.8.5 2020-03-17 16:12:44 +02:00
Alexander Bokovoy
6d5d5ab36b FreeIPA 4.8.5 2020-03-17 16:12:01 +02:00
Alexander Bokovoy
7bdea0a373 Support OpenDNSSEC 2.1
Resolves: #1809492
2020-03-03 17:03:12 +02:00
François Cami
485092e39c Fix audit_as_req() callback usage.
Fixes: rhbz#1803786
Signed-off-by: François Cami <fcami@redhat.com>
2020-02-17 17:53:05 +01:00
Alexander Bokovoy
76138553c1 Fix constraint delegation for krb5 1.18 update
Fixes: rhbz#1797096
2020-02-01 10:14:56 +02:00
Fedora Release Engineering
1343c174cd - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-01-28 18:58:21 +00:00
Alexander Bokovoy
6684913272 Add pre-req patches for KDB fixes 2020-01-28 10:33:22 +02:00
Alexander Bokovoy
a7de121edc Rebuild against krb5 1.18 beta 2020-01-28 10:22:32 +02:00
Alexander Bokovoy
229f6e6fdd Rebuild against Samba 4.12RC1 2020-01-26 22:07:15 +02:00
Alexander Bokovoy
8ae86f33dc Revert "Rebuild against krb5 1.18 beta"
This reverts commit 87131d93f7.
2020-01-26 22:05:24 +02:00
Alexander Bokovoy
106979cbb5 Revert "Fix typo"
This reverts commit 099c181d69.
2020-01-26 22:05:02 +02:00
Alexander Bokovoy
099c181d69 Fix typo 2020-01-25 01:01:57 +02:00
Alexander Bokovoy
87131d93f7 Rebuild against krb5 1.18 beta 2020-01-25 00:37:09 +02:00
Adam Williamson
7ba1008817 Backport PR #4045 to fix overlapping DNS zone check bugs 2019-12-16 09:50:34 -08:00
Alexander Bokovoy
89ac168643 FreeIPA 4.8.4 release 2019-12-14 14:56:41 +02:00
Alexander Bokovoy
0827a2c92c Update dependencies for FreeIPA 4.8.4 release 2019-12-14 14:53:43 +02:00
Alexander Bokovoy
504c0ac7cd New upstream security release 4.8.3 2019-11-26 16:17:22 +02:00
Rob Crittenden
1463c20af5 Update to 4.8.2
- Replace %%{_libdir} macro in BuildRequires (#1746882)
- Restore user-nsswitch.conf before calling authselect (#1746557)
- ipa service-find does not list cifs service created by
  ipa-client-samba (#1731433)
- Occasional 'whoami.data is undefined' error in FreeIPA web UI
  (#1699109)
- ipa-kra-install fails due to fs.protected_regular=1 (#1698384)
2019-11-12 14:45:10 -05:00
Alexander Bokovoy
44e6cfb46a Don't create log files from the helper scripts
Fixes rhbz#1754189
2019-10-20 13:18:47 +03:00
Christian Heimes
341de25783 Fix compat issue with preexec_fn in Python 3.8
Fixes: rhbz#1759290
2019-10-08 10:37:26 +02:00
Alexander Bokovoy
2c65074a31 Fix bogus changelog date 2019-10-01 09:41:30 +03:00
Alexander Bokovoy
56d3eef1e2 Fix compatibility with Samba 4.11
Fixes: rhbz#1757089
2019-10-01 09:40:40 +03:00
Miro Hrončok
92c399779f Rebuilt for Python 3.8 2019-08-19 10:14:17 +02:00
Alexander Bokovoy
d3d8a98ebf Update to FreeIPA 4.8.1 2019-08-14 18:55:41 +03:00
Fedora Release Engineering
452bd5ce72 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-07-25 01:00:19 +00:00
Alexander Bokovoy
5eefa180c1 FreeIPA 4.8.0 release 2019-07-03 10:36:06 +03:00
Alexander Bokovoy
a38d5dea8b Handle upgrade when trust is configured but not established yet
Fixes: rhbz#1708808
2019-05-11 11:59:25 +03:00
Alexander Bokovoy
e4170a4cc4 Bump release as the previous version was already built 2019-05-03 23:26:05 +03:00
Alexander Bokovoy
b4d8a0ae2d Use krb5 1.17-17 for krb5-kdb-version 2019-05-03 23:23:37 +03:00
Alexander Bokovoy
fb39356a83 Rebuild to drop upper limit for Kerberos package
After krb5-server will provide krb5-kdb-version, we'll switch to it
2019-05-03 23:09:22 +03:00
Alexander Bokovoy
f287b17875 Merge #3 Drop upper bound on krb5 version 2019-05-03 20:06:54 +00:00
Adam Williamson
be564e23eb Backport PR #3104 to fix a font path error 2019-05-01 16:29:01 -07:00
Alexander Bokovoy
3eda80f6d8 Revert MINSSF defaults because realmd cannot join FreeIPA right now
realmd uses anonymous LDAP connection for the discovery and validation
and fails to validate it is joining FreeIPA server.
2019-05-01 21:30:10 +03:00
Alexander Bokovoy
7eef088ee0 Update spec file 2019-04-29 23:01:26 +03:00
Alexander Bokovoy
7d9a415144 First release candidate for FreeIPA 4.8.0 2019-04-29 22:40:13 +03:00
Robbie Harwood
a05de75daf Drop upper bound on krb5 version
This check is no longer needed now that krb5 exports the KDB version.

Signed-off-by: Robbie Harwood <rharwood@redhat.com>

(This commit originally proposed upstream as #3009.)
2019-04-08 15:29:30 -04:00
Alexander Bokovoy
21ff3cd3b5 Fixed rhbz#1696963 2019-04-06 23:00:21 +03:00
Alexander Bokovoy
7987809d8d Fix breakage for Samba 4.10 and 389-ds 1.4.1.2 2019-04-06 11:31:42 +03:00
Alexander Bokovoy
8368b30429 Remove python2 support 2019-02-28 11:23:33 +02:00
Alexander Bokovoy
8b08a231c9 Fix ipa-client-automount to work with new nfs-utils
nfs-utils no longer create /etc/sysconfig/nfs, take that into account
using upstream FreeIPA patch.

See https://bugzilla.redhat.com/show_bug.cgi?id=1668836 for nfs-utils
detalis.
2019-02-28 11:05:01 +02:00
François Cami
9cf5a63a52 - Fix FTBS due to Samba having removed
talloc_strackframe.h and memory.h (#1678670)
- Fix CA setup when fs.protected_regular=1 (#1677027)
2019-02-19 15:46:50 +01:00
Alexander Bokovoy
34d547a636 Rebuild for python-kdcproxy 0.4.1 and disable Python dep generator use 2019-02-11 20:42:52 +02:00
Alexander Bokovoy
4dd28889a2 Fix mass rebuild failure
Fix space/tabs issues reported by 'fedpkg lint'
2019-02-08 20:40:17 +02:00
Fedora Release Engineering
c0efa305a7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-01-31 20:08:31 +00:00
Igor Gnatenko
6a9720386c Remove unneeded %clean section
It is the behavior since EPEL5.

Signed-off-by: Igor Gnatenko <ignatenkobrain@fedoraproject.org>
2019-01-29 05:45:51 +01:00
Igor Gnatenko
088a11d56a Remove obsolete BuildRoot tag
Signed-off-by: Igor Gnatenko <ignatenkobrain@fedoraproject.org>
2019-01-29 05:35:04 +01:00
Igor Gnatenko
640d55c06f Remove obsolete Group tag
References: https://fedoraproject.org/wiki/Changes/Remove_Group_Tag
2019-01-28 20:24:02 +01:00
Alexander Bokovoy
413580e0c6 Update to FreeIPA 4.7.2 2018-12-03 13:34:40 +02:00
Adam Williamson
d489fe9ffe Update PR #2610 patch to tiran's modified version 2018-11-28 00:37:51 -08:00
Adam Williamson
38293c2b0c Backport PR #2610 to fix for authselect 1.0.2+ (see #1645708) 2018-11-27 17:13:12 -08:00