Fedora Release Engineering
8b518cbb8f
- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages
2016-07-19 07:06:29 +00:00
Petr Vobornik
1e163887b2
Rebase 0001-Workarounds-for-SELinux-execmem-violations-in-crypto.patch
2016-03-24 16:43:12 +01:00
Petr Vobornik
ffe6f461b2
Update to upstream 4.3.1
2016-03-24 16:21:34 +01:00
Petr Vobornik
21c82e0cbb
fix build with Samba 4.4
...
- Fix build with Samba 4.4
- Update SELinux requires to fix connection check during installation
2016-02-04 12:18:14 +01:00
Dennis Gilmore
101663ab3b
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
2016-02-03 20:46:39 +00:00
Petr Vobornik
f43314092f
spec: do not require arch specific ipalib package from noarch packages
...
noarch packages should not contain:
Requires: some-package-{?_isa}
2016-01-19 18:53:41 +01:00
Petr Vobornik
b2442d51ba
Workarounds for SELinux execmem violations in crypto
2015-12-18 17:48:36 +01:00
Petr Vobornik
00828c7569
Update to upstream 4.3.0
2015-12-18 17:48:36 +01:00
Petr Vobornik
a33b200323
Workarounds for SELinux execmem violations in cryptography
...
ipaserver.dcerpc uses M2Crypto again on Python 2.7 and Dogtag's
pki.client no longer tries to use PyOpenSSL instead of Python's ssl
module.
Some dependencies like Dogtag's pki.client library and custodia use
python-requsts to make HTTPS connection. python-requests prefers
PyOpenSSL over Python's stdlib ssl module. PyOpenSSL is build on top
of python-cryptography which trigger a execmem SELinux violation
in the context of Apache HTTPD (httpd_execmem).
When requests is imported, it always tries to import pyopenssl glue
code from urllib3's contrib directory. The import of PyOpenSSL is
enough to trigger the SELinux denial.
A hack in wsgi.py prevents the import by raising an ImportError.
2015-12-08 21:28:39 +01:00
Petr Vobornik
efcb307b47
Update to upstream 4.2.3
2015-11-02 19:58:16 +01:00
Alexander Bokovoy
5e5a1f4339
Rebuild against krb5 1.14
2015-10-21 19:45:51 +03:00
Alexander Bokovoy
08336be7d8
Add dependency to samba-common-tools to -trust-ad subpackage
...
Samba packaging moved samba-common to be multi-architecture-friendly
and moved net utility to samba-common-tools. We use net utility in
ipa-adtrust-install, thus we need to depend on the correct package.
2015-10-21 19:40:20 +03:00
Petr Vobornik
e26c3e5b2a
Update to upstream 4.2.2
2015-10-08 14:30:13 +02:00
Petr Vobornik
ece84f751e
Update to upstream 4.2.1
2015-09-07 19:01:45 +02:00
Dennis Gilmore
a944f13c98
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
2015-06-17 06:41:22 +00:00
Alexander Bokovoy
54c544a18d
Fix typo in the patch to fix trusts
2015-05-12 15:42:37 +03:00
Alexander Bokovoy
9e1a9ca424
Separate build- and install time requires for Samba
2015-05-11 20:44:44 +03:00
Alexander Bokovoy
3291aa48e8
Fix establishing trust when using Samba 4.2
...
Fixes: 1219834
2015-05-11 20:32:13 +03:00
Petr Vobornik
5e8ed97275
replace mod_auth-kerb with mod_auth_gssapi
2015-03-30 15:51:59 +02:00
Alexander Bokovoy
c25f465e18
Upstreamed patch
2015-03-26 16:54:08 +02:00
Alexander Bokovoy
32b772b3ee
Upstream 4.1.4 release to fix CVE-2015-1827
2015-03-26 16:46:20 +02:00
Petr Vobornik
37a047a11a
Timeout when performing time sync during client installation
...
https://fedorahosted.org/freeipa/ticket/4842
2015-03-17 10:35:32 +01:00
Petr Vobornik
b0ad0e0344
Add missing sssd python dependencies
...
https://bugzilla.redhat.com/show_bug.cgi?id=1197218
2015-03-04 18:49:31 +01:00
Petr Vobornik
fd86e26a5f
Update to upstream 4.1.3
...
- see http://www.freeipa.org/page/Releases/4.1.3
2015-02-18 18:32:22 +01:00
Alexander Bokovoy
a69b40e56b
Fix wrong date in the changelog
2015-01-19 11:26:26 +02:00
Alexander Bokovoy
c504f905a4
Unblock rawhide
...
- Support Samba PASSDB 0.2.0 with libsamba-passdb
- Fix marshalling of NETLOGON responses over CLDAP
- Use python-dateutil15 instead of python-dateutil 2.x until we validate
the new version
2015-01-19 11:22:49 +02:00
Petr Vobornik
81defaec91
Update to upstream 4.1.2
...
- see http://www.freeipa.org/page/Releases/4.1.2
- fix CVE-2014-7850
2014-11-25 14:36:38 +01:00
Simo Sorce
da888bc1a9
Patch blokers and feature freze exceptions
...
- Resolves: bz1165674
- Resolves: bz1165856 (CVE-2014-7850)
- Fixes DNS install issue that prevents the server from working
2014-11-21 13:18:37 +01:00
Martin Kosek
366080a717
Lower pki-ca requires to 10.1.2
...
Current Dogtag 10.2 and it's requirements are not properly packaged for
CentOS, yet. To enable FreeIPA running on CentOS 7.0, lower the
Requires on Fedora 20 and CentOS platform on Dogtag 10.1.2 which
has the patches required by FreeIPA backported and which has all
dependencies avaiable.
https://fedorahosted.org/freeipa/ticket/4737
2014-11-19 12:58:29 +01:00
Petr Spacek
9a877166ea
Fix minimal version of BIND for Fedora 20 and 21
2014-11-10 09:32:25 +01:00
Petr Vobornik
00870e3919
Update to upstream 4.1.1
...
- see http://www.freeipa.org/page/Releases/4.1.1
- fix CVE-2014-7828
2014-11-06 14:42:41 +01:00
Petr Vobornik
c8a68dfb66
Fix armv7 build failure, external CA install
2014-10-22 14:41:16 +02:00
Petr Vobornik
7ccb103e8e
Update to upstream 4.1.0
...
see http://www.freeipa.org/page/Releases/4.1.0
2014-10-21 19:02:12 +02:00
Petr Viktorin
743ef0138f
Update to upstream 4.0.3 - see http://www.freeipa.org/page/Releases/4.0.3
2014-09-12 21:59:09 +02:00
Petr Viktorin
694ce2174a
Update to upstream 4.0.1 - see http://www.freeipa.org/page/Releases/4.0.2
2014-09-05 19:56:45 +02:00
Pádraig Brady
c1d3c76c37
update to Java/8
...
Java/7 is no longer available in rawhide,
so update to allow rebuilds to proceed.
2014-09-02 18:40:34 +01:00
Pádraig Brady
cf4ceb30fb
rebuild for libunistring soname bump
2014-09-02 18:09:28 +01:00
Peter Robinson
21b496feed
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
2014-08-16 13:08:47 +00:00
Martin Kosek
f08947f751
Update to upstream 4.0.1
2014-07-25 14:14:39 +02:00
Petr Viktorin
92ad420100
Update to upstream 4.0.0
...
Remove Fedora patches, all are in the upstream release
Remove the freeipa-server-strict package
Update to upstream 4.0.0
2014-07-07 19:25:32 +02:00
Dennis Gilmore
da4983b208
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
2014-06-07 07:48:25 -05:00
Petr Vobornik
a291203c66
Increase Java Stack size for Web UI build on aarch64
2014-05-21 10:11:48 +02:00
Peter Robinson
a14925ccb8
Add rhino as dependency to fix FTBFS
2014-04-16 15:15:57 +01:00
Martin Kosek
78bfe5614a
Update to upstream 3.3.5
2014-03-28 13:34:35 +01:00
Martin Kosek
9ea7eb2ddf
3.3.4-3
...
- Move ipa-otpd socket directory to /var/run/krb5kdc
- Require krb5-server 1.11.5-3 supporting the new directory
- ipa_lockout plugin did not work with users's without krbPwdPolicyReference
2014-02-11 18:06:25 +01:00
Martin Kosek
5b79ddb067
3.3.4-2
...
- Fix hardened build
2014-01-29 08:54:27 +01:00
Martin Kosek
9d21232151
3.3.4-1
...
- Update to upstream 3.3.4
- Install CA anchor into standard location (#928478 )
- ipa-client-install part of ipa-server-install fails on reinstall (#1044994 )
- Remove mod_ssl workaround (RHEL bug #1029046 )
- Enable syncrepl plugin to support bind-dyndb-ldap 4.0
2014-01-28 13:37:46 +01:00
Martin Kosek
3242eeabec
3.3.3-5
...
- Build crashed with rhino exception on s390 architectures (#1040576 )
2014-01-03 13:44:59 +01:00
Martin Kosek
84f4ed20a9
Fix typo in patch specification part
2013-12-13 15:52:59 +01:00
Martin Kosek
2071255d02
3.3.3-4
...
- Build crashed rhino exception on some architectures (#1040576 )
2013-12-13 15:48:01 +01:00