Commit Graph

28 Commits

Author SHA1 Message Date
Florence Blanc-Renaud db00e46a5c ipa-4.9.8-7
- Resolves: rhbz#2067971 Consequences of FIPS crypto policy tightening in RHEL 9
2022-03-24 08:35:50 +01:00
Florence Blanc-Renaud 9b88d4c513 ipa-4.9.8-6
- Resolves: rhbz#2057467 Backport latest test fixes in python3-ipatests

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2022-02-24 17:15:11 +01:00
Alexander Bokovoy c728f32d9b add IPA test suite fixes
Resolves: rhbz#2053025

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2022-02-14 17:11:23 +02:00
Alexander Bokovoy 0384e3429f fix memory leak in CLDAP responder
Resolves: rhbz#2053586

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2022-02-14 15:09:07 +02:00
Florence Blanc-Renaud c7bf31948f ipa-4.9.8-3
- Resolves: rhbz#2050540 Unable to join RHEL 8.5 Replica to RHEL 7.9 Master for migration purposes
- Resolves: rhbz#2051582 Enable ipa-ccache-sweep.timer during server installation
- Resolves: rhbz#2051844 ipa-join tests are failing due to changes in expected output

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2022-02-11 15:04:45 +01:00
Florence Blanc-Renaud b412308f26 ipa-4.9.8-2
- Resolves: rhbz#2040619 - Changing default pac type to 'nfs:NONE and MS-PAC' doesnot display error 'ipa: ERROR: no modifications to be performed'
- Resolves: rhbz#2048510 - [rhel-9.0] Backport latest test fixes in python3-ipatests
- Resolves: rhbz#2049104 - User can't log in after ipa-user-mod --user-auth-type=hardened
- Resolves: rhbz#2049174 - KRA GetStatus service blocked by IPA proxy
2022-02-03 09:21:01 +01:00
Florence Blanc-Renaud 103dc90372 Update rpminspect's annocheck policy
annocheck is now using "hardened" policy both for rhel and centos.
Override the options for "hardened" instead of "rhel-policy".
2022-01-25 17:26:51 +01:00
Florence Blanc-Renaud b28fca276d Remove old patches
- Resolves: rhbz#2015608 - [Rebase] Rebase ipa to latest 4.9.x release RHEL9
2021-12-03 09:34:04 +01:00
Florence Blanc-Renaud 848d623257 ipa-4.9.8-1
- Resolves: rhbz#2015608 - [Rebase] Rebase ipa to latest 4.9.x release RHEL9
- Resolves: rhbz#1825010 - Concerns regarding 'ipa pwpolicy-mod --minlife 24 --maxlife 1'
- Resolves: rhbz#1966289 - Info about searchrecordslimit set search limit to 10,000 after upgrade
- Resolves: rhbz#1980356 - reinstalling samba client causes winbindd coredump
- Resolves: rhbz#1986054 - fix automountlocation-tofiles output
- Resolves: rhbz#2020205 - Missing bind-pkcs11-utils causing failures in OpenDNSSec
- Resolves: rhbz#2021445 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
2021-12-02 21:16:40 +01:00
Florence Blanc-Renaud 717b817b82 ipa-4.9.6-9
- Resolves: rhbz#2010701 ipa-server-install fails while 'configuring certificate server instance'
- Resolves: rhbz#2005864 ipa cert-request replaces user certificate instead of adding
- Resolves: rhbz#2003005 AVC denied { read } comm="ipa-custodia" on aarch64 during installation of ipa-server
- Resolves: rhbz#2003004 extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
- Resolves: rhbz#2003003 subid: subid-match displays the DN of the owner, not its UID.
- Resolves: rhbz#2013116 ipa migrate-ds command fails to warn when compat plugin is enabled
2021-10-12 09:35:41 +02:00
Florence Blanc-Renaud 992ffe6b89 ipa-4.9.6-6
- Resolves: rhbz#1998098 - Backport latest test fixes in python3-ipatests
2021-08-26 15:51:00 +02:00
Florence Blanc-Renaud 6ff3da92fc ipa-4.9.6-5
- Resolves: rhbz#1988383 Do SRV discovery in ipa-getkeytab if -s and -H aren't provided
- Resolves: rhbz#1986329 ipa-server install failure without DNS
- Resolves: rhbz#1980734 Remove python3-pexpect as dependency for ipatests pkg
- Resolves: rhbz#1992538 Backport recent test fixes in python3-ipatests
2021-08-17 10:34:03 +02:00
Mohan Boddu 6e57c7ade0 Rebuilt for IMA sigs, glibc 2.34, aarch64 flags
Related: rhbz#1991688
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2021-08-09 20:58:02 +00:00
Rob Crittenden d7b02057af ipa-4.9.6-4
- Use new method in check to prevent removal of last KRA (#1985072)
- ipatests: NAMED_CRYPTO_POLICY_FILE not defined for RHEL (#1982952)
- Fix index definition for memberOf (#1952028)

Resolves: #1985072, #1982952, #1952028
2021-07-23 09:31:03 -04:00
Florence Blanc-Renaud 5a5afdbc6f ipa-4.9.6-3
- Resolves: rhbz#1979629 Add checks to prevent assigning authentication indicators to internal IPA services
- Resolves: rhbz#1982212 ipa-trust-add fails with "not enough quota"
- Resolves: rhbz#1952028 [RFE] Add support for managing subuids and subgids in FreeIPA
- Resolves: rhbz#1981789 [man page] contradiction in ipa-server-upgrade command's man page and usage
2021-07-15 18:19:28 +02:00
Florence Blanc-Renaud 2f8d027c58 ipa-4.9.6-2
- Resolves: rhbz#1955440 ipa installation fails to configure chrony
- Resolves: rhbz#1976761 Package python3-ipatests (from CRB repo) Requires python3-coverage
- Resolves: rhbz#1979609 Unable to set ipaUserAuthType with stageuser-add
- Resolves: rhbz#1979629 Add checks to prevent assigning authentication indicators to internal IPA services
2021-07-09 12:56:20 +02:00
Florence Blanc-Renaud 42299a57bb ipa-4.9.6-1.el9
- Resolves: rhbz#1969351 Rebase IPA to latest 4.9.x version
- Resolves: rhbz#1976288 ansible-freeipa automember test fails with `automember_add_condition: testgroup: 'objectclass'` due to ldap cache
- Resolves: rhbz#1975139 Upgrade error: Add failure missing required attribute "objectclass"
- Resolves: rhbz#1973024 CA_less ipa-server-install fails if CA cert subject contains non ascii chars
- Resolves: rhbz#1966101 [RFE] - IDM - Allow specifying permanent logging settings for BIND
- Resolves: rhbz#1962570 IPA in c9s should not require redhat-logos-ipa as a runtime package
- Resolves: rhbz#1957736 [RFE] IPA to allow configuring auto-private-groups at idrange level
2021-06-29 19:30:17 +02:00
Mohan Boddu 7c6303e5c2 Rebuilt for RHEL 9 BETA for openssl 3.0
Related: rhbz#1971065
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2021-06-16 03:26:20 +00:00
Francisco Trivino c25442d1e6 Add gating definition for RHEL 9
Related: rhbz#1947473

Signed-off-by: Francisco Trivino <ftrivino@redhat.com>
2021-05-05 13:29:11 +00:00
Florence Blanc-Renaud 16785f4548 ipa-4.9.3-2.el9
- Resolves: #1951304 - ipa: FTBFS in Red Hat Enterprise Linux 9 CentOS Stream
2021-04-20 08:30:17 +02:00
Florence Blanc-Renaud 1d7b04711c rpminspect: add automatic waiver for runpath check
The "runpath" check of rpminspect raises an error related
to DT_RPATH using /usr/lib64/samba for /usr/lib64/samba/pdb/ipasam.so.
This can be waived as ipasam.so is a plugin for smdb and
requires to have DT_RPATH set.
Add the path /usr/lib64/samba to the list of allowed DT_RPATH
to ignore the issue.

Resolves: #1947029 rpminspect false positive in runpath check
Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2021-04-07 16:29:26 +02:00
DistroBaker dcf7347419 Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/freeipa.git#34b883f55ed4e94c11f9b3ee5c1833fea768e075
2021-04-01 03:45:19 +00:00
DistroBaker d31cff2c7b Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/freeipa.git#3cbe72f9cbfe1e02e2a289c84517e1ff5649fac4
2021-03-04 12:55:14 +00:00
DistroBaker 62e000f7fb Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/freeipa.git#3cbe72f9cbfe1e02e2a289c84517e1ff5649fac4
2021-03-04 12:30:45 +00:00
DistroBaker 6a6233ecfc Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/freeipa.git#41b946dfeb35544f4011cf5777ba33fd98d11f72
2021-02-09 16:33:26 +01:00
DistroBaker 7056e92461 Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/freeipa.git#41b946dfeb35544f4011cf5777ba33fd98d11f72
2020-12-17 07:07:32 +00:00
Petr Šabata ea9c3fc5e8 RHEL 9.0.0 Alpha bootstrap
The content of this branch was automatically imported from Fedora ELN
with the following as its source:
https://src.fedoraproject.org/rpms/ipa#ae2240c8d9b2f7c44116d3b48dbc0f77f0d53431
2020-10-15 13:41:11 +02:00
Release Configuration Management 3e477970b4 New branch setup 2020-10-08 15:18:23 +00:00