Commit Graph

53 Commits

Author SHA1 Message Date
Florence Blanc-Renaud
e57a97aa67 ipa-4.11.0-5
- Resolves: RHEL-12589 ipa: Invalid CSRF protection
- Resolves: RHEL-19748 ipa hbac-test did not report that it hit an arbitrary search limit
- Resolves: RHEL-21059 'DogtagCertsConfigCheck' fails, displaying the error message 'Malformed directive: ca.signing.certnickname=caSigningCert cert-pki-ca'
- Resolves: RHEL-21804 ipa client 4.10.2 - Failed to obtain host TGT
- Resolves: RHEL-21809 CA less servers are failing to be added in topology segment for domain suffix
- Resolves: RHEL-21810 ipa-client-install --automount-location does not work
- Resolves: RHEL-21811 Handle change in behavior of pki-server ca-config-show in pki 11.5.0
- Resolves: RHEL-21812 Backport latest test fixes in ipa
- Resolves: RHEL-21813 krb5kdc fails to start when pkinit and otp auth type is enabled in ipa
- Resolves: RHEL-21815 IPA 389ds plugins need to have better logging and tracing
- Resolves: RHEL-21937 Make sure a default NetBIOS name is set if not passed in by ADTrust instance constructor

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-01-18 17:08:12 +01:00
Florence Blanc-Renaud
6a71086391 ipa-4.11.0-4
- Resolves: RHEL-16985 Handle samba 4.19 changes in samba.security.dom_sid()

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2023-12-01 17:12:39 +01:00
Florence Blanc-Renaud
1c59d31bde ipa-4.11.0-3
- Resolves: RHEL-14428 healthcheck reports nsslapd-accesslog-logbuffering is set to 'off'

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2023-11-20 10:48:30 +01:00
Florence Blanc-Renaud
80c7b3b6fc ipa-4.11.0-2
- Resolves: RHEL-14292 Backport latest test fixes in python3-ipatests
- Resolves: RHEL-15443 Server install: failure to install with externally signed CA because of timezone issue
- Resolves: RHEL-15444 Minimum length parameter in pwpolicy cannot be removed with empty string
- Resolves: RHEL-14842 Upstream xmlrpc tests are failing in RHEL9.4

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2023-11-06 17:15:36 +01:00
Florence Blanc-Renaud
7cca66eef5 ipa-4.11.0-1
- Resolves: RHEL-11652 Rebase ipa to latest 4.11.x version for RHEL 9.4
2023-10-06 10:59:48 +02:00
Florence Blanc-Renaud
6ef486fbd4 ipa-4.10.2-4
- Resolves: rhbz#2231847 RHEL 8.8 & 9.2 fails to create AD trust with STIG applied
- Resolves: rhbz#2232056 Include latest test fixes in python3-ipatests

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2023-08-17 15:23:04 +02:00
Florence Blanc-Renaud
02ac1c9481 ipa-4.10.2-3
- Resolves: rhbz#2229712 Delete operation protection for admin user
- Resolves: rhbz#2227831 Interrupt request processing in ipadb_fill_info3() if connection to 389ds is lost
- Resolves: rhbz#2227784 libipa_otp_lasttoken plugin memory leak
- Resolves: rhbz#2224570 Improved error messages are needed when attempting to add a non-existing idp to a user
- Resolves: rhbz#2230251 Backport latest test fixes to python3-ipatests

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2023-08-10 08:36:05 +02:00
Florence Blanc-Renaud
466d149b0e ipa-4.10.2-2
- Resolves: rhbz#2192969 Better handling of the command line and web UI cert search and/or list features
- Resolves: rhbz#2214933 Uninstalling of the IPA server is encountering a failure during the unconfiguration of the CA (Unconfiguring CA)
- Resolves: rhbz#2216114 After updating the RHEL from 8.7 to 8.8, IPA services fails to start
- Resolves: rhbz#2216549 Upgrade to 4.9.10-6.0.1 fails: attributes are managed by topology plugin
- Resolves: rhbz#2216611 Backport latest test fixes in python3-ipatests
- Resolves: rhbz#2216872 User authentication failing on OTP validation using multiple tokens, succeeds with password only

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2023-06-29 10:40:49 +02:00
Florence Blanc-Renaud
0113f2748f ipa-4.10.2-1
- Resolves: rhbz#2196426 [Rebase] Rebase ipa to latest 4.10.x release for RHEL 9.3
- Resolves: rhbz#2192969 Better handling of the command line and web UI cert search and/or list features
- Resolves: rhbz#2192625 Better catch of the IPA web UI event "IPA Error 4301:CertificateOperationError", and IPA httpd error CertificateOperationError
- Resolves: rhbz#2188567 IPA client Kerberos configuration incompatible with java
- Resolves: rhbz#2182683 Tolerate absence of PAC ticket signature depending of domain and servers capabilities [rhel-9]
- Resolves: rhbz#2180914 Sequence processing failures for group_add using server context
- Resolves: rhbz#2165880 Add RBCD support to IPA
- Resolves: rhbz#2160399 get_ranges - [file ipa_sidgen_common.c, line 276]: Failed to convert LDAP entry to range struct

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2023-06-06 17:20:03 +02:00
Florence Blanc-Renaud
86091b593d ipa-4.10.1-6
- Resolves: rhbz#2169632 Backport latest test fixes in python3-ipatests

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2023-02-22 11:56:15 +01:00
Florence Blanc-Renaud
00abb6c62b ipa-4.10.1-5
- Resolves: rhbz#2162656 Passwordless (GSSAPI) SSH not working for subdomain
- Resolves: rhbz#2166326 Removing the last DNS type for ipa-ca does not work
- Resolves: rhbz#2167473 RFE - Add a warning note about possible performance impact of the Auto Member rebuild task
- Resolves: rhbz#2168244 requestsearchtimelimit=0 doesn't seems to be work with ipa-acme-manage pruning command

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2023-02-13 16:22:35 +01:00
Florence Blanc-Renaud
d5f3f77077 ipa-4.10.1-4
- Resolves: rhbz#2161284 'ERROR Could not remove /tmp/tmpbkw6hawo.ipabkp' can be seen prior to 'ipa-client-install' command was successful
- Resolves: rhbz#2164403 ipa-trust-add with --range-type=ipa-ad-trust-posix fails while creating an ID range
- Resolves: rhbz#2162677 RFE: Implement support for PKI certificate and request pruning
- Resolves: rhbz#2167312 - Backport latest test fixes in python3-ipatests

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2023-02-06 09:12:53 +01:00
Alexander Bokovoy
f7ee6e148d Rebuild against krb5 1.20.1 ABI
Resolves: rhbz#2155425

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2022-12-22 10:09:15 +02:00
Florence Blanc-Renaud
7faaf4f321 ipa-4.10.1-2
- Resolves: rhbz#2148887 MemberManager with groups fails
- Resolves: rhbz#2150335 idm:client is missing dependency on krb5-pkinit

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2022-12-09 14:31:00 +01:00
Florence Blanc-Renaud
b01c9f88f3 ipa-4.10.1-1
- Resolves: rhbz#2141315
[Rebase] Rebase ipa to latest 4.10.x release for RHEL 9.2
- Resolves: rhbz#2094673
ipa-client-install should just use system wide CA store and do not specify TLS_CACERT in ldap.conf
- Resolves: rhbz#2117167
After leapp upgrade on ipa-client ipa-server package installation failed. (`REQ_FULL_WITH_MEMBERS` returns object from wrong domain)
- Resolves: rhbz#2127833
Password Policy Grace login limit allows invalid maximum value
- Resolves: rhbz#2143224
[RFE] add certificate support to ipa-client instead of one time password
- Resolves: rhbz#2144736
vault interoperability with older RHEL systems is broken
- Resolves: rhbz#2148258
ipa-client-install does not maintain server affinity during installation
- Resolves: rhbz#2148379
Add warning for empty targetattr when creating ACI with RBAC
- Resolves: rhbz#2148380
OTP token sync always returns OK even with random numbers
- Resolves: rhbz#2148381
Deprecated feature idnssoaserial in IdM appears when creating reverse dns zones
- Resolves: rhbz#2148382
Introduction of URI records for kerberos breaks location functionality

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2022-11-25 13:43:35 +01:00
Francisco Trivino
0e045611f2 Rebuild against samba-4.17.2
Related: RHBZ#2131993

Signed-off-by: Francisco Trivino <ftrivino@redhat.com>
2022-11-03 19:50:52 +01:00
Rafael Guterres Jeffman
8fd756106e ipa-4.10.0-7
- Resolves: rhbz#2124547
  Resolves: rhbz#2137555
  Attempt to log in as "root" user with admin's password in Web UI does not properly fail

Signed-off-by: Rafael Guterres Jeffman <rjeffman@redhat.com>
2022-10-25 10:51:20 -03:00
Florence Blanc-Renaud
caae578990 ipa-4.10.0-6
- Resolves: rhbz#2110014
  ldap bind occurs when admin user changes password with gracelimit=0
- Resolves: rhbz#2112901
  RFE: Allow grace login limit to be set in IPA WebUI
- Resolves: rhbz#2115495
  group password policy by default does not allow grace logins
- Resolves: rhbz#2116966
  ipa-replica-manage displays traceback: Unexpected error: 'bool' object has no attribute 'lower'
2022-08-19 17:02:13 +02:00
Francisco Trivino
c4b1dec10b Rebuild for samba-4.16.3-101.el9
ipa-4.10.0-5
  - Resolves: rhbz#2109645

Rebuild due to Samba rebase to the the latest 4.16.x release

side-tag: c9s-build-side-652-stack-gate

Signed-off-by: Francisco Trivino <ftrivino@redhat.com>
2022-07-28 12:49:04 +02:00
Francisco Trivino
aec008c1b3 Rebuild for samba-4.16.3-100.el9
ipa-4.10.0-4
- Resolves: rhbz#2109645
  Rebuild due to Samba rebase to the the latest 4.16.x release

side-tag: c9s-build-side-652-stack-gate

Signed-off-by: Francisco Trivino <ftrivino@redhat.com>
2022-07-22 16:48:49 +02:00
Florence Blanc-Renaud
d94f3829f4 ipa-4.10.0-3
- Resolves: rhbz#2105294
  IdM WebUI Pagination Size should not allow empty value

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2022-07-15 13:12:46 +02:00
Florence Blanc-Renaud
f569c41e74 ipa-4.10.0-2
- Resolves: rhbz#2091988
  [RFE] Add code to check password expiration on ldap bind
2022-06-30 16:22:52 +02:00
Florence Blanc-Renaud
bb4db90d38 ipa-4.10.0-1
- Resolves: rhbz#747959
  [RFE] Support random serial numbers in IPA certificates
- Resolves: rhbz#2100227
  [UX] Preserving a user account produces output saying it was deleted
2022-06-30 09:33:47 +02:00
Florence Blanc-Renaud
e6c101f535 ipa-4.9.10-1
- Resolves: rhbz#2079469 [Rebase] Rebase ipa to latest 4.9.x release
- Resolves: rhbz#2012911 named journalctl logs shows 'zone testrealm.test/IN: serial (serialnumber) write back to LDAP failed.'
- Resolves: rhbz#2069202 [RFE] add support for authenticating against external IdP services using OAUTH2 preauthenticaiton mechanism provided by SSSD
- Resolves: rhbz#2083218 ipa-dnskeysyncd floods /var/log/messages with DEBUG messages
- Resolves: rhbz#2089750 RFE: Improve error message with more detail for ipa-replica-install command
- Resolves: rhbz#2091988 [RFE] Add code to check password expiration on ldap bind
- Resolves: rhbz#2094400 [RFE] ipa-client-install should provide option to enable subid: sss in /etc/nsswitch.conf
- Resolves: rhbz#2096922 secret in ipa-pki-proxy.conf is not changed if new requiredSecret value is present in /etc/pki/pki-tomcat/server.xml
2022-06-17 10:55:11 +02:00
Florence Blanc-Renaud
6ed32726f7 ipa-4.9.8-8
- Resolves: rhbz#2067971 Consequences of FIPS crypto policy tightening in RHEL 9
2022-04-06 18:08:01 +02:00
Florence Blanc-Renaud
db00e46a5c ipa-4.9.8-7
- Resolves: rhbz#2067971 Consequences of FIPS crypto policy tightening in RHEL 9
2022-03-24 08:35:50 +01:00
Florence Blanc-Renaud
9b88d4c513 ipa-4.9.8-6
- Resolves: rhbz#2057467 Backport latest test fixes in python3-ipatests

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2022-02-24 17:15:11 +01:00
Alexander Bokovoy
c728f32d9b add IPA test suite fixes
Resolves: rhbz#2053025

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2022-02-14 17:11:23 +02:00
Alexander Bokovoy
0384e3429f fix memory leak in CLDAP responder
Resolves: rhbz#2053586

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2022-02-14 15:09:07 +02:00
Florence Blanc-Renaud
c7bf31948f ipa-4.9.8-3
- Resolves: rhbz#2050540 Unable to join RHEL 8.5 Replica to RHEL 7.9 Master for migration purposes
- Resolves: rhbz#2051582 Enable ipa-ccache-sweep.timer during server installation
- Resolves: rhbz#2051844 ipa-join tests are failing due to changes in expected output

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2022-02-11 15:04:45 +01:00
Florence Blanc-Renaud
b412308f26 ipa-4.9.8-2
- Resolves: rhbz#2040619 - Changing default pac type to 'nfs:NONE and MS-PAC' doesnot display error 'ipa: ERROR: no modifications to be performed'
- Resolves: rhbz#2048510 - [rhel-9.0] Backport latest test fixes in python3-ipatests
- Resolves: rhbz#2049104 - User can't log in after ipa-user-mod --user-auth-type=hardened
- Resolves: rhbz#2049174 - KRA GetStatus service blocked by IPA proxy
2022-02-03 09:21:01 +01:00
Florence Blanc-Renaud
103dc90372 Update rpminspect's annocheck policy
annocheck is now using "hardened" policy both for rhel and centos.
Override the options for "hardened" instead of "rhel-policy".
2022-01-25 17:26:51 +01:00
Florence Blanc-Renaud
b28fca276d Remove old patches
- Resolves: rhbz#2015608 - [Rebase] Rebase ipa to latest 4.9.x release RHEL9
2021-12-03 09:34:04 +01:00
Florence Blanc-Renaud
848d623257 ipa-4.9.8-1
- Resolves: rhbz#2015608 - [Rebase] Rebase ipa to latest 4.9.x release RHEL9
- Resolves: rhbz#1825010 - Concerns regarding 'ipa pwpolicy-mod --minlife 24 --maxlife 1'
- Resolves: rhbz#1966289 - Info about searchrecordslimit set search limit to 10,000 after upgrade
- Resolves: rhbz#1980356 - reinstalling samba client causes winbindd coredump
- Resolves: rhbz#1986054 - fix automountlocation-tofiles output
- Resolves: rhbz#2020205 - Missing bind-pkcs11-utils causing failures in OpenDNSSec
- Resolves: rhbz#2021445 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
2021-12-02 21:16:40 +01:00
Florence Blanc-Renaud
717b817b82 ipa-4.9.6-9
- Resolves: rhbz#2010701 ipa-server-install fails while 'configuring certificate server instance'
- Resolves: rhbz#2005864 ipa cert-request replaces user certificate instead of adding
- Resolves: rhbz#2003005 AVC denied { read } comm="ipa-custodia" on aarch64 during installation of ipa-server
- Resolves: rhbz#2003004 extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
- Resolves: rhbz#2003003 subid: subid-match displays the DN of the owner, not its UID.
- Resolves: rhbz#2013116 ipa migrate-ds command fails to warn when compat plugin is enabled
2021-10-12 09:35:41 +02:00
Florence Blanc-Renaud
992ffe6b89 ipa-4.9.6-6
- Resolves: rhbz#1998098 - Backport latest test fixes in python3-ipatests
2021-08-26 15:51:00 +02:00
Florence Blanc-Renaud
6ff3da92fc ipa-4.9.6-5
- Resolves: rhbz#1988383 Do SRV discovery in ipa-getkeytab if -s and -H aren't provided
- Resolves: rhbz#1986329 ipa-server install failure without DNS
- Resolves: rhbz#1980734 Remove python3-pexpect as dependency for ipatests pkg
- Resolves: rhbz#1992538 Backport recent test fixes in python3-ipatests
2021-08-17 10:34:03 +02:00
Mohan Boddu
6e57c7ade0 Rebuilt for IMA sigs, glibc 2.34, aarch64 flags
Related: rhbz#1991688
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2021-08-09 20:58:02 +00:00
Rob Crittenden
d7b02057af ipa-4.9.6-4
- Use new method in check to prevent removal of last KRA (#1985072)
- ipatests: NAMED_CRYPTO_POLICY_FILE not defined for RHEL (#1982952)
- Fix index definition for memberOf (#1952028)

Resolves: #1985072, #1982952, #1952028
2021-07-23 09:31:03 -04:00
Florence Blanc-Renaud
5a5afdbc6f ipa-4.9.6-3
- Resolves: rhbz#1979629 Add checks to prevent assigning authentication indicators to internal IPA services
- Resolves: rhbz#1982212 ipa-trust-add fails with "not enough quota"
- Resolves: rhbz#1952028 [RFE] Add support for managing subuids and subgids in FreeIPA
- Resolves: rhbz#1981789 [man page] contradiction in ipa-server-upgrade command's man page and usage
2021-07-15 18:19:28 +02:00
Florence Blanc-Renaud
2f8d027c58 ipa-4.9.6-2
- Resolves: rhbz#1955440 ipa installation fails to configure chrony
- Resolves: rhbz#1976761 Package python3-ipatests (from CRB repo) Requires python3-coverage
- Resolves: rhbz#1979609 Unable to set ipaUserAuthType with stageuser-add
- Resolves: rhbz#1979629 Add checks to prevent assigning authentication indicators to internal IPA services
2021-07-09 12:56:20 +02:00
Florence Blanc-Renaud
42299a57bb ipa-4.9.6-1.el9
- Resolves: rhbz#1969351 Rebase IPA to latest 4.9.x version
- Resolves: rhbz#1976288 ansible-freeipa automember test fails with `automember_add_condition: testgroup: 'objectclass'` due to ldap cache
- Resolves: rhbz#1975139 Upgrade error: Add failure missing required attribute "objectclass"
- Resolves: rhbz#1973024 CA_less ipa-server-install fails if CA cert subject contains non ascii chars
- Resolves: rhbz#1966101 [RFE] - IDM - Allow specifying permanent logging settings for BIND
- Resolves: rhbz#1962570 IPA in c9s should not require redhat-logos-ipa as a runtime package
- Resolves: rhbz#1957736 [RFE] IPA to allow configuring auto-private-groups at idrange level
2021-06-29 19:30:17 +02:00
Mohan Boddu
7c6303e5c2 Rebuilt for RHEL 9 BETA for openssl 3.0
Related: rhbz#1971065
Signed-off-by: Mohan Boddu <mboddu@redhat.com>
2021-06-16 03:26:20 +00:00
Francisco Trivino
c25442d1e6 Add gating definition for RHEL 9
Related: rhbz#1947473

Signed-off-by: Francisco Trivino <ftrivino@redhat.com>
2021-05-05 13:29:11 +00:00
Florence Blanc-Renaud
16785f4548 ipa-4.9.3-2.el9
- Resolves: #1951304 - ipa: FTBFS in Red Hat Enterprise Linux 9 CentOS Stream
2021-04-20 08:30:17 +02:00
Florence Blanc-Renaud
1d7b04711c rpminspect: add automatic waiver for runpath check
The "runpath" check of rpminspect raises an error related
to DT_RPATH using /usr/lib64/samba for /usr/lib64/samba/pdb/ipasam.so.
This can be waived as ipasam.so is a plugin for smdb and
requires to have DT_RPATH set.
Add the path /usr/lib64/samba to the list of allowed DT_RPATH
to ignore the issue.

Resolves: #1947029 rpminspect false positive in runpath check
Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2021-04-07 16:29:26 +02:00
DistroBaker
dcf7347419 Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/freeipa.git#34b883f55ed4e94c11f9b3ee5c1833fea768e075
2021-04-01 03:45:19 +00:00
DistroBaker
d31cff2c7b Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/freeipa.git#3cbe72f9cbfe1e02e2a289c84517e1ff5649fac4
2021-03-04 12:55:14 +00:00
DistroBaker
62e000f7fb Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/freeipa.git#3cbe72f9cbfe1e02e2a289c84517e1ff5649fac4
2021-03-04 12:30:45 +00:00
DistroBaker
6a6233ecfc Merged update from upstream sources
This is an automated DistroBaker update from upstream sources.
If you do not know what this is about or would like to opt out,
contact the OSCI team.

Source: https://src.fedoraproject.org/rpms/freeipa.git#41b946dfeb35544f4011cf5777ba33fd98d11f72
2021-02-09 16:33:26 +01:00