Commit Graph

326 Commits

Author SHA1 Message Date
Alexander Bokovoy
f25a4e55eb Fix ipatests dependency to python3-pexpect
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2021-02-15 21:34:42 +02:00
Alexander Bokovoy
9c43e47a35 Update to FreeIPA 4.9.2
New upstream release.

Add RHEL/Fedora ELN-only branding patch.

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2021-02-15 21:02:25 +02:00
Alexander Bokovoy
179e81bf0a FreeIPA 4.9.1 release 2021-01-27 15:38:23 +02:00
Fedora Release Engineering
0b71cc63e9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2021-01-26 05:54:38 +00:00
Rob Crittenden
c4a47619fb Set client keytab location for 389ds
Resolves: RHBZ#1918075
2021-01-20 17:48:10 -05:00
Alexander Bokovoy
9ed0331cde FreeIPA 4.9.0 release
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2020-12-23 17:07:21 +02:00
Alexander Bokovoy
d10972a2bf Test a fix for rhbz#1902811 2020-12-16 08:11:09 +02:00
Alexander Bokovoy
d1d2d3bc50 Remove outdated patch reference for RHEL build 2020-12-16 07:51:20 +02:00
Alexander Bokovoy
dcdddd25b4 FreeIPA 4.9.0 release candidate 3 2020-12-10 18:41:26 +02:00
Alexander Bokovoy
b91bf7ae0f Apply 4.9.0rc2 fixes from upstream
Allow mod_auth_gssapi to create and access ccaches in /run/ipa/ccaches
Fixes: https://pagure.io/freeipa/issue/8613

upgrade: provide DOMAIN to the server upgrade dictionary
Fixes: https://pagure.io/freeipa/issue/8615
2020-12-09 20:07:18 +02:00
Alexander Bokovoy
3ad697a03a Correct selinux requirement
freeipa-selinux subpackage is used by both client and server but
requires freeipa-server subpackage unconditionally. This needs to be
removed.

Originally, upstream spec file did not have this bug. It was brought
in with unification of the specfiles.

Resolves: rhbz#1883005

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2020-12-04 22:21:50 +02:00
Alexander Bokovoy
ae7e82eec2 Update to FreeIPA 4.9.0 release candidate 2 2020-12-04 13:53:27 +02:00
Alexander Bokovoy
41b946dfeb Remove old freeipa-server requirement in selinux subpackage 2020-11-19 20:53:07 +02:00
Alexander Bokovoy
d0324d20d6 Update spec file 2020-11-19 20:45:31 +02:00
Alexander Bokovoy
5245a181b9 Fix client-only build
Upstream PR: https://github.com/freeipa/freeipa/pull/5273.patch
2020-11-18 13:05:01 +02:00
Alexander Bokovoy
792b04177b Remove obsolete patches 2020-11-18 12:08:02 +02:00
Alexander Bokovoy
a5238c00f7 Fix build directory location for release candidates 2020-11-18 12:00:47 +02:00
Alexander Bokovoy
0d298a885e FreeIPA 4.9.0 release candidate 1
- Update to new upstream release
- Unify most of Fedora/RHEL/Upstream spec files
2020-11-18 11:56:37 +02:00
Adam Williamson
f5ffc4abf3 Backport #5212 for deployment failures with 389-ds-base 1.4.4.6+ 2020-10-28 15:16:06 -07:00
Alexander Bokovoy
deafacd653 Handle better upgrade of sshd_config
Fixes: rhbz#1887928
2020-10-13 18:54:47 +03:00
Alexander Bokovoy
45879303cf Properly handle upgrade when systemd-resolved is enabled 2020-09-29 14:04:30 +03:00
Alexander Bokovoy
ede0ac6cb6 Fix permissions of systemd-resolved configuration file
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2020-09-28 15:38:44 +03:00
Alexander Bokovoy
649963736f Make selinux subpackage dependency in -common versioned 2020-09-27 18:11:56 +03:00
Alexander Bokovoy
cc0d18ca0a Fix dependency between freeipa-selinux and freeipa-common
We need to make sure freeipa-selinux subpackage pulls the same NVR set of
freeipa-* packages. We can achieve this with freeipa-common dependency.
Using freeipa-server was wrong as it pulled server packages into a
client-only deployment.

Rsolves: rhbz#1883005

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2020-09-27 18:05:53 +03:00
Alexander Bokovoy
dd627d4562 Support upgrade F32 to F33 with systemd-resolved 2020-09-26 16:41:34 +03:00
Alexander Bokovoy
90249d2730 Update changelog 2020-09-26 12:25:51 +03:00
Alexander Bokovoy
3c2acac7db Update to FreeIPA 4.8.10 2020-09-26 12:23:38 +03:00
Alexander Bokovoy
be9ba85ab6 Support older installations on upgrade 2020-08-21 15:34:04 +03:00
François Cami
8ac40118cb FreeIPA 4.8.7 upstream release 2020-08-20 19:24:07 +02:00
Alexander Bokovoy
9255ad4636 Make use of unshare+chroot in ipa-extdom-extop unittests to work against glibc 2.32 2020-08-03 12:36:19 +03:00
Fedora Release Engineering
3c3db56f45 - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-08-01 01:04:16 +00:00
Merlin Mathesius
05cc0230f3 Conditional fixes for ELN to set krb5-kdb version appropriately
Signed-off-by: Merlin Mathesius <mmathesi@redhat.com>
2020-07-30 08:23:26 -05:00
Fedora Release Engineering
043318b878 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-07-27 17:48:52 +00:00
Alexander Bokovoy
b7be92ba08 FreeIPA 4.8.7 upstream release 2020-06-10 23:45:00 +03:00
Miro Hrončok
21412083bf Rebuilt for Python 3.9 2020-05-26 02:45:52 +02:00
Alexander Bokovoy
c2ce1eaf19 FreeIPA 4.8.6 release 2020-03-27 09:35:21 +02:00
Alexander Bokovoy
307dce1d32 Roll up post-release fixes from upstream
Move freeipa-selinux to be a dependency of freeipa-common instead of
freeipa-server as client is also using some of the defined contexts.
2020-03-21 22:41:22 +02:00
Alexander Bokovoy
96a53ecb23 Do not build selinux policy subpackage for client-only build 2020-03-18 18:05:13 +02:00
Alexander Bokovoy
6147e44e8d Depend on selinux-policy-devel 3.14.6-9 for the build
https://github.com/fedora-selinux/selinux-policy/pull/333 is only fixed
in selinux-policy-devel-3.14.6-9.fc33.
2020-03-18 17:39:50 +02:00
Alexander Bokovoy
6803b54398 Upstream release FreeIPA 4.8.5 2020-03-17 16:12:44 +02:00
Alexander Bokovoy
6d5d5ab36b FreeIPA 4.8.5 2020-03-17 16:12:01 +02:00
Alexander Bokovoy
7bdea0a373 Support OpenDNSSEC 2.1
Resolves: #1809492
2020-03-03 17:03:12 +02:00
François Cami
485092e39c Fix audit_as_req() callback usage.
Fixes: rhbz#1803786
Signed-off-by: François Cami <fcami@redhat.com>
2020-02-17 17:53:05 +01:00
Alexander Bokovoy
76138553c1 Fix constraint delegation for krb5 1.18 update
Fixes: rhbz#1797096
2020-02-01 10:14:56 +02:00
Fedora Release Engineering
1343c174cd - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2020-01-28 18:58:21 +00:00
Alexander Bokovoy
6684913272 Add pre-req patches for KDB fixes 2020-01-28 10:33:22 +02:00
Alexander Bokovoy
a7de121edc Rebuild against krb5 1.18 beta 2020-01-28 10:22:32 +02:00
Alexander Bokovoy
229f6e6fdd Rebuild against Samba 4.12RC1 2020-01-26 22:07:15 +02:00
Alexander Bokovoy
8ae86f33dc Revert "Rebuild against krb5 1.18 beta"
This reverts commit 87131d93f7.
2020-01-26 22:05:24 +02:00
Alexander Bokovoy
106979cbb5 Revert "Fix typo"
This reverts commit 099c181d69.
2020-01-26 22:05:02 +02:00
Alexander Bokovoy
099c181d69 Fix typo 2020-01-25 01:01:57 +02:00
Alexander Bokovoy
87131d93f7 Rebuild against krb5 1.18 beta 2020-01-25 00:37:09 +02:00
Adam Williamson
7ba1008817 Backport PR #4045 to fix overlapping DNS zone check bugs 2019-12-16 09:50:34 -08:00
Alexander Bokovoy
89ac168643 FreeIPA 4.8.4 release 2019-12-14 14:56:41 +02:00
Alexander Bokovoy
0827a2c92c Update dependencies for FreeIPA 4.8.4 release 2019-12-14 14:53:43 +02:00
Alexander Bokovoy
504c0ac7cd New upstream security release 4.8.3 2019-11-26 16:17:22 +02:00
Rob Crittenden
1463c20af5 Update to 4.8.2
- Replace %%{_libdir} macro in BuildRequires (#1746882)
- Restore user-nsswitch.conf before calling authselect (#1746557)
- ipa service-find does not list cifs service created by
  ipa-client-samba (#1731433)
- Occasional 'whoami.data is undefined' error in FreeIPA web UI
  (#1699109)
- ipa-kra-install fails due to fs.protected_regular=1 (#1698384)
2019-11-12 14:45:10 -05:00
Alexander Bokovoy
44e6cfb46a Don't create log files from the helper scripts
Fixes rhbz#1754189
2019-10-20 13:18:47 +03:00
Christian Heimes
341de25783 Fix compat issue with preexec_fn in Python 3.8
Fixes: rhbz#1759290
2019-10-08 10:37:26 +02:00
Alexander Bokovoy
2c65074a31 Fix bogus changelog date 2019-10-01 09:41:30 +03:00
Alexander Bokovoy
56d3eef1e2 Fix compatibility with Samba 4.11
Fixes: rhbz#1757089
2019-10-01 09:40:40 +03:00
Miro Hrončok
92c399779f Rebuilt for Python 3.8 2019-08-19 10:14:17 +02:00
Alexander Bokovoy
d3d8a98ebf Update to FreeIPA 4.8.1 2019-08-14 18:55:41 +03:00
Fedora Release Engineering
452bd5ce72 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-07-25 01:00:19 +00:00
Alexander Bokovoy
5eefa180c1 FreeIPA 4.8.0 release 2019-07-03 10:36:06 +03:00
Alexander Bokovoy
a38d5dea8b Handle upgrade when trust is configured but not established yet
Fixes: rhbz#1708808
2019-05-11 11:59:25 +03:00
Alexander Bokovoy
e4170a4cc4 Bump release as the previous version was already built 2019-05-03 23:26:05 +03:00
Alexander Bokovoy
b4d8a0ae2d Use krb5 1.17-17 for krb5-kdb-version 2019-05-03 23:23:37 +03:00
Alexander Bokovoy
fb39356a83 Rebuild to drop upper limit for Kerberos package
After krb5-server will provide krb5-kdb-version, we'll switch to it
2019-05-03 23:09:22 +03:00
Alexander Bokovoy
f287b17875 Merge #3 Drop upper bound on krb5 version 2019-05-03 20:06:54 +00:00
Adam Williamson
be564e23eb Backport PR #3104 to fix a font path error 2019-05-01 16:29:01 -07:00
Alexander Bokovoy
3eda80f6d8 Revert MINSSF defaults because realmd cannot join FreeIPA right now
realmd uses anonymous LDAP connection for the discovery and validation
and fails to validate it is joining FreeIPA server.
2019-05-01 21:30:10 +03:00
Alexander Bokovoy
7eef088ee0 Update spec file 2019-04-29 23:01:26 +03:00
Alexander Bokovoy
7d9a415144 First release candidate for FreeIPA 4.8.0 2019-04-29 22:40:13 +03:00
Robbie Harwood
a05de75daf Drop upper bound on krb5 version
This check is no longer needed now that krb5 exports the KDB version.

Signed-off-by: Robbie Harwood <rharwood@redhat.com>

(This commit originally proposed upstream as #3009.)
2019-04-08 15:29:30 -04:00
Alexander Bokovoy
21ff3cd3b5 Fixed rhbz#1696963 2019-04-06 23:00:21 +03:00
Alexander Bokovoy
7987809d8d Fix breakage for Samba 4.10 and 389-ds 1.4.1.2 2019-04-06 11:31:42 +03:00
Alexander Bokovoy
8368b30429 Remove python2 support 2019-02-28 11:23:33 +02:00
Alexander Bokovoy
8b08a231c9 Fix ipa-client-automount to work with new nfs-utils
nfs-utils no longer create /etc/sysconfig/nfs, take that into account
using upstream FreeIPA patch.

See https://bugzilla.redhat.com/show_bug.cgi?id=1668836 for nfs-utils
detalis.
2019-02-28 11:05:01 +02:00
François Cami
9cf5a63a52 - Fix FTBS due to Samba having removed
talloc_strackframe.h and memory.h (#1678670)
- Fix CA setup when fs.protected_regular=1 (#1677027)
2019-02-19 15:46:50 +01:00
Alexander Bokovoy
34d547a636 Rebuild for python-kdcproxy 0.4.1 and disable Python dep generator use 2019-02-11 20:42:52 +02:00
Alexander Bokovoy
4dd28889a2 Fix mass rebuild failure
Fix space/tabs issues reported by 'fedpkg lint'
2019-02-08 20:40:17 +02:00
Fedora Release Engineering
c0efa305a7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2019-01-31 20:08:31 +00:00
Igor Gnatenko
6a9720386c Remove unneeded %clean section
It is the behavior since EPEL5.

Signed-off-by: Igor Gnatenko <ignatenkobrain@fedoraproject.org>
2019-01-29 05:45:51 +01:00
Igor Gnatenko
088a11d56a Remove obsolete BuildRoot tag
Signed-off-by: Igor Gnatenko <ignatenkobrain@fedoraproject.org>
2019-01-29 05:35:04 +01:00
Igor Gnatenko
640d55c06f Remove obsolete Group tag
References: https://fedoraproject.org/wiki/Changes/Remove_Group_Tag
2019-01-28 20:24:02 +01:00
Alexander Bokovoy
413580e0c6 Update to FreeIPA 4.7.2 2018-12-03 13:34:40 +02:00
Adam Williamson
d489fe9ffe Update PR #2610 patch to tiran's modified version 2018-11-28 00:37:51 -08:00
Adam Williamson
38293c2b0c Backport PR #2610 to fix for authselect 1.0.2+ (see #1645708) 2018-11-27 17:13:12 -08:00
Alexander Bokovoy
e5b9ea7287 Increase release 2018-11-11 18:43:45 +02:00
Alexander Bokovoy
df4cd9334b Rebuild with krb5-1.17
Also bump SSSD version to pick up return of pysss.getgrouplist() API
2018-11-11 18:42:51 +02:00
Rob Crittenden
c3d08f1176 Update to upstream 4.7.1 2018-10-05 15:51:43 -04:00
Thomas Woerner
eb63032682 Committing for Christian Heimes:
- Remove Python 2 support from Fedora 30
- https://fedoraproject.org/wiki/Changes/FreeIPA_Python_2_Removal
2018-09-25 11:09:19 +02:00
Thomas Woerner
2a327151b7 - Enable python2 client packages for f30 for now again 2018-09-04 15:56:20 +02:00
Thomas Woerner
f076221002 Fix only client build for Fedora>=28 and RHEL>7, readd special patch handing 2018-09-04 13:54:23 +02:00
Thomas Woerner
d73b97aca6 Force generation of aclocal.m4 and configuration scripts 2018-09-04 12:04:14 +02:00
Thomas Woerner
480173e259 Fixed bad comment line 2018-09-03 18:03:41 +02:00
Thomas Woerner
e7de033e9e - Restore SELinux context of session_dir /etc/httpd/alias (pagure#7662)
- Restore SELinux context of template_dir /var/log/dirsrv/slapd-X (pagure#7662)
- Add "389-ds-base-legacy-tools" to requires
- Refactor os-release and platform information (#1609475)
- Don't check for systemd service (#1609475)
- Switched to upstream spec file with small adaptions
2018-09-03 17:51:54 +02:00
Thomas Woerner
f6a1c1b62c Update to upstream 4.7.0
- New BuildRequires for nodejs and uglify-js
- New Requires for 389-ds-base-legacy-tools in server (RHBZ#1606541)
- Do not build python2-ipaserver and python2-ipatests for Fedora 29 and up
- Do not build any python2 packages for Fedora 30
- Added ipatest man pages to python3-ipatests packages also
- Added ipatest bindir links to python3-ipatests for Fedora up to 28
- Dropped explicit copy of freeipa.template, install is doing this now
- Added upstream fix: (f3faecb) Fix $-style format string in ipa_ldap_init
- Added upstream fix: (4b592fe,1a7baa2) Added reason to raise of errors.NotFound
2018-07-26 14:15:24 +02:00
Alexander Bokovoy
d895dd1288 Use versioned python macros 2018-07-16 16:26:12 +03:00