Commit Graph

380 Commits

Author SHA1 Message Date
Florence Blanc-Renaud
26cff073ee ipa-4.12.2-5
- Resolves: RHEL-61636 Uninstall ACME separately during PKI uninstallation

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-10-29 15:30:23 +01:00
Florence Blanc-Renaud
80f94e10a4 ipa-4.12.2-4
Bump version
Related: RHEL-59777 Rebase Samba to the latest 4.21.x release

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-10-21 18:05:17 +02:00
Florence Blanc-Renaud
66cc1eaeec ipa-4.12.2-4
- Related: RHEL-59777 Rebase Samba to the latest 4.21.x release
- Resolves: RHEL-59659 ipa dns-zone --allow-query '!198.18.2.0/24;any;' fails with Unrecognized IPAddress flags
- Resolves: RHEL-61636 Uninstall ACME separately during PKI uninstallation
- Resolves: RHEL-61723 Include latest fixes in python3-ipatests packages
- Resolves: RHEL-63325 Last expired OTP token would be considered as still assigned to the user

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-10-21 17:45:24 +02:00
Rafael Guterres Jeffman
c94e6ae745 ipa-4.12.2-3
Resolves: RHEL-33818 Remove python3-ipalib's dependency on python3-netifaces

Signed-off-by: Rafael Guterres Jeffman <rjeffman@redhat.com>
2024-09-24 10:22:22 -03:00
Florence Blanc-Renaud
5d90090676 ipa-4.12.2.2
- Resolves: RHEL-47294 SID generation task is failing when SELinux is in Enforcing mode
- Resolves: RHEL-56472 Include latest fixes in python3-ipatests packages
- Resolves: RHEL-56917 RFE add a tool to quickly detect and fix issues with IPA ID ranges
- Resolves: RHEL-56965 Backport test fixes in python3-ipatests
- Resolves: RHEL-58067 ipa replication installation fails in FIPS mode on rhel10
- Resolves: RHEL-59265 Default hbac rules are duplicated on remote server post ipa-migrate in prod-mode
- Resolves: RHEL-59266 Also enable SSSD's ssh service when enabling sss_ssh_knownhosts

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-09-18 11:23:26 +02:00
Florence Blanc-Renaud
0378d5e4e5 ipa-4.12.2.1
- Resolves: RHEL-54545 Covscan issues: Resource Leak
- Resolves: RHEL-54304 support for python cryptography 43.0.0
- Resolves: RHEL-49805 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w
- Resolves: RHEL-46897 With unreachable AD, ipa trust returns an internal error

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-08-21 21:17:57 +02:00
Florence Blanc-Renaud
86420dd2f3 ipa-4.12.1-4
- Resolves: RHEL-53501 adtrustinstance only prints issues in check_inst() and does not log them
- Resolves: RHEL-52305 Unconditionally add MS-PAC to global config
- Resolves: RHEL-52223 ipa-replica/server-install with softhsm needs to check permission/ownership of /var/lib/softhsm/tokens to avoid install failure
- Resolves: RHEL-51937 Include latest fixes in python3-ipatests packages
- Resolves: RHEL-50805 ipa-migrate -Z with invalid cert options fails with 'ValueError: option error'
- Resolves: RHEL-49805 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w
- Resolves: RHEL-49592 'Unable to log in as uid=admin-replica.testrealm.test,ou=people,o=ipaca' during replica install
- Resolves: RHEL-4879 RFE - Keep the configured value for the "nsslapd-ignore-time-skew" after a "force-sync"

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-08-08 17:24:14 +02:00
Florence Blanc-Renaud
6c2a5fa538 ipa-4.12.1-3
- Resolves: RHEL-49452 Include latest fixes in python3-ipatests packages
- Resolves: RHEL-49433 Adjust "ipa config-mod --addattr ipaconfigstring=EnforceLDAPOTP" to allow for non OTP users in some cases
- Resolves: RHEL-49432 ipa-migrate stage-mode is failing with error: Modifying a mapped attribute in a managed entry is not allowed
- Resolves: RHEL-49413 ipa-migrate with -Z option fails with ValueError: option error
- Resolves: RHEL-47157 ipa-migrate -V options fails to display version
- Resolves: RHEL-47148 Pagure #9629: Syntax error uninstalling the selinux-luna subpackage
- Resolves: RHEL-40892 ipa-server-install: token_password_file read in kra.install_check after calling hsm_validator in ca.install_check

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-07-18 13:25:00 +02:00
Florence Blanc-Renaud
fcc298685a ipa-4.12.1-2
- Resolves: RHEL-46607 kdc.crt certificate not getting automatically renewed by certmonger in IPA Hidden replica
- Resolves: RHEL-46606 ipa-client rpm post script creates always ssh_config.orig even if nothing needs to be changed
- Resolves: RHEL-46605 IPA Web UI not showing replication agreement for non-admin users
- Resolves: RHEL-46592 [RFE] Allow IPA SIDgen task to continue if it finds an entity that SID can't be assigned to
- Resolves: RHEL-46556 Include latest fixes in python3-ipatests packages
- Resolves: RHEL-42705 PSKC.xml issues with ipa_otptoken_import.py

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-07-08 19:27:27 +02:00
Troy Dawson
605fed4ed0 Bump release for June 2024 mass rebuild 2024-06-24 08:51:28 -07:00
Sudhir Menon
b1684f15a7 Include gating.yaml for c10s
Signed-off-by: Sudhir Menon <sumenon@redhat.com>
2024-06-13 18:35:13 +05:30
Julien Rische
38e4126e68 ipa-4.12.1-1
- CVE-2024-3183 freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force
  Resolves: RHEL-32233
- CVE-2024-2698 freeipa: delegation rules allow a proxy service to impersonate any user to access another target service
  Resolves: RHEL-40881

Signed-off-by: Julien Rische <jrische@redhat.com>
2024-06-12 17:57:09 +02:00
Florence Blanc-Renaud
881a120bf5 rpminspect: add automatic waiver for runpath check
The "runpath" check of rpminspect raises an error related
to DT_RPATH using /usr/lib64/samba for /usr/lib64/samba/pdb/ipasam.so.
This can be waived as ipasam.so is a plugin for smdb and
requires to have DT_RPATH set.
Add the path /usr/lib64/samba to the list of allowed DT_RPATH
to ignore the issue.

Signed-off-by: Florence Blanc-Renaud <flo@redhat.com>
2024-06-05 12:35:25 +02:00
Florence Blanc-Renaud
90dae868c3 ipa-4.12.0-1
- Resolves: RHEL-39144 Rebase ipa to the latest 4.12 version for RHEL 10
- Resolves: RHEL-30537 ipa: freeipa: argument injection into the username field of the /ipa/session/login_password requests
2024-06-04 19:55:30 +02:00
Troy Dawson
123abb92ab Bump release to rebuild on correct samba
Signed-off-by: Troy Dawson <tdawson@redhat.com>
2024-02-22 10:58:02 -08:00
Alexander Bokovoy
d41e5ca07b Support 389-ds with lmdb backend
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2024-02-08 18:24:08 +02:00
Alexander Bokovoy
f407801376 Detect samba private libraries
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2024-01-30 20:11:07 +02:00
Alexander Bokovoy
7365e8a23f More backports
remove CA affinity patch, not ready for backport yet.

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2024-01-30 18:09:49 +02:00
Alexander Bokovoy
f19c883a04 Rebuild against Samba 4.20rc1
Add upstream fixes
- Fix memory leak in Kerberos KDC driver
- Fix possible crash in IPA command line tool when accessing Kerberos credentials
- Compatibility fix for Python Cryptography 42.0.0
- Fix CA affinity when installing replica

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2024-01-30 17:40:53 +02:00
Fedora Release Engineering
dc24d637fb Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-24 12:01:16 +00:00
Fedora Release Engineering
9d0ac5b4ee Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild 2024-01-19 19:46:15 +00:00
Alexander Bokovoy
297837b973 FreeIPA security release for CVE-2023-5455
Release notes:
https://www.freeipa.org/release-notes/4-11-1.html

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2024-01-10 14:23:42 +02:00
Alexander Bokovoy
cbef046169 Backport various fixes found by RHEL and upstream tests
- timezone shift in handling certificates (due to py3.12 adaptation)
- 'reason' vs 'Reason' in PKI revocation JSON API response
- allow removal of minlength attribute from a custom password policy

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-11-08 11:50:46 +02:00
Alexander Bokovoy
eb660edcd1 Adopt to Samba changes in malformed SID processing
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-10-23 18:16:23 +03:00
Alexander Bokovoy
f81c02d7c7 FreeIPA 4.11.0 release
Update Fedora part of the spec file as we don't support building 4.11+
for versions below Fedora 39.

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-10-03 16:11:28 +03:00
Alexander Bokovoy
f3e42960a7 Depend on selinux-policy-38.28-1
- Depend on selinux-policy-38.28-1.fc39
- Add SELinux policy for passkey_child to be used without ipa-otpd
- Related: rhbz#2238474

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-09-18 15:31:55 +03:00
Alexander Bokovoy
2aa5a94633 Restore SELinux context during IPA client uninstallation
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-09-12 20:07:54 +03:00
Alexander Bokovoy
f52df9fbd5 Configure SSSD to access USB devices when enrolling IPA client
Resolves: rhbz#2238474

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-09-12 08:47:02 +03:00
Alexander Bokovoy
f4aadac5c3 Update to FreeIPA 4.11.0-beta1
Sync spec file to the upstream's template
2023-08-21 18:56:10 +03:00
Fedora Release Engineering
685d576312 Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-07-19 20:13:36 +00:00
Miro Hrončok
4ca56b848a Use ssl.match_hostname from urllib3 as it was removed from Python 3.12 2023-07-05 08:53:26 +02:00
Python Maint
bdbff27a6d Rebuilt for Python 3.12 2023-06-27 12:03:21 +02:00
Alexander Bokovoy
e2e40e4ca3 Upstream release 4.10.2
Synchronize patches with CentOS 9 Stream

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-06-13 14:46:27 +03:00
Alexander Bokovoy
4d4375dd2d Support python-cryptography 40.0
Use upstream fixes from https://pagure.io/freeipa/issue/9355

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-05-15 15:01:10 +03:00
Jerry James
c9357e5423 Change fontawesome-fonts R to match fontawesome 4.x 2023-03-30 10:40:45 -06:00
Rafael Guterres Jeffman
2c8ae7cea5 Migrated to SPDX license.
Signed-off-by: Rafael Guterres Jeffman <rjeffman@redhat.com>
2023-02-28 22:33:24 -03:00
Yaakov Selkowitz
61685c38bd Update RHEL requirement versions 2023-02-01 10:32:13 -05:00
Alexander Bokovoy
796470e053 Rebuild against samba 4.18.0RC1
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2023-01-20 15:14:23 +02:00
Fedora Release Engineering
8ab874381a Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2023-01-19 03:52:45 +00:00
Alexander Bokovoy
9ab0396eec Rebuild against krb5 1.20.1
ABI change brings KDB version 9.0

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2022-12-01 17:42:46 +02:00
Alexander Bokovoy
d118b2bff1 Remove unused patches
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2022-11-27 08:21:38 +02:00
Alexander Bokovoy
bb102603da FreeIPA upstream release 4.10.1
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2022-11-27 08:20:59 +02:00
Alexander Bokovoy
a8a38b93f4 Rebuild against final samba 4.17 version
Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2022-09-14 12:55:28 +03:00
Adam Williamson
e554452b70 Rebuild against new samba-client-libs (for F37)
This is not actually needed on Rawhide, but I'm doing the rebuild
on both branches so Rawhide stays 'ahead' of F37 and the repos
stay in sync.
2022-08-24 11:30:05 -07:00
Thomas Woerner
7ca049e5b2 - Set passwordgracelimit to match global policy on group pw policies
- Fix dns resolver for nameservers with ports
- webui: Allow grace login limit
- Disabling gracelimit does not prevent LDAP binds
2022-08-24 14:08:02 +02:00
Adam Williamson
4c13a8ea64 Rebuild against new libndr 2022-08-09 09:50:09 -07:00
Alexander Bokovoy
cc272c95c6 Rebuild against samba 4.16.3-2.fc37
Resolves: rhbz#2110746

Signed-off-by: Alexander Bokovoy <abokovoy@redhat.com>
2022-07-26 12:30:18 +03:00
Fedora Release Engineering
2cec094c03 Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
Signed-off-by: Fedora Release Engineering <releng@fedoraproject.org>
2022-07-21 03:36:30 +00:00
Rob Crittenden
e304b9f95e freeIPA 4.10.0 upstream release
Release notes: https://www.freeipa.org/page/Releases/4.10.0

Signed-off-by: Rob Crittenden <rcritten@redhat.com>
2022-06-30 11:28:59 -04:00
Python Maint
6d962d6a46 Rebuilt for Python 3.11 2022-06-16 13:34:41 +02:00