5bae5ab37aipa-4.12.2-17 - Resolves: RHEL-88043 Server installation: dot-forwarder not added as a forwarder - Resolves: RHEL-86481 Include latest fixes in python3-ipatests package - Resolves: RHEL-85788 ipa-sidgen: fix memory leak in ipa_sidgen_add_post_op() - Resolves: RHEL-88899 [RFE] Add check on CA cert expiry for ipa-cert-fix
imports/c10s/ipa-4.12.2-17.el10
Florence Blanc-Renaud
2025-04-29 17:49:26 +0200
9b0db8834cRemove '-q' from '%autopatch' call as it is not available in RHEL
Rafael Guterres Jeffman
2025-03-31 15:57:03 -0300
74fc7d8915ipa release 4.9.13-16
Rafael Guterres Jeffman
2025-03-31 14:18:24 -0300
9744eaabe1ipa-4.12.2-15 - Resolves: RHEL-84481 Protect all IPA service principals - Resolves: RHEL-84277 [RFE] IDM support UIDs up to 4,294,967,293 - Resolves: RHEL-84276 Ipa client --raw --structured throws internal error - Resolves: RHEL-82707 Search size limit tooltip has Search time limit tooltip text - Resolves: RHEL-82089 IPU 9 -> 10: ipa-server breaks the in-place upgrade due to failed scriptlet - Resolves: RHEL-68800 ipa-migrate with LDIF file from backup of remote server, fails with error 'change collided with another change' - Resolves: RHEL-30658 ipa-cacert-manage install fails with CAs having the same subject DN (subject key mismatch info)
Florence Blanc-Renaud
2025-03-25 16:43:36 +0100
518fbd80d0ipa-4.12.2-16 - Resolves: RHEL-84648 ipa-cacert-manage install fails with CAs having the same subject DN (subject key mismatch info) - Resolves: RHEL-84279 IPU 9 -> 10: ipa-server breaks the in-place upgrade due to failed scriptlet - Resolves: RHEL-84275 Search size limit tooltip has Search time limit tooltip text - Resolves: RHEL-81200 Ipa client --raw --structured throws internal error - Resolves: RHEL-68803 ipa-migrate with LDIF file from backup of remote server, fails with error 'change collided with another change' - Resolves: RHEL-67686 [RFE] IDM support UIDs up to 4,294,967,293 - Resolves: RHEL-67633 ipa-healthcheck has tests which call fips-mode-setup - Resolves: RHEL-4845 Protect *all* IPA service principals
imports/c10s/ipa-4.12.2-16.el10
Florence Blanc-Renaud
2025-03-24 11:56:22 +0100
144db502e5ipa-4.12.2-14 - Resolves: RHEL-80345 Use new bind9.18-dyndb-ldap and bind9.18 only for DNS over TLS with the ipa-server-encrypted-dns package
Thomas Woerner
2025-03-20 13:04:10 +0100
38cf0fbb20ipa-4.12.2-11 - Resolves: RHEL-67913 Add DNS over TLS Support, require bind9.18 32:9.18.29-2 and bind-dyndb-ldap 11.11-1
Thomas Woerner
2025-02-11 18:33:45 +0100
73e3a943d0ipa-4.12.2-14 - Resolves: RHEL-78766 Include latest fixes in python3-ipatests package - Resolves: RHEL-77965 ipa-server-install failing on slow hsm
imports/c10s/ipa-4.12.2-14.el10
Florence Blanc-Renaud
2025-02-11 18:08:52 +0100
837c02b504ipa-4.12.2-13 - Resolves: RHEL-67912 Add DNS over TLS Support, require bind 32:9.18.33-2 and bind-dyndb-ldap 11.11-1
Thomas Woerner
2025-02-11 17:43:26 +0100
1b6180a5e1Import OL ipa-4.12.2-1.0.1.el9_5.4
eabdullin
2025-02-05 12:46:05 +0300
5a34f265f7ipa-4.12.2-12 - Resolves: RHEL-72580 A slow HSM can cause IPA server installation to fail setting up certificate tracking
imports/c10s/ipa-4.12.2-12.el10
Florence Blanc-Renaud
2025-01-28 14:12:51 +0100
e62b5538d9ipa-4.12.2-10 - Resolves: RHEL-73022 A slow HSM can cause IPA server installation to fail setting up certificate tracking
Florence Blanc-Renaud
2025-01-28 13:36:13 +0100
d45f8dce3dipa-4.12.2-11 - Resolves: RHEL-75658 Include latest fixes in python3-ipatests package - Resolves: RHEL-74466 kinit with external idp user is failing
imports/c10s/ipa-4.12.2-11.el10
Florence Blanc-Renaud
2025-01-22 09:46:51 +0100
85a695e7eeipa-4.12.2-9 - Resolves: RHEL-74465 kinit with external idp user is failing - Resolves: RHEL-75656 Include latest fixes in python3-ipatests package
Florence Blanc-Renaud
2025-01-21 17:55:45 +0100
97c1695387Import OL ipa-4.12.2-1.0.1.el9_5.3
eabdullin
2025-01-17 09:45:37 +0300
84d0312b89ipa-4.12.2-10 - Resolves: RHEL-72580 A slow HSM can cause IPA server installation to fail setting up certificate tracking - Resolves: RHEL-71964 KRA installation failure caused by a certificate mismatch in NSS DB and configuration file - Resolves: RHEL-71262 Include latest fixes in python3-ipatests package - Resolves: RHEL-67190 CVE-2024-11029 ipa: Administrative user data leaked through systemd journal
imports/c10s/ipa-4.12.2-10.el10
Florence Blanc-Renaud
2025-01-16 13:49:29 +0100
ed508b4be8ipa-4.12.2-8 - Resolves: RHEL-73022 A slow HSM can cause IPA server installation to fail setting up certificate tracking [rhel-9] - Resolves: RHEL-71261 [RHEL-9.6] Include latest fixes in python3-ipatests package - Resolves: RHEL-67191 CVE-2024-11029 ipa: Administrative user data leaked through systemd journal [rhel-9.6] - Resolves: RHEL-59040 KRA installation failure caused by a certificate mismatch in NSS DB and configuration file.
Florence Blanc-Renaud
2025-01-15 18:19:41 +0100
8570e5b965- Add ipa-idrange-fix - ipatests: Add missing comma in test_idrange_no_rid_bases_reversed - ipatests: Fixes for ipa-idrange-fix testsuite - Do not let user with an expired OTP token to log in if only OTP is allowed
changed/a9/ipa-4.12.2-1.el9_5.2.alma.1
a9
eabdullin
2024-12-23 12:22:37 +0300
85c240179aMerge branch 'c9' into a9
eabdullin
2024-12-23 12:12:06 +0300
dd295410e9Import AL stable
eabdullin
2024-12-23 12:11:00 +0300
4c20458190ipa-4.12.2-7 - Resolves: RHEL-70760 Fix typo in ipa-migrate log file i.e 'Privledges' to 'Privileges' - Resolves: RHEL-70481 ipa-server-upgrade fails after established trust with ad - Resolves: RHEL-69927 add support for python cryptography 44.0.0 - Resolves: RHEL-69908 All user groups are not being included during HSM token validation - Resolves: RHEL-69900 Upgrade to ipa-server-4.12.2-1.el9 OTP-based bind to LDAP without enforceldapotp is broken
Florence Blanc-Renaud
2024-12-11 10:47:47 +0100
8f97c76dbaipa-4.12.2-9 - Resolves: RHEL-70759 Fix typo in ipa-migrate log file i.e 'Privledges' to 'Privileges' - Resolves: RHEL-70477 ipa-server-upgrade fails after established trust with ad - Resolves: RHEL-70253 Upgrade to ipa-server-4.12.2-1.el9 OTP-based bind to LDAP without enforceldapotp is broken - Resolves: RHEL-69926 add support for python cryptography 44.0.0 - Resolves: RHEL-69635 All user groups are not being included during HSM token validation
imports/c10s/ipa-4.12.2-9.el10
Florence Blanc-Renaud
2024-12-11 09:46:58 +0100
644504a963ipa-4.12.2-6 - Resolves: RHEL-68448 ipa trust-add fails in FIPS mode with an internal error has occurred - Resolves: RHEL-69301 Support GSSAPI in Cockpit on IPA servers
Florence Blanc-Renaud
2024-11-27 18:50:12 +0100
9fadb53aa0ipatests: Update ipa-adtrust-install test
Rafael Guterres Jeffman
2024-11-27 11:44:56 -0300
19240eadc4ipa-4.12.2-5 - Resolves: RHEL-67414 ipa dns-zone --allow-query '!198.18.2.0/24;any;' fails with Unrecognized IPAddress flags - Resolves: RHEL-67410 ipa-migrate should also migrate DNS forward zones - Resolves: RHEL-67409 ipa-migrate in stage mode fails with TypeError: 'NoneType' object is not iterable - Resolves: RHEL-66964 Include latest fixes in python3-ipatests packages - Resolves: RHEL-64135 IDP configuration in the IdM WebUI shows Organization is required
Florence Blanc-Renaud
2024-11-20 09:49:21 +0100
e2ceb15ca1Backports for 4.9.13-12 release:
Rafael Guterres Jeffman
2024-11-13 17:31:55 -0300
255a8322a5ipa-4.12.2-7 - Resolves: RHEL-66599 vault-add fails in FIPS mode - Resolves: RHEL-66598 ipa-migrate should also migrate DNS forward zones - Resolves: RHEL-66597 ipa-migrate in stage mode fails with TypeError: 'NoneType' object is not iterable - Resolves: RHEL-66595 Sentences truncated in man pages - Resolves: RHEL-66592 IDP configuration in the IdM WebUI shows Organization is required - Resolves: RHEL-65650 ipa-server-install with setup-dns fails 'job for ipa.service failed because the control process exited with error code'
imports/c10s/ipa-4.12.2-7.el10
Florence Blanc-Renaud
2024-11-08 11:37:33 +0100
c8a18bb46dipa-4.12.2-2 - Related: RHEL-59788 Rebase Samba to the latest 4.21.x release - Fixes: RHEL-61642 Uninstall ACME separately during PKI uninstallation - Fixes: RHEL-56963 SSSD offline causing test-adtrust-install failure - Fixes: RHEL-56473 Include latest fixes in python3-ipatests packages - Fixes: RHEL-48104 Default hbac rules are duplicated on remote server post ipa-migrate in prod-mode - Fixes: RHEL-45330 [RFE] add a tool to quickly detect and fix issues with IPA ID ranges - Fixes: RHEL-40376 SID generation task is failing when SELinux is in Enforcing mode - Fixes: RHEL-4915 Last expired OTP token would be c
Florence Blanc-Renaud
2024-10-21 19:24:16 +0200
80f94e10a4ipa-4.12.2-4 Bump version Related: RHEL-59777 Rebase Samba to the latest 4.21.x release
imports/c10s/ipa-4.12.2-4.el10
Florence Blanc-Renaud
2024-10-21 18:05:17 +0200
66cc1eaeecipa-4.12.2-4 - Related: RHEL-59777 Rebase Samba to the latest 4.21.x release - Resolves: RHEL-59659 ipa dns-zone --allow-query '!198.18.2.0/24;any;' fails with Unrecognized IPAddress flags - Resolves: RHEL-61636 Uninstall ACME separately during PKI uninstallation - Resolves: RHEL-61723 Include latest fixes in python3-ipatests packages - Resolves: RHEL-63325 Last expired OTP token would be considered as still assigned to the user
Florence Blanc-Renaud
2024-10-21 17:39:50 +0200
c94e6ae745ipa-4.12.2-3 Resolves: RHEL-33818 Remove python3-ipalib's dependency on python3-netifaces
imports/c10s/ipa-4.12.2-3.el10
Rafael Guterres Jeffman
2024-09-24 10:21:52 -0300
5d90090676ipa-4.12.2.2 - Resolves: RHEL-47294 SID generation task is failing when SELinux is in Enforcing mode - Resolves: RHEL-56472 Include latest fixes in python3-ipatests packages - Resolves: RHEL-56917 RFE add a tool to quickly detect and fix issues with IPA ID ranges - Resolves: RHEL-56965 Backport test fixes in python3-ipatests - Resolves: RHEL-58067 ipa replication installation fails in FIPS mode on rhel10 - Resolves: RHEL-59265 Default hbac rules are duplicated on remote server post ipa-migrate in prod-mode - Resolves: RHEL-59266 Also enable SSSD's ssh service when enabling sss_ssh_knownhosts
imports/c10s/ipa-4.12.2-2.el10
Florence Blanc-Renaud
2024-09-18 11:23:26 +0200
86420dd2f3ipa-4.12.1-4 - Resolves: RHEL-53501 adtrustinstance only prints issues in check_inst() and does not log them - Resolves: RHEL-52305 Unconditionally add MS-PAC to global config - Resolves: RHEL-52223 ipa-replica/server-install with softhsm needs to check permission/ownership of /var/lib/softhsm/tokens to avoid install failure - Resolves: RHEL-51937 Include latest fixes in python3-ipatests packages - Resolves: RHEL-50805 ipa-migrate -Z with invalid cert options fails with 'ValueError: option error' - Resolves: RHEL-49805 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w - Resolves: RHEL-49592 'Unable to log in as uid=admin-replica.testrealm.test,ou=people,o=ipaca' during replica install - Resolves: RHEL-4879 RFE - Keep the configured value for the "nsslapd-ignore-time-skew" after a "force-sync"
imports/c10s/ipa-4.12.1-4.el10
Florence Blanc-Renaud
2024-08-08 15:57:12 +0200
3979c73861ipa-4.12.0-7 - Resolves: RHEL-53500 adtrustinstance only prints issues in check_inst() and does not log them - Resolves: RHEL-52306 Unconditionally add MS-PAC to global config - Resolves: RHEL-52300 RFE - Keep the configured value for the "nsslapd-ignore-time-skew" after a "force-sync" - Resolves: RHEL-52222 ipa-replica/server-install with softhsm needs to check permission/ownership of /var/lib/softhsm/tokens to avoid install failure - Resolves: RHEL-51944 Include latest fixes in python3-ipatests packages - Resolves: RHEL-50804 ipa-migrate -Z with invalid cert options fails with 'ValueError: option error' - Resolves: RHEL-49602 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w - Resolves: RHEL-27856 'Unable to log in as uid=admin-replica.testrealm.test,ou=people,o=ipaca' during replica install
Florence Blanc-Renaud
2024-08-08 16:12:28 +0200
8b6d847e67ipa-4.12.0-6 - Resolves: RHEL-47292 Include latest fixes in python3-ipatests packages - Resolves: RHEL-47146 Syntax error uninstalling the selinux-luna subpackage - Resolves: RHEL-46009 ipa-migrate with -Z option fails with ValueError: option error - Resolves: RHEL-46003 ipa-migrate -V options fails to display version - Resolves: RHEL-45463 ipa-migrate stage-mode is failing with error: Modifying a mapped attribute in a managed entry is not allowed - Resolves: RHEL-40890 ipa-server-install: token_password_file read in kra.install_check after calling hsm_validator in ca.install_check - Resolves: RHEL-40661 Adjust "ipa config-mod --addattr ipaconfigstring=EnforceLDAPOTP" to allow for non OTP users in some cases
Florence Blanc-Renaud
2024-07-18 14:24:55 +0200
6c2a5fa538ipa-4.12.1-3 - Resolves: RHEL-49452 Include latest fixes in python3-ipatests packages - Resolves: RHEL-49433 Adjust "ipa config-mod --addattr ipaconfigstring=EnforceLDAPOTP" to allow for non OTP users in some cases - Resolves: RHEL-49432 ipa-migrate stage-mode is failing with error: Modifying a mapped attribute in a managed entry is not allowed - Resolves: RHEL-49413 ipa-migrate with -Z option fails with ValueError: option error - Resolves: RHEL-47157 ipa-migrate -V options fails to display version - Resolves: RHEL-47148 Pagure #9629: Syntax error uninstalling the selinux-luna subpackage - Resolves: RHEL-40892 ipa-server-install: token_password_file read in kra.install_check after calling hsm_validator in ca.install_check
imports/c10s/ipa-4.12.1-3.el10
Florence Blanc-Renaud
2024-07-18 13:25:00 +0200
880d21b828Backports for 4.9.13-9 release:
Rafael Guterres Jeffman
2024-07-17 12:33:21 -0300
fcc298685aipa-4.12.1-2 - Resolves: RHEL-46607 kdc.crt certificate not getting automatically renewed by certmonger in IPA Hidden replica - Resolves: RHEL-46606 ipa-client rpm post script creates always ssh_config.orig even if nothing needs to be changed - Resolves: RHEL-46605 IPA Web UI not showing replication agreement for non-admin users - Resolves: RHEL-46592 [RFE] Allow IPA SIDgen task to continue if it finds an entity that SID can't be assigned to - Resolves: RHEL-46556 Include latest fixes in python3-ipatests packages - Resolves: RHEL-42705 PSKC.xml issues with ipa_otptoken_import.py
Florence Blanc-Renaud
2024-07-08 19:27:27 +0200
d0ca280108ipa-4.12.0-5 - Resolves: RHEL-37285 IPA Web UI not showing replication agreement for non-admin users - Resolves: RHEL-42703 PSKC.xml issues with ipa_otptoken_import.py - Resolves: RHEL-41194 ipa-client rpm post script creates always ssh_config.orig even if nothing needs to be changed - Resolves: RHEL-39477 kdc.crt certificate not getting automatically renewed by certmonger in IPA Hidden replica - Resolves: RHEL-46559 Include latest fixes in python3-ipatests packages - Resolves: RHEL-22188 [RFE] Allow IPA SIDgen task to continue if it finds an entity that SID can't be assigned to
Florence Blanc-Renaud
2024-07-08 18:35:11 +0200
605fed4ed0Bump release for June 2024 mass rebuild
Troy Dawson
2024-06-24 08:51:28 -0700
b1684f15a7Include gating.yaml for c10s
Sudhir Menon
2024-06-13 18:35:13 +0530
3e4c75a7b3ipa-4.12.0-3 - Related: RHEL-34809 temporarily revert a commit that depends on newer version of python-jwcrypto
Florence Blanc-Renaud
2024-06-05 15:07:32 +0200
90dae868c3ipa-4.12.0-1 - Resolves: RHEL-39144 Rebase ipa to the latest 4.12 version for RHEL 10 - Resolves: RHEL-30537 ipa: freeipa: argument injection into the username field of the /ipa/session/login_password requests
Florence Blanc-Renaud
2024-06-04 19:55:30 +0200
86ca9218d9ipa-4.12.0-2 - Resolves: RHEL-39950 ipa-client can't be installed because of a missing dependency
Florence Blanc-Renaud
2024-06-04 16:01:25 +0200
b4517960e4ipa-4.12.0-1 - Resolves: RHEL-39140 Rebase ipa to the latest 4.12 version for RHEL 9.5 - Resolves: RHEL-34757 The change for preventing deletion of the admin user caused a regression in disable - Resolves: RHEL-30553 Depend on nfsv4-client-utils or nfs-utils - Resolves: RHEL-29762 IPA sidgen fails to create SID for manually set ID for a new range [rhel-9.5.0] - Resolves: RHEL-26261 Fix replica connection check for use with AD administrator - Resolves: RHEL-18062 ipa ca-show NAME --certificate-out=file creates empty file when NAME does not exist - Resolves: RHEL-12149 traceback in ipaserver/dcerpc.py - Resolves: RHEL-4810 [RFE] FreeIPA-to-FreeIPA migration - Resolves: RHEL-4807 [RFE] Support in IPA for HSM boxes
Florence Blanc-Renaud
2024-05-29 19:24:35 +0200