Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
Name: ipa-server | Distribution: CentOS |
Version: 4.12.2 | Vendor: CentOS |
Release: 8.el10 | Build date: Wed Nov 27 20:02:27 2024 |
Group: Unspecified | Build host: ppc64le-07.stream.rdu2.redhat.com |
Size: 1956833 | Source RPM: ipa-4.12.2-8.el10.src.rpm |
Packager: [email protected] | |
Url: http://www.freeipa.org/ | |
Summary: The IPA authentication server |
IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). If you are installing an IPA server, you need to install this package.
GPL-3.0-or-later
* Wed Nov 27 2024 Florence Blanc-Renaud <[email protected]> - 4.12.2-8 - Resolves: RHEL-69300 Support GSSAPI in Cockpit on IPA servers - Resolves: RHEL-68447 ipa trust-add fails in FIPS mode with an internal error has occurred - Resolves: RHEL-57674 Use RSNv3 and enable cert pruning by default in RHEL 10.0 * Fri Nov 08 2024 Florence Blanc-Renaud <[email protected]> - 4.12.2-7 - Resolves: RHEL-66599 vault-add fails in FIPS mode - Resolves: RHEL-66598 ipa-migrate should also migrate DNS forward zones - Resolves: RHEL-66597 ipa-migrate in stage mode fails with TypeError: 'NoneType' object is not iterable - Resolves: RHEL-66595 Sentences truncated in man pages - Resolves: RHEL-66592 IDP configuration in the IdM WebUI shows Organization is required - Resolves: RHEL-65650 ipa-server-install with setup-dns fails 'job for ipa.service failed because the control process exited with error code' * Thu Oct 31 2024 Florence Blanc-Renaud <[email protected]> - 4.12.2-6 - Resolves: RHEL-64018 Bump release for October 2024 mass rebuild * Tue Oct 29 2024 Florence Blanc-Renaud <[email protected]> - 4.12.2-5 - Resolves: RHEL-61636 Uninstall ACME separately during PKI uninstallation * Mon Oct 21 2024 Florence Blanc-Renaud <[email protected]> - 4.12.2-4 - Related: RHEL-59777 Rebase Samba to the latest 4.21.x release - Resolves: RHEL-59659 ipa dns-zone --allow-query '!198.18.2.0/24;any;' fails with Unrecognized IPAddress flags - Resolves: RHEL-61636 Uninstall ACME separately during PKI uninstallation - Resolves: RHEL-61723 Include latest fixes in python3-ipatests packages - Resolves: RHEL-63325 Last expired OTP token would be considered as still assigned to the user * Tue Sep 24 2024 Rafael Guteres Jeffman <[email protected]> - 4.12.2-3 - Resolves: RHEL-33818 Remove python3-ipalib's dependency on python3-netifaces * Wed Sep 18 2024 Florence Blanc-Renaud <[email protected]> - 4.12.2-2 - Resolves: RHEL-47294 SID generation task is failing when SELinux is in Enforcing mode - Resolves: RHEL-56472 Include latest fixes in python3-ipatests packages - Resolves: RHEL-56917 RFE add a tool to quickly detect and fix issues with IPA ID ranges - Resolves: RHEL-56965 Backport test fixes in python3-ipatests - Resolves: RHEL-58067 ipa replication installation fails in FIPS mode on rhel10 - Resolves: RHEL-59265 Default hbac rules are duplicated on remote server post ipa-migrate in prod-mode - Resolves: RHEL-59266 Also enable SSSD's ssh service when enabling sss_ssh_knownhosts * Thu Aug 22 2024 Florence Blanc-Renaud <[email protected]> - 4.12.2-1 - Resolves: RHEL-54545 Covscan issues: Resource Leak - Resolves: RHEL-54304 support for python cryptography 43.0.0 - Resolves: RHEL-49805 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w - Resolves: RHEL-46897 With unreachable AD, ipa trust returns an internal error * Thu Aug 08 2024 Florence Blanc-Renaud <[email protected]> - 4.12.1-4 - Resolves: RHEL-53501 adtrustinstance only prints issues in check_inst() and does not log them - Resolves: RHEL-52305 Unconditionally add MS-PAC to global config - Resolves: RHEL-52223 ipa-replica/server-install with softhsm needs to check permission/ownership of /var/lib/softhsm/tokens to avoid install failure - Resolves: RHEL-51937 Include latest fixes in python3-ipatests packages - Resolves: RHEL-50805 ipa-migrate -Z with invalid cert options fails with 'ValueError: option error' - Resolves: RHEL-49805 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w - Resolves: RHEL-49592 'Unable to log in as uid=admin-replica.testrealm.test,ou=people,o=ipaca' during replica install - Resolves: RHEL-4879 RFE - Keep the configured value for the "nsslapd-ignore-time-skew" after a "force-sync" * Thu Jul 18 2024 Florence Blanc-Renaud <[email protected]> - 4.12.1-3 - Resolves: RHEL-49452 Include latest fixes in python3-ipatests packages - Resolves: RHEL-49433 Adjust "ipa config-mod --addattr ipaconfigstring=EnforceLDAPOTP" to allow for non OTP users in some cases - Resolves: RHEL-49432 ipa-migrate stage-mode is failing with error: Modifying a mapped attribute in a managed entry is not allowed - Resolves: RHEL-49413 ipa-migrate with -Z option fails with ValueError: option error - Resolves: RHEL-47157 ipa-migrate -V options fails to display version - Resolves: RHEL-47148 Pagure #9629: Syntax error uninstalling the selinux-luna subpackage - Resolves: RHEL-40892 ipa-server-install: token_password_file read in kra.install_check after calling hsm_validator in ca.install_check * Mon Jul 08 2024 Florence Blanc-Renaud <[email protected]> - 4.12.1-2 - Resolves: RHEL-46607 kdc.crt certificate not getting automatically renewed by certmonger in IPA Hidden replica - Resolves: RHEL-46606 ipa-client rpm post script creates always ssh_config.orig even if nothing needs to be changed - Resolves: RHEL-46605 IPA Web UI not showing replication agreement for non-admin users - Resolves: RHEL-46592 [RFE] Allow IPA SIDgen task to continue if it finds an entity that SID can't be assigned to - Resolves: RHEL-46556 Include latest fixes in python3-ipatests packages - Resolves: RHEL-42705 PSKC.xml issues with ipa_otptoken_import.py * Mon Jun 24 2024 Troy Dawson <[email protected]> - 4.12.1-1.1 - Bump release for June 2024 mass rebuild * Wed Jun 12 2024 Julien Rische <[email protected]> - 4.12.1-1 - Resolves: RHEL-32233 CVE-2024-3183 freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force - Resolves: RHEL-40881 CVE-2024-2698 freeipa: delegation rules allow a proxy service to impersonate any user to access another target service * Tue Jun 04 2024 Florence Blanc-Renaud <[email protected]> - 4.12.0-1 - Resolves: RHEL-39144 Rebase ipa to the latest 4.12 version for RHEL 10 - Resolves: RHEL-30537 ipa: freeipa: argument injection into the username field of the /ipa/session/login_password requests * Thu Feb 22 2024 Troy Dawson <[email protected]> - 4.11.1-4 - Bump release to rebuild on correct samba * Thu Feb 08 2024 Alexander Bokovoy <[email protected]> - 4.11.1-3 - Support 389-ds with lmdb backend * Wed Jan 24 2024 Fedora Release Engineering <[email protected]> - 4.11.1-2 - Rebuild against Samba 4.20rc1 - Fix memory leak in Kerberos KDC driver - Fix possible crash in IPA command line tool when accessing Kerberos credentials - Compatibility fix for Python Cryptography 42.0.0 - NetBIOS defaults fix - Fix default host keytab retrieval permissions * Wed Jan 24 2024 Fedora Release Engineering <[email protected]> - 4.11.1-1.2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Fri Jan 19 2024 Fedora Release Engineering <[email protected]> - 4.11.1-1.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild * Wed Jan 10 2024 Alexander Bokovoy <[email protected]> - 4.11.1-1 - Security release: CVE-2023-5455 - Resolves: rhbz#2257646 * Wed Nov 08 2023 Alexander Bokovoy <[email protected]> - 4.11.0-7 - ipalib: fix the IPACertificate validity dates (python 3.12 compatibility) - Handle PKI revocation response differences in JSON API - Allow removal of minimal length from a custom password policy * Mon Oct 23 2023 Alexander Bokovoy <[email protected]> - 4.11.0-6 - Adopt trust to AD code to Samba changes in case SIDs are malformed * Tue Oct 03 2023 Alexander Bokovoy <[email protected]> - 4.11.0-5 - FreeIPA 4.11.0 release - Simplify Fedora spec file - Release notes: https://www.freeipa.org/release-notes/4-11-0.html * Mon Sep 18 2023 Alexander Bokovoy <[email protected]> - 4.11.0-4.beta1 - Depend on selinux-policy-38.28-1.fc39 - Add SELinux policy for passkey_child to be used without ipa-otpd - Related: rhbz#2238474 * Tue Sep 12 2023 Alexander Bokovoy <[email protected]> - 4.11.0-3.beta1 - Restore properly SELinux context during IPA client uninstallation - Related: rhbz#2238474 * Tue Sep 12 2023 Alexander Bokovoy <[email protected]> - 4.11.0-2.beta1 - Set 'sssd_use_usb' SELinux boolean when enrolling IPA client - Resolves: rhbz#2238474 * Mon Aug 21 2023 Alexander Bokovoy <[email protected]> - 4.11.0-1.beta1 - FreeIPA 4.11.0 beta 1 - Release notes: https://www.freeipa.org/release-notes/4-11-0-beta.html * Wed Jul 19 2023 Fedora Release Engineering <[email protected]> - 4.10.2-1.3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Wed Jul 05 2023 Miro HronĨok <[email protected]> - 4.10.2-1.2 - Use ssl.match_hostname from urllib3 as it was removed from Python 3.12 * Tue Jun 27 2023 Python Maint <[email protected]> - 4.10.2-1.1 - Rebuilt for Python 3.12 * Tue Jun 13 2023 Alexander Bokovoy <[email protected]> - 4.10.2-1 - Upstream release FreeIPA 4.10.2 - Synchronize patches with CentOS 9 Stream * Mon May 15 2023 Alexander Bokovoy <[email protected]> - 4.10.1-5 - Support python-cryptography 40.0 * Thu Mar 30 2023 Jerry James <[email protected]> - 4.10.1-4 - Change fontawesome-fonts R to match fontawesome 4.x * Fri Jan 20 2023 Alexander Bokovoy <[email protected]> - 4.10.1-3 - Rebuild against Samba 4.18.0RC1 * Thu Jan 19 2023 Fedora Release Engineering <[email protected]> - 4.10.1-2.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Thu Dec 01 2022 Alexander Bokovoy <[email protected]> - 4.10.1-2 - Rebuild against krb5-1.20.1-1
/etc/dbus-1/system.d/org.freeipa.server.conf /etc/oddjobd.conf.d/ipa-server.conf /usr/lib/.build-id /usr/lib/.build-id/23 /usr/lib/.build-id/23/18861f83cb594bb992e45503114c6d2d17eb65 /usr/lib/.build-id/24 /usr/lib/.build-id/24/a0e28d77988cb687a4061105c244cd0713d772 /usr/lib/.build-id/2c /usr/lib/.build-id/2c/6fa0d5b0f63f59fd938e93fe5c4c87ca1a2e86 /usr/lib/.build-id/3c /usr/lib/.build-id/3c/f7cfe5a1b17e84daaa97d78320768938cce712 /usr/lib/.build-id/48 /usr/lib/.build-id/48/2dc2a024b5f41c80bc7eb3b15e91d1896b7dda /usr/lib/.build-id/48/8d32baa67f0ecf4e522b0443ce7354c7acad70 /usr/lib/.build-id/4b /usr/lib/.build-id/4b/ef0175081b453b4bb8364f83617c31388db855 /usr/lib/.build-id/6a /usr/lib/.build-id/6a/f4b6f1c5af62f37a76fe16c0ecb1c79dcb9f15 /usr/lib/.build-id/8b /usr/lib/.build-id/8b/36f25447b74198fbfec034383a8deaad01e5ff /usr/lib/.build-id/98 /usr/lib/.build-id/98/0ff98469b1c4ab7165e0d4bc752208bb9310f4 /usr/lib/.build-id/9c /usr/lib/.build-id/9c/84bbae7b8c2d1764468bcb795d8b939d7cef03 /usr/lib/.build-id/a0 /usr/lib/.build-id/a0/6ce89d697fb5dffc1559e5ab8a744bdda99943 /usr/lib/.build-id/ae /usr/lib/.build-id/ae/b606b75a54c0f2a7fe95ab6752c92cc3163dce /usr/lib/.build-id/b3 /usr/lib/.build-id/b3/90db7450c3b410152bea7ebc8fec7e928e9226 /usr/lib/.build-id/bc /usr/lib/.build-id/bc/9cd29467a84378bf8fe2e234206102d8030e90 /usr/lib/.build-id/d4 /usr/lib/.build-id/d4/8984a75072946f61bf60d47859ef5e64bf64e6 /usr/lib/.build-id/d9 /usr/lib/.build-id/d9/1ab192240092c0534fb790ce6e0d37f7de51fc /usr/lib/.build-id/dc /usr/lib/.build-id/dc/921ad076ad8602079d349503f96cfe00a9ba93 /usr/lib/.build-id/df /usr/lib/.build-id/df/d4d8e35749d8559814b088e85e2ebbb0d07ae8 /usr/lib/systemd/catalog/ipa.catalog /usr/lib/systemd/system/ipa-ccache-sweep.service /usr/lib/systemd/system/ipa-ccache-sweep.timer /usr/lib/systemd/system/ipa-otpd.socket /usr/lib/systemd/system/[email protected] /usr/lib/systemd/system/ipa.service /usr/lib64/dirsrv/plugins/libipa_dns.so /usr/lib64/dirsrv/plugins/libipa_enrollment_extop.so /usr/lib64/dirsrv/plugins/libipa_extdom_extop.so /usr/lib64/dirsrv/plugins/libipa_graceperiod.so /usr/lib64/dirsrv/plugins/libipa_lockout.so /usr/lib64/dirsrv/plugins/libipa_modrdn.so /usr/lib64/dirsrv/plugins/libipa_otp_counter.so /usr/lib64/dirsrv/plugins/libipa_otp_lasttoken.so /usr/lib64/dirsrv/plugins/libipa_pwd_extop.so /usr/lib64/dirsrv/plugins/libipa_range_check.so /usr/lib64/dirsrv/plugins/libipa_repl_version.so /usr/lib64/dirsrv/plugins/libipa_sidgen.so /usr/lib64/dirsrv/plugins/libipa_sidgen_task.so /usr/lib64/dirsrv/plugins/libipa_uuid.so /usr/lib64/dirsrv/plugins/libipa_winsync.so /usr/lib64/dirsrv/plugins/libtopology.so /usr/lib64/krb5/plugins/kdb/ipadb.so /usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit /usr/libexec/certmonger/ipa-server-guard /usr/libexec/ipa /usr/libexec/ipa/certmonger /usr/libexec/ipa/certmonger/renew_ca_cert /usr/libexec/ipa/certmonger/renew_kdc_cert /usr/libexec/ipa/certmonger/renew_ra_cert /usr/libexec/ipa/certmonger/renew_ra_cert_pre /usr/libexec/ipa/certmonger/restart_dirsrv /usr/libexec/ipa/certmonger/restart_httpd /usr/libexec/ipa/certmonger/stop_pkicad /usr/libexec/ipa/custodia /usr/libexec/ipa/custodia/ipa-custodia-dmldap /usr/libexec/ipa/custodia/ipa-custodia-pki-tomcat /usr/libexec/ipa/custodia/ipa-custodia-pki-tomcat-wrapped /usr/libexec/ipa/custodia/ipa-custodia-ra-agent /usr/libexec/ipa/ipa-ccache-sweeper /usr/libexec/ipa/ipa-custodia /usr/libexec/ipa/ipa-custodia-check /usr/libexec/ipa/ipa-httpd-kdcproxy /usr/libexec/ipa/ipa-httpd-pwdreader /usr/libexec/ipa/ipa-otpd /usr/libexec/ipa/ipa-pki-retrieve-key /usr/libexec/ipa/ipa-pki-wait-running /usr/libexec/ipa/ipa-print-pac /usr/libexec/ipa/ipa-subids /usr/libexec/ipa/oddjob /usr/libexec/ipa/oddjob/org.freeipa.server.config-enable-sid /usr/libexec/ipa/oddjob/org.freeipa.server.conncheck /usr/libexec/ipa/oddjob/org.freeipa.server.trust-enable-agent /usr/sbin/ipa-acme-manage /usr/sbin/ipa-advise /usr/sbin/ipa-backup /usr/sbin/ipa-ca-install /usr/sbin/ipa-cacert-manage /usr/sbin/ipa-cert-fix /usr/sbin/ipa-compat-manage /usr/sbin/ipa-crlgen-manage /usr/sbin/ipa-csreplica-manage /usr/sbin/ipa-idrange-fix /usr/sbin/ipa-kra-install /usr/sbin/ipa-ldap-updater /usr/sbin/ipa-managed-entries /usr/sbin/ipa-migrate /usr/sbin/ipa-otptoken-import /usr/sbin/ipa-pkinit-manage /usr/sbin/ipa-replica-conncheck /usr/sbin/ipa-replica-install /usr/sbin/ipa-replica-manage /usr/sbin/ipa-restore /usr/sbin/ipa-server-certinstall /usr/sbin/ipa-server-install /usr/sbin/ipa-server-upgrade /usr/sbin/ipa-winsync-migrate /usr/sbin/ipactl /usr/share/doc/ipa-server /usr/share/doc/ipa-server/Contributors.txt /usr/share/doc/ipa-server/README.md /usr/share/licenses/ipa-server /usr/share/licenses/ipa-server/COPYING /usr/share/man/man1/ipa-acme-manage.1.gz /usr/share/man/man1/ipa-advise.1.gz /usr/share/man/man1/ipa-backup.1.gz /usr/share/man/man1/ipa-ca-install.1.gz /usr/share/man/man1/ipa-cacert-manage.1.gz /usr/share/man/man1/ipa-cert-fix.1.gz /usr/share/man/man1/ipa-compat-manage.1.gz /usr/share/man/man1/ipa-crlgen-manage.1.gz /usr/share/man/man1/ipa-csreplica-manage.1.gz /usr/share/man/man1/ipa-idrange-fix.1.gz /usr/share/man/man1/ipa-kra-install.1.gz /usr/share/man/man1/ipa-ldap-updater.1.gz /usr/share/man/man1/ipa-managed-entries.1.gz /usr/share/man/man1/ipa-migrate.1.gz /usr/share/man/man1/ipa-otptoken-import.1.gz /usr/share/man/man1/ipa-pkinit-manage.1.gz /usr/share/man/man1/ipa-replica-conncheck.1.gz /usr/share/man/man1/ipa-replica-install.1.gz /usr/share/man/man1/ipa-replica-manage.1.gz /usr/share/man/man1/ipa-restore.1.gz /usr/share/man/man1/ipa-server-certinstall.1.gz /usr/share/man/man1/ipa-server-install.1.gz /usr/share/man/man1/ipa-server-upgrade.1.gz /usr/share/man/man1/ipa-winsync-migrate.1.gz /usr/share/man/man8/ipactl.8.gz
Generated by rpm2html 1.8.1
Fabrice Bellet, Tue Jan 7 10:12:39 2025