Fri, 22 Nov 2024 00:03:51 CST | login

Information for build ipa-4.10.1-9.el9_2

ID27120
Package Nameipa
Version4.10.1
Release9.el9_2
Epoch
DraftFalse
Sourcegit+https://git.cclinux.org/stage/rpms/ipa.git#7ee2d857142eb9fd314e51cc96377e1dc98de3c0
SummaryThe Identity, Policy and Audit system
DescriptionIPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts).
Built bydistrobuild
State complete
Volume DEFAULT
StartedFri, 15 Sep 2023 19:36:46 CST
CompletedFri, 15 Sep 2023 20:24:08 CST
Taskbuild (dist-circle9_2-updates, /stage/rpms/ipa.git:7ee2d857142eb9fd314e51cc96377e1dc98de3c0)
Extra{'source': {'original_url': 'git+https://git.cclinux.org/stage/rpms/ipa.git?#7ee2d857142eb9fd314e51cc96377e1dc98de3c0'}}
Tags
dist-circle9-compose
dist-circle9-updates
RPMs
src
ipa-4.10.1-9.el9_2.src.rpm (info) (download)
aarch64
ipa-client-4.10.1-9.el9_2.aarch64.rpm (info) (download)
ipa-client-epn-4.10.1-9.el9_2.aarch64.rpm (info) (download)
ipa-client-samba-4.10.1-9.el9_2.aarch64.rpm (info) (download)
ipa-server-4.10.1-9.el9_2.aarch64.rpm (info) (download)
ipa-server-trust-ad-4.10.1-9.el9_2.aarch64.rpm (info) (download)
ipa-client-debuginfo-4.10.1-9.el9_2.aarch64.rpm (info) (download)
ipa-debuginfo-4.10.1-9.el9_2.aarch64.rpm (info) (download)
ipa-debugsource-4.10.1-9.el9_2.aarch64.rpm (info) (download)
ipa-server-debuginfo-4.10.1-9.el9_2.aarch64.rpm (info) (download)
ipa-server-trust-ad-debuginfo-4.10.1-9.el9_2.aarch64.rpm (info) (download)
i686
ipa-client-4.10.1-9.el9_2.i686.rpm (info) (download)
ipa-client-epn-4.10.1-9.el9_2.i686.rpm (info) (download)
ipa-client-samba-4.10.1-9.el9_2.i686.rpm (info) (download)
ipa-client-debuginfo-4.10.1-9.el9_2.i686.rpm (info) (download)
ipa-debugsource-4.10.1-9.el9_2.i686.rpm (info) (download)
noarch
ipa-client-common-4.10.1-9.el9_2.noarch.rpm (info) (download)
ipa-common-4.10.1-9.el9_2.noarch.rpm (info) (download)
ipa-python-compat-4.10.1-9.el9_2.noarch.rpm (info) (download)
ipa-selinux-4.10.1-9.el9_2.noarch.rpm (info) (download)
ipa-server-common-4.10.1-9.el9_2.noarch.rpm (info) (download)
ipa-server-dns-4.10.1-9.el9_2.noarch.rpm (info) (download)
python3-ipaclient-4.10.1-9.el9_2.noarch.rpm (info) (download)
python3-ipalib-4.10.1-9.el9_2.noarch.rpm (info) (download)
python3-ipaserver-4.10.1-9.el9_2.noarch.rpm (info) (download)
python3-ipatests-4.10.1-9.el9_2.noarch.rpm (info) (download)
ppc64le
ipa-client-4.10.1-9.el9_2.ppc64le.rpm (info) (download)
ipa-client-epn-4.10.1-9.el9_2.ppc64le.rpm (info) (download)
ipa-client-samba-4.10.1-9.el9_2.ppc64le.rpm (info) (download)
ipa-server-4.10.1-9.el9_2.ppc64le.rpm (info) (download)
ipa-server-trust-ad-4.10.1-9.el9_2.ppc64le.rpm (info) (download)
ipa-client-debuginfo-4.10.1-9.el9_2.ppc64le.rpm (info) (download)
ipa-debuginfo-4.10.1-9.el9_2.ppc64le.rpm (info) (download)
ipa-debugsource-4.10.1-9.el9_2.ppc64le.rpm (info) (download)
ipa-server-debuginfo-4.10.1-9.el9_2.ppc64le.rpm (info) (download)
ipa-server-trust-ad-debuginfo-4.10.1-9.el9_2.ppc64le.rpm (info) (download)
s390x
ipa-client-4.10.1-9.el9_2.s390x.rpm (info) (download)
ipa-client-epn-4.10.1-9.el9_2.s390x.rpm (info) (download)
ipa-client-samba-4.10.1-9.el9_2.s390x.rpm (info) (download)
ipa-server-4.10.1-9.el9_2.s390x.rpm (info) (download)
ipa-server-trust-ad-4.10.1-9.el9_2.s390x.rpm (info) (download)
ipa-client-debuginfo-4.10.1-9.el9_2.s390x.rpm (info) (download)
ipa-debuginfo-4.10.1-9.el9_2.s390x.rpm (info) (download)
ipa-debugsource-4.10.1-9.el9_2.s390x.rpm (info) (download)
ipa-server-debuginfo-4.10.1-9.el9_2.s390x.rpm (info) (download)
ipa-server-trust-ad-debuginfo-4.10.1-9.el9_2.s390x.rpm (info) (download)
x86_64
ipa-client-4.10.1-9.el9_2.x86_64.rpm (info) (download)
ipa-client-epn-4.10.1-9.el9_2.x86_64.rpm (info) (download)
ipa-client-samba-4.10.1-9.el9_2.x86_64.rpm (info) (download)
ipa-server-4.10.1-9.el9_2.x86_64.rpm (info) (download)
ipa-server-trust-ad-4.10.1-9.el9_2.x86_64.rpm (info) (download)
ipa-client-debuginfo-4.10.1-9.el9_2.x86_64.rpm (info) (download)
ipa-debuginfo-4.10.1-9.el9_2.x86_64.rpm (info) (download)
ipa-debugsource-4.10.1-9.el9_2.x86_64.rpm (info) (download)
ipa-server-debuginfo-4.10.1-9.el9_2.x86_64.rpm (info) (download)
ipa-server-trust-ad-debuginfo-4.10.1-9.el9_2.x86_64.rpm (info) (download)
Logs
aarch64
build.log
hw_info.log
installed_pkgs.log
mock_output.log
noarch_rpmdiff.json
root.log
state.log
i686
build.log
hw_info.log
installed_pkgs.log
mock_output.log
noarch_rpmdiff.json
root.log
state.log
ppc64le
build.log
hw_info.log
installed_pkgs.log
mock_output.log
noarch_rpmdiff.json
root.log
state.log
s390x
build.log
hw_info.log
installed_pkgs.log
mock_output.log
noarch_rpmdiff.json
root.log
state.log
x86_64
build.log
hw_info.log
installed_pkgs.log
mock_output.log
noarch_rpmdiff.json
root.log
state.log
Changelog * Fri Sep 15 2023 earthloong <earthloong@cclinux.org> - 4.10.1-9 - Add ipaplatform flag * Wed Aug 09 2023 Florence Blanc-Renaud <flo@redhat.com> - 4.10.1-9 - Resolves: rhbz#2230074 Interrupt request processing in ipadb_fill_info3() if connection to 389ds is lost * Tue Jul 18 2023 Florence Blanc-Renaud <flo@redhat.com> - 4.10.1-8 - Resolves: rhbz#2223556 User authentication failing on OTP validation using multiple tokens, succeeds with password only * Thu Jun 01 2023 Julien Rische <jrische@redhat.com> - 4.10.1-7 - Resolves: rhbz#2211389 Handle PAC signatures based on domain and server capabilities * Wed Feb 22 2023 Florence Blanc-Renaud <flo@redhat.com> - 4.10.1-6 - Resolves: rhbz#2169632 Backport latest test fixes in python3-ipatests * Mon Feb 13 2023 Florence Blanc-Renaud <flo@redhat.com> - 4.10.1-5 - Resolves: rhbz#2162656 Passwordless (GSSAPI) SSH not working for subdomain - Resolves: rhbz#2166326 Removing the last DNS type for ipa-ca does not work - Resolves: rhbz#2167473 RFE - Add a warning note about possible performance impact of the Auto Member rebuild task - Resolves: rhbz#2168244 requestsearchtimelimit=0 doesn't seems to be work with ipa-acme-manage pruning command * Mon Feb 06 2023 Florence Blanc-Renaud <flo@redhat.com> - 4.10.1-4 - Resolves: rhbz#2161284 'ERROR Could not remove /tmp/tmpbkw6hawo.ipabkp' can be seen prior to 'ipa-client-install' command was successful - Resolves: rhbz#2164403 ipa-trust-add with --range-type=ipa-ad-trust-posix fails while creating an ID range - Resolves: rhbz#2162677 RFE: Implement support for PKI certificate and request pruning - Resolves: rhbz#2167312 - Backport latest test fixes in python3-ipatests * Wed Dec 21 2022 Alexander Bokovoy <abokovoy@redhat.com> - 4.10.1-3 - Rebuild against krb5 1.20.1 ABI - Resolves: rhbz#2155425 * Fri Dec 09 2022 Florence Blanc-Renaud <flo@redhat.com> - 4.10.1-2 - Resolves: rhbz#2148887 MemberManager with groups fails - Resolves: rhbz#2150335 idm:client is missing dependency on krb5-pkinit * Fri Nov 25 2022 Florence Blanc-Renaud <flo@redhat.com> - 4.10.1-1 - Resolves: rhbz#2141315 [Rebase] Rebase ipa to latest 4.10.x release for RHEL 9.2 - Resolves: rhbz#2094673 ipa-client-install should just use system wide CA store and do not specify TLS_CACERT in ldap.conf - Resolves: rhbz#2117167 After leapp upgrade on ipa-client ipa-server package installation failed. (`REQ_FULL_WITH_MEMBERS` returns object from wrong domain) - Resolves: rhbz#2127833 Password Policy Grace login limit allows invalid maximum value - Resolves: rhbz#2143224 [RFE] add certificate support to ipa-client instead of one time password - Resolves: rhbz#2144736 vault interoperability with older RHEL systems is broken - Resolves: rhbz#2148258 ipa-client-install does not maintain server affinity during installation - Resolves: rhbz#2148379 Add warning for empty targetattr when creating ACI with RBAC - Resolves: rhbz#2148380 OTP token sync always returns OK even with random numbers - Resolves: rhbz#2148381 Deprecated feature idnssoaserial in IdM appears when creating reverse dns zones - Resolves: rhbz#2148382 Introduction of URI records for kerberos breaks location functionality * Tue Oct 25 2022 Rafael Jeffman <rjeffman@redhat.com> - 4.10.0-7 - Resolves: rhbz#2124547 Attempt to log in as "root" user with admin's password in Web UI does not properly fail - Resolves: rhbz#2137555 Attempt to log in as "root" user with admin's password in Web UI does not properly fail [rhel-9.1.0.z] * Fri Aug 19 2022 Florence Blanc-Renaud <flo@redhat.com> - 4.10.0-6 - Resolves: rhbz#2110014 ldap bind occurs when admin user changes password with gracelimit=0 - Resolves: rhbz#2112901 RFE: Allow grace login limit to be set in IPA WebUI - Resolves: rhbz#2115495 group password policy by default does not allow grace logins - Resolves: rhbz#2116966 ipa-replica-manage displays traceback: Unexpected error: 'bool' object has no attribute 'lower' * Thu Jul 28 2022 Francisco Trivino <ftrivino@redhat.com> - 4.10.0-5 - Resolves: rhbz#2109645 - Rebuild for samba-4.16.3-101.el9 * Thu Jul 21 2022 Francisco Trivino <ftrivino@redhat.com> - 4.10.0-4 - Resolves: rhbz#2109645 - Rebuild for samba-4.16.3-100.el9 * Fri Jul 15 2022 Florence Blanc-Renaud <flo@redhat.com> - 4.10.0-3 - Resolves: rhbz#2105294 IdM WebUI Pagination Size should not allow empty value * Thu Jun 30 2022 Florence Blanc-Renaud <frenaud@redhat.com> - 4.10.0-2 - Resolves: rhbz#2091988 [RFE] Add code to check password expiration on ldap bind * Thu Jun 30 2022 Florence Blanc-Renaud <frenaud@redhat.com> - 4.10.0-1 - Resolves: rhbz#747959 [RFE] Support random serial numbers in IPA certificates - Resolves: rhbz#2100227 [UX] Preserving a user account produces output saying it was deleted * Fri Jun 17 2022 Florence Blanc-Renaud <frenaud@redhat.com> - 4.9.10-1 - Resolves: rhbz#2079469 [Rebase] Rebase ipa to latest 4.9.x release - Resolves: rhbz#2012911 named journalctl logs shows 'zone testrealm.test/IN: serial (serialnumber) write back to LDAP failed.' - Resolves: rhbz#2069202 [RFE] add support for authenticating against external IdP services using OAUTH2 preauthenticaiton mechanism provided by SSSD - Resolves: rhbz#2083218 ipa-dnskeysyncd floods /var/log/messages with DEBUG messages - Resolves: rhbz#2089750 RFE: Improve error message with more detail for ipa-replica-install command - Resolves: rhbz#2091988 [RFE] Add code to check password expiration on ldap bind - Resolves: rhbz#2094400 [RFE] ipa-client-install should provide option to enable subid: sss in /etc/nsswitch.conf - Resolves: rhbz#2096922 secret in ipa-pki-proxy.conf is not changed if new requiredSecret value is present in /etc/pki/pki-tomcat/server.xml * Wed Apr 06 2022 Florence Blanc-Renaud <frenaud@redhat.com> - 4.9.8-8 - Resolves: rhbz#2067971 Consequences of FIPS crypto policy tightening in RHEL 9 - tests: ensure AD-SUPPORT subpolicy is active in more cases - ipatests: fix check for AD topology being present * Thu Mar 24 2022 Florence Blanc-Renaud <frenaud@redhat.com> - 4.9.8-7 - Resolves: rhbz#2067971 Consequences of FIPS crypto policy tightening in RHEL 9 - KRB instance: make provision to work with crypto policy without SHA-1 HMAC types - tests: ensure AD-SUPPORT subpolicy is active - ipatests: extend AES keyset to SHA2-based ones - freeipa.spec: bump crypto-policies dependency for CentOS 9 Stream - Kerberos instance: default to AES256-SHA2 for master key encryption - test_otp: do not use paramiko unless it is really needed - test_krbtpolicy: skip SPAKE-related tests in FIPS mode - Support AES for KRA archival wrapping - Set AES as default for KRA archival wrapping * Thu Feb 24 2022 Florence Blanc-Renaud <frenaud@redhat.com> - 4.9.8-6 - Resolves: rhbz#2057467 Backport latest test fixes in python3-ipatests - ipatests: Tests for Autoprivate group. - mark xfail for test_idoverride_with_auto_private_group[hybrid] - Mark xfail test_gidnumber_not_corresponding_existing_group[true,hybrid] * Mon Feb 14 2022 Alexander Bokovoy <abokovoy@redhat.com> - 4.9.8-5 - Resolves: rhbz#2053025 - add IPA test suite fixes * Mon Feb 14 2022 Alexander Bokovoy <abokovoy@redhat.com> - 4.9.8-4 - Resolves: rhbz#2053586 IPA LDAP plugin ipa-cldap memory leak - fix memory leak in CLDAP responder * Fri Feb 11 2022 Florence Blanc-Renaud <frenaud@redhat.com> - 4.9.8-3 - Resolves: rhbz#2050540 Unable to join RHEL 8.5 Replica to RHEL 7.9 Master for migration purposes - Don't always override the port in import_included_profiles - Resolves: rhbz#2051582 Enable ipa-ccache-sweep.timer during server installation - Test ipa-ccache-sweep.timer enabled by default during installation - Enable the ccache sweep timer during installation - Resolves: rhbz#2051844 ipa-join tests are failing due to changes in expected output - Remove ipa-join errors from behind the debug option * Thu Feb 03 2022 Florence Blanc-Renaud <frenaud@redhat.com> - 4.9.8-2 - Resolves: rhbz#2040619 - Changing default pac type to 'nfs:NONE and MS-PAC' doesnot display error 'ipa: ERROR: no modifications to be performed' - Config plugin: return EmptyModlist when no change is applied - config plugin: add a test ensuring EmptyModlist is returned - Resolves: rhbz#2048510 - [rhel-9.0] Backport latest test fixes in python3-ipatests - ipatests: webui: Tests for subordinate ids. - ipatests: webui: Use safe-loader for loading YAML configuration file - ipatests: Fix test_ipa_cert_fix.py::TestCertFixReplica teardown - Test cases for ipa-replica-conncheck command - PEP8 Fixes - ipatests: Test empty cert request doesn't force certmonger to segfault - ipatests: Test default value of nsslapd-sizelimit. - Extend test to see if replica is not shown when running `ipa-replica-manage list -v <FQDN>` - Added test automation for SHA384withRSA CSR support - Resolves: rhbz#2049104 - User can't log in after ipa-user-mod --user-auth-type=hardened - ipa-kdb: do not remove keys for hardened auth-enabled users - ipatests: add case for hardened-only ticket policy - Resolves: rhbz#2049174 - KRA GetStatus service blocked by IPA proxy - ipa-pki-proxy.conf: provide access to /kra/admin/kra/getStatus * Thu Dec 02 2021 Florence Blanc-Renaud <frenaud@redhat.com> - 4.9.8-1 - Resolves: rhbz#2015608 - [Rebase] Rebase ipa to latest 4.9.x release RHEL9 - Resolves: rhbz#1825010 - Concerns regarding 'ipa pwpolicy-mod --minlife 24 --maxlife 1' - Resolves: rhbz#1966289 - Info about searchrecordslimit set search limit to 10,000 after upgrade - Resolves: rhbz#1980356 - reinstalling samba client causes winbindd coredump - Resolves: rhbz#1986054 - fix automountlocation-tofiles output - Resolves: rhbz#2020205 - Missing bind-pkcs11-utils causing failures in OpenDNSSec - Resolves: rhbz#2021445 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets - ipa-kdb: issue PAC_REQUESTER_SID only for TGTs - ipa-kdb: fix requester SID check according to MS-KILE and MS-SFU updates * Tue Oct 05 2021 Florence Blanc-Renaud <frenaud@redhat.com> - 4.9.6-9 - Resolves: rhbz#2010701 ipa-server-install fails while 'configuring certificate server instance' - Parse getStatus as JSON not XML - Parse cert chain as JSON not XML - Specify PKI installation log paths - Make Dogtag return XML for ipa cert-find * Fri Sep 17 2021 Florence Blanc-Renaud <frenaud@redhat.com> - 4.9.6-8 - Resolves: rhbz#2005864 ipa cert-request replaces user certificate instead of adding - Don't store entries with a usercertificate in the LDAP cache - ipatests: Test that a user can be issued multiple certificates