Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

ipa-server-4.12.2-1.el10 RPM for x86_64

From CentOS Stream 10 AppStream for x86_64

Name: ipa-server Distribution: CentOS
Version: 4.12.2 Vendor: CentOS
Release: 1.el10 Build date: Thu Aug 22 08:00:06 2024
Group: Unspecified Build host: x86-02.stream.rdu2.redhat.com
Size: 1176339 Source RPM: ipa-4.12.2-1.el10.src.rpm
Packager: builder@centos.org
Url: http://www.freeipa.org/
Summary: The IPA authentication server
IPA is an integrated solution to provide centrally managed Identity (users,
hosts, services), Authentication (SSO, 2FA), and Authorization
(host access control, SELinux user roles, services). The solution provides
features for further integration with Linux based clients (SUDO, automount)
and integration with Active Directory based infrastructures (Trusts).
If you are installing an IPA server, you need to install this package.

Provides

Requires

License

GPL-3.0-or-later

Changelog

* Thu Aug 22 2024 Florence Blanc-Renaud <flo@redhat.com> - 4.12.2.1
  - Resolves: RHEL-54545 Covscan issues: Resource Leak
  - Resolves: RHEL-54304 support for python cryptography 43.0.0
  - Resolves: RHEL-49805 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w
  - Resolves: RHEL-46897 With unreachable AD, ipa trust returns an internal error
* Thu Aug 08 2024 Florence Blanc-Renaud <flo@redhat.com> - 4.12.1-4
  - Resolves: RHEL-53501 adtrustinstance only prints issues in check_inst() and does not log them
  - Resolves: RHEL-52305 Unconditionally add MS-PAC to global config
  - Resolves: RHEL-52223 ipa-replica/server-install with softhsm needs to check permission/ownership of /var/lib/softhsm/tokens to avoid install failure
  - Resolves: RHEL-51937 Include latest fixes in python3-ipatests packages
  - Resolves: RHEL-50805 ipa-migrate -Z with invalid cert options fails with 'ValueError: option error'
  - Resolves: RHEL-49805 misleading warning for missing ipa-selinux-nfast package on luna hsm h/w
  - Resolves: RHEL-49592 'Unable to log in as uid=admin-replica.testrealm.test,ou=people,o=ipaca' during replica install
  - Resolves: RHEL-4879 RFE - Keep the configured value for the "nsslapd-ignore-time-skew" after a "force-sync"
* Thu Jul 18 2024 Florence Blanc-Renaud <flo@redhat.com> - 4.12.1-3
  - Resolves: RHEL-49452 Include latest fixes in python3-ipatests packages
  - Resolves: RHEL-49433 Adjust "ipa config-mod --addattr ipaconfigstring=EnforceLDAPOTP" to allow for non OTP users in some cases
  - Resolves: RHEL-49432 ipa-migrate stage-mode is failing with error: Modifying a mapped attribute in a managed entry is not allowed
  - Resolves: RHEL-49413 ipa-migrate with -Z option fails with ValueError: option error
  - Resolves: RHEL-47157 ipa-migrate -V options fails to display version
  - Resolves: RHEL-47148 Pagure #9629: Syntax error uninstalling the selinux-luna subpackage
  - Resolves: RHEL-40892 ipa-server-install: token_password_file read in kra.install_check after calling hsm_validator in ca.install_check
* Mon Jul 08 2024 Florence Blanc-Renaud <flo@redhat.com> - 4.12.1-2
  - Resolves: RHEL-46607 kdc.crt certificate not getting automatically renewed by certmonger in IPA Hidden replica
  - Resolves: RHEL-46606 ipa-client rpm post script creates always ssh_config.orig even if nothing needs to be changed
  - Resolves: RHEL-46605 IPA Web UI not showing replication agreement for non-admin users
  - Resolves: RHEL-46592 [RFE] Allow IPA SIDgen task to continue if it finds an entity that SID can't be assigned to
  - Resolves: RHEL-46556 Include latest fixes in python3-ipatests packages
  - Resolves: RHEL-42705 PSKC.xml issues with ipa_otptoken_import.py
* Mon Jun 24 2024 Troy Dawson <tdawson@redhat.com> - 4.12.1-1.1
  - Bump release for June 2024 mass rebuild
* Wed Jun 12 2024 Julien Rische <jrische@redhat.com> - 4.12.1-1
  - Resolves: RHEL-32233 CVE-2024-3183 freeipa: user can obtain a hash of the passwords of all domain users and perform offline brute force
  - Resolves: RHEL-40881 CVE-2024-2698 freeipa: delegation rules allow a proxy service to impersonate any user to access another target service
* Tue Jun 04 2024 Florence Blanc-Renaud <flo@redhat.com> - 4.12.0-1
  - Resolves: RHEL-39144 Rebase ipa to the latest 4.12 version for RHEL 10
  - Resolves: RHEL-30537 ipa: freeipa: argument injection into the username field of the /ipa/session/login_password requests
* Thu Feb 22 2024 Troy Dawson <tdawson@redhat.com> - 4.11.1-4
  - Bump release to rebuild on correct samba
* Thu Feb 08 2024 Alexander Bokovoy <abokovoy@redhat.com> - 4.11.1-3
  - Support 389-ds with lmdb backend
* Wed Jan 24 2024 Fedora Release Engineering <releng@fedoraproject.org> - 4.11.1-2
  - Rebuild against Samba 4.20rc1
  - Fix memory leak in Kerberos KDC driver
  - Fix possible crash in IPA command line tool when accessing Kerberos credentials
  - Compatibility fix for Python Cryptography 42.0.0
  - NetBIOS defaults fix
  - Fix default host keytab retrieval permissions
* Wed Jan 24 2024 Fedora Release Engineering <releng@fedoraproject.org> - 4.11.1-1.2
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Fri Jan 19 2024 Fedora Release Engineering <releng@fedoraproject.org> - 4.11.1-1.1
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Wed Jan 10 2024 Alexander Bokovoy <abokovoy@redhat.com> - 4.11.1-1
  - Security release: CVE-2023-5455
  - Resolves: rhbz#2257646
* Wed Nov 08 2023 Alexander Bokovoy <abokovoy@redhat.com> - 4.11.0-7
  - ipalib: fix the IPACertificate validity dates (python 3.12 compatibility)
  - Handle PKI revocation response differences in JSON API
  - Allow removal of minimal length from a custom password policy
* Mon Oct 23 2023 Alexander Bokovoy <abokovoy@redhat.com> - 4.11.0-6
  - Adopt trust to AD code to Samba changes in case SIDs are malformed
* Tue Oct 03 2023 Alexander Bokovoy <abokovoy@redhat.com> - 4.11.0-5
  - FreeIPA 4.11.0 release
  - Simplify Fedora spec file
  - Release notes: https://www.freeipa.org/release-notes/4-11-0.html
* Mon Sep 18 2023 Alexander Bokovoy <abokovoy@redhat.com> - 4.11.0-4.beta1
  - Depend on selinux-policy-38.28-1.fc39
  - Add SELinux policy for passkey_child to be used without ipa-otpd
  - Related: rhbz#2238474
* Tue Sep 12 2023 Alexander Bokovoy <abokovoy@redhat.com> - 4.11.0-3.beta1
  - Restore properly SELinux context during IPA client uninstallation
  - Related: rhbz#2238474
* Tue Sep 12 2023 Alexander Bokovoy <abokovoy@redhat.com> - 4.11.0-2.beta1
  - Set 'sssd_use_usb' SELinux boolean when enrolling IPA client
  - Resolves: rhbz#2238474
* Mon Aug 21 2023 Alexander Bokovoy <abokovoy@redhat.com> - 4.11.0-1.beta1
  - FreeIPA 4.11.0 beta 1
  - Release notes: https://www.freeipa.org/release-notes/4-11-0-beta.html
* Wed Jul 19 2023 Fedora Release Engineering <releng@fedoraproject.org> - 4.10.2-1.3
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Wed Jul 05 2023 Miro HronĨok <mhroncok@redhat.com> - 4.10.2-1.2
  - Use ssl.match_hostname from urllib3 as it was removed from Python 3.12
* Tue Jun 27 2023 Python Maint <python-maint@redhat.com> - 4.10.2-1.1
  - Rebuilt for Python 3.12
* Tue Jun 13 2023 Alexander Bokovoy <abokovoy@redhat.com> - 4.10.2-1
  - Upstream release FreeIPA 4.10.2
  - Synchronize patches with CentOS 9 Stream
* Mon May 15 2023 Alexander Bokovoy <abokovoy@redhat.com> - 4.10.1-5
  - Support python-cryptography 40.0
* Thu Mar 30 2023 Jerry James <loganjerry@gmail.com> - 4.10.1-4
  - Change fontawesome-fonts R to match fontawesome 4.x
* Fri Jan 20 2023 Alexander Bokovoy <abokovoy@redhat.com> - 4.10.1-3
  - Rebuild against Samba 4.18.0RC1
* Thu Jan 19 2023 Fedora Release Engineering <releng@fedoraproject.org> - 4.10.1-2.1
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Thu Dec 01 2022 Alexander Bokovoy <abokovoy@redhat.com> - 4.10.1-2
  - Rebuild against krb5-1.20.1-1
* Sun Nov 27 2022 Alexander Bokovoy <abokovoy@redhat.com> - 4.10.1-1
  - Upstream release FreeIPA 4.10.1
* Wed Sep 14 2022 Alexander Bokovoy <abokovoy@redhat.com> - 4.10.0-6
  - Rebuild against final samba 4.17.0 release
* Wed Aug 24 2022 Adam Williamson <awilliam@redhat.com> - 4.10.0-5
  - Rebuild against new samba-client-libs (for F37)
* Wed Aug 24 2022 Thomas Woerner <twoerner@redhat.com> - 4.10.0-4
  - Disabling gracelimit does not prevent LDAP binds
  - webui: Allow grace login limit
  - Fix dns resolver for nameservers with ports
  - Set passwordgracelimit to match global policy on group pw policies

Files

/etc/dbus-1/system.d/org.freeipa.server.conf
/etc/oddjobd.conf.d/ipa-server.conf
/usr/lib/.build-id
/usr/lib/.build-id/01
/usr/lib/.build-id/01/391e0a5e3378234cffa363ebfcf063521af6e2
/usr/lib/.build-id/0d
/usr/lib/.build-id/0d/fc7ca5e7f3dd91b3270992c7cf05e5afe1f427
/usr/lib/.build-id/28
/usr/lib/.build-id/28/c18dc48e33d2c2f4dcada1c1a24e914cdbc346
/usr/lib/.build-id/29
/usr/lib/.build-id/29/3b76d819b60f2ccfb1f751f4a089e9af15cbe1
/usr/lib/.build-id/35
/usr/lib/.build-id/35/89fef42a477e7b3d5abe2cbff5268b58d12726
/usr/lib/.build-id/3a
/usr/lib/.build-id/3a/e4c9d9abf2fdfa3c736cad011d8df93f98eff0
/usr/lib/.build-id/67
/usr/lib/.build-id/67/7b44e1f5d7d35283d41321be7ca6146970caaa
/usr/lib/.build-id/6c
/usr/lib/.build-id/6c/db1b8a7290ba054967594fc8b656dcd9fb91de
/usr/lib/.build-id/6e
/usr/lib/.build-id/6e/809251367029df8cc2b9d2a7ebba6596fed70b
/usr/lib/.build-id/72
/usr/lib/.build-id/72/4b4460f279f1e9523b4ec7dd686e32a71050da
/usr/lib/.build-id/74
/usr/lib/.build-id/74/b9053c8fef1f5fff054743b7385c3f8b2da838
/usr/lib/.build-id/a5
/usr/lib/.build-id/a5/d6b48728c385e24495f97fcd9acee76e894b2a
/usr/lib/.build-id/a9
/usr/lib/.build-id/a9/870078516c032753b12c99f00c70255b295a2a
/usr/lib/.build-id/ae
/usr/lib/.build-id/ae/051696c23d2bf9be7ba7da8b109064e941bb00
/usr/lib/.build-id/b7
/usr/lib/.build-id/b7/4f5bd349abdf7764b199cdb7b12f5c789f400d
/usr/lib/.build-id/be
/usr/lib/.build-id/be/518fe689238ad1a7750c5dc7486ffc4af5da0a
/usr/lib/.build-id/e5
/usr/lib/.build-id/e5/c31b4362c4b920f5b42d71f3089a79859d8783
/usr/lib/.build-id/e9
/usr/lib/.build-id/e9/b13a18ea86a918ccf5a6e619558825c5da55f4
/usr/lib/.build-id/fc
/usr/lib/.build-id/fc/2449376436d9a74118c1ddb11f1d2cbf521a5c
/usr/lib/systemd/catalog/ipa.catalog
/usr/lib/systemd/system/ipa-ccache-sweep.service
/usr/lib/systemd/system/ipa-ccache-sweep.timer
/usr/lib/systemd/system/ipa-otpd.socket
/usr/lib/systemd/system/ipa-otpd@.service
/usr/lib/systemd/system/ipa.service
/usr/lib64/dirsrv/plugins/libipa_dns.so
/usr/lib64/dirsrv/plugins/libipa_enrollment_extop.so
/usr/lib64/dirsrv/plugins/libipa_extdom_extop.so
/usr/lib64/dirsrv/plugins/libipa_graceperiod.so
/usr/lib64/dirsrv/plugins/libipa_lockout.so
/usr/lib64/dirsrv/plugins/libipa_modrdn.so
/usr/lib64/dirsrv/plugins/libipa_otp_counter.so
/usr/lib64/dirsrv/plugins/libipa_otp_lasttoken.so
/usr/lib64/dirsrv/plugins/libipa_pwd_extop.so
/usr/lib64/dirsrv/plugins/libipa_range_check.so
/usr/lib64/dirsrv/plugins/libipa_repl_version.so
/usr/lib64/dirsrv/plugins/libipa_sidgen.so
/usr/lib64/dirsrv/plugins/libipa_sidgen_task.so
/usr/lib64/dirsrv/plugins/libipa_uuid.so
/usr/lib64/dirsrv/plugins/libipa_winsync.so
/usr/lib64/dirsrv/plugins/libtopology.so
/usr/lib64/krb5/plugins/kdb/ipadb.so
/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit
/usr/libexec/certmonger/ipa-server-guard
/usr/libexec/ipa
/usr/libexec/ipa/certmonger
/usr/libexec/ipa/certmonger/renew_ca_cert
/usr/libexec/ipa/certmonger/renew_kdc_cert
/usr/libexec/ipa/certmonger/renew_ra_cert
/usr/libexec/ipa/certmonger/renew_ra_cert_pre
/usr/libexec/ipa/certmonger/restart_dirsrv
/usr/libexec/ipa/certmonger/restart_httpd
/usr/libexec/ipa/certmonger/stop_pkicad
/usr/libexec/ipa/custodia
/usr/libexec/ipa/custodia/ipa-custodia-dmldap
/usr/libexec/ipa/custodia/ipa-custodia-pki-tomcat
/usr/libexec/ipa/custodia/ipa-custodia-pki-tomcat-wrapped
/usr/libexec/ipa/custodia/ipa-custodia-ra-agent
/usr/libexec/ipa/ipa-ccache-sweeper
/usr/libexec/ipa/ipa-custodia
/usr/libexec/ipa/ipa-custodia-check
/usr/libexec/ipa/ipa-httpd-kdcproxy
/usr/libexec/ipa/ipa-httpd-pwdreader
/usr/libexec/ipa/ipa-otpd
/usr/libexec/ipa/ipa-pki-retrieve-key
/usr/libexec/ipa/ipa-pki-wait-running
/usr/libexec/ipa/ipa-print-pac
/usr/libexec/ipa/ipa-subids
/usr/libexec/ipa/oddjob
/usr/libexec/ipa/oddjob/org.freeipa.server.config-enable-sid
/usr/libexec/ipa/oddjob/org.freeipa.server.conncheck
/usr/libexec/ipa/oddjob/org.freeipa.server.trust-enable-agent
/usr/sbin/ipa-acme-manage
/usr/sbin/ipa-advise
/usr/sbin/ipa-backup
/usr/sbin/ipa-ca-install
/usr/sbin/ipa-cacert-manage
/usr/sbin/ipa-cert-fix
/usr/sbin/ipa-compat-manage
/usr/sbin/ipa-crlgen-manage
/usr/sbin/ipa-csreplica-manage
/usr/sbin/ipa-kra-install
/usr/sbin/ipa-ldap-updater
/usr/sbin/ipa-managed-entries
/usr/sbin/ipa-migrate
/usr/sbin/ipa-otptoken-import
/usr/sbin/ipa-pkinit-manage
/usr/sbin/ipa-replica-conncheck
/usr/sbin/ipa-replica-install
/usr/sbin/ipa-replica-manage
/usr/sbin/ipa-restore
/usr/sbin/ipa-server-certinstall
/usr/sbin/ipa-server-install
/usr/sbin/ipa-server-upgrade
/usr/sbin/ipa-winsync-migrate
/usr/sbin/ipactl
/usr/share/doc/ipa-server
/usr/share/doc/ipa-server/Contributors.txt
/usr/share/doc/ipa-server/README.md
/usr/share/licenses/ipa-server
/usr/share/licenses/ipa-server/COPYING
/usr/share/man/man1/ipa-acme-manage.1.gz
/usr/share/man/man1/ipa-advise.1.gz
/usr/share/man/man1/ipa-backup.1.gz
/usr/share/man/man1/ipa-ca-install.1.gz
/usr/share/man/man1/ipa-cacert-manage.1.gz
/usr/share/man/man1/ipa-cert-fix.1.gz
/usr/share/man/man1/ipa-compat-manage.1.gz
/usr/share/man/man1/ipa-crlgen-manage.1.gz
/usr/share/man/man1/ipa-csreplica-manage.1.gz
/usr/share/man/man1/ipa-kra-install.1.gz
/usr/share/man/man1/ipa-ldap-updater.1.gz
/usr/share/man/man1/ipa-managed-entries.1.gz
/usr/share/man/man1/ipa-migrate.1.gz
/usr/share/man/man1/ipa-otptoken-import.1.gz
/usr/share/man/man1/ipa-pkinit-manage.1.gz
/usr/share/man/man1/ipa-replica-conncheck.1.gz
/usr/share/man/man1/ipa-replica-install.1.gz
/usr/share/man/man1/ipa-replica-manage.1.gz
/usr/share/man/man1/ipa-restore.1.gz
/usr/share/man/man1/ipa-server-certinstall.1.gz
/usr/share/man/man1/ipa-server-install.1.gz
/usr/share/man/man1/ipa-server-upgrade.1.gz
/usr/share/man/man1/ipa-winsync-migrate.1.gz
/usr/share/man/man8/ipactl.8.gz


Generated by rpm2html 1.8.1

Fabrice Bellet, Sat Sep 14 08:53:11 2024