-
Mon Sep 28 2026 EL Errata <el-errata_ww@oracle.com> - 4.13.4-1.0.1
- Set IPAPLATFORM=rhel when build on Oracle Linux [Orabug: 29516674]
- Add bind to ipa-server-common Requires [Orabug: 36518596]
-
Mon Sep 14 2026 Florence Blanc-Renaud <flo@redhat.com> - 4.13.4-1
- Resolves: RHEL-248199 CVE-2026-79678 ipa: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service
- Resolves: RHEL-245626 CVE-2026-19550 ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes [rhel-10.2.z]
- Resolves: RHEL-245473 CVE-2026-76578 ipa: FreeIPA: unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI
- Resolves: RHEL-240909 CVE-2026-13097 ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore [rhel-10.2.z]
- Resolves: RHEL-240842 CVE-2026-11861 ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships [rhel-10.2.z]
- Resolves: RHEL-240821 CVE-2026-73197 ipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read [rhel-10.2.z]
- Resolves: RHEL-240800 CVE-2026-73198 ipa: FreeIPA: Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read [rhel-10.2.z]
- Resolves: RHEL-240768 ipa-migrate tool is renaming host records & host info in automount information [rhel-10.2.z]
- Resolves: RHEL-238676 ipa-migrate: require Replication Administrator privilege [rhel-10.2.z]
- Resolves: RHEL-238673 ipa-epn: drop_privileges method is mixing uid and gid [rhel-10.2.z]
- Resolves: RHEL-238526 ipa env: support only simple * wildcard [rhel-10.2.z]
- Resolves: RHEL-238522 host-mod: handle the password attribute when set with --setattr userpassword= [rhel-10.2.z]
- Resolves: RHEL-238518 ipa-otptoken-import hardening [rhel-10.2.z]
- Resolves: RHEL-238516 Remove NetBIOS dependencies in Identity Manager [rhel-10.2.z]
- Resolves: RHEL-238510 WebUI Hardening [rhel-10.2.z]
- Resolves: RHEL-218853 CVE-2026-18147 ipa: FreeIPA/IdM: Cross-Site Scripting vulnerability allows arbitrary code execution via crafted URL
- Resolves: RHEL-173375 [Cursor Automated] Include latest fixes in python3-ipatests package [RHEL10.2]
-
Wed Apr 15 2026 Florence Blanc-Renaud <flo@redhat.com> - 4.13.1-3.2
- Resolves: RHEL-168516 TestIPAMigrationProdMode tests are missing
-
Fri Apr 10 2026 Florence Blanc-Renaud <flo@redhat.com> - 4.13.1-3.1
- Resolves: RHEL-155027 Adding a group with 32Bit Idrange fails
- Resolves: RHEL-153145 IdM password policy Min lifetime is not enforced when high minlife is set
- Resolves: RHEL-166864 Include latest fixes in python3-ipatests package
-
Wed Feb 11 2026 Florence Blanc-Renaud <flo@redhat.com> - 4.13.1-3
- Resolves: RHEL-4895 ipa use systemd-sysusers
-
Fri Feb 06 2026 Florence Blanc-Renaud <flo@redhat.com> - 4.13.1-2
- Resolves: RHEL-146023 When using xmlrpc, ipa server failed with assert type(value) in (unicode, float, int, bool, type(None))
- Resolves: RHEL-145855 Include latest fixes in python3-ipatests package
- Resolves: RHEL-88855 ipa uninstallation is failing with message "'NoneType' object has no attribute 'lower'"
- Resolves: RHEL-43143 ipa-advise client script requires keytab (should just require root access on client system)
- Resolves: RHEL-4895 ipa use systemd-sysusers
- Resolves: RHEL-4823 Names of domains from a trusted forest should be compared case-insentive
-
Fri Jan 16 2026 Florence Blanc-Renaud <flo@redhat.com> - 4.13.1-1
- Resolves: RHEL-140587 Support replaceable WebUI artwork for RHEL and CentOS
- Resolves: RHEL-113778 Command that retrieve and install new CA certificates
- Resolves: RHEL-141296 AddressSanitizer: SEGV ipa-pwd-extop/common.c:584 in ipapwd_gen_checks
- Resolves: RHEL-141011 Include latest fixes in python3-ipatests package
- Resolves: RHEL-119339 Memory leaks in IPA plugins
-
Mon Dec 08 2025 Florence Blanc-Renaud <flo@redhat.com> - 4.13.0-1
- Resolves: RHEL-120956 Rebase ipa to latest 4.13.x version for RHEL 10.2
- Resolves: RHEL-90121 Add modern WebUI as submodule and enable routing in Apache
- Resolves: RHEL-132337 Include latest fixes in python3-ipatests package
- Resolves: RHEL-129965 Fix ipatests for kdcproxy after CVE-2025-59088 fix
- Resolves: RHEL-129547 Switch IPA to use the PKI python API directly rather than RPC calls
- Resolves: RHEL-133342 After upgrade from 9.7 to 9.8 ipactl restart fails to restart winbind service
-
Mon Nov 17 2025 Florence Blanc-Renaud <flo@redhat.com> - 4.12.2-27
- Resolves: RHEL-122767 ATTR_NAME_BY_OID is missing OID 2.5.4.97, organizationIdentifier
- Resolves: RHEL-119628 Include fixes in python3-ipatests
- Resolves: RHEL-110204 RFE: Enable external password reset agents to use ipa_pwd_extop in RHEL IdM
- Resolves: RHEL-119481 RFE: Update IdM password policy configurations to meet M-22-09 by restricting spaces and require number character class
- Resolves: RHEL-126761 [RFE] Support storing LWCA private keys on an HSM
- Resolves: RHEL-86030 [RFE] ipa-client-automount should have an option to include domain of the machine.
- Resolves: RHEL-119617 test_cacert_manage fails due to expired Let's Encrypt R3 certificate
-
Tue Sep 30 2025 Florence Blanc-Renaud <flo@redhat.com> - 4.12.2-26
- Resolves: RHEL-118446 ipa: Privilege escalation from host to domain admin in FreeIPA