-
Mon Jul 20 2026 EL Errata <el-errata_ww@oracle.com> - 2.12.0-3.0.1.el10_2.1
- Restore default debug level for sss_cache [Orabug: 32810448]
-
Wed Jul 08 2026 - Tomas Halman <thalman@redhat.com> - 2.12.0-3.1
- Resolves: RHEL-192056 - CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole
- Resolves: RHEL-192064 - CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass
-
Tue Apr 14 2026 Tomas Halman <thalman@redhat.com> - 2.12.0-3
- Resolves: RHEL-167749 - SSSD IdP (Entra ID): listing group members does not work
- Resolves: RHEL-167757 - sssd-kcm fails to start if krb5_renew_interval is specified
-
Thu Apr 02 2026 Tomas Halman <thalman@redhat.com> - 2.12.0-2
- Resolves: RHEL-148232 - Failed to resolve indirect group-members of nested non-POSIX group
-
Thu Jan 15 2026 Sumit Bose <sbose@redhat.com> - 2.12.0-1
- Resolves: RHEL-139110 - Rebase SSSD for RHEL 10.2
- Resolves: RHEL-132552 - sssd_be: segfault at 8 ip 00007f6fd25b2b90 sp 00007ffc02dfbae0 error 4 in libsss_ipa.so[7f6fd25ae000+4d000]
- Resolves: RHEL-132505 - RFE: package LDAP provider support for subid ranges
- Resolves: RHEL-130571 - SSSD: change a default value of 'session_provider' sssd.conf option to 'none'
- Resolves: RHEL-129636 - sssd service fails to start after updating to 2.9.6-4 or 2.9.7-4
- Resolves: RHEL-128594 - 'sssd_nss' hangs when looking up an object by ID that has expired cache entry and filtered out by name
- Resolves: RHEL-127792 - Remove SSSD option ipa_enable_dns_sites
- Resolves: RHEL-120501 - Crash in 'sss_client/autofs/sss_autofs.c'
- Resolves: RHEL-120287 - CVE-2025-11561 sssd: SSSD default Kerberos configuration allows privilege escalation on AD-joined Linux systems [rhel-10.2]
- Resolves: RHEL-114468 - Spam in 'sssd_kcm.log' during normal operations
- Resolves: RHEL-113111 - Including innapropriate IPv6 addresses in dyndns_update
- Resolves: RHEL-104221 - The SSSD cache is filled with groups having GID=0, causing the cache index to grow excessively large. This, in turn, leads to timeouts
- Resolves: RHEL-94545 - When the user name of an AD user in an IPA-AD trust environment overwritten, the user private group, the users primary group, cannot be lookup up by the overwritten name.
- Resolves: RHEL-77184 - AD user in external group is not cleared when expiring the cache
- Resolves: RHEL-72935 - sss_override does not work on AD UPN
- Resolves: RHEL-11913 - GDM Support for IdM IdP feature and MFA [SSSD]
- Resolves: RHEL-4990 - [RFE] SSSD support for Azure AD / Microsoft Entra ID (or general direct support of OIDC authentication)
-
Mon Sep 22 2025 Pavel Filipenský <pfilipen@redhat.com> - 2.11.1-3
- Related: RHEL-114545 - Rebase Samba to the latest 4.23.x release
-
Thu Aug 14 2025 Alexey Tikhonov <atikhono@redhat.com> - 2.11.1-2
- Related: RHEL-77184 - AD user in external group is not cleared when expiring the cache
Patch used to fix this ticket causes a regression (RHEL-106987) and is being reverted.
-
Thu Jul 31 2025 Alexey Tikhonov <atikhono@redhat.com> - 2.11.1-1
- Resolves: RHEL-95058 - Rebase SSSD for RHEL 10.1
- Resolves: RHEL-77184 - AD user in external group is not cleared when expiring the cache
-
Fri Jun 13 2025 Alexey Tikhonov <atikhono@redhat.com> - 2.11.0-3
- Related: RHEL-89870 - Rebase Samba to the latest 4.22.x release
-
Fri Jun 06 2025 Alexey Tikhonov <atikhono@redhat.com> - 2.11.0-2
- Resolves: RHEL-95058 - Rebase SSSD for RHEL 10.1