- 
    Mon May 19 2014 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-33
    - Release 1.2.11.15-33
- Resolves: Bug 1094412 - fix memleak introduced by "Simple paged results should support async search (957864)" (DS 47623)
- Resolves: Bug 1094413 - rhds91 389-ds-base-1.2.11.15-31.el6_5 crash on paged searches followed by simple srch (DS 47707) 
- 
    Tue Mar 11 2014 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-32
    - Resolves: bug 1074847 - EMBARGOED CVE-2014-0132 389-ds-base: 389-ds: flaw in parsing authzid can lead to privilege escalation [rhel-6.5.z] (Ticket 47739 - directory server is insecurely misinterpreting authzid on a SASL/GSSAPI bind) 
- 
    Tue Dec 03 2013 Rich Megginson <rmeggins@redhat.com> - 1.2.11.15-31
    - Resolves: bug 1037271 - regression in ipa due to patch for ns-slapd stuck in DS_Sleep 
- 
    Mon Nov 04 2013 Rich Megginson <rmeggins@redhat.com> - 1.2.11.15-30
    - Resolves: bug 1024977 CVE-2013-4485 389-ds-base: DoS due to improper handling of ger attr searches 
- 
    Tue Oct 15 2013 Rich Megginson <rmeggins@redhat.com> - 1.2.11.15-29
    - Bump version to 1.2.11.15-29
- Resolves: bug 1008013:  DS91: ns-slapd stuck in DS_Sleep 
- 
    Tue Oct 08 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-28
    - Bump version to 1.2.11.15-28
- Resolves: Bug 1016038 - Users from AD sub OU does not sync to IPA (ticket 47488) 
- 
    Mon Sep 30 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-27
    - Bump version to 1.2.11.15-27
- Resolves: Bug 1013735 - CLEANALLRUV doesnt run across all replicas (ticket 47509) 
- 
    Fri Sep 27 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-26
    - Bump version to 1.2.11.15-26
- Resolves: Bug 947583 - ldapdelete returns non-leaf entry error while trying to remove a leaf entry (ticket 47534) 
- 
    Thu Sep 26 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-25
    - Bump version to 1.2.11.15-25
- Resolves: Bug 1006846 - 2Master replication with SASL/GSSAPI auth broken (ticket 47523)
- Resolves: Bug 1007452 - Under specific values of nsDS5ReplicaName, replication may get broken or updates (ticket 47489) 
- 
    Tue Sep 17 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-24
    - Bump version to 1.2.11.15-24
- Resolves: Bug 982325 - Overflow in nsslapd-disk-monitoring-threshold; Changed CONFIG_INT to CONFIG_LONG for nsslapd-disk-monioring-threshold (ticket 47427) 
- 
    Wed Aug 28 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-23
    - Bump version to 1.2.11.15-23
- Resolves: Bug 1000632 - CVE-2013-4283 389-ds-base: ns-slapd crash due to bogus DN
- Resolves: Bug 1002260 - server fails to start after upgrade(schema error) (ticket 47318) 
- 
    Wed Aug 07 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-22
    - Bump version to 1.2.11.15-22
- Resolves: Bug 923909 - 389-ds-base cannot handle Kerberos tickets with PAC (ticket 632)
- Resolves: Bug 928159 - CVE-2013-1897 389-ds: unintended information exposure when rootdse is enabled
- Resolves: Bug 947583 - ldapdelete returns non-leaf entry error while trying to remove a leaf entry (ticket 47367)
- Resolves: Bug 951616 - error syncing group if group member user is not synced (ticket 47327)
- Resolves: Bug 953052 - DESC should not be empty as per RFC 2252 (ldapv3) (ticket 47376)
- Resolves: Bug 957305 - DS instance crashes under a high load (ticket 47349)
- Resolves: Bug 957864 - Simple paged results should support async search (ticket 47347)
- Resolves: Bug 958522 - loading an entry from the database should use str2entry_fast (ticket 531)
- Resolves: Bug 962885 - RHEL 6.2 to 6.4 ipa upgrade selinuxusermap data not replicating (ticket 47362)
- Resolves: Bug 963234 - When integrating with Red Hat IDM/DS, an LDAP protocol error is thrown (ticket 47361)
- Resolves: Bug 966781 - new ldap connections can block ldaps and ldapi connections (ticket 47359)
- Resolves: Bug 968383 - Wrong error code return when using EXTERNAL SASL and untrusted certificate (ticket 580)
- Resolves: Bug 968503 - flush_ber error sending back start_tls response will deadlock (ticket 47375)
- Resolves: Bug 969210 - make listen backlog size configurable (ticket 47377)
- Resolves: Bug 970995 - RHDS not shutting down when disk monitoring threshold is reached to half. (ticket 47385)
- Resolves: Bug 971033 - connections attribute in cn=snmp,cn=monitor is counted twice (ticket 47383)
- Resolves: Bug 971966 - 389 DS Replication failures due to Fractional updates (ticket 47386)
- Resolves: Bug 972976 - ldbm errors when adding/modifying/deleting entries (ticket 47392)
- Resolves: Bug 973583 - ns-slapd instance crashed with signal 11 SIGSEGV (ticket 47391)
- Resolves: Bug 974361 - Account policy plugin fails to lock user when policy is created for individual users to lock based to createtimestamp. (ticket 47397)
- Resolves: Bug 974719 - rhds90 crash on tombstone modrdn (ticket 47396)
- Resolves: Bug 974875 - Attributes fail to be encrypted/decrypted properly when replicated (ticket 47393)
- Resolves: Bug 975243 - DS9 still observes altStateAttrName as createTimestamp when attribute is removed from the account policy (ticket 47395)
- Resolves: Bug 975250 - Changelog deadlock replication failures with DNA (ticket 47410)
- Resolves: Bug 976546 - Attribute names are incorrect in search results (ticket 47402)
- Resolves: Bug 979169 - allow setting db deadlock rejection policy (ticket 47409)
- Resolves: Bug 979435 - Replication problem with add-delete requests on single-value (ticket 47424)
- Resolves: Bug 979515 - CVE-2013-2219 Directory Server: ACLs inoperative in some search scenarios
- Resolves: Bug 982325 - Overflow in nsslapd-disk-monitoring-threshold (ticket 47427)
- Resolves: Bug 983091 - Memory leak in 389-ds-base 1.2.11.15 (ticket 47428)
- Resolves: Bug 986131 - Very large entryusn values after enabling the USN plugin and the lastusn value is negative. (ticket 47435)
- Resolves: Bug 986424 - fix recent compiler warnings (ticket 47378)
- Resolves: Bug 986857 - Disk Monitoring not checking filesystem with logs (ticket 47441)
- Resolves: Bug 987703 - memleaks in set_krb5_creds (ticket 47421)
- Resolves: Bug 988562 - deadlock after adding and deleting entries (ticket 47449)
- Resolves: Bug 989692 - Sorting with attributes in ldapsearch gives incorrect result (ticket 543) 
- 
    Wed Aug 07 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-21
    This patch is found broken and duplicated.  Getting rid of it in 1.2.11.15-22.
  commit 2b3a50d55707ffa281c922ec188850576b757934
  Author: Mark Reynolds <mreynolds@redhat.com>
  Date:   Tue Jul 23 10:28:45 2013 -0400
  Add patch 0049 for Tickets-47427-47441 
- 
    Fri Jul 26 2013 Mark Reynolds <mreynolds@redhat.com> - 1.2.11.15-20
    - Resolves: Bug 984970 - Overflow in nsslapd-disk-monitoring-threshold(part 5 limits not displayed correctly). (ticket 47427) 
- 
    Thu Jul 25 2013 Mark Reynolds <mreynolds@redhat.com> - 1.2.11.15-19
    - Resolves: Bug 984970 - Overflow in nsslapd-disk-monitoring-threshold(part 4). (ticket 47427) 
- 
    Thu Jul 25 2013 Mark Reynolds <mreynolds@redhat.com> - 1.2.11.15-19
    - Bump version to 1.2.11.15-19
- Resolves: Bug 984970 - Overflow in nsslapd-disk-monitoring-threshold(part 3). (ticket 47427) 
- 
    Tue Jul 23 2013 Mark Reynolds <mreynolds@redhat.com> - 1.2.11.15-19
    - Bump version to 1.2.11.15-19
- Resolves: Bug 982325 - Overflow in nsslapd-disk-monitoring-threshold(part 2). (ticket 47427)
- Resolves: Bug 986857 - Disk Monitoring not checking filesystem with logs (ticket 47741) 
- 
    Mon Jul 15 2013 Mark Reynolds <mreynolds@redhat.com> - 1.2.11.15-18
    - Bump version to 1.2.11.15-18
- Resolves: Bug 970995 - DS not shutting down when disk monitoring threshold is reached to half. (Ticket 47385)
- Resolves: Bug 982325 - Overflow in nsslapd-disk-monitoring-threshold. (ticket 47427) 
- 
    Wed Apr 10 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-14
    - Resolves: Bug 921937 - ns-slapd crashes sporadically with segmentation fault in libslapd.so (ticket 627)
- Resolves: Bug 923503 - cleanAllRUV task fails to cleanup config upon completion (ticket 623) 
- 
    Thu Mar 28 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-13
    bump version to 1.2.11.15-13
- Resolves: Bug 923503 - cleanAllRUV task fails to cleanup config upon completion (ticket 623)
- Resolves: Bug 923502 - Coverity issue 13091
- Resolves: Bug 923407 - Deadlock in DNA plug-in (ticket 634)
- Resolves: Bug 921937 - ns-slapd crashes sporadically with segmentation fault in libslapd.so (ticket 627)
- Resolves: Bug 923504 - crash in aci evaluation (ticket 628)
- Resolves: Bug 928159 - unintended information exposure when anonymous access is set to rootdse (ticket 47308) 
- 
    Fri Feb 22 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-12
    - Resolves: Bug 910581 - dse.ldif is 0 length after server kill or machine kill
- Resolves: Bug 908861 - Error messages encountered when using POSIX winsync
- Resolves: Bug 907985 - DNA: use event queue for config update only at the start up
- Resolves: Bug 830334 - Invalid chaining config triggers a disk full error and shutdown
- Resolves: Bug 906583 - DS returns error 20 when replacing values of a multi-valued attribute  (only when replication is enabled)
- Resolves: Bug 906005 - Valgrind reports memleak in modify_update_last_modified_attr
- Resolves: Bug 905825 - PamConfig schema not updated during upgrade
- Resolves: Bug 913215 - ns-slapd segfaults while trying to delete a tombstone entry
- Resolves: Bug 913229 - unauthenticated denial of service vulnerability in handling of LDAPv3 control data 
- 
    Mon Jan 21 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-11
    - Resolves: Bug 896256 - updating package touches configuration files 
- 
    Tue Jan 08 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-10
    - Resolves: Bug 889083 - For modifiersName/internalModifiersName feature, internalModifiersname is not working for DNA plugin 
- 
    Fri Jan 04 2013 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-9
    - Resolves: Bug 891930 - DNA plugin no longer reports additional info when range is depleted 
- 
    Tue Dec 18 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.11.15-8
    - Resolves: Bug 887855 - RootDN Access Control plugin is missing after upgrade from RHEL63 to RHEL64 
- 
    Fri Dec 07 2012 Noriko Hosoi <nhosoi@redhat.com> - 1.2.11.15-7
    - Resolves: Bug 830355 - [RFE] improve cleanruv functionality 
- Resolves: Bug 876650 - Coverity revealed defects 
- Ticket #20 - [RFE] Allow automember to work on entries that have already been added (Bug 768084)
- Resolves: Bug 834074 - [RFE] Disable replication agreements
- Resolves: Bug 878111 - ns-slapd segfaults if it cannot rename the logs 
- 
    Thu Nov 29 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.11.15-6
    - Resolves: Bug 880305 - spec file missing dependencies for x86_64 6ComputeNode
-   use perl-Socket6 on RHEL6 
- 
    Tue Nov 27 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.11.15-5
    - Resolves: Bug 880305 - spec file missing dependencies for x86_64 6ComputeNode 
- 
    Fri Nov 16 2012 Noriko Hosoi <nhoso@redhat.com> - 1.2.11.15-4
    - Resolves: Bug 868841 - Newly created users with organizationalPerson objectClass fails to sync from AD to DS with missing attribute error
- Resolves: Bug 868853 - Winsync: DS error logs report wrong version of Windows AD when winsync is configured.
- Resolves: Bug 875862 - crash in DNA if no dnamagicregen is specified
- Resolves: Bug 876694 - RedHat Directory Server crashes (segfaults) when moving ldap entry
- Resolves: Bug 876727 - Search with a complex filter including range search is slow
- Ticket #495 - internalModifiersname not updated by DNA plugin (Bug 834053) 
- 
    Mon Nov 05 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.11.15-3
    - Resolves: Bug 870158 - slapd entered to infinite loop during new index addition
- Resolves: Bug 870162 - Cannot abandon simple paged result search
- c970af0 Coverity defects
- 1ac087a Fixing compiler warnings in the posix-winsync plugin
- 2f960e4 Coverity defects
- Ticket #491 - multimaster_extop_cleanruv returns wrong error codes 
- 
    Tue Oct 09 2012 Noriko Hosoi<nhosoi@redhat.com> - 1.2.11.15-2
    - Resolves: Bug 834063 [RFE] enable attribute that tracks when a password was last set on an entry in the LDAP store; Ticket #478 passwordTrackUpdateTime stops working with subtree password policies 
- Resolves: Bug 847868 [RFE] support posix schema for user and group sync; Ticket #481 expand nested posix groups
- Resolves: Bug 860772 Change on SLAPI_MODRDN_NEWSUPERIOR is not evaluated in acl 
- Resolves: Bug 863576 Dirsrv deadlock locking up IPA
- Resolves: Bug 864594 anonymous limits are being applied to directory manager 
- 
    Tue Sep 25 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.11.15-1
    - Resolves: Bug 856657 dirsrv init script returns 0 even when few or all instances fail to start
- Resolves: Bug 858580 389 prevents from adding a posixaccount with userpassword after schema reload 
- 
    Fri Sep 14 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.11.14-1
    - Resolves: Bug 852202 Ipa master system initiated more than a dozen simultaneous replication sessions, shut itself down and wiped out its db
- Resolves: Bug 855438 CLEANALLRUV task gets stuck on winsync replication agreement 
- 
    Tue Sep 04 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.11.13-1
    - Resolves: Bug 847868 [RFE] support posix schema for user and group sync
-  fix upgrade issue with plugin config schema
-  posix winsync has default plugin precedence of 25 
- 
    Fri Aug 31 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.11.12-1
    - Resolves: Bug 800051 Rebase 389-ds-base to 1.2.11
- Resolves: Bug 742054 SASL/PLAIN binds do not work 
- Resolves: Bug 742381 MOD operations with chained delete/add get back error 53 on backend config
- Resolves: Bug 746642 [RFE] define pam_passthru service per subtree
- Resolves: Bug 757836 logconv.pl restarts count on conn=0 instead of conn=1
- Resolves: Bug 768084 [RFE] Allow automember to work on entries that have already been added
- Resolves: Bug 782975 krbExtraData is being null modified and replicated on each ssh login
- Resolves: Bug 803873 Sync with group attribute containing () fails
- Resolves: Bug 818762 winsync should not delete entry that appears to be out of scope
- Resolves: Bug 830001 unhashed#user#password visible after changing password [rhel-6.4]
- Resolves: Bug 830256 Audit log - clear text password in user changes
- Resolves: Bug 830331 ns-slapd exits/crashes if /var fills up
- Resolves: Bug 830334 Invalid chaining config triggers a disk full error and shutdown
- Resolves: Bug 830335 restore of replica ldif file on second master after deleting two records shows only 1 deletion
- Resolves: Bug 830336 db deadlock return should not log error
- Resolves: Bug 830337 usn + mmr = deletions are not replicated
- Resolves: Bug 830338 Change DS to purge ticket from krb cache in case of authentication error
- Resolves: Bug 830340 Make the CLEANALLRUV task one step
- Resolves: Bug 830343 managed entry sometimes doesn't delete the managed entry
- Resolves: Bug 830344 [RFE] Improve replication agreement status messages
- Resolves: Bug 830346 ADD operations not in audit log
- Resolves: Bug 830347 389 DS does not support multiple paging controls on a single connection
- Resolves: Bug 830348 Slow shutdown when you have 100+ replication agreements
- Resolves: Bug 830349 cannot use & in a sasl map search filter
- Resolves: Bug 830353 valgrind reported memleaks and mem errors
- Resolves: Bug 830355 [RFE] improve cleanruv functionality
- Resolves: Bug 830356 coverity 12625-12629 - leaks, dead code, unchecked return
- Resolves: Bug 832560 [abrt] 389-ds-base-1.2.10.6-1.fc16: slapi_attr_value_cmp: Process /usr/sbin/ns-slapd was killed by signal 11 (SIGSEGV)
- Resolves: Bug 833202 transaction retries need to be cache aware
- Resolves: Bug 833218 ldapmodify returns Operations error
- Resolves: Bug 833222 memberOf attribute and plugin behaviour between sub-suffixes
- Resolves: Bug 834046 [RFE] Add nsTLS1 attribute to schema and objectclass nsEncryptionConfig
- Resolves: Bug 834047 Fine Grained Password policy: if passwordHistory is on, deleting the password fails.
- Resolves: Bug 834049 [RFE] Add schema for DNA plugin
- Resolves: Bug 834052 [RFE] limiting Directory Manager (nsslapd-rootdn) bind access by source host (e.g. 127.0.0.1)
- Resolves: Bug 834053 [RFE] Plugins - ability to control behavior of modifyTimestamp/modifiersName
- Resolves: Bug 834054 Should only update modifyTimestamp/modifiersName on MODIFY ops
- Resolves: Bug 834056 Automembership plugin fails in a MMR setup, if data and config area mixed in the plugin configuration
- Resolves: Bug 834057 ldap-agent crashes on start with signal SIGSEGV
- Resolves: Bug 834058 [RFE] logconv.pl : use of getopts to parse commandline options
- Resolves: Bug 834060 passwordMaxFailure should lockout password one sooner - and should be configurable to avoid regressions
- Resolves: Bug 834061 [RFE] RHDS: Implement SO_KEEPALIVE in network calls.
- Resolves: Bug 834063 [RFE] enable attribute that tracks when a password was last set on an entry in the LDAP store
- Resolves: Bug 834064 dnaNextValue gets incremented even if the user addition fails
- Resolves: Bug 834065 Adding Replication agreement should complain if required nsds5ReplicaCredentials not supplied
- Resolves: Bug 834074 [RFE] Disable replication agreements
- Resolves: Bug 834075 logconv.pl reporting unindexed search with different search base than shown in access logs
- Resolves: Bug 835238 Account Usability Control Not Working
- Resolves: Bug 836386 slapi_ldap_bind() doesn't check bind results
- Resolves: Bug 838706 referint modrdn not working if case is different
- Resolves: Bug 840153 Impossible to rename entry (modrdn) with Attribute Uniqueness plugin enabled
- Resolves: Bug 841600 Referential integrity plug-in does not work when update interval is not zero
- Resolves: Bug 842437 dna memleak reported by valgrind
- Resolves: Bug 842438 Report during startup if nsslapd-cachememsize is too small
- Resolves: Bug 842440 memberof performance enhancement
- Resolves: Bug 842441 "Server is unwilling to perform" when running ldapmodify on nsds5ReplicaStripAttrs
- Resolves: Bug 847868 [RFE] support posix schema for user and group sync
- Resolves: Bug 850683 nsds5ReplicaEnabled can be set with any invalid values.
- Resolves: Bug 852087 [RFE] add attribute nsslapd-readonly so we can reference it in acis
- Resolves: Bug 852088 server to server ssl client auth broken with latest openldap
- Resolves: Bug 852839 variable dn should not be used in ldbm_back_delete 
- 
    Thu Jun 28 2012 Noriko Hosoi <nhosoi@redhat.com> - 1.2.10.2-20
    - Resolves: Bug 835238 - Account Usability Control Not Working 
- 
    Wed Jun 20 2012 Noriko Hosoi <nhosoi@redhat.com> - 1.2.10.2-19
    - Resolves: Bug 834096 - slapi_attr_value_cmp: Process /usr/sbin/ns-slapd was killed by signal 11 (SIGSEGV) 
- 
    Tue Jun 12 2012 Noriko Hosoi <nhosoi@redhat.com> - 1.2.10.2-18
    - Resolves: Bug 830001 - unhashed#user#password visible after changing password
-- patch 0020 disallows users' direct modify on unhashed#user#password 
- 
    Mon Jun 11 2012 Noriko Hosoi <nhosoi@redhat.com> - 1.2.10.2-17
    - Resolves: Bug 830001 - unhashed#user#password visible after changing password
-- patch 0019 fixes deref issue. 
- 
    Fri Jun 08 2012 Noriko Hosoi <nhosoi@redhat.com> - 1.2.10.2-16
    - Resolves: Bug 830001 - unhashed#user#password visible after changing password
- Resolves: Bug 830256 - Audit log - clear text password in user changes 
- 
    Tue May 22 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.2-15
    - Resolves: Bug 824014 - DS Shuts down intermittently 
- 
    Fri May 18 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.2-14
    - Resolves: Bug 819643 - Database RUV could mismatch the one in changelog under the stress
-- patch 0015 fixes a small memleak in previous patch 
- 
    Thu May 17 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.2-13
    - Resolves: Bug 822700 - Bad DNs in ACIs can segfault ns-slapd 
- 
    Mon May 14 2012 Noriko Hosoi <nhosoi@redhat.com> - 1.2.10.2-12
    - Resolves: Bug 819643 - Database RUV could mismatch the one in changelog under the stress
- Resolves: Bug 821542 - letters in object's cn get converted to lowercase when renaming object 
- 
    Thu May 10 2012 Noriko Hosoi <nhosoi@redhat.com> - 1.2.10.2-11
    - Resolves: Bug 819643 - Database RUV could mismatch the one in changelog under the stress
- 1.2.10.2-10 was built from the private branch 
- 
    Wed May 09 2012 Noriko Hosoi <nhosoi@redhat.com> - 1.2.10.2-10
    - Resolves: Bug 819643 - Database RUV could mismatch the one in changelog under the stress 
- 
    Thu May 03 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.2-9
    - Resolves: Bug 815991 - crash in ldap_initialize with multiple threads
-  previous fix was still crashing in ldclt 
- 
    Mon Apr 30 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.2-8
    - Resolves: Bug 815991 - crash in ldap_initialize with multiple threads 
- 
    Tue Apr 24 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.2-7
    - Resolves: Bug 813964 - IPA dirsvr seg-fault during system longevity test 
- 
    Tue Apr 10 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.2-6
    - Resolves: Bug 811291 - [abrt] 389-ds-base-1.2.10.4-2.fc16: index_range_read_ext: Process /usr/sbin/ns-slapd was killed by signal 11 (SIGSEGV)
- typo in previous patch 
- 
    Tue Apr 10 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.2-5
    - Resolves: Bug 811291 - [abrt] 389-ds-base-1.2.10.4-2.fc16: index_range_read_ext: Process /usr/sbin/ns-slapd was killed by signal 11 (SIGSEGV) 
- 
    Wed Mar 21 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.2-4
    - Resolves: Bug 803930 - ipa not starting after upgade because of missing data
- get rid of posttrans - move update code to post 
- 
    Tue Mar 13 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.2-3
    - Resolves: Bug 800215 - Certain CMP operations hang or cause ns-slapd to crash 
- 
    Tue Mar 06 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.2-2
    - Resolves: Bug 800215 - Certain CMP operations hang or cause ns-slapd to crash 
- Resolves: Bug 800217 - fix valgrind reported issues 
- 
    Thu Feb 23 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.2-1
    - Resolves: Bug 766989 - Rebase 389-ds-base to 1.2.10
- Resolves: Bug 796770 - crash when replicating orphaned tombstone entry 
- 
    Tue Feb 14 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.1-1
    - Resolves: Bug 766989 - Rebase 389-ds-base to 1.2.10
- Resolves: Bug 790491 - 389 DS Segfaults during replica install in FreeIPA 
- 
    Mon Feb 13 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10.0-1
    - Resolves: Bug 766989 - Rebase 389-ds-base to 1.2.10 
- 
    Mon Feb 06 2012 Rich Megginson <rmeggins@redhat.com> - 1.2.10-0.11.rc2
    - Resolves: Bug 766989 - Rebase 389-ds-base to 1.2.10 
- 
    Mon Dec 19 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.16-1
    - Bug 759301 - Incorrect entryUSN index under high load in replicated environment
- Bug 743979 - Add slapi_rwlock API and use POSIX rwlocks
- WARNING - patches 0030 and 0031 remove and add back the file configure
- this is necessary because the merge commit to "rebase" RHEL-6 to 1.2.9.6
- seriously messed up configure - so in order to add the patch for 743979
- which also touched configure, the file had to be removed and added back
- also note that the commit for the RHEL-6 branch to remove configure does
- not work - the way patch works, it has to match every line exactly in
- order to remove the file, and because the merge commit messed things
- up, it doesn't work
- So, DO NOT TOUCH 0030-remove-configure-to-get-rid-of-merge-conflict.patch
- BECAUSE IT IS HAND CRAFTED and not generated by git format-patch
- if you must regenerate this file,
- git format-patch ...args... to generate a file in patch format
- remove all of the patch matches (all the lines beginning with -)
- get the 1.2.9.6 version of configure from the source tarball
- wc -l configure to get the number of lines in the file
- sed 's/^/-/' configure >> thefile.patch
- edit thefile.patch to have the right number of lines and have the
- patch commands in the correct place
- PROFIT!!! 
- 
    Mon Nov 28 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.15-1
    - Bug 752577 - crash when simple paged fails to send entry to client
- Bug 757897 - rhds81 modrn operation and 100% cpu use in replication
- Bug 757898 - Fix Coverity (11104) Resource leak: ids_sasl_user_to_entry (slapd/saslbind.c) 
- 
    Tue Nov 08 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.14-1
    - Bug 752155 - Use restorecon after creating init script lock file 
- 
    Thu Oct 06 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.13-1
    - Bug 742381 - part3 - MOD operations with chained delete/add get
-  back error 53 on backend config 
- 
    Mon Oct 03 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.12-2
    - add the actual patch commands for the new patch files 
- 
    Mon Oct 03 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.12-1
    - Bug 742661 - allow resource limits to be set for paged searches
-  independently of limits for other searches/operations
- Bug 742381 - part2 - MOD operations with chained delete/add get
-  back error 53 on backend config
- Bug 742382 - allow nsslapd-idlistscanlimit to be set dynamically and per-user
- Bug 742381 - MOD operations with chained delete/add get back
-  error 53 on backend config
- Bug 739959 - Allow separate fractional attrs for incremental and total protocols 
- 
    Fri Sep 16 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.11-1
    - Bug 739196 - Consolidate DS and DS replication bits in one package in RHEL 6.2
- There were two patches in ds-replication for RHEL 6.2 that were added post
- rebase - the two patches for 722292 - these are now in the 389-ds-base package
- and have been cherry-picked to the RHEL-6 internal branch 
- 
    Wed Sep 07 2011 Nathan Kinder <nkinder@redhat.com> - 1.2.9.10-1
    - Bug 736137 - renaming a managed entry does not update mepmanagedby 
- 
    Thu Sep 01 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.9-1
    - Bug 735217 - simple paged search + ip/dns based ACI hangs server 
- 
    Wed Aug 31 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.8-1
    - Bug 733443 - large targetattr list with syntax errors cause server to crash or hang
- Bug 734267 - upgradednformat failed to add RDN value - subtree and user account lockout policies implemented?
- Bug 733434 - passwordisglobalpolicy attribute brakes TLS chaining
- Bug 733442 - Ignore an error 32 in this case since we're adding a new AutoMember definition
- Bug 733440 - RFE: add option to allow server to start with an expired certificate 
- 
    Wed Aug 24 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.7-1
    - not released internally 
- 
    Wed Aug 10 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.6-1
    - Bug 728510 - Run dirsync after sending updates to AD
- Bug 729717 - Fatal error messages when syncing deletes from AD
- Bug 729369 - upgrade DB to upgrade from entrydn to entryrdn format is not working.
- Bug 729378 - delete user subtree container in AD + modify password in DS == DS crash
- Bug 723937 - Slapi_Counter API broken on  32-bit F15
-   fixed again - separate tests for atomic ops and atomic bool cas 
- 
    Mon Aug 08 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.5-1
    - Bug 727511 - ldclt SSL search requests are failing with "illegal error number -1" error
-  Fix another coverity NULL deref in previous patch 
- 
    Thu Aug 04 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.4-1
    - Bug 727511 - ldclt SSL search requests are failing with "illegal error number -1" error
-  Fix coverity NULL deref in previous patch 
- 
    Wed Aug 03 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.3-1
    - Bug 727511 - ldclt SSL search requests are failing with "illegal error number -1" error
-  previous patch broke build on el5 
- 
    Wed Aug 03 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.2-1
    - Bug 727511 - ldclt SSL search requests are failing with "illegal error number -1" error 
- 
    Tue Aug 02 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.1-2
    - Bug 723937 - Slapi_Counter API broken on  32-bit F15
-   fixed to use configure test for GCC provided 64-bit atomic functions 
- 
    Wed Jul 27 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.9.1-1
    - Bug 663752 - Cert renewal for attrcrypt and encchangelog
-   this was "re-fixed" due to a deadlock condition with cl2ldif task cancel
- Bug 725953 - Winsync: DS entries fail to sync to AD, if the User's CN entry contains a comma
- Bug 725743 - Make memberOf use PRMonitor for it's operation lock
- Bug 725542 - Instance upgrade fails when upgrading 389-ds-base package
- Bug 723937 - Slapi_Counter API broken on  32-bit F15
- look for separate openldap ldif library
- Split automember regex rules into separate entries
- writing Inf file shows SchemaFile = ARRAY(0xhexnum)
- add support for ldif files with changetype: add
- Bug 703703 - setup-ds-admin.pl asks for legal agreement to a non-existant file
- Bug 713209 - Update sudo schema
- Bug 719069 - clean up compiler warnings in 389-ds-base 1.2.9 
- 
    Wed Jul 27 2011 Nathan Kinder <nkinder@redhat.com> - 1.2.8.7-1
    - Bug 726136 - memberOf plug-in can deadlock when used with other plug-ins
- Bug 725912 - Instance upgrade fails when upgrading 389-ds-base package 
- 
    Mon Jul 11 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.6-1
    - Bug 720452 - RDN with % can cause crashes or missing entries
- Bug 720051 - RSA Authentication Server timeouts when using simple paged results on RHDS 8.2.
- Bug 720458 - Directory Server 8.2 logs "Netscape Portable Runtime error -5961 (TCP connection reset by peer.)" to error log whereas Directory Server 8.1 did not
- Bug 720459 - Update sudo schema 
- 
    Fri Jul 01 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.5-1
    - Bug 718351 - Intensive updates on masters could break the consumer's cache
- Bug 714298 - unresponsive LDAP service when deleting vlv on replica 
- 
    Tue Jun 21 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.4-3
    - Bug 714298 - unresponsive LDAP service when deleting vlv on replica - memleak in previous patch 
- 
    Mon Jun 20 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.4-2
    - Bug 714298 - unresponsive LDAP service when deleting vlv on replica 
- 
    Fri Jun 17 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.4-1
    - Bug 706209 - LEGAL: RHEL6.1 License issue for 389-ds-base package
- Bug 713317 - Cert renewal for attrcrypt and encchangelog
- Bug 711266 - DS can not restart after create a new objectClass has entryusn attribute
- Bug 712167 - ns-slapd segfaults using suffix referrals
- Bug 709868 - only allow FIPS approved cipher suites in FIPS mode
- Bug 711516 - Support upgrade from Red Hat Directory Server
- Bug 711241 - memory leak found by reliab12
- Bug 711265 - Cannot disable SSLv3 and use TLS only
- Bug 711513 - slapd stops responding 
- 
    Wed May 18 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.3-4
    - Resolves: Bug 705172 - 389-ds should only be supported and supplied in channels for i386 and x86_64 Server distributions - RHEL 6.1 0day Advisory
- use ix86 macro instead of hardcoded i386 etc. 
- 
    Wed May 18 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.3-3
    - Resolves: Bug 705172 - 389-ds should only be supported and supplied in channels for i386 and x86_64 Server distributions - RHEL 6.1 0day Advisory
- cannot use wildcard in ExclusiveArch 
- 
    Wed May 18 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.3-2
    - Resolves: Bug 705172 - 389-ds should only be supported and supplied in channels for i386 and x86_64 Server distributions - RHEL 6.1 0day Advisory 
- 
    Mon May 02 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.3-1
    - Resolves: Bug 697663 - memory leak: entryusn value is leaked when an entry is deleted
- Resolves: Bug 699458 - windows sync can lose old multi-valued attribute values when a new value is added
- Resolves: Bug 700215 - ldclt core dumps
- Resolves: Bug 700665 - Linked attributes callbacks access free'd pointers after close
- Resolves: Bug 701057 - userpasswd not replicating 
- 
    Thu Apr 14 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.2-1
    - 389-ds-base-1.2.8.2
- Bug 696407 - If an entry with a mixed case RDN is turned to be
-    a tombstone, it fails to assemble DN from entryrdn 
- 
    Fri Apr 08 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.1-1
    - 389-ds-base-1.2.8.1
- Bug 693962 - Full replica push loses some entries with multi-valued RDNs 
- 
    Tue Apr 05 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.0-2
    - added srcver because the version from the source is now
- different than the source in the package 
- 
    Tue Apr 05 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8.0-1
    - 389-ds-base-1.2.8.0
- Bug 693523 - Unable to change schema online
- Bug 693520 - matching rules do not inherit from superior attribute type
- Bug 693522 - nsMatchingRule does not work with multiple values
- Bug 693519 - cannot use localized matching rules
- Bug 693516 - Segfault on index update during full replication push on 1.2.7.5 
- 
    Tue Mar 29 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8-0.9.rc4
    - Bug 668385 - DS pipe log script is executed as many times as the dirsrv service is restarted
- bump version to 1.2.8.rc4 - bump ds console version to 1.2.5 
- 
    Mon Mar 28 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8-0.8.rc2
    - Bug 690536 - Double free in dse_add() 
- 
    Tue Mar 22 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8-0.7.rc2
    - 389-ds-base-1.2.8 release candidate 2 - git tag 389-ds-base-1.2.8.rc2
- Bug 689908 - (cov#10610) Fix Coverity NULL pointer dereferences
- Bug 689895 - ns-newpwpolicy.pl needs to use the new DN format
- Bug 689889 - RFE: allow fine grained password policy duration attributes
-              in days, hours, minutes, as well
- Bug 688730 - Exported tombstone cannot be imported correctly
- Bug 684349 - slapd crashing when traffic replayed
- Bug 682897 - Allow maxlogsize to be set if logmaxdiskspace is -1
- introduce the concept of the srcprerel - with rc2, we did not rebase
- the source, we are still using the .rc1 source tarball, so we use
- srcprerel of .rc1 but package pre-release is .rc2 
- 
    Wed Mar 02 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8-0.6.rc1
    - 389-ds-base-1.2.8 release candidate 1 - git tag 389-ds-base-1.2.8.rc1
- Resolves: Bug 680575 - Rebase 389-ds-base to pick the latest features and fixes 
- Resolves: Bug 681720 - setup-ds-admin.pl - improve hostname validation
- Resolves: Bug 681611 - RFE: allow fine grained password policy duration attributes in 
-     days, hours, minutes, as well
- Resolves: Bug 681550 - setup-ds-admin.pl --debug does not log to file
- Resolves: Bug 681379 - ns-slapd segfaults if I have more than 100 DBs
- Resolves: Bug 680290 - setup-ds.pl should set SuiteSpotGroup automatically
- Resolves: Bug 681351 - crash in ldap-agent when using OpenLDAP
- Resolves: Bug 681332 - modifying attr value crashes the server, which is supposed to
-     be indexed as substring type, but has octetstring syntax
- Resolves: Bug 680305 - ds-logpipe.py script is failing to validate "-s" and
-     "--serverpid" options with "-t". 
- 
    Mon Feb 28 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8-0.5.a3
    - Bug 676598 - 389-ds-base multilib: file conflicts
- split off libs into a separate -libs package
- remove old crufty fedora-ds stuff 
- 
    Thu Feb 24 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8-0.4.a3
    - do not create /var/run/dirsrv - setup will create it instead
- remove the fedora-ds initscript upgrade stuff - we do not support that anymore
- convert the remaining lua stuff to plain old shell script 
- 
    Wed Feb 09 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8-0.3.a3
    - 1.2.8.a3 release - git tag 389-ds-base-1.2.8.a3
- Bug 675320 - empty modify operation with repl on or lastmod off will crash server
- Bug 675265 - preventryusn gets added to entries on a failed delete
- Bug 677774 - added support for tmpfiles.d
- Bug 666076 - dirsrv crash (1.2.7.5) with multiple simple paged result search
es
- Bug 672468 - Don't use empty path elements in LD_LIBRARY_PATH
- Bug 671199 - Don't allow other to write to rundir
- Bug 678646 - Ignore tombstone operations in managed entry plug-in
- Bug 676053 - export task followed by import task causes cache assertion
- Bug 677440 - clean up compiler warnings in 389-ds-base 1.2.8
- Bug 675113 - ns-slapd core dump in windows_tot_run if oneway sync is used
- Bug 676689 - crash while adding a new user to be synced to windows
- Bug 604881 - admin server log files have incorrect permissions/ownerships
- Bug 668385 - DS pipe log script is executed as many times as the dirsrv serv
ice is restarted
- Bug 675853 - dirsrv crash segfault in need_new_pw() 
- 
    Thu Feb 03 2011 Rich Megginson <rmeggins@redhat.com> - 1.2.8-0.2.a2
    - 1.2.8.a2 release - git tag 389-ds-base-1.2.8.a2
- Errata Patches in patch files
- Bug 666076 - dirsrv crash (1.2.7.5) with multiple simple paged result searches
- Bug 671199 - Don't allow other to write to rundir
- Bug 672468 - Don't use empty path elements in LD_LIBRARY_PATH
- bugs fixed in released code
- Bug 674430 - Improve error messages for attribute uniqueness
- Bug 616213 - insufficient stack size for HP-UX on PA-RISC
- Bug 615052 - intrinsics and 64-bit atomics code fails to compile
-    on PA-RISC
- Bug 151705 - Need to update Console Cipher Preferences with new ciphers
- Bug 668862 - init scripts return wrong error code
- Bug 670616 - Allow SSF to be set for local (ldapi) connections
- Bug 667935 - DS pipe log script's logregex.py plugin is not redirecting the 
-    log output to the text file
- Bug 668619 - slapd stops responding
- Bug 624547 - attrcrypt should query the given slot/token for
-    supported ciphers
- Bug 646381 - Faulty password for nsmultiplexorcredentials does not give any 
-    error message in logs 
- 
    Fri Jan 21 2011 Nathan Kinder <nkinder@redhat.com> - 1.2.8-0.1.a1
    - 1.2.8-0.1.a1 release
- many bug fixes 
- 
    Fri Dec 17 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.7.5-1
    - 1.2.7.5 release - git tag 389-ds-base-1.2.7.5
- Bug 663597 - Memory leaks in normalization code 
- 
    Fri Dec 10 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.7.4-1
    - 1.2.7.4 release - git tag 389-ds-base-1.2.7.4
- Bug 661792 - Valid managed entry config rejected 
- 
    Wed Dec 08 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.7.3-1
    - 1.2.7.3 release - git tag 389-ds-base-1.2.7.3
- Bug 658312 - Invalid free in Managed Entry plug-in
- Bug 641944 - Don't normalize non-DN RDN values 
- 
    Fri Dec 03 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.7.2-1
    - 1.2.7.2 release - git tag 389-ds-base-1.2.7.2
- Bug 659456 - Incorrect usage of ber_printf() in winsync code
- Bug 658309 - Process escaped characters in managed entry mappings
- Bug 197886 - Initialize return value for UUID generation code
- Bug 658312 - Allow mapped attribute types to be quoted
- Bug 197886 - Avoid overflow of UUID generator 
- 
    Tue Nov 23 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.7.1-1
    - 1.2.7.1 release - git tag 389-ds-base-1.2.7.1
- Bug 656515 - Allow Name and Optional UID syntax for grouping attributes
- Bug 656392 - Remove calls to ber_err_print()
- Bug 625950 - hash nsslapd-rootpw changes in audit log 
- 
    Tue Nov 16 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.7-1
    - the 1.2.7 release
- remove the ds-replication sub-package - there will be a new package for it
- remove the selinux policy - dirsrv policy will be provided by the base OS 
- 
    Wed Nov 03 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.7-0.7.a5
    - create ds-replication sub package 
- 
    Tue Nov 02 2010 Kevin Wright <kwright@redhat.com> - 1.2.7-0.6.a4
    - bumped the version to get it to build in brew 
- 
    Mon Nov 01 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.7-0.5.a4
    - 1.2.7.a4 release - git tag 389-ds-base-1.2.7.a4
- Bug 647932 - multiple memberOf configuration adding memberOf where there is 
no member
- Bug 491733 - dbtest crashes
- Bug 606545 - core schema should include numSubordinates
- Bug 638773 - permissions too loose on pid and lock files
- Bug 189985 - Improve attribute uniqueness error message
- Bug 619623 - attr-unique-plugin ignores requiredObjectClass on modrdn operat
ions
- Bug 619633 - Make attribute uniqueness obey requiredObjectClass 
- 
    Wed Oct 27 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.7-0.4.a3
    - 1.2.7.a3 release - a2 was never released - this is a rebuild to pick up
- Bug 644608 - RHDS 8.1->8.2 upgrade fails to properly migrate ACIs
- Adding the ancestorid fix code to ##upgradednformat.pl. 
- 
    Fri Oct 22 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.7-0.3.a3
    - 1.2.7.a3 release - a2 was never released
- Bug 644608 - RHDS 8.1->8.2 upgrade fails to properly migrate ACIs
- Bug 629681 - Retro Changelog trimming does not behave as expected
- Bug 645061 - Upgrade: 06inetorgperson.ldif and 05rfc4524.ldif
-              are not upgraded in the server instance schema dir 
- 
    Tue Oct 19 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.7-0.2.a2
    - 1.2.7.a2 release - a1 was the OpenLDAP testday release
- git tag 389-ds-base-1.2.7.a2
- added openldap support on platforms that use openldap with moznss
- for crypto (F-14 and later)
- many bug fixes
- Account Policy Plugin (keep track of last login, disable old accounts) 
- 
    Fri Oct 08 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.7-0.1.a1
    - added openldap support 
- 
    Wed Sep 29 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.6.1-3
    - bump rel to rebuild again 
- 
    Mon Sep 27 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.6.1-2
    - bump rel to rebuild 
- 
    Thu Sep 23 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.6.1-1
    - This is the 1.2.6.1 release - git tag 389-ds-base-1.2.6.1
- Bug 634561 - Server crushes when using Windows Sync Agreement
- Bug 635987 - Incorrect sub scope search result with ACL containing ldap:///self
- Bug 612264 - ACI issue with (targetattr='userPassword')
- Bug 606920 - anonymous resource limit- nstimelimit - also applied to "cn=directory manager"
- Bug 631862 - crash - delete entries not in cache + referint 
- 
    Thu Aug 26 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.6-1
    - This is the final 1.2.6 release 
- 
    Tue Aug 10 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.6-0.11.rc7
    - 1.2.6 release candidate 7
- git tag 389-ds-base-1.2.6.rc7
- Bug 621928 - Unable to enable replica (rdn problem?) on 1.2.6 rc6 
- 
    Mon Aug 02 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.6-0.10.rc6
    - 1.2.6 release candidate 6
- git tag 389-ds-base-1.2.6.rc6
- Bug 617013 - repl-monitor.pl use cpu upto 90%
- Bug 616618 - 389 v1.2.5 accepts 2 identical entries with different DN formats
- Bug 547503 - replication broken again, with 389 MMR replication and TCP errors
- Bug 613833 - Allow dirsrv_t to bind to rpc ports
- Bug 612242 - membership change on DS does not show on AD
- Bug 617629 - Missing aliases in new schema files
- Bug 619595 - Upgrading sub suffix under non-normalized suffix disappears
- Bug 616608 - SIGBUS in RDN index reads on platforms with strict alignments
- Bug 617862 - Replication: Unable to delete tombstone errors
- Bug 594745 - Get rid of dirsrv_lib_t label 
- 
    Wed Jul 14 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.6-0.9.rc3
    - make selinux-devel explicit Require the base package in order
- to comply with Fedora Licensing Guidelines 
- 
    Thu Jul 01 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.6-0.8.rc3
    - 1.2.6 release candidate 3
- git tag 389-ds-base-1.2.6.rc3
- Bug 603942 - null deref in _ger_parse_control() for subjectdn
- 609256  - Selinux: pwdhash fails if called via Admin Server CGI
- 578296  - Attribute type entrydn needs to be added when subtree rename switch is on
- 605827 - In-place upgrade: upgrade dn format should not run in setup-ds-admin.pl
- Bug 604453 - SASL Stress and Server crash: Program quits with the assertion failure in PR_Poll
- Bug 604453 - SASL Stress and Server crash: Program quits with the assertion failure in PR_Poll
- 606920 - anonymous resource limit - nstimelimit - also applied to "cn=directory manager" 
- 
    Wed Jun 16 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.6-0.7.rc2
    - 1.2.6 release candidate 2 
- 
    Mon Jun 14 2010 Nathan Kinder <nkinder@redhat.com> - 1.2.6-0.6.rc1
    - install replication session plugin header with devel package 
- 
    Wed Jun 09 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.6-0.5.rc1
    - 1.2.6 release candidate 1 
- 
    Tue Jun 01 2010 Marcela Maslanova <mmaslano@redhat.com> - 1.2.6-0.4.a4.1
    - Mass rebuild with perl-5.12.0 
- 
    Wed May 26 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.6-0.4.a4
    - 1.2.6.a4 release 
- 
    Wed Apr 07 2010 Nathan Kinder <nkinder@redhat.com> - 1.2.6-0.4.a3
    - 1.2.6.a3 release
- add managed entries plug-in
- many bug fixes
- moved selinux subpackage into base package 
- 
    Fri Apr 02 2010 Caolán McNamara <caolanm@redhat.com> - 1.2.6-0.3.a2
    - rebuild for icu 4.4 
- 
    Tue Mar 02 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.6-0.2.a2
    - 1.2.6.a2 release
- add support for matching rules
- many bug fixes 
- 
    Thu Jan 14 2010 Nathan Kinder <nkinder@redhat.com> - 1.2.6-0.1.a1
    - 1.2.6.a1 release
- Added SELinux policy and subpackages 
- 
    Tue Jan 12 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.5-1
    - 1.2.5 final release 
- 
    Mon Jan 04 2010 Rich Megginson <rmeggins@redhat.com> - 1.2.5-0.5.rc4
    - 1.2.5.rc4 release 
- 
    Thu Dec 17 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.5-0.4.rc3
    - 1.2.5.rc3 release 
- 
    Mon Dec 07 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.5-0.3.rc2
    - 1.2.5.rc2 release 
- 
    Wed Dec 02 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.5-0.2.rc1
    - 1.2.5.rc1 release 
- 
    Thu Nov 12 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.5-0.1.a1
    - 1.2.5.a1 release 
- 
    Thu Oct 29 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.4-1
    - 1.2.4 release
- resolves bug 221905 - added support for Salted MD5 (SMD5) passwords - primarily for migration
- resolves bug 529258 - Make upgrade remove obsolete schema from 99user.ldif 
- 
    Mon Sep 14 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.3-1
    - 1.2.3 release
- added template-initconfig to %files
- %posttrans now runs update to update the server instances
- servers are shutdown, then restarted if running before install
- scriptlets mostly use lua now to pass data among scriptlet phases 
- 
    Tue Sep 01 2009 Caolán McNamara <caolanm@redhat.com> - 1.2.2-2
    - rebuild with new openssl to fix dependencies 
- 
    Tue Aug 25 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.2-1
    - backed out - added template-initconfig to %files - this change is for the next major release
- bump version to 1.2.2
- fix reopened 509472 db2index all does not reindex all the db backends correctly
- fix 518520 -  pre hashed salted passwords do not work
- see https://bugzilla.redhat.com/show_bug.cgi?id=518519 for the list of
- bugs fixed in 1.2.2 
- 
    Fri Aug 21 2009 Tomas Mraz <tmraz@redhat.com> - 1.2.1-5
    - rebuilt with new openssl 
- 
    Wed Aug 19 2009 Noriko Hosoi <nhosoi@redhat.com> - 1.2.1-4
    - added template-initconfig to %files 
- 
    Wed Aug 12 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.1-3
    - added BuildRequires pcre 
- 
    Fri Jul 24 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.2.1-2
    - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild 
- 
    Mon May 18 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.1-1
    - change name to 389
- change version to 1.2.1
- added initial support for numeric string syntax
- added initial support for syntax validation
- added initial support for paged results including sorting 
- 
    Tue Apr 28 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.0-4
    - final release 1.2.0
- Resolves: bug 475338 - LOG: the intenal type of maxlogsize, maxdiskspace and minfreespace should be 64-bit integer
- Resolves: bug 496836 - SNMP ldap-agent on Solaris: Unable to open semaphore for server: 389
- CVS tag: FedoraDirSvr_1_2_0 FedoraDirSvr_1_2_0_20090428 
- 
    Mon Apr 06 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.0-3
    - re-enable ppc builds 
- 
    Thu Apr 02 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.0-2
    - exclude ppc builds - needs extensive porting work 
- 
    Mon Mar 30 2009 Rich Megginson <rmeggins@redhat.com> - 1.2.0-1
    - new release 1.2.0
- Made devel package depend on mozldap-devel
- only create run dir if it does not exist
- CVS tag: FedoraDirSvr_1_2_0_RC1 FedoraDirSvr_1_2_0_RC1_20090330 
- 
    Thu Oct 30 2008 Noriko Hosoi <nhosoi@redhat.com> - 1.1.3-7
    - added db4-utils to Requires for verify-db.pl 
- 
    Mon Oct 13 2008 Noriko Hosoi <nhosoi@redhat.com> - 1.1.3-6
    - Enabled LDAPI autobind 
- 
    Thu Oct 09 2008 Rich Megginson <rmeggins@redhat.com> - 1.1.3-5
    - updated update to patch bug463991-bdb47.patch 
- 
    Thu Oct 09 2008 Rich Megginson <rmeggins@redhat.com> - 1.1.3-4
    - updated patch bug463991-bdb47.patch 
- 
    Mon Sep 29 2008 Rich Megginson <rmeggins@redhat.com> - 1.1.3-3
    - added patch bug463991-bdb47.patch
- make ds work with bdb 4.7 
- 
    Wed Sep 24 2008 Rich Megginson <rmeggins@redhat.com> - 1.1.3-2
    - rolled back bogus winsync memory leak fix 
- 
    Tue Sep 23 2008 Rich Megginson <rmeggins@redhat.com> - 1.1.3-1
    - winsync api improvements for modify operations 
- 
    Fri Jun 13 2008 Rich Megginson <rmeggins@redhat.com> - 1.1.2-1
    - This is the 1.1.2 release.  The bugs fixed can be found here
- https://bugzilla.redhat.com/showdependencytree.cgi?id=452721
- Added winsync-plugin.h to the devel subpackage 
- 
    Fri Jun 06 2008 Rich Megginson <rmeggins@redhat.com> - 1.1.1-2
    - bump rev to rebuild and pick up new version of ICU 
- 
    Fri May 23 2008 Rich Megginson <rmeggins@redhat.com> - 1.1.1-1
    - 1.1.1 release candidate - several bug fixes 
- 
    Wed Apr 16 2008 Rich Megginson <rmeggins@redhat.com> - 1.1.0.1-4
    - fix bugzilla 439829 - patch to allow working with NSS 3.11.99 and later 
- 
    Tue Mar 18 2008 Tom "spot" Callaway <tcallawa@redhat.com> - 1.1.0.1-3
    - add patch to allow server to work with NSS 3.11.99 and later
- do NSS_Init after fork but before detaching from console 
- 
    Tue Mar 18 2008 Tom "spot" Callaway <tcallawa@redhat.com> - 1.1.0.1-3
    - add Requires for versioned perl (libperl.so) 
- 
    Wed Feb 27 2008 Rich Megginson <rmeggins@redhat.com> - 1.1.0.1-2
    - previous fix for 434403 used the wrong patch
- this is the right one 
- 
    Wed Feb 27 2008 Rich Megginson <rmeggins@redhat.com> - 1.1.0.1-1
    - Resolves bug 434403 - GCC 4.3 build fails
- Rolled new source tarball which includes Nathan's fix for the struct ucred
- NOTE: Change version back to 1.1.1 for next release
- this release was pulled from CVS tag FedoraDirSvr110_gcc43 
- 
    Tue Feb 19 2008 Fedora Release Engineering <rel-eng@fedoraproject.org> - 1.1.0-5
    - Autorebuild for GCC 4.3 
- 
    Thu Dec 20 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-4
    - This is the GA release of Fedora DS 1.1
- Removed version numbers for BuildRequires and Requires
- Added full URL to source tarball 
- 
    Fri Dec 07 2007 Release Engineering <rel-eng at fedoraproject dot org> - 1.1.0-3
    - Rebuild for deps 
- 
    Wed Nov 07 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-2.0
    - This is the beta2 release
- new file added to package - /etc/sysconfig/dirsrv - for setting
- daemon environment as is usual in other linux daemons 
- 
    Thu Aug 16 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-1.2
    - fix build breakage due to open()
- mock could not find BuildRequires: db4-devel >= 4.2.52
- mock works if >= version is removed - it correctly finds db4.6 
- 
    Fri Aug 10 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-1.1
    - Change pathnames to use the pkgname macro which is dirsrv
- get rid of cvsdate in source name 
- 
    Fri Jul 20 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-0.3.20070720
    - Added Requires for perldap, cyrus sasl plugins
- Removed template-migrate* files
- Added perl module directory
- Removed install.inf - setup-ds.pl can now easily generate one 
- 
    Mon Jun 18 2007 Nathan Kinder <nkinder@redhat.com> - 1.1.0-0.2.20070320
    - added requires for mozldap-tools 
- 
    Tue Mar 20 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-0.1.20070320
    - update to latest sources
- added migrateTo11 to allow migrating instances from 1.0.x to 1.1
- ldapi support
- fixed pam passthru plugin ENTRY method 
- 
    Fri Feb 23 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-0.1.20070223
    - Renamed package to fedora-ds-base, but keep names of paths/files/services the same
- use the shortname macro (fedora-ds) for names of paths, files, and services instead
- of name, so that way we can continue to use e.g. /etc/fedora-ds instead of /etc/fedora-ds-base
- updated to latest sources 
- 
    Tue Feb 13 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-0.1.20070213
    - More cleanup suggested by Dennis Gilmore
- This is the fedora extras candidate based on cvs tag FedoraDirSvr110a1 
- 
    Fri Feb 09 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-1.el4.20070209
    - latest sources
- added init scripts
- use /etc as instconfigdir 
- 
    Wed Feb 07 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-1.el4.20070207
    - latest sources
- moved all executables to _bindir 
- 
    Mon Jan 29 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-1.el4.20070129
    - latest sources
- added /var/tmp/fedora-ds to dirs 
- 
    Fri Jan 26 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-8.el4.20070125
    - added logconv.pl
- added slapi-plugin.h to devel package
- added explicit dirs for /var/log/fedora-ds et. al. 
- 
    Thu Jan 25 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-7.el4.20070125
    - just move all .so files into the base package from the devel package 
- 
    Thu Jan 25 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-6.el4.20070125
    - Move the plugin *.so files into the main package instead of the devel
- package because they are loaded directly by name via dlopen 
- 
    Fri Jan 19 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-5.el4.20070125
    - Move the script-templates directory to datadir/fedora-ds 
- 
    Fri Jan 19 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-4.el4.20070119
    - change mozldap to mozldap6 
- 
    Fri Jan 19 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-3.el4.20070119
    - remove . from cvsdate define 
- 
    Fri Jan 19 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-2.el4.20070119
    - Having a problem building in Brew - may be Release format 
- 
    Fri Jan 19 2007 Rich Megginson <rmeggins@redhat.com> - 1.1.0-1.el4.cvs20070119
    - Changed version to 1.1.0 and added Release 1.el4.cvs20070119
- merged in changes from Fedora Extras candidate spec file 
- 
    Mon Jan 15 2007 Rich Megginson <rmeggins@redhat.com> - 1.1-0.1.cvs20070115
    - Bump component versions (nspr, nss, svrcore, mozldap) to their latest
- remove unneeded patches 
- 
    Tue Jan 09 2007 Dennis Gilmore <dennis@ausil.us> - 1.1-0.1.cvs20070108
    - update to a cvs snapshot
- fedorafy the spec 
- create -devel subpackage
- apply a patch to use mozldap not mozldap6
- apply a patch to allow --prefix to work correctly 
- 
    Mon Dec 04 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-16
    - Fixed the problem where the server would crash upon shutdown in dblayer
- due to a race condition among the database housekeeping threads
- Fix a problem with normalized absolute paths for db directories 
- 
    Tue Nov 28 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-15
    - Touch all of the ldap/admin/src/scripts/*.in files so that they
- will be newer than their corresponding script template files, so
- that make will rebuild them. 
- 
    Mon Nov 27 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-14
    - Chown new schema files when copying during instance creation 
- 
    Tue Nov 21 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-13
    - Configure will get ldapsdk_bindir from pkg-config, or $libdir/mozldap6 
- 
    Tue Nov 21 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-12
    - use eval to sed ./configure into ../configure 
- 
    Tue Nov 21 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-11
    - jump through hoops to be able to run ../configure 
- 
    Tue Nov 21 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-10
    - Need to make built dir in setup section 
- 
    Tue Nov 21 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-9
    - The template scripts needed to use @libdir@ instead of hardcoding
- /usr/lib
- Use make DESTDIR=$RPM_BUILD_ROOT install instead of % makeinstall
- do the actual build in a "built" subdirectory, until we remove
- the old script templates 
- 
    Thu Nov 16 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-8
    - Make replication plugin link with libdb 
- 
    Wed Nov 15 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-7
    - Have make define LIBDIR, BINDIR, etc. for C code to use
- especially for create_instance.h 
- 
    Tue Nov 14 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-6
    - Forgot to checkin new config.h.in for AC_CONFIG_HEADERS 
- 
    Tue Nov 14 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-5
    - Add perldap as a Requires; update sources 
- 
    Thu Nov 09 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-4
    - Fix ds_newinst.pl
- Remove obsolete #defines 
- 
    Thu Nov 09 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-3
    - Update sources; rebuild to populate brew yum repo with dirsec-nss 
- 
    Tue Nov 07 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-2
    - Update sources 
- 
    Thu Nov 02 2006 Rich Megginson <rmeggins@redhat.com> - 1.0.99-1
    - initial revision