-
Wed Jan 10 2024 EL Errata <el-errata_ww@oracle.com> - 4.6.8-5.0.1
- Blank out header-logo.png product-name.png
- Replace login-screen-logo.png [Orabug: 20362818]
-
Tue Nov 21 2023 Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.16
- Resolves: RHEL-12570 ipa: Invalid CSRF protection
-
Thu Aug 03 2023 Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.15
- Resolves: 2209636 libipa_otp_lasttoken plugin memory leak
-
Thu Mar 23 2023 Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.14
- Resolves: 2180919 [rhel-7] Sequence processing failures for group_add using server context
- ipaserver: deepcopy objectclasses list from IPA config
-
Mon Mar 20 2023 Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.13
- Resolves: 2148249 - ipa-client-install does not maintain server affinity during installation
- Defer creating the final krb5.conf on clients
- Move client certificate request after krb5.conf is created
- server install: remove error log about missing bkup file
-
Wed Oct 05 2022 Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.12
- Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
- idviews: use cached ipaOriginalUid value when resolving ID override
- Resolves: 2124369 - OTP token sync always returns OK even with random numbers
- ipa otptoken-sync: return error when sync fails
- ipatests: add negative test for otptoken-sync
- ipatests: python2 does not support f-strings
- Fix otptoken_sync plugin
-
Tue May 10 2022 Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.11
- Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
- WebUI: Add confirmation dialog for changing default user/host group
-
Thu Dec 02 2021 Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.10
- Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server
- Fix cert_request for KDC cert
- Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
- SMB: switch IPA domain controller role
-
Wed Sep 08 2021 Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.9
- Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
- extdom: return LDAP_NO_SUCH_OBJECT if domains differ
-
Tue Jun 22 2021 Florence Blanc-Renaud <frenaud@redhat.com> - 4.6.8-5.el7_9.7
- Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
- CA less installation: non ASCII chars in CA subject
- ipatests: use non-ascii chars in CA-less install
- Resolves: #1974328 - Revise PKINIT upgrade code
- Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server