- 
    Wed Oct 01 2025 EL Errata <el-errata_ww@oracle.com> - 4.9.13-20.0.1
    
- Set IPAPLATFORM=rhel when build on Oracle Linux [Orabug: 29516674]
   
  
  - 
    Thu Sep 11 2025 Rafael Jeffman <rjeffman@redhat.com> - 4.9.13-20
    
- Refactor ipatests for unique krbcanonicalname
  Resolves: RHEL-110061
   
  
  - 
    Thu Sep 11 2025 Rafael Jeffman <rjeffman@redhat.com> - 4.9.13-19
    
- Enforce uniqueness across krbprincipalname and krbcanonicalname
  ipa-kdb: enforce PAC presence on TGT for TGS-REQ
  ipatests: extend test for unique krbcanonicalname
  Resolves: RHEL-110061
   
  
  - 
    Tue Jun 03 2025 Rafael Jeffman <rjeffman@redhat.com> - 4.9.13-18
    
- Set krbCanonicalName admin@REALM on the admin user
  Resolves: RHEL-89895
   
  
  - 
    Mon May 19 2025 Rafael Jeffman <rjeffman@redhat.com> - 4.9.13-17
    
- kdb: keeep ipadb_get_connection() from succeding with null LDAP context
  Resolves: RHEL-58453
   
  
  - 
    Mon Mar 31 2025 Rafael Jeffman <rjeffman@redhat.com> - 4.9.13-16
    
- Add a- heck into ipa-cert-fix tool to avoid updating certs if CA is close to expire
  Resolves: RHEL-4941
- Fix rpminspect's 'patches' warnings
  Resolves: RHEL-22497
   
  
  - 
    Mon Mar 10 2025 Rafael Jeffman <rjeffman@redhat.com> - 4.9.13-15
    
- Replica CA installation: ignore skew during initial replication
  Resolves RHEL-80995
   
  
  - 
    Wed Nov 27 2024 Rafael Jeffman <rjeffman@redhat.com> - 4.9.13-14
    
- ipatests: Update ipa-adtrust-install test
  Resolves: RHEL-40894
   
  
  - 
    Thu Nov 14 2024 Rafael Jeffman <rjeffman@redhat.com> - 4.9.13-13
    
- Add ipa-idrange-fix
  Resolves: RHEL-56920
- Unconditionally add MS-PAC to global config on update
  Resolves: RHEL-49437
- ipatests: Update ipa-adtrust-install test
  Resolves: RHEL-40894
- Require python-qrcode version 5.3 or later
  Related: RHEL-15090
   
  
  - 
    Wed Jul 17 2024 Rafael Jeffman <rjeffman@redhat.com> - 4.9.13-12
    
- Allow the admin user to be disabled
  Resolves: RHEL-34756
- ipa-otptoken-import: open the key file in binary mode
  Resolves: RHEL-39616
- ipa-crlgen-manage: manage the cert status task execution time
  Resolves: RHEL-30280
- idrange-add: add a warning because 389ds restart is required
  Resolves: RHEL-28996
- PKINIT certificate: fix renewal on hidden replica
  Resolves: RHEL-4913, RHEL-45908