- 
    Thu Jan 11 2024 David Sloboda <david.x.sloboda@oracle.com> - 4.9.12-11.0.1
    
- Resolves: 2242828 Invalid CSRF protection (CVE-2023-5455)
   
  
  - 
    Fri Oct 20 2023 EL Errata <el-errata_ww@oracle.com> - 4.9.12-9.0.1
    
- Set IPAPLATFORM=rhel when build on Oracle Linux [Orabug: 29516674]
   
  
  - 
    Wed Oct 04 2023 Julien Rische <jrische@redhat.com> - 4.9.12-9
    
- ipa-kdb: Make AD-SIGNEDPATH optional with krb5 DAL 8 and older
  Resolves: RHEL-12198
   
  
  - 
    Thu Aug 31 2023 Rafael Jeffman <rjeffman@redhat.com> - 4.9.12-8
    
- Require krb5 release 1.18.2-25 or later
  Resolves: RHBZ#2234711
   
  
  - 
    Wed Aug 16 2023 Rafael Jeffman <rjeffman@redhat.com> - 4.9.12-7
    
- ipatests: fix test_topology
  Resolves: RHBZ#2232351
- Installer: activate nss and pam services in sssd.conf
  Resolves: RHBZ#2216532
   
  
  - 
    Thu Aug 10 2023 Rafael Jeffman <rjeffman@redhat.com> - 4.9.12-6
    
- ipa-kdb: fix error handling of is_master_host()
  Resolves: RHBZ#2214638
- ipatests: enable firewall rule for http service on acme client
  Resolves: RHBZ#2230256
- User plugin: improve error related to non existing idp
  Resolves: RHBZ#2224572
- Prevent admin user from being deleted
  Resolves: RHBZ#1821181
- Fix memory leak in the OTP last token plugin
  Resolves: RHBZ#2227783
   
  
  - 
    Mon Jul 17 2023 Rafael Jeffman <rjeffman@redhat.com> - 4.9.12-5
    
- Upgrade: fix replica agreement, fix backported patch
  Related: RHBZ#2216551
   
  
  - 
    Fri Jun 30 2023 Rafael Jeffman <rjeffman@redhat.com> - 4.9.12-4
    
- kdb: Use-krb5_pac_full_sign_compat() when available
  Resolves: RHBZ#2176406
- OTP: fix-data-type-to-avoid-endianness-issue
  Resolves: RHBZ#2218293
- Upgrade: fix replica agreement
  Resolves: RHBZ#2216551
- Upgrade: add PKI drop-in file if missing
  Resolves: RHBZ#2215336
- Use the python-cryptography parser directly in cert-find
  Resolves: RHBZ#2164349
- Backport test updates
  Resolves: RHBZ#221884
   
  
  - 
    Wed Jun 21 2023 Julien Rische <jrische@redhat.com> - 4.9.12-3
    
- Rely on sssd-krb5 to include SSSD-generated krb5 configuration
  Resolves: RHBZ#2214563
   
  
  - 
    Thu May 25 2023 Rafael Jeffman <rjeffman@redhat.com> - 4.9.12-2
    
- Use the OpenSSL certificate parser in cert-find
  Resolves: RHBZ#2209947