- 
    Thu Nov 05 2020 David Sloboda <david.x.sloboda@oracle.com> - 4.8.7-12.0.1
    
- Set IPAPLATFORM=rhel when build on Oracle Linux [Orabug: 29516674]
   
  
  - 
    Wed Sep 23 2020 Thomas Woerner <twoerner@redhat.com> - 4.8.7-12
    
- Require selinux sub package in the proper version
  Related: RHBZ#1868432
- SELinux: do not double-define node_t and pki_tomcat_cert_t
  Related: RHBZ#1868432
- SELinux: add dedicated policy for ipa-pki-retrieve-key + ipatests
  Related: RHBZ#1868432
- dogtaginstance.py: add --debug to pkispawn
  Resolves: RHBZ#1879604
   
  
  - 
    Thu Sep 10 2020 Thomas Woerner <twoerner@redhat.com> - 4.8.7-11
    
- SELinux Policy: let custodia replicate keys
  Resolves: RHBZ#1868432
   
  
  - 
    Wed Aug 19 2020 Thomas Woerner <twoerner@redhat.com> - 4.8.7-10
    
- Set mode of /etc/ipa/ca.crt to 0644 in CA-less installations
  Resolves: RHBZ#1870202
   
  
  - 
    Mon Aug 17 2020 Thomas Woerner <twoerner@redhat.com> - 4.8.7-9
    
- CAless installation: set the perms on KDC cert file
  Resolves: RHBZ#1863616
- EPN: handle empty attributes
  Resolves: RHBZ#1866938
- IPA-EPN: enhance input validation
  Resolves: RHBZ#1866291
- EPN: enhance input validation
  Resolves: RHBZ#1863079
- Require new samba build 4.12.3-52
  Related: RHBZ#1868558
- Require new selinux-policy build 3.14.3-52
  Related: RHBZ#1869311
   
  
  - 
    Fri Jul 31 2020 Thomas Woerner <twoerner@redhat.com> - 4.8.7-8
    
- [WebUI] IPA Error 3007: RequirmentError" while adding members in
  "User ID overrides" tab (updated)
  Resolves: RHBZ#1757045
- ipa-client-install: use the authselect backup during uninstall
  Resolves: RHBZ#1810179
- Replace SSLCertVerificationError with CertificateError for py36
  Resolves: RHBZ#1858318
- Fix AVC denial during ipa-adtrust-install --add-agents
  Resolves: RHBZ#1859213
   
  
  - 
    Wed Jul 15 2020 Thomas Woerner <twoerner@redhat.com> - 4.8.7-7
    
- replica install failing with avc denial for custodia component
  Resolves: RHBZ#1857157
   
  
  - 
    Tue Jul 14 2020 Thomas Woerner <twoerner@redhat.com> - 4.8.7-6
    
- selinux don't audit rules deny fetching trust topology
  Resolves: RHBZ#1845596
- fix iPAddress cert issuance for >1 host/service
  Resolves: RHBZ#1846352
- Specify cert_paths when calling PKIConnection
  Resolves: RHBZ#1849155
- Update crypto policy to allow AD-SUPPORT when installing IPA
  Resolves: RHBZ#1851139
- Add version to ipa-idoverride-memberof obsoletes
  Related: RHBZ#1846434
   
  
  - 
    Thu Jul 02 2020 Thomas Woerner <twoerner@redhat.com> - 4.8.7-5
    
- Add missing ipa-selinux package
  Resolves: RHBZ#1853263
   
  
  - 
    Mon Jun 29 2020 Thomas Woerner <twoerner@redhat.com> - 4.8.7-4
    
- Remove client-epn left over files for ONLY_CLIENT
  Related: RHBZ#1847999