-
Wed Mar 29 2023 EL Errata <el-errata_ww@oracle.com> - 2.8.2-2.0.1
- Restore default debug level for sss_cache [Orabug: 32810448]
-
Mon Jan 16 2023 Alexey Tikhonov <atikhono@redhat.com> - 2.8.2-2
- Resolves: rhbz#2160001 - Reference to 'sssd-ldap-attributes' man page is missing in 'sssd-ldap', etc man pages
- Resolves: rhbz#2143159 - automount killed by SIGSEGV
-
Fri Dec 16 2022 Alexey Tikhonov <atikhono@redhat.com> - 2.8.2-1
- Resolves: rhbz#2127510 - Rebase SSSD for RHEL 9.2
- Resolves: rhbz#1608496 - sssd failing to register dynamic DNS addresses against an AD server due to unnecessary DNS search
- Resolves: rhbz#2110091 - SSSD doesn't handle changes in 'resolv.conf' properly (when started right before network service)
- Resolves: rhbz#2136791 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level.
- Resolves: rhbz#2139684 - [sssd] RHEL 9.2 Tier 0 Localization
- Resolves: rhbz#2139837 - Analyzer: Optimize and remove duplicate messages in verbose list
- Resolves: rhbz#2142794 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged
- Resolves: rhbz#2144893 - changing password with ldap_password_policy = shadow does not take effect immediately
- Resolves: rhbz#2148737 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around
-
Fri Nov 04 2022 Alexey Tikhonov <atikhono@redhat.com> - 2.8.1-1
- Resolves: rhbz#2127510 - Rebase SSSD for RHEL 9.2
- Resolves: rhbz#1507035 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file
- Resolves: rhbz#1766490 - Use negative cache better and domain checks for lookup by SIDs
- Resolves: rhbz#1964121 - RFE: Add an option to sssd config to convert home directories to lowercase (or add a new template for the 'override_homedir' option)
- Resolves: rhbz#2074307 - reduce debug level in case well_known_sid_to_name() fails
- Resolves: rhbz#2096031 - SSSD: sdap_handle_id_collision_for_incomplete_groups debug message missing a new line
- Resolves: rhbz#2103325 - Supported AD group types should be explained in the docs
- Resolves: rhbz#2111388 - authenticating against external IdP services okta (native app) with OAuth client secret failed
- Resolves: rhbz#2115171 - SSSD: duplicate dns_resolver_* option in man sssd.conf
- Resolves: rhbz#2127492 - sssd timezone issues sudonotafter
- Resolves: rhbz#2128840 - [RFE] provide dbus method to find users by attr
- Resolves: rhbz#2128883 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict)
- Resolves: rhbz#2136791 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level.
- Resolves: rhbz#2139837 - Analyzer: Optimize and remove duplicate messages in verbose list
-
Fri Aug 26 2022 Alexey Tikhonov <atikhono@redhat.com> - 2.7.3-4
- Related: rhbz#1978119 - [Improvement] avoid interlocking among threads that use `libsss_nss_idmap` API (or other sss_client libs)
-
Tue Aug 23 2022 Alexey Tikhonov <atikhono@redhat.com> - 2.7.3-3
- Resolves: rhbz#2116389 - rpc.gssd crash when access a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-2.el9
- Resolves: rhbz#2119373 - sssctl analyze --logdir option requires sssd to be configured
- Resolves: rhbz#2120657 - Incorrect request ID tracking from responder to backend
-
Mon Aug 08 2022 Alexey Tikhonov <atikhono@redhat.com> - 2.7.3-2
- Resolves: rhbz#2106660 - [regression] sssd goes offline with forced ldaps configuration
- Resolves: rhbz#2109451 - virsh command will hang after the host run several auto test cases
- Resolves: rhbz#2098654 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL
- Resolves: rhbz#2106685 - [regression] sssctl analyze fails to parse PAM related sssd logs
-
Tue Jul 05 2022 Alexey Tikhonov <atikhono@redhat.com> - 2.7.3-1
- Resolves: rhbz#2069376 - Rebase SSSD for RHEL 9.1
- Resolves: rhbz#1936551 - [Improvement] Provide user feedback when login fails due to blocked PIN
- Resolves: rhbz#1978119 - [Improvement] avoid interlocking among threads that use `libsss_nss_idmap` API (or other sss_client libs)
- Resolves: rhbz#2062665 - [sssd] RHEL 9.1 Tier 0 Localization
-
Mon Jun 13 2022 Alexey Tikhonov <atikhono@redhat.com> - 2.7.1-2
- Resolves: rhbz#2073095 - Harden kerberos ticket validation (additional patch)
- Resolves: rhbz#2061795 - Unable to lookup AD user if the AD group contains '@' symbol (additional patch)
-
Sat Jun 04 2022 Alexey Tikhonov <atikhono@redhat.com> - 2.7.1-1
- Resolves: rhbz#2069376 - Rebase SSSD for RHEL 9.1
- Resolves: rhbz#1893192 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets
- Resolves: rhbz#1927553 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file
- Resolves: rhbz#2089216 - pam_sss_gss ceased to work after upgrade to 8.6
- Resolves: rhbz#2090776 - Add idp authentication indicator in man page of sssd.conf
- Resolves: rhbz#1927195 - sssd runs out of proxy child slots and doesn't clear the counter for Active requests
- Resolves: rhbz#2073095 - Harden kerberos ticket validation
- Resolves: rhbz#2082455 - 'getent hosts' not return hosts if they have more than one CN in LDAP
- Resolves: rhbz#2087581 - Regression "Missing internal domain data." when setting ad_domain to incorrect