معرفی شرکت ها


ipa-server-4.6.8-5.el7.centos.12.x86_64.rpm


Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر
Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر
Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر
Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر
Card image cap
تبلیغات ما

مشتریان به طور فزاینده ای آنلاین هستند. تبلیغات می تواند به آنها کمک کند تا کسب و کار شما را پیدا کنند.

مشاهده بیشتر

توضیحات

The IPA authentication server
ویژگی مقدار
سیستم عامل Linux
توزیع CentOS 7
مخزن Centos updates x86_64
نام بسته ipa-server
نام فایل بسته ipa-server-4.6.8-5.el7.centos.12.x86_64.rpm
نسخه بسته 4.6.8
انتشار بسته 5.el7.centos.12
معماری بسته x86_64
نگهدارنده -
تاریخ ساخت Wed 09 Nov 2022 06
هاست سازنده x86-02.bsys.centos.org
نوع بسته .rpm
آدرس صفحه اصلی http://www.freeipa.org/
مجوز GPLv3+
حجم دانلود 535K
حجم نصب 1.031M
IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). If you are installing an IPA server, you need to install this package.


جایگزین ها

بسته نسخه معماری مخزن
ipa-server-4.6.8-5.el7.centos.x86_64.rpm 4.6.8 x86_64 CentOS os
ipa-server-common-4.6.8-5.el7.centos.noarch.rpm 4.6.8 noarch CentOS os
ipa-server-dns-4.6.8-5.el7.centos.noarch.rpm 4.6.8 noarch CentOS os
ipa-server-trust-ad-4.6.8-5.el7.centos.x86_64.rpm 4.6.8 x86_64 CentOS os
ipa-server-dns-4.6.8-5.el7.centos.10.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-trust-ad-4.6.8-5.el7.centos.5.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-4.6.8-5.el7.centos.7.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-4.6.8-5.el7.centos.11.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-trust-ad-4.6.8-5.el7.centos.14.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-common-4.6.8-5.el7.centos.14.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-dns-4.6.8-5.el7.centos.15.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-4.6.8-5.el7.centos.6.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-dns-4.6.8-5.el7.centos.4.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-common-4.6.8-5.el7.centos.9.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-trust-ad-4.6.8-5.el7.centos.4.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-common-4.6.8-5.el7.centos.4.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-4.6.8-5.el7.centos.4.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-4.6.8-5.el7.centos.15.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-trust-ad-4.6.8-5.el7.centos.10.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-common-4.6.8-5.el7.centos.7.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-common-4.6.8-5.el7.centos.11.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-trust-ad-4.6.8-5.el7.centos.6.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-dns-4.6.8-5.el7.centos.6.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-trust-ad-4.6.8-5.el7.centos.7.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-common-4.6.8-5.el7.centos.5.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-dns-4.6.8-5.el7.centos.12.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-common-4.6.8-5.el7.centos.10.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-trust-ad-4.6.8-5.el7.centos.15.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-common-4.6.8-5.el7.centos.15.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-trust-ad-4.6.8-5.el7.centos.12.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-common-4.6.8-5.el7.centos.6.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-dns-4.6.8-5.el7.centos.9.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-dns-4.6.8-5.el7.centos.14.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-4.6.8-5.el7.centos.14.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-4.6.8-5.el7.centos.9.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-trust-ad-4.6.8-5.el7.centos.11.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-common-4.6.8-5.el7.centos.12.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-dns-4.6.8-5.el7.centos.5.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-trust-ad-4.6.8-5.el7.centos.9.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-4.6.8-5.el7.centos.5.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-4.6.8-5.el7.centos.10.x86_64.rpm 4.6.8 x86_64 CentOS updates
ipa-server-dns-4.6.8-5.el7.centos.7.noarch.rpm 4.6.8 noarch CentOS updates
ipa-server-dns-4.6.8-5.el7.centos.11.noarch.rpm 4.6.8 noarch CentOS updates


نیازمندی

مقدار نام
- /bin/sh
- /bin/sh
- /bin/sh
- /bin/sh
- /bin/sh
- /etc/systemd/system
- /usr/bin/python2
>= 1.3.10.2-12 389-ds-base
>= 1.3.10.2-12 389-ds-base
- acl
>= 0.78.4-10 certmonger
= 4.6.8-5.el7.centos.12 config(ipa-server)
- cyrus-sasl-gssapi(x86-64)
- fontawesome-fonts
>= 0.7.0-2 gssproxy
- gzip
>= 2.4.6-31 httpd
= 4.6.8-5.el7.centos.12 ipa-client
= 4.6.8-5.el7.centos.12 ipa-common
= 4.6.8-5.el7.centos.12 ipa-server-common
>= 1.15.1-36 krb5-pkinit-openssl
>= 1.15 krb5-server
>= 1.15.1-36 krb5-server
- krb5-server < 1.15.100
- libc.so.6()(64bit)
- libc.so.6(GLIBC_2.14)(64bit)
- libc.so.6(GLIBC_2.2.5)(64bit)
- libc.so.6(GLIBC_2.3)(64bit)
- libc.so.6(GLIBC_2.3.4)(64bit)
- libc.so.6(GLIBC_2.4)(64bit)
- libc.so.6(GLIBC_2.8)(64bit)
- libcom_err.so.2()(64bit)
- libcrypto.so.10()(64bit)
- libcrypto.so.10(libcrypto.so.10)(64bit)
- libdl.so.2()(64bit)
- libgcc_s.so.1()(64bit)
- libgcc_s.so.1(GCC_3.0)(64bit)
- libgcc_s.so.1(GCC_3.3.1)(64bit)
- libk5crypto.so.3()(64bit)
- libk5crypto.so.3(k5crypto_3_MIT)(64bit)
- libkrad.so.0()(64bit)
- libkrad.so.0(krad_0_MIT)(64bit)
- libkrb5.so.3()(64bit)
- libkrb5.so.3(krb5_3_MIT)(64bit)
- liblber-2.4.so.2()(64bit)
- libldap_r-2.4.so.2()(64bit)
- libndr-krb5pac.so.0()(64bit)
- libndr-krb5pac.so.0(NDR_KRB5PAC_0.0.1)(64bit)
- libndr-nbt.so.0()(64bit)
- libndr-nbt.so.0(NDR_NBT_0.0.1)(64bit)
- libndr-standard.so.0()(64bit)
- libndr.so.0()(64bit)
- libndr.so.0(NDR_0.0.1)(64bit)
- libnspr4.so()(64bit)
- libnss3.so()(64bit)
- libnss3.so(NSS_3.10.2)(64bit)
- libnss3.so(NSS_3.15)(64bit)
- libnss3.so(NSS_3.2)(64bit)
- libnss3.so(NSS_3.3)(64bit)
- libnss3.so(NSS_3.4)(64bit)
- libnssutil3.so()(64bit)
- libplc4.so()(64bit)
- libplds4.so()(64bit)
- libpthread.so.0()(64bit)
- libpthread.so.0(GLIBC_2.2.5)(64bit)
- libsamba-util.so.0()(64bit)
- libsamba-util.so.0(SAMBA_UTIL_0.0.1)(64bit)
- libsmime3.so()(64bit)
- libssl3.so()(64bit)
- libsss_certmap.so.0()(64bit)
- libsss_certmap.so.0(SSS_CERTMAP_0.0)(64bit)
- libsss_nss_idmap.so.0()(64bit)
- libsss_nss_idmap.so.0(SSS_NSS_IDMAP_0.1.0)(64bit)
- libsss_nss_idmap.so.0(SSS_NSS_IDMAP_0.4.0)(64bit)
- libtalloc.so.2()(64bit)
- libtalloc.so.2(TALLOC_2.0.2)(64bit)
- libtevent.so.0()(64bit)
- libunistring.so.0()(64bit)
- libuuid.so.1()(64bit)
- libuuid.so.1(UUID_1.0)(64bit)
- libverto.so.1()(64bit)
>= 1.5.0 mod_auth_gssapi
>= 0.9.9 mod_lookup_identity
>= 1.0.14-7 mod_nss
- mod_session
- mod_wsgi
>= 3.44.0-7 nss
>= 3.44.0-7 nss-tools
- ntp
- oddjob
- open-sans-fonts
- openldap-clients > 2.4.35-4
>= 1:1.0.1e-42 openssl
- p11-kit
>= 10.5.18-13 pki-ca
>= 10.5.18-13 pki-kra
>= 2.1.14-37 policycoreutils
- python
- python
>= 1.2.0-3 python-gssapi
>= 2.4.15 python-ldap
= 4.6.8-5.el7.centos.12 python2-ipaserver
- rtld(GNU_HASH)
>= 3.13.1-224 selinux-policy
>= 3.13.1-224 selinux-policy-base
- shadow-utils
>= 0.56.0-4 slapi-nis
>= 2.0.0rc1-1 softhsm
>= 1.15.2 sssd-dbus
- systemd-python
- systemd-units
- systemd-units
- systemd-units
- systemd-units
>= 38 systemd-units
- tar


ارائه دهنده

مقدار نام
= 4.6.8-5.el7.centos.12 config(ipa-server)
= 4.6.8 freeipa-server
= 4.6.8-5.el7.centos.12 ipa-server
= 4.6.8-5.el7.centos.12 ipa-server(x86-64)
- libipa_cldap.so()(64bit)
- libipa_dns.so()(64bit)
- libipa_enrollment_extop.so()(64bit)
- libipa_extdom_extop.so()(64bit)
- libipa_lockout.so()(64bit)
- libipa_modrdn.so()(64bit)
- libipa_otp_counter.so()(64bit)
- libipa_otp_lasttoken.so()(64bit)
- libipa_pwd_extop.so()(64bit)
- libipa_range_check.so()(64bit)
- libipa_repl_version.so()(64bit)
- libipa_sidgen.so()(64bit)
- libipa_sidgen_task.so()(64bit)
- libipa_uuid.so()(64bit)
- libipa_winsync.so()(64bit)
- libtopology.so()(64bit)


نحوه نصب


نصب پکیج rpm ipa-server:

    sudo yum localinstall ipa-server-4.6.8-5.el7.centos.12.x86_64.rpm


فایل ها

مسیرها
/etc/dbus-1/system.d/org.freeipa.server.conf
/etc/oddjobd.conf.d/ipa-server.conf
/usr/lib/systemd/system/ipa-dnskeysyncd.service
/usr/lib/systemd/system/ipa-ods-exporter.service
/usr/lib/systemd/system/ipa-ods-exporter.socket
/usr/lib/systemd/system/ipa-otpd.socket
/usr/lib/systemd/system/ipa-otpd@.service
/usr/lib/systemd/system/ipa.service
/usr/lib64/dirsrv/plugins/libipa_cldap.so
/usr/lib64/dirsrv/plugins/libipa_dns.so
/usr/lib64/dirsrv/plugins/libipa_enrollment_extop.so
/usr/lib64/dirsrv/plugins/libipa_extdom_extop.so
/usr/lib64/dirsrv/plugins/libipa_lockout.so
/usr/lib64/dirsrv/plugins/libipa_modrdn.so
/usr/lib64/dirsrv/plugins/libipa_otp_counter.so
/usr/lib64/dirsrv/plugins/libipa_otp_lasttoken.so
/usr/lib64/dirsrv/plugins/libipa_pwd_extop.so
/usr/lib64/dirsrv/plugins/libipa_range_check.so
/usr/lib64/dirsrv/plugins/libipa_repl_version.so
/usr/lib64/dirsrv/plugins/libipa_sidgen.so
/usr/lib64/dirsrv/plugins/libipa_sidgen_task.so
/usr/lib64/dirsrv/plugins/libipa_uuid.so
/usr/lib64/dirsrv/plugins/libipa_winsync.so
/usr/lib64/dirsrv/plugins/libtopology.so
/usr/lib64/krb5/plugins/kdb/ipadb.so
/usr/libexec/certmonger/dogtag-ipa-ca-renew-agent-submit
/usr/libexec/certmonger/ipa-server-guard
/usr/libexec/ipa
/usr/libexec/ipa/certmonger
/usr/libexec/ipa/certmonger/renew_ca_cert
/usr/libexec/ipa/certmonger/renew_kdc_cert
/usr/libexec/ipa/certmonger/renew_ra_cert
/usr/libexec/ipa/certmonger/renew_ra_cert_pre
/usr/libexec/ipa/certmonger/restart_dirsrv
/usr/libexec/ipa/certmonger/restart_httpd
/usr/libexec/ipa/certmonger/stop_pkicad
/usr/libexec/ipa/ipa-custodia
/usr/libexec/ipa/ipa-custodia-check
/usr/libexec/ipa/ipa-dnskeysync-replica
/usr/libexec/ipa/ipa-dnskeysyncd
/usr/libexec/ipa/ipa-httpd-kdcproxy
/usr/libexec/ipa/ipa-ods-exporter
/usr/libexec/ipa/ipa-otpd
/usr/libexec/ipa/ipa-pki-retrieve-key
/usr/libexec/ipa/oddjob
/usr/libexec/ipa/oddjob/org.freeipa.server.conncheck
/usr/libexec/ipa/oddjob/org.freeipa.server.trust-enable-agent
/usr/sbin/ipa-advise
/usr/sbin/ipa-backup
/usr/sbin/ipa-ca-install
/usr/sbin/ipa-cacert-manage
/usr/sbin/ipa-cert-fix
/usr/sbin/ipa-compat-manage
/usr/sbin/ipa-crlgen-manage
/usr/sbin/ipa-csreplica-manage
/usr/sbin/ipa-kra-install
/usr/sbin/ipa-ldap-updater
/usr/sbin/ipa-managed-entries
/usr/sbin/ipa-nis-manage
/usr/sbin/ipa-otptoken-import
/usr/sbin/ipa-pkinit-manage
/usr/sbin/ipa-replica-conncheck
/usr/sbin/ipa-replica-install
/usr/sbin/ipa-replica-manage
/usr/sbin/ipa-replica-prepare
/usr/sbin/ipa-restore
/usr/sbin/ipa-server-certinstall
/usr/sbin/ipa-server-install
/usr/sbin/ipa-server-upgrade
/usr/sbin/ipa-winsync-migrate
/usr/sbin/ipactl
/usr/share/doc/ipa-server-4.6.8
/usr/share/doc/ipa-server-4.6.8/Contributors.txt
/usr/share/doc/ipa-server-4.6.8/README.md
/usr/share/licenses/ipa-server-4.6.8
/usr/share/licenses/ipa-server-4.6.8/COPYING
/usr/share/man/man1/ipa-advise.1.gz
/usr/share/man/man1/ipa-backup.1.gz
/usr/share/man/man1/ipa-ca-install.1.gz
/usr/share/man/man1/ipa-cacert-manage.1.gz
/usr/share/man/man1/ipa-cert-fix.1.gz
/usr/share/man/man1/ipa-compat-manage.1.gz
/usr/share/man/man1/ipa-crlgen-manage.1.gz
/usr/share/man/man1/ipa-csreplica-manage.1.gz
/usr/share/man/man1/ipa-kra-install.1.gz
/usr/share/man/man1/ipa-ldap-updater.1.gz
/usr/share/man/man1/ipa-managed-entries.1.gz
/usr/share/man/man1/ipa-nis-manage.1.gz
/usr/share/man/man1/ipa-otptoken-import.1.gz
/usr/share/man/man1/ipa-pkinit-manage.1.gz
/usr/share/man/man1/ipa-replica-conncheck.1.gz
/usr/share/man/man1/ipa-replica-install.1.gz
/usr/share/man/man1/ipa-replica-manage.1.gz
/usr/share/man/man1/ipa-replica-prepare.1.gz
/usr/share/man/man1/ipa-restore.1.gz
/usr/share/man/man1/ipa-server-certinstall.1.gz
/usr/share/man/man1/ipa-server-install.1.gz
/usr/share/man/man1/ipa-server-upgrade.1.gz
/usr/share/man/man1/ipa-winsync-migrate.1.gz
/usr/share/man/man8/ipactl.8.gz


گزارش تغییرات

تاریخ آخرین تغییر جزئیات
2022-11-02

Roll in CentOS Branding

2022-10-05

Resolves: 2084223 - 'ipa idview-show idviewname' & IPA WebUI takes longer time to return the results
idviews: use cached ipaOriginalUid value when resolving ID override
Resolves: 2124369 - OTP token sync always returns OK even with random numbers
ipa otptoken-sync: return error when sync fails
ipatests: add negative test for otptoken-sync
ipatests: python2 does not support f-strings
Fix otptoken_sync plugin

2022-05-10

Resolves: 2082272 - [RFE] Require confirmation to change "Default host group" in IdM automember rules
WebUI: Add confirmation dialog for changing default user/host group

2021-12-02

Resolves: 2025848 - RHEL 8.6 IPA Replica Failed to configure PKINIT setup against a RHEL 7.9 IPA server
Fix cert_request for KDC cert
Resolves: 2021444 - CVE-2020-25719 ipa: samba: Samba AD DC did not always rely on the SID and PAC in Kerberos tickets
SMB: switch IPA domain controller role

2021-09-08

Resolves: #2000261 - extdom: LDAP_INVALID_SYNTAX returned instead of LDAP_NO_SUCH_OBJECT
extdom: return LDAP_NO_SUCH_OBJECT if domains differ

2021-06-22

Resolves: #1956550 - IPA server installation fails when cert contains non-ASCII character
CA less installation: non ASCII chars in CA subject
ipatests: use non-ascii chars in CA-less install
Resolves: #1974328 - Revise PKINIT upgrade code
Allow PKINIT to be enabled when updating from a pre-PKINIT IPA CA server

2021-05-11

Resolves: #1959349 - Need to bump pki + ds version

2021-04-06

Resolves: #1931405 krb5kdc crash - Segmentation fault in ldap_first_entry().
ipa-kdb: fix compiler warnings
ipa-kdb: add missing prototypes
ipa-kdb: reformat ipa_kdb_certauth
ipa-kdb: mark test functions as static
ipa-kdb: do not use OpenLDAP functions with NULL LDAP context
Resolves: #1835741 krb5kdc crashing on ipa server
Resolves: #1929372 krb5kdc is crashing intermittently on IPA server.

2021-01-29

Resolves: #1897253 IPA WebUI inaccessible after upgrading to RHEL 8.3.- idoverride-memberof.js missing
wgi/plugins.py: ignore empty plugin directories
Resolves: #1895197 improve IPA PKI susbsystem detection by other means than a directory presence, use pki-server subsystem-find
Improve PKI subsystem detection
ipatests: add test for PKI subsystem detection
ipatest: fix test_upgrade.py::TestUpgrade::()::test_kra_detection
Resolves: #1892793 Authentication and login times are over several seconds due to unindexed ipaExternalMember
Add more indices
Resolves: #1884819 IdM Web UI shows users as disabled
fix cert-find errors in CA-less deployment
Resolves: #1863619 CA-less install does not set required permissions on KDC certificate
CAless installation: set the perms on KDC cert file
ipatests: check KDC cert permissions in CA less install
Resolves: #1859248 CVE-2020-11023 ipa: jquery: Passing HTML containing <option> elements to manipulation methods could result in untrusted code execution
WebUI: Fix jQuery DOM manipulation issues
Resolves: #1846349 cannot issue certs with multiple IP addresses corresponding to different hosts
fix iPAddress cert issuance for >1 host/service

2020-06-18

Resolves: #1826659 IPA: Ldap authentication failure due to Kerberos principal expiration UTC timestamp
ipa-pwd-extop: use timegm() instead of mktime() to preserve timezone offset

2020-06-05

Resolves: #1842950 ipa-adtrust-install fails when replica is offline
ipa-adtrust-install: avoid failure when replica is offline
Resolves: #1831856 CVE-2020-11022 ipa: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method
WebUI: Apply jQuery patch to fix htmlPrefilter issue

2020-05-12

Resolves: #1834385 Man page syntax issue detected by rpminspect
Man pages: fix syntax issues
Resolves: #1829787 ipa service-del deletes the required principal when specified in lower/upper case
Make check_required_principal() case-insensitive
Resolves: #1825829 ipa-advise on a RHEL7 IdM server generate a configuration script for client having hardcoded python3
ipa-advise: fallback to /usr/libexec/platform-python if python3 not found
Resolves: #1812020 CVE-2015-9251 ipa: js-jquery: Cross-site scripting via cross-domain ajax requests
Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1
Resolves: #1713487 CVE-2019-11358 ipa: js-jquery: prototype pollution in object's prototype leading to denial of service or remote code execution or property injection
Web UI: Upgrade jQuery version 2.0.3 -> 3.4.1

2020-04-15

Resolves: #1802408 CVE-2020-1722 ipa: No password length restriction leads to denial of service
Add interactive prompt for the LDAP bind password to ipa-getkeytab
CVE-2020-1722: prevent use of too long passwords

2020-04-02

Resolves: #1819725 - Rebase IPA to latest 4.6.x version
Resolves: #1817927 - host-add --password logs cleartext userpassword to Apache error log
Resolves: #1817923 - IPA upgrade is failing with error "Failed to get request: bus, object_path and dbus_interface must not be None."
Resolves: #1817922 - covscan memory leaks report
Resolves: #1817919 - Enable compat tree to provide information about AD users and groups on trust agents
Resolves: #1817918 - Secure tomcat AJP connector
Resolves: #1817886 - ipa group-add-member: prevent adding IPA objects as external members
Resolves: #1788718 - ipa-server-install incorrectly setting slew mode (-x) when setting up ntpd

2020-03-24

Resolves: #1754902 - Running ipa-server-install fails when RHEL 7.7 packages are installed on RHEL 7.6
Resolves: #1404770 - ID Views: do not allow custom Views for the masters
idviews: prevent applying to a master
Resolves: #1801791 - Compatibility Schema difference in functionality for systems following RHEL 7.5 -> 7.6 upgrade path as opposed to new RHEL 7.6 systems
install/updates: move external members past schema compat update
Resolves: #1795890 - ipa-pkinit-manage enable fails on replica if it doesn't host the CA
pkinit setup: fix regression on master install
pkinit enable: use local dogtag only if host has CA
Resolves: #1788907 - Renewed certs are not picked up by IPA CAs
Allow an empty cookie in dogtag-ipa-ca-renew-agent-submit
Resolves: #1780548 - Man page ipa-cacert-manage does not display correctly on RHEL
ipa-cacert-manage man page: fix indentation
Resolves: #1782587 - add "systemctl restart sssd" to warning message when adding trust agents to replicas
adtrust.py: mention restarting sssd when adding trust agents
Resolves: #1771356 - Default client configuration breaks ssh in FIPS mode
Use default ssh host key algorithms
Resolves: #1755535 - ipa-advise on a RHEL7 IdM server is not able to generate a configuration script for a RHEL8 IdM client
smartcard: make the ipa-advise script compatible with authselect/authconfig
Resolves: #1758406 - KRA authentication fails when IPA CA has custom Subject DN
upgrade: fix ipakra people entry 'description' attribute
krainstance: set correct issuer DN in uid=ipakra entry
Resolves: #1756568 - ipa-server-certinstall man page does not match built-in help
ipa-server-certinstall manpage: add missing options
Resolves: #1206690 - UPG not being enforced properly
ipa user_add: do not check group if UPG is disabled
Resolves: #1811982 - CVE-2018-14042 ipa: bootstrap: Cross-site Scripting (XSS) in the data-container property of tooltip.
Resolves: #1811978 - CVE-2018-14040 ipa: bootstrap: Cross-site Scripting (XSS) in the collapse data-parent attribute
Resolves: #1811972 - CVE-2016-10735 ipa: bootstrap: XSS in the data-target attribute
Resolves: #1811969 -CVE-2018-20676 ipa: bootstrap: XSS in the tooltip data-viewport attribute
Resolves: #1811966 - CVE-2018-20677 ipa: bootstrap: XSS in the affix configuration target property
Resolves: #1811962 - CVE-2019-8331 ipa: bootstrap: XSS in the tooltip or popover data-template attribute
Web UI: Upgrade Bootstrap version 3.3.7 -> 3.4.1
Resolves: #1769791 - Invisible part of notification area in Web UI intercepts clicks of some page elements
WebUI: Fix notification area layout
Resolves: #1545755 - ipa-replica-prepare should not update pki admin password
Fix indentation levels
ipa-pwd-extop: use SLAPI_BIND_TARGET_SDN
ipa-pwd-extop: don't check password policy for non-Kerberos account set by DM or a passsync manager
Don't save password history on non-Kerberos accounts

2019-12-04

Resolves: #1778777 - After upgrade AD Trust Agents were removed from LDAP
trust upgrade: ensure that host is member of adtrust agents