Package libipa_hbac-devel: Information

  • Default inline alert: Version in the repository: 2.9.4-alt1

Binary package: libipa_hbac-devel
Version: 2.6.3-alt1
Architecture: i586
Build time:  Mar 15, 2022, 03:51 AM in the task #293575
Source package: sssd
Category: Development/C
Report package bug
License: LGPLv3+
Summary: FreeIPA HBAC Evaluator library
Description: 
Utility library to validate FreeIPA HBAC rules for authorization requests

Maintainer: Evgeny Sinelnikov


Last changed


Jan. 27, 2022 Evgeny Sinelnikov 2.6.3-alt1
- AD Domain in the AD Forest Missing after sssd latest update
- sdap_idmap.c/sssd_idmap.c incorrectly calculates rangesize from upper/lower
- Regression on rawhide with ssh auth using password
- sssd-ad broken in 2.6.2, 389 used as kerberos port
- sssd error triggers backtrace: write_krb5info_file_from_fo_server
Jan. 12, 2022 Evgeny Sinelnikov 2.6.2-alt1
- Update to latest release:
  + Lookup with fully-qualified name does not work with cache_first is True.
  + sssd_be segfault due to empty forest root name.
  + Groups are missing while performing id lookup as SSSD switching to offline
    mode due to the wrong domain name in the ldap-pings(netlogon).
  + LDAP sp_expire policy does not match other libraries.
  + Passwordless (GSSAPI) SSH not working due to missing
    includedir  /var/lib/sss/pubconf/krb5.include.d directive in /etc/krb5.conf.
  + pam responder does not call initgroups to refresh the user entry.
  + FindByValidCertificate() treats unconfigured CA as Invalid certificate provide.
  + sssd does not use kerberos port that is set.
Dec. 13, 2021 Evgeny Sinelnikov 2.6.1-alt3
- Update with latest libldb-2.3.2-alt2 fixes.
- Backport newest fixes from upstream:
  + utils: ignore systemd and sd-pam process in get_active_uid_linux()
  + cldap: use dns_resolver_server_timeout timeout for cldap ping
  + ad: only send cldap-ping to our local domain
  + ad: make ad_srv_plugin_ctx_switch_site() public
  + ad: use already discovered forest name