pagure Logo
  • Log In

freeipa

Clone
Source Code
GIT
  • Source
  • Issues  1066
  • Roadmap 
  • Stats
 Overview  Files  Commits  Branches  Forks  Releases

Commits 16003

Branch: ipa-4-12-CVE-2025-7493
ipa-1-0 ipa-1-1 ipa-1-2 ipa-2-0 ipa-2-1 ipa-2-2 ipa-3-0 ipa-3-1 ipa-3-2 ipa-3-3 ipa-4-0 ipa-4-1 ipa-4-10 ipa-4-10-CVE-2023-5455 ipa-4-11 ipa-4-11-CVE-2023-5455 ipa-4-11-CVE-2024-2698-and-CVE-2024-3183 ipa-4-12 ipa-4-12-CVE-2024-11029 ipa-4-12-CVE-2024-2698-and-CVE-2024-3183 ipa-4-12-CVE-2025-4404 ipa-4-12-CVE-2025-7493 ipa-4-2 ipa-4-3 ipa-4-4 ipa-4-5 ipa-4-6 ipa-4-6-CVE-2019-10195-and-CVE-2019-14867 ipa-4-6-CVE-2020-10747 ipa-4-6-CVE-2023-5455 ipa-4-7 ipa-4-7-CVE-2019-10195-and-CVE-2019-14867 ipa-4-8 ipa-4-8-CVE-2019-10195-and-CVE-2019-14867 ipa-4-8-CVE-2020-10747 ipa-4-9 ipa-4-9-CVE-2023-5455 master webui-cleanup
This branch contains 73 commits not in the main branch master
Become IPA 4.12.5
Antonio Torres • a month ago  
96ea6f9
ipatests: extend test for unique krbcanonicalname
Florence Blanc-Renaud • a month ago  
20c03a3
ipa-kdb: enforce PAC presence on TGT for TGS-REQ
Julien Rische • a month ago  
bb24703
Enforce uniqueness across krbprincipalname and krbcanonicalname
Rob Crittenden • a month ago  
67a9d53
Become IPA 4.12.4
Antonio Torres • 5 months ago  
f2fc367
Set krbCanonicalName=admin@REALM on the admin user
Rob Crittenden • 5 months ago  
e8c410a
kdb: keep ipadb_get_connection() from succeeding with null LDAP context
Julien Rische • 5 months ago  
6ae52a2
Become IPA 4.12.3
Antonio Torres • 10 months ago  
f33a0e8
ipa-otpd: use oidc_child's --client-secret-stdin option
Sumit Bose • 10 months ago  
7a5a10b
ipa tools: remove sensitive material from the commandline
Alexander Bokovoy • 10 months ago  
3b38efe
Unify use of option parsers
Alexander Bokovoy • 10 months ago  
cf84a22
Become IPA v4.12.2
Rob Crittenden • a year ago  
c7da7e0
ipatests: Test to check that the configured value for "nsslapd-ignore-time-skew" remains on even after a "force-sync" is done
Sudhir Menon • a year ago  
f5c7237
ipatests: Replace 'usermod -r' command with 'gpasswd -d' in test_hsm.py
Sudhir Menon • a year ago  
ed813fe
Fix some resource leaks identified by a static analyzer
Rob Crittenden • a year ago  
21c6ccc
Ignore TripleDES python-cryptography import warnings
Rob Crittenden • a year ago  
d0684a7
Correct usage of public_key_algorithm_oid in ipalib/x509
Rob Crittenden • a year ago  
5cc7941
trust-add: handle unavailable domain
Florence Blanc-Renaud • a year ago  
f37c2eb
HSM: fix the module name
Florence Blanc-Renaud • a year ago  
1fc63e2
ipatests: skip HSM test if pki < 11.5.9
Florence Blanc-Renaud • a year ago  
84751a2
ipatests: ipa-migrate tool with -Z option (CACERTFILE)
Sudhir Menon • a year ago  
8046023
ipatests: Verify that SIDgen task continue even if it fails to assign sid
Mohammad Rizwan • a year ago  
ee96c12
ipatests: increase the timeout for test_hsm.py::TestHSMInstall
Florence Blanc-Renaud • a year ago  
81401e6
Log errors reported by adtrustinstance.check_inst() using logger
Rob Crittenden • a year ago  
e83d949
Force a logout in KerberosSession if a login is needed
Rob Crittenden • a year ago  
ffba696
Replica CA installation: ignore time skew during initial replication
Florence Blanc-Renaud • a year ago  
aadb805
Get rid of unicode and long helpers in ipa-otptoken-import
Alexander Bokovoy • a year ago  
7b5f3d7
ipalib/constants.py: factor out TripleDES use
Alexander Bokovoy • a year ago  
fc02904
ipalib/x509.py: get rid of unicode helper
Alexander Bokovoy • a year ago  
7f9c890
ipalib/x509.py: support Cryptography 43
Alexander Bokovoy • a year ago  
531bd05
Run HSM validation as pkiuser to verify token permissions
Rob Crittenden • a year ago  
38b83c2
ipatests: Fix usage of token_password_file
Rob Crittenden • a year ago  
f03a96a
ipa-migrate - properly handle invalid certificates
Mark Reynolds • a year ago  
0e4fbc3
spec file: do not use nodejs-22 on f39 and f40
Florence Blanc-Renaud • a year ago  
2ddca5d
Fix a copy/paste issue when detecting the HSM SELinux subpackage
Rob Crittenden • a year ago  
fdd471d
Remove RC4 and 3DES default encryption types on update
Julien Rische • a year ago  
9f88188
Unconditionally add MS-PAC to global config on update
Julien Rische • a year ago  
d1a485a
ipatests: remove xfail for test_ipa_migrate_stage_mode
Florence Blanc-Renaud • a year ago  
6eb6a92
ipatests: remove xfail for test_ipa_migrate_version_option
Florence Blanc-Renaud • a year ago  
de94080
Issue 9621 - ipa-migrate - should not update mapped attributes in managed entries
Mark Reynolds • a year ago  
85a853b
ipatests: Test replica installation using AD admin.
Anuja More • a year ago  
8b70315
ipa-pwd-extop: differentiate OTP requirements in LDAP binds
Alexander Bokovoy • a year ago  
051d61f
Added new testsuite(ipa_ipa_migration) in prci definitions
Sudhir Menon • a year ago  
ab47696
ipa-migrate - starttls does not work
Mark Reynolds • a year ago  
eeade50
Include token password options in ipa-kra-install man page
Rob Crittenden • a year ago  
6c53a22
ipatests: tests related to --token-password-file
Mohammad Rizwan • a year ago  
4ea1ad6
Re-organize HSM validation to be more consistent/less duplication
Rob Crittenden • a year ago  
7ab1bcb
Fix syntax error in the selinux-luna %postun script
Rob Crittenden • a year ago  
1b278de
ipa-migrate - remove -V option
Mark Reynolds • a year ago  
efa5719
The -d option of the ipa-advise command was able to used.
Shunsuke matsumoto • a year ago  
06c02f5
ipa_sidgen: Allow sidgen_task to continue after finding issues
Thomas Woerner • a year ago  
a8e75bb
test_replica_install_after_restore: kinit after restore
Florence Blanc-Renaud • a year ago  
d635d70
Uninstall: stop sssd-kcm before removing KCM ccaches database
Florence Blanc-Renaud • a year ago  
6fe268a
ipa-ods-enforcer: stop must also stop the socket
Florence Blanc-Renaud • a year ago  
2f902ef
ipatests: Tests for ipa-ipa migration tool
Sudhir Menon • a year ago  
90b22ff
ipa-advise ipa-backup ipa-restore: Fix --v option of the manual.
TAKAHASHI Masatsuna • a year ago  
52ea4ad
ipatests: fix / permissions for test_nested_group_members
Florence Blanc-Renaud • a year ago  
48ff7da
Clean up more files and directories created by the installer(s)
Rob Crittenden • a year ago  
9e36491
ipatests: fix / permissions to allow ssh with private key
Florence Blanc-Renaud • a year ago  
60c127d
ipatests: mark test_ca_show_error_handling as xfail
Florence Blanc-Renaud • a year ago  
4521fe5
ipatests: configure gating and nightly tests on ipa-4-12 branch
Florence Blanc-Renaud • a year ago  
58154be
ipatests: add test for PKINIT renewal on hidden replica
Florence Blanc-Renaud • a year ago  
467ec04
PKINIT certificate: fix renewal on hidden replica
Florence Blanc-Renaud • a year ago  
c8e3fde
ipatests: add test for ticket 9610
Florence Blanc-Renaud • a year ago  
4d51446
spec file: do not create /etc/ssh/ssh_config.orig if unchanged
Florence Blanc-Renaud • a year ago  
09e66dc
ipa-otptoken-import: open the key file in binary mode
Florence Blanc-Renaud • a year ago  
9de053e
Add iparepltopoconf objectclass to topology permissions
Rob Crittenden • a year ago  
ebccaac
Use a unique task name for each backend in ipa-backup
Rob Crittenden • a year ago  
584d0ce
Bump minor version number
Antonio Torres • a year ago  
5b3735b
kdb: apply combinatorial logic for ticket flags
Julien Rische • a year ago  
4a61184
kdb: fix vulnerability in GCD rules handling
Julien Rische • a year ago  
f77c0a5
Back to git snapshots
Antonio Torres • a year ago  
ea37593
Become IPA 4.12.0
Antonio Torres • a year ago  
407408e
Become IPA 4.12.5
Antonio Torres • a month ago  
96ea6f9
ipatests: extend test for unique krbcanonicalname
Florence Blanc-Renaud • a month ago  
20c03a3
ipa-kdb: enforce PAC presence on TGT for TGS-REQ
Julien Rische • a month ago  
bb24703
Enforce uniqueness across krbprincipalname and krbcanonicalname
Rob Crittenden • a month ago  
67a9d53
Become IPA 4.12.4
Antonio Torres • 5 months ago  
f2fc367
Set krbCanonicalName=admin@REALM on the admin user
Rob Crittenden • 5 months ago  
e8c410a
kdb: keep ipadb_get_connection() from succeeding with null LDAP context
Julien Rische • 5 months ago  
6ae52a2
Become IPA 4.12.3
Antonio Torres • 10 months ago  
f33a0e8
ipa-otpd: use oidc_child's --client-secret-stdin option
Sumit Bose • 10 months ago  
7a5a10b
ipa tools: remove sensitive material from the commandline
Alexander Bokovoy • 10 months ago  
3b38efe
Unify use of option parsers
Alexander Bokovoy • 10 months ago  
cf84a22
Become IPA v4.12.2
Rob Crittenden • a year ago  
c7da7e0
ipatests: Test to check that the configured value for "nsslapd-ignore-time-skew" remains on even after a "force-sync" is done
Sudhir Menon • a year ago  
f5c7237
ipatests: Replace 'usermod -r' command with 'gpasswd -d' in test_hsm.py
Sudhir Menon • a year ago  
ed813fe
Fix some resource leaks identified by a static analyzer
Rob Crittenden • a year ago  
21c6ccc
Ignore TripleDES python-cryptography import warnings
Rob Crittenden • a year ago  
d0684a7
Correct usage of public_key_algorithm_oid in ipalib/x509
Rob Crittenden • a year ago  
5cc7941
trust-add: handle unavailable domain
Florence Blanc-Renaud • a year ago  
f37c2eb
HSM: fix the module name
Florence Blanc-Renaud • a year ago  
1fc63e2
ipatests: skip HSM test if pki < 11.5.9
Florence Blanc-Renaud • a year ago  
84751a2
ipatests: ipa-migrate tool with -Z option (CACERTFILE)
Sudhir Menon • a year ago  
8046023
ipatests: Verify that SIDgen task continue even if it fails to assign sid
Mohammad Rizwan • a year ago  
ee96c12
ipatests: increase the timeout for test_hsm.py::TestHSMInstall
Florence Blanc-Renaud • a year ago  
81401e6
Log errors reported by adtrustinstance.check_inst() using logger
Rob Crittenden • a year ago  
e83d949
Force a logout in KerberosSession if a login is needed
Rob Crittenden • a year ago  
ffba696
Replica CA installation: ignore time skew during initial replication
Florence Blanc-Renaud • a year ago  
aadb805
Get rid of unicode and long helpers in ipa-otptoken-import
Alexander Bokovoy • a year ago  
7b5f3d7
ipalib/constants.py: factor out TripleDES use
Alexander Bokovoy • a year ago  
fc02904
ipalib/x509.py: get rid of unicode helper
Alexander Bokovoy • a year ago  
7f9c890
ipalib/x509.py: support Cryptography 43
Alexander Bokovoy • a year ago  
531bd05
Run HSM validation as pkiuser to verify token permissions
Rob Crittenden • a year ago  
38b83c2
ipatests: Fix usage of token_password_file
Rob Crittenden • a year ago  
f03a96a
ipa-migrate - properly handle invalid certificates
Mark Reynolds • a year ago  
0e4fbc3
spec file: do not use nodejs-22 on f39 and f40
Florence Blanc-Renaud • a year ago  
2ddca5d
Fix a copy/paste issue when detecting the HSM SELinux subpackage
Rob Crittenden • a year ago  
fdd471d
Remove RC4 and 3DES default encryption types on update
Julien Rische • a year ago  
9f88188
Unconditionally add MS-PAC to global config on update
Julien Rische • a year ago  
d1a485a
ipatests: remove xfail for test_ipa_migrate_stage_mode
Florence Blanc-Renaud • a year ago  
6eb6a92
ipatests: remove xfail for test_ipa_migrate_version_option
Florence Blanc-Renaud • a year ago  
de94080
Issue 9621 - ipa-migrate - should not update mapped attributes in managed entries
Mark Reynolds • a year ago  
85a853b
ipatests: Test replica installation using AD admin.
Anuja More • a year ago  
8b70315
ipa-pwd-extop: differentiate OTP requirements in LDAP binds
Alexander Bokovoy • a year ago  
051d61f
Added new testsuite(ipa_ipa_migration) in prci definitions
Sudhir Menon • a year ago  
ab47696
ipa-migrate - starttls does not work
Mark Reynolds • a year ago  
eeade50
Include token password options in ipa-kra-install man page
Rob Crittenden • a year ago  
6c53a22
ipatests: tests related to --token-password-file
Mohammad Rizwan • a year ago  
4ea1ad6
Re-organize HSM validation to be more consistent/less duplication
Rob Crittenden • a year ago  
7ab1bcb
Fix syntax error in the selinux-luna %postun script
Rob Crittenden • a year ago  
1b278de
ipa-migrate - remove -V option
Mark Reynolds • a year ago  
efa5719
The -d option of the ipa-advise command was able to used.
Shunsuke matsumoto • a year ago  
06c02f5
ipa_sidgen: Allow sidgen_task to continue after finding issues
Thomas Woerner • a year ago  
a8e75bb
  • « Newer
  • page 1 of 321
  • » Older
Powered by Pagure 5.14.1
Documentation • File an Issue • About • SSH Hostkey/Fingerprint
© Red Hat, Inc. and others.