--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2018-2f11593fb0
2018-05-01 13:40:35.611617
--------------------------------------------------------------------------------
Name : sssd
Product : Fedora 27
Version : 1.16.1
Release : 3.fc27
URL :
https://pagure.io/SSSD/sssd/
Summary : System Security Services Daemon
Description :
Provides a set of daemons to manage access to remote directories and
authentication mechanisms. It provides an NSS and PAM interface toward
the system and a plug-gable back-end system to connect to multiple different
account sources. It is also the basis to provide client auditing and policy
services for projects like FreeIPA.
The sssd sub-package is a meta-package that contains the daemon as well as all
the existing back ends.
--------------------------------------------------------------------------------
Update Information:
Resolves: upstream#3684 - A group is not updated if its member is removed with
the cleanup task, but the group does not change Resolves: upstream#3558 - sudo:
report error when two rules share cn Tone down shutdown messages for socket
activated responders IPA: Qualify the externalUser sudo attribute Resolves:
upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15
Resolves: upstream#3402 - Support alternative sources for the files provider
Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option Resolves:
upstream#3679 - Make nss netgroup requests more robust Resolves: upstream#3634 -
sssctl COMMAND --help fails if sssd is not configured Resolves: upstream#3469 -
extend sss-certmap man page regarding priority processing Improve docs/debug
message about GC detection Resolves: upstream#3715 - ipa 389-ds-base crash in
krb5-libs - k5_copy_etypes list out of bound? Resolves: upstream#2653 - Group
renaming issue when "id_provider = ldap" is set. Document which principal does
the AD provider use Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If
a rule is defined, but contains no SIDs Resolves: upstream#3520 - Files provider
supports only BE_FILTER_ENUM Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file
sssd_nss error: The Data Provider returned an error
[org.freedesktop.sssd.Error.DataProvider.Fatal]
--------------------------------------------------------------------------------
ChangeLog:
* Fri Apr 27 2018 Fabiano Fid��ncio <fidencio(a)fedoraproject.org> - 1.16.1-3
- Resolves: upstream#3684 - A group is not updated if its member is removed
with the cleanup task, but the group does not
change
- Resolves: upstream#3558 - sudo: report error when two rules share cn
- Tone down shutdown messages for socket activated responders
- IPA: Qualify the externalUser sudo attribute
- Resolves: upstream#3550 - refresh_expired_interval does not work with
netgrous in 1.15
- Resolves: upstream#3402 - Support alternative sources for the files provider
- Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option
- Resolves: upstream#3679 - Make nss netgroup requests more robust
- Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not
configured
- Resolves: upstream#3469 - extend sss-certmap man page regarding priority
processing
- Improve docs/debug message about GC detection
- Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes
list out of bound?
- Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is
set.
- Document which principal does the AD provider use
- Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is
defined, but contains no SIDs
- Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM
- Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data
Provider returned an error
[org.freedesktop.sssd.Error.DataProvider.Fatal]
* Fri Mar 30 2018 Fabiano Fid��ncio <fidencio(a)fedoraproject.org> - 1.16.1-2
- Resolves: upstream#3573 - sssd won't show netgroups with blank domain
- Resolves: upstream#3660 - confdb_expand_app_domains() always fails
- Resolves: upstream#3658 - Application domain is not interpreted correctly
- Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to
json_loads()
- Resolves: upstream#3386 - KCM: Payload buffer is too small
- Resolves: upstream#3666 - Fix usage of str.decode() in our tests
- A few KCM misc fixes
* Fri Mar 9 2018 Fabiano Fid��ncio <fidencio(a)fedoraproject.org> - 1.16.1-1
- New upstream release 1.16.1
-
https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html
* Tue Feb 20 2018 Lukas Slebodnik <lslebodn(a)fedoraproject.org> - 1.16.0-8
- Resolves: upstream#3621 - backport bug fix found by static analyzers
* Wed Feb 14 2018 Fabiano Fid��ncio <fidencio(a)fedoraproject.org> - 1.16.0-7
- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile
with no specific host/hostgroup set
- Resolves: upstream#3621 - FleetCommander integration must not require
capability DAC_OVERRIDE
* Wed Feb 7 2018 Lukas Slebodnik <lslebodn(a)fedoraproject.org> - 1.16.0-6
- Resolves: upstream#3618 - selinux_child segfaults in a docker container
* Mon Dec 4 2017 Lukas Slebodnik <lslebodn(a)fedoraproject.org> - 1.16.0-5
- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in
setnetgrent_result_timeout
- Resolves: upstream#3588 - sssd_nss consumes more memory until restarted
or machine swaps
- Resolves: failure in glibc tests
https://sourceware.org/bugzilla/show_bug.cgi?id=22530
- Resolves: upstream#3451 - When sssd is configured with id_provider proxy and
auth_provider ldap, login fails if the LDAP server
is not allowing anonymous binds
- Resolves: upstream#3285 - SSSD needs restart after incorrect clock is
corrected with AD
- Resolves: upstream#3586 - Give a more detailed debug and system-log message
if krb5_init_context() failed
- Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet
in /etc/systemd/system
- Backport few upstream features from 1.16.1
* Tue Nov 21 2017 Lukas Slebodnik <lslebodn(a)fedoraproject.org> - 1.16.0-4
- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next
* Fri Nov 17 2017 Jakub Hrozek <jhrozek(a)redhat.com> - 1.16.0-3
- Backport extended NSS API from upstream master branch
* Fri Nov 3 2017 Lukas Slebodnik <lslebodn(a)fedoraproject.org> - 1.16.0-2
- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade
* Fri Oct 20 2017 Lukas Slebodnik <lslebodn(a)fedoraproject.org> - 1.16.0-1
- New upstream release 1.16.0
-
https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider
returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]
https://bugzilla.redhat.com/show_bug.cgi?id=1540703
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2018-2f11593fb0' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------