<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=utf-8">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<p>Release date: 2017-03-23</p>
<p>The FreeIPA team would like to announce FreeIPA 4.4.4 release!<br>
<br>
It can be downloaded from <a class="moz-txt-link-freetext" href="http://www.freeipa.org/page/Downloads">http://www.freeipa.org/page/Downloads</a>.
Builds for<br>
Fedora 24 will be available in the official COPR repository
<a class="moz-txt-link-rfc2396E" href="https://copr.fedorainfracloud.org/coprs/g/freeipa/freeipa-4-4/"><https://copr.fedorainfracloud.org/coprs/g/freeipa/freeipa-4-4/></a>.</p>
<p>This announcement is also available at<a
class="moz-txt-link-rfc2396E"
href="http://www.freeipa.org/page/Releases/4.4.4">
<http://www.freeipa.org/page/Releases/4.4.4></a>.</p>
<p><br>
== Highlights in 4.4.4 ==<br>
=== Enhancements ===<br>
=== Known Issues ===<br>
=== Bug fixes ===<br>
FreeIPA 4.4.4 is a stabilization release for the features
delivered as a<br>
part of 4.4.0.<br>
<br>
== Upgrading ==<br>
Upgrade instructions are available on [[Upgrade]] page.<br>
<br>
== Feedback ==<br>
Please provide comments, bugs and other feedback via the
freeipa-users mailing<br>
list (<a class="moz-txt-link-freetext" href="http://www.redhat.com/mailman/listinfo/freeipa-users">http://www.redhat.com/mailman/listinfo/freeipa-users</a>) or
#freeipa<br>
channel on Freenode.</p>
<p>== Resolved tickets ==<br>
* 6776 krb5 1.15 broke DAL principal free<br>
* 6738 Ipa-kra-install fails with weird output when backspace is
used during typing Directory Manager password<br>
* 6713 ipa: Insufficient permission check for ca-del, ca-disable
and ca-enable commands (CVE-2017-2590)<br>
* 6647 batch param compatibility is incorrect<br>
* 6608 IPA server installation should check if IPv6 stack is
enabled<br>
* 6600 Legacy client tests doesn't have tree domain role.<br>
* 6588 replication race condition prevents IPA to install<br>
* 6575 ipa-replica-install fails on requesting DS cert when master
is not configured with IPv6<br>
* 6070 ipa-replica-install fails to install when resolv.conf
incomplete entries<br>
== Detailed changelog since 4.4.3 ==<br>
=== Alexander Bokovoy (1) ===<br>
* ipa-kdb: support KDB DAL version 6.1<br>
<br>
=== David Kupka (1) ===<br>
* ipapython.ipautil.nolog_replace: Do not replace empty value<br>
<br>
=== Florence Blanc-Renaud (1) ===<br>
* Do not configure PKI ajp redirection to use "::1"<br>
<br>
=== Fraser Tweedale (2) ===<br>
* ca: correctly authorise ca-del, ca-enable and ca-disable<br>
* Set up DS TLS on replica in CA-less topology<br>
<br>
=== Ganna Kaihorodova (1) ===<br>
* Tests: Add tree root domain role in legacy client tests<br>
<br>
=== Jan Cholasta (1) ===<br>
* compat: fix `Any` params in `batch` and `dnsrecord`<br>
<br>
=== Martin Basti (7) ===<br>
* Become IPA 4.4.4<br>
* Update Contributors.txt<br>
* FreeIPA 4.4.4 translations<br>
* Bump python-dns to improve processing of non-complete
resolv.conf<br>
* Use proper logging for error messages<br>
* Wait until HTTPS principal entry is replicated to replica<br>
* wait_for_entry: use only DN as parameter<br>
<br>
=== Stanislav Laznicka (2) ===<br>
* Add debug log in case cookie retrieval went wrong<br>
* Fix cookie with Max-Age processing<br>
<br>
=== Tomas Krizek (1) ===<br>
* server install: require IPv6 stack to be enabled<br>
<br>
=== Thorsten Scherf (1) ===<br>
* added ssl verification using IPA trust anchor<br>
</p>
</body>
</html>