[Freeipa-interest] FreeIPA 4.9.4 and 4.9.5 released

Alexander Bokovoy abokovoy at redhat.com
Mon Jun 14 17:38:26 UTC 2021


The FreeIPA team would like to announce FreeIPA 4.9.4 and 4.9.5 releases!

Yes, this is not a mistake. First we created FreeIPA 4.9.4 on June
4th but then found a late time regression that took us more than ten
days to sort out, thus going with the FreeIPA 4.9.5 release.

This regression concerns an edge case of an unauthenticated or almost
expired user credential's run of 'ipa' command line tool returning
a non-processed Python exception instead of a human-readable error
message. This, in turn uncovered a bit of a misconfiguration on the IPA
server side which could trigger this behavior. In a process of
investigating it we also found a bug in GSS-Proxy tool.

FreeIPA 4.9.4 release notes are large and can be found at
https://www.freeipa.org/page/Releases/4.9.4

FreeIPA 4.9.5 is released and can be downloaded from
http://www.freeipa.org/page/Downloads. Builds for Fedora distributions
will be available from the official repository soon. FreeIPA
installation is currently broken in Fedora Rawhide due to an ongoing
migration to Python 3.10 in Fedora where mod_wsgi does not yet support
Python 3.10.

== Highlights in 4.9.5

=== Bug fixes

FreeIPA 4.9.5 is a stabilization release for the features delivered as a
part of 4.9.0 version series.

There are 7 bug-fixes since FreeIPA 4.9.4 release. Details of the
bug-fixes can be seen in the list of resolved tickets below.

== Upgrading

Upgrade instructions are available on Upgrade page.

== Feedback

Please provide comments, bugs and other feedback via the freeipa-users
mailing list
(https://lists.fedoraproject.org/archives/list/freeipa-users@lists.fedorahosted.org/)
or #freeipa channel on Freenode.

== Resolved tickets

* https://pagure.io/freeipa/issue/8691[#8691] 
   [Tracker] Nightly failure (fc33) in test_winsyncmigrate.py: ipa-replica-manage connect --winsync error
* https://pagure.io/freeipa/issue/8702[#8702]
   (https://bugzilla.redhat.com/show_bug.cgi?id=1780317[rhbz#1780317])
   ipa-cert-fix: False Positive Status for cert renewal.
* https://pagure.io/freeipa/issue/8756[#8756]
   [Tracker] 389ds coredump in test_caless.py::TestReplicaInstall::test_wildcard_http
* https://pagure.io/freeipa/issue/8868[#8868]
   Nightly test failure in test_integration/test_fips.py::TestInstallFIPS
* https://pagure.io/freeipa/issue/8873[#8873]
   Missing credential cache can raise 500 when authenticating instead of 401
* https://pagure.io/freeipa/issue/8876[#8876]
   Nightly failure in test_installation.py::TestInstallWithCA1::test_install_with_bad_ldap_conf 
* https://pagure.io/freeipa/issue/8877[#8877]
   Nightly test failure in test_nfs.py: runner VM runs out of disk space due to huge sssd log file

== Detailed changelog since 4.9.4

=== Armando Neto (1)

* ipatests: Bump PR-CI boxes
https://pagure.io/freeipa/c/79e0919132adf0df764400f9c27268cbadd2578b[commit]

=== Alexander Bokovoy (3)

* Become FreeIPA 4.9.5
https://pagure.io/freeipa/c/e045f118c87346bfab5b5634fd23f3054f082f7f[commit]
* get_credentials: return ValueError for missing creds
https://pagure.io/freeipa/c/5238651da06547bb004de2434ae7d357422ba735[commit]
https://pagure.io/freeipa/issue/8873[#8873]
* Back to git snapshots
https://pagure.io/freeipa/c/b25f5bd9109b87916e097dd8353ea5f0dc49e398[commit]

=== Florence Blanc-Renaud (4)

* ipa-cert-fix man page: add note about certmonger renewal
https://pagure.io/freeipa/c/06a445aff10c1ab84e8784ab41b0a838e500e617[commit]
https://pagure.io/freeipa/issue/8702[#8702]
* freeipa.spec: bump 389-ds version
https://pagure.io/freeipa/c/6eb535334d33f8f375b856e3a2d0b8853b318b4d[commit]
https://pagure.io/freeipa/issue/8691[#8691],
https://pagure.io/freeipa/issue/8756[#8756]
* ipatests: delete the replica before uninstallation
https://pagure.io/freeipa/c/2b22450dfdc1657b463683b09b9c69816f9152d9[commit]
https://pagure.io/freeipa/issue/8876[#8876]
* ipatests: set selinux context for fips mode
https://pagure.io/freeipa/c/13b257d7a05fd255df472144712edb34604dbe06[commit]
https://pagure.io/freeipa/issue/8868[#8868]

=== Stanislav Levin (2)

* gssproxy: Don't refresh expired delegated credentials
https://pagure.io/freeipa/c/0fd06f33b83aec19a88c594d3750bc476157ab83[commit]
* krb_utils: Simplify get_credentials
https://pagure.io/freeipa/c/700be74975cad998e7dbcc4fb437e6b0bbd77305[commit]
https://pagure.io/freeipa/issue/8873[#8873]

=== Sergey Orlov (2)

* ipatests: disable test_nfs.py::TestNFS in nightly runs on Fedora 33
https://pagure.io/freeipa/c/c9f5acc0d281f1a27471091648c36f94528c5a29[commit]
https://pagure.io/freeipa/issue/8877[#8877]
* ipatests: temporary disable execution of test_nfs.py::TestNFS in nightly runs
https://pagure.io/freeipa/c/6ee14f513711ae9be799cfa2bd009f13c5248932[commit]
https://pagure.io/freeipa/issue/8877[#8877]


-- 
/ Alexander Bokovoy
Sr. Principal Software Engineer
Security / Identity Management Engineering
Red Hat Limited, Finland
_______________________________________________
FreeIPA-devel mailing list -- freeipa-devel at lists.fedorahosted.org
To unsubscribe send an email to freeipa-devel-leave at lists.fedorahosted.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedorahosted.org/archives/list/freeipa-devel@lists.fedorahosted.org
Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure




More information about the Freeipa-interest mailing list