Change log for freeipa package in Ubuntu

156 of 56 results
Published in disco-release on 2019-02-05
Deleted in disco-proposed (Reason: moved to release)
freeipa (4.7.2-1ubuntu1) disco; urgency=medium

  * tests: Disabled, they are for the server.

 -- Timo Aaltonen <email address hidden>  Tue, 05 Feb 2019 23:37:16 +0200
Superseded in disco-proposed on 2019-02-05
freeipa (4.7.2-1) unstable; urgency=medium

  * New upstream release.
  * client.tmpfile: Use /run instead of /var/run.
  * control.common: Use same arch set on node-uglify build-dep as for
    nodejs. (Closes: #918579)
  * fix-fontawesome-path.diff: Refreshed.
  * rules: Build only the client until Dogtag works again.

 -- Timo Aaltonen <email address hidden>  Tue, 05 Feb 2019 12:39:34 +0200

Available diffs

Superseded in disco-proposed on 2019-02-05
Deleted in disco-release on 2019-02-07 (Reason: LP: #1813155, remove dogtag-pki and demote rdep freeipa)
Deleted in disco-proposed on 2019-02-07 (Reason: moved to release)
freeipa (4.7.1-3) unstable; urgency=medium

  * control: Replace libsvrcore-dev build-dep with 389-ds-base-dev.
  * tests: Install only the packages which are used for testing.
  * rules: Don't run git on clean. (Closes: #912202)
  * control: Nodejs is not available on all archs, build server packages
    only where it is.
  * control: Add systemd to python-ipalib depends. (Closes: #851158)

 -- Timo Aaltonen <email address hidden>  Thu, 06 Dec 2018 02:22:35 +0200
Superseded in disco-release on 2019-01-08
Published in cosmic-release on 2018-10-18
Deleted in cosmic-proposed (Reason: moved to release)
freeipa (4.7.1-2ubuntu1) cosmic; urgency=medium

  * Upload to cosmic.

 -- Timo Aaltonen <email address hidden>  Thu, 18 Oct 2018 14:32:28 +0300
Superseded in cosmic-release on 2018-10-18
Deleted in cosmic-proposed on 2018-10-19 (Reason: moved to release)
freeipa (4.7.1-1) unstable; urgency=medium

  * New upstream release.
    - fix-replicainstall.diff dropped, not applicable anymore
    - ipa-httpd-pwdreader-force-fqdn.diff dropped, obsolete
    - refresh patches
    - server: drop ipa-replica-prepare
  * dont-migrate-to-authselect.diff We don't have authselect, so just
    return true when trying to migrate to it. (LP: #1793994)
  * control: Move client dependency on chrony to recommends. (Closes:
    #909803)
  * control: Build server on any arch again.
  * tests: Don't fail the tests, just dump the log if something goes
    wrong.

 -- Timo Aaltonen <email address hidden>  Tue, 09 Oct 2018 10:30:09 +0300
Superseded in cosmic-release on 2018-10-10
Deleted in cosmic-proposed on 2018-10-11 (Reason: moved to release)
freeipa (4.7.0-1ubuntu4) cosmic; urgency=medium

  * Actually build server on architecture any.

 -- Dimitri John Ledkov <email address hidden>  Tue, 02 Oct 2018 23:32:01 +0100
Superseded in cosmic-proposed on 2018-10-02
freeipa (4.7.0-1ubuntu3) cosmic; urgency=medium

  * Go back to ignore the results of the autopkgtest, it passes for me
    locally. All previous `pass' results also fail in a similar fashion
    thus this is not a regression in v4.7.0.

 -- Dimitri John Ledkov <email address hidden>  Tue, 02 Oct 2018 18:33:11 +0100

Available diffs

Superseded in cosmic-proposed on 2018-10-02
freeipa (4.7.0-1ubuntu2) cosmic; urgency=medium

  * Cherrypick upstream patches for compat with curl, pyasn1.

 -- Dimitri John Ledkov <email address hidden>  Tue, 02 Oct 2018 14:35:42 +0100

Available diffs

Superseded in cosmic-proposed on 2018-10-02
freeipa (4.7.0-1ubuntu1) cosmic; urgency=medium

  * Re-enable building on any architecture.

 -- Dimitri John Ledkov <email address hidden>  Tue, 02 Oct 2018 12:00:24 +0100
Superseded in cosmic-proposed on 2018-10-02
freeipa (4.7.0-1) unstable; urgency=medium

  * New upstream release. (LP: #1772447, #1772450)
    - fix-version.diff: Dropped, not needed
    - hack-duplicate-cert-directive.diff: Dropped, fixed upstream
    - ldap-multiarch.diff: Dropped, fixed upstream
    - support-pam-mkhomedir.diff: Dropped, fixed upstream
    - fix-apache-ssl-setup.diff: Dropped, fixed upstream
    - fix-httpd-group.diff: Dropped, fixed upstream
    - fix-named-conf-template.diff: Dropped, fixed upstream
    - fix-paths.diff: Dropped, fixed upstream
    - refresh patches
  * tests/server-install: Fix the fake domain, single label domains are not
    supported anymore.
  * server.postinst: Fix upgrade from earlier version.
  * fix-fontawesome-path.diff: Fix the path to font-awesome. (LP:
    #1772921)
  * fix-krb5kdc-cert-path.diff: Apache can't access KDC certs, move them
    to /var/lib/ipa/certs. (LP: #1772447)
  * ipa-httpd-pwdreader-force-fqdn.diff: Make sure HOSTNAME is a FQDN. (LP:
    #1769485)
  * control: Add libjs-scriptaculous to server depends.
  * fix-gzip-path.diff: Fix path to gzip. (LP: #1778236)
  * control, rules: Switch rhino to nodejs for ui build.
  * d/s/local-options: Add some files to ignore.
  * control, copyright: Add node-uglify to build-depends, the embedded
    copy was removed.
  * control, fix-py3-lesscpy-name.diff: Add python3-lesscpy to build-
    depends, call the binary with the correct name.
  * control: Add python3-pkg-resources to build-depends.
  * client.install: Add new template.
  * control: Update vcs urls.
  * control: Mark priority as optional.
  * control, rules: Bump dh to 11.
  * control: Add adduser to server depends.
  * source/lintian-overrides: Updated.
  * control: Bump policy to 4.1.5.
  * control: Update maintainer list address.
  * control: Build the server only on archs where 389-ds-base is
    available.
  * control: Bump python-ldap build-dep to 3.1.

 -- Timo Aaltonen <email address hidden>  Fri, 28 Sep 2018 14:10:34 +0300
Superseded in cosmic-proposed on 2018-09-30
freeipa (4.7.0~pre2-0ubuntu1) cosmic; urgency=medium

  * New upstream prerelease.
    - fix-version.diff: Dropped, not needed
    - hack-duplicate-cert-directive.diff: Dropped, fixed upstream
    - refresh patches
  * tests/server-install: Fix the fake domain, single label domains are not
    supported anymore.
  * tests: If the server install fails, just dump the log and exit
    successfully.
  * server.postinst: Fix upgrade from earlier version.
  * Create-kadm5.acl-if-it-doesn-t-exist.diff: Fix kadmind startup issue
    if kadm5.acl doesn't exist. (LP: #1772447)
  * fix-fontawesome-path.diff: Fix the path to font-awesome. (LP:
    #1772921)
  * fix-krb5kdc-cert-path.diff: Apache can't access KDC certs, move them
    to /var/lib/ipa/certs. (LP: #1772447)
  * ipa-httpd-pwdreader-force-fqdn.diff: Make sure HOSTNAME is a FQDN. (LP:
    #1769485)
  * dont-allow-compressed-certs.diff: mod_deflate is enabled by default on
    Debian, but the current apache config doesn't know how to uncompress the
    received cert data so disallow gzip content for now. (LP: #1772450)
  * control: Add libjs-scriptaculous to server depends.
  * fix-gzip-path.diff: Fix path to gzip. (LP: #1778236)
  * control: Drop libsvrcore-dev from build-depends, bump 389-ds-base-
    dev build-dep.

 -- Timo Aaltonen <email address hidden>  Thu, 27 Sep 2018 22:30:30 +0300
Superseded in cosmic-release on 2018-10-03
Published in bionic-release on 2018-04-26
Deleted in bionic-proposed (Reason: moved to release)
freeipa (4.7.0~pre1+git20180411-2ubuntu2) bionic; urgency=medium

  * server.postinst: Fix upgrade from earlier version.

 -- Timo Aaltonen <email address hidden>  Thu, 26 Apr 2018 18:15:49 +0300
Superseded in bionic-release on 2018-04-26
Deleted in bionic-proposed on 2018-04-27 (Reason: moved to release)
freeipa (4.7.0~pre1+git20180411-2ubuntu1) bionic; urgency=medium

  * tests/server-install: Fix the fake domain, single label domains are not
    supported anymore.
  * tests: If the server install fails, just dump the log and exit
    successfully.

 -- Timo Aaltonen <email address hidden>  Wed, 18 Apr 2018 17:50:11 +0300
Superseded in bionic-proposed on 2018-04-18
freeipa (4.7.0~pre1+git20180411-2) experimental; urgency=medium

  * fix-bind-ldap-so-path.diff: Dropped, the plugin uses non-MA path
    now, fix depends to match.
  * control: Add python-augeas to python-ipaclient depends. (LP: #1764615)
  * ldap-multiarch.diff: Replace hack-libarch.diff with a new patch to
    support more than x86. (LP: #1600634)

 -- Timo Aaltonen <email address hidden>  Tue, 17 Apr 2018 23:47:32 +0300
Superseded in bionic-proposed on 2018-04-18
freeipa (4.7.0~pre1+git20180411-1) experimental; urgency=medium

  * New upstream prerelease + git snapshot.
  * tests: Fix whitespace.
  * client.dirs: Add /var/lib/ipa-client/pki.
  * server.post*: Enable session, session_cookie apache modules.
  * control: Add sssd-dbus to server Depends.
  * fix-httpd-group.diff: Fix apache group for Debian.
  * control: Bump dependency on certmonger.
  * support-pam-mkhomedir.diff: Add support for enabling pam_mkhomedir.
    (LP: #1336869)
  * control: Add libsss-certmap-dev to build-depends.
  * control: Drop hardcoded libcurl3 dependency from client.
  * control*, rules: Add support for client-only build.
  * Fold admintools into the client package.
  * fix-bind-ldap-so-path.diff: Use multiarch path to bind/ldap.so.
  * fix-ipa-conf.diff: Dropped, upstream.
  * rules: Force building with python2.
  * server.install: Updated.
  * debian/.gitignore: Ignore d/control.
  * rules: If git is installed, revert po/ on clean.
  * server.dirs: Add missing directories, fix some permissions in
    postinst.
  * control.server: Bump dogtag dependencies to 10.6.0~.
  * control.server: Drop mod-nss from Depends, mod_ssl is used instead.
  * enable-mod-nss-during-setup.diff: Dropped, not needed anymore.
  * server.postinst/postrm: Enable/disable mod_ssl.
  * control: Bump 389-ds-base dependency.
  * rules: Modify python scripts to use python2.
  * fix-paths.diff: Add some paths to platform data.
  * hack-tomcat-race.diff: Restarting pki-tomcatd takes time, and renew_ca_cert
    does that several times in a row, so wait for 80s before starting migrating
    profiles to ldap to make sure the instance is up.
  * fix-apache-ssl-setup.diff: Fix mod_ssl setup.
  * hack-duplicate-cert-directive.diff: Delete a duplicate
    SSLCertificateFile directive until upstream is fixed.
  * server.postinst: Enable default-ssl site.
  * control: Depend on chrony instead of ntp.
  * fix-paths.diff: Add CHRONY_CONF.
  * python-ipaserver.install: Updated after dropping NTP.
  * fix-version.diff: Append +git to prerelease tag, don't require git.
  * pydist_overrides: Added.
  * rules: Update clean target.
  * control: Bump depends on bind9.

 -- Timo Aaltonen <email address hidden>  Thu, 12 Apr 2018 14:01:56 +0300
Superseded in bionic-proposed on 2018-03-06
freeipa (4.4.4-4build1) bionic; urgency=medium

  * No-change rebuild for the curl transition.

 -- Adam Conrad <email address hidden>  Tue, 06 Mar 2018 14:20:37 -0700

Available diffs

Superseded in bionic-proposed on 2018-04-12
Deleted in bionic-proposed on 2018-04-14 (Reason: Making room for a no-change rebuild of the release pocket...)
freeipa (4.6.3-1ubuntu1) bionic; urgency=medium

  * Move hard-coded dependency on libcurl3 to libcurl4

 -- Steve Langasek <email address hidden>  Thu, 01 Mar 2018 09:05:59 -0800

Available diffs

Superseded in bionic-proposed on 2018-03-01
freeipa (4.6.3-1build4) bionic; urgency=medium

  * No-change rebuild against libcurl4

 -- Steve Langasek <email address hidden>  Wed, 28 Feb 2018 08:35:17 +0000

Available diffs

Superseded in bionic-proposed on 2018-02-28
freeipa (4.6.3-1build3) bionic; urgency=medium

  * No-change rebuild against libcurl4

 -- Steve Langasek <email address hidden>  Wed, 28 Feb 2018 06:50:42 +0000
Superseded in bionic-proposed on 2018-02-28
freeipa (4.6.3-1build2) bionic; urgency=medium

  * Rebuild against new libunistring2.

 -- Gianfranco Costamagna <email address hidden>  Tue, 13 Feb 2018 16:31:19 +0100
Superseded in bionic-proposed on 2018-02-15
freeipa (4.6.3-1build1) bionic; urgency=high

  * No change rebuild against openssl1.1.

 -- Dimitri John Ledkov <email address hidden>  Wed, 07 Feb 2018 11:35:25 +0000
Superseded in bionic-proposed on 2018-02-07
freeipa (4.6.3-1) unstable; urgency=medium

  * New upstream release.
  * support-kdb-dal-7.0.diff: Dropped, upstream.
  * tests: Force hostname as 'autopkgtest' if the system didn't have
    one.

 -- Timo Aaltonen <email address hidden>  Fri, 02 Feb 2018 17:27:41 +0200

Available diffs

Superseded in bionic-proposed on 2018-02-02
freeipa (4.6.2-4) unstable; urgency=medium

  * client.postinst: Migrate from old nssdb only if it exists.

 -- Timo Aaltonen <email address hidden>  Tue, 30 Jan 2018 17:42:08 +0200

Available diffs

Superseded in bionic-proposed on 2018-01-30
freeipa (4.6.2-3) unstable; urgency=medium

  * tests: Add some debug info, and fail properly.

 -- Timo Aaltonen <email address hidden>  Mon, 29 Jan 2018 13:17:25 +0200

Available diffs

Superseded in bionic-proposed on 2018-01-29
freeipa (4.6.2-2) unstable; urgency=medium

  * server.postinst: Fix output redirection.

 -- Timo Aaltonen <email address hidden>  Sat, 20 Jan 2018 21:33:26 +0200

Available diffs

Superseded in bionic-proposed on 2018-01-20
freeipa (4.6.2-1) unstable; urgency=medium

  * New upstream release.
    - Remove upstreamed patches:
      add-debian-platform.diff,
      ipa-kdb-support-dal-version-5-and-6.diff,
      purge-firefox-extension.diff,
      fix-ipa-otpd-install.diff,
      fix-ipa-otpd-service.diff,
      purge-firefox-extension.diff,
      prefix.patch,
      fix-kdcproxy-path.diff,
      fix-is-running.diff,
      fix-pkcs11-helper.diff,
      fix-dnssec-services.diff
    - Remove obsolete patches: fix-memcached.diff,
      fix-oddjobs.diff,
      fix-kdcproxy-paths.diff
    - Refresh rest of the patches
  * control et al: Memcached is not used anymore.
  * control, server.install: Depend on gssproxy.
  * control: Build-depend on python-jinja2, add CSR files to python-
    ipaclient.
  * *.install: Updated.
  * client.postinst: Fix update_ipa_nssdb import.
  * rules, autoreconf: Refactor the build to match current upstream,
    drop d/autoreconf.
  * local-options: Ignore some files not on tarballs.
  * rules: Migrate to dh_missing.
  * Drop server tmpfile, ship upstream one, and create ipaapi/kdcproxy
    users/groups on install and add www-data to ipaapi group.
  * control: Add python-sss to python-ipaserver depends.
  * rules: Disable building on a builddirectory, it's broken upstream
    for now.
  * control: Drop libcurl4-nss-dev from build-depends, bump libkrb5-dev
    build-dependency.
  * control: Bump dependency on bind9 and bind9-dyndb-ldap.
  * control: add libapache2-mod-lookup-identity to server dependencies,
    enable/disable it in postinst/postrm.
  * control: Depend on newer custodia, move dep on python-custodia to
    python-ipaserver.
  * control: Add python-sss to client depends.
  * Add support for krb 1.16. (Closes: #887814)

 -- Timo Aaltonen <email address hidden>  Sat, 20 Jan 2018 12:41:28 +0200

Available diffs

Deleted in bionic-release on 2018-03-07 (Reason: FTBFS and stuck, blocks curl transition; temporarily remo...)
Deleted in bionic-proposed on 2018-03-07 (Reason: moved to release)
freeipa (4.4.4-4) unstable; urgency=medium

  [ Timo Aaltonen ]
  * fix-opendnssec-setup.diff: Use /usr/sbin prefix for ods binaries.
  * samba-4.7-fix-*: Add backported commits to allow building against
    samba 4.7. (Closes: #880841)

  [ Steve Langasek ]
  * Fix autopkgtest to be robust in the face of changed iproute2 output.

 -- Timo Aaltonen <email address hidden>  Sat, 16 Dec 2017 09:15:37 +0200
Superseded in bionic-proposed on 2017-12-17
freeipa (4.4.4-3ubuntu2) bionic; urgency=medium

  * Fix autopkgtest to be robust in the face of changed iproute2 output

 -- Steve Langasek <email address hidden>  Fri, 15 Dec 2017 11:29:32 -0800

Available diffs

Superseded in bionic-release on 2017-12-17
Published in artful-release on 2017-10-15
Deleted in artful-proposed (Reason: moved to release)
freeipa (4.4.4-3ubuntu1) artful; urgency=medium

  * fix-opendnssec-setup.diff: Use /usr/sbin prefix for ods binaries.

 -- Timo Aaltonen <email address hidden>  Sun, 15 Oct 2017 09:50:35 +0300
Superseded in artful-release on 2017-10-15
Deleted in artful-proposed on 2017-10-16 (Reason: moved to release)
freeipa (4.4.4-3) unstable; urgency=medium

  * fix-opendnssec-setup.diff: Fix a typo. (Closes: #878095)

 -- Timo Aaltonen <email address hidden>  Mon, 09 Oct 2017 23:51:56 +0300

Available diffs

Obsolete in zesty-updates on 2018-06-22
Deleted in zesty-proposed on 2018-06-22 (Reason: moved to -updates)
freeipa (4.4.3-3ubuntu2.1) zesty; urgency=medium

  * client.dirs: Ship /etc/krb5.conf.d, because not having that breaks
    the installer when krb5.conf tries to include it. (LP: #1693154)

 -- Timo Aaltonen <email address hidden>  Wed, 14 Jun 2017 13:56:03 +0300

Available diffs

Superseded in artful-release on 2017-10-10
Deleted in artful-proposed on 2017-10-11 (Reason: moved to release)
Deleted in artful-release on 2017-10-11 (Reason: lp: #1716842, needs porting work for tomcat8)
Deleted in artful-proposed on 2017-10-11 (Reason: moved to release)
freeipa (4.4.4-1) unstable; urgency=medium

  * Upload to unstable. (Closes: #862846)
  * New upstream release.
    - CVE-2017-2590
    - ipa-kdb-support-dal-version-5-and-6.diff: Dropped, upstream.
    - purge-firefox-extension.diff: Refreshed.
  * fix-is-running.diff: Add a third argument to is_running() in
    ipaplatform/debian/services.py. (Closes: #856533)
  * fix-kdcproxy-path.diff: Update debian/paths.py to use correct path
    for ipa-httpd-kdcproxy.
  * client.dirs: Ship /etc/krb5.conf.d, because not having that breaks
    the installer when krb5.conf tries to include that.
  * copyright, watch: Update source/release location.
  * control, ipaserver: Move adtrustinstance python files to python-
    ipaserver, and add samba-common to python-ipaserver depends so that
    uninstall works.
  * fix-pkcs11-helper.diff: Fix ipa-dnskeysyncd setup which was broken
    by softhsm 2.2.
  * fix-opendnssec-setup.diff: Opendnssec 2.0.x broke DNSSEC setup, fix
    it.

 -- Timo Aaltonen <email address hidden>  Wed, 17 May 2017 21:19:22 +0300
Superseded in artful-release on 2017-05-19
Obsolete in zesty-release on 2018-06-22
Deleted in zesty-proposed on 2018-06-22 (Reason: moved to release)
freeipa (4.4.3-3ubuntu2) zesty; urgency=medium

  * No-change rebuild against ldns2.

 -- Mattia Rizzolo <email address hidden>  Mon, 10 Apr 2017 10:55:39 +0200

Available diffs

Superseded in zesty-release on 2017-04-10
Deleted in zesty-proposed on 2017-04-11 (Reason: moved to release)
freeipa (4.4.3-3ubuntu1) zesty; urgency=medium

  * fix-is-running.diff: Add a third argument to is_running() in
    ipaplatform/debian/services.py.

 -- Timo Aaltonen <email address hidden>  Fri, 17 Feb 2017 01:40:15 +0200
Superseded in zesty-proposed on 2017-02-17
freeipa (4.4.3-2ubuntu1) zesty; urgency=medium

  * client.postinst: Fix logfile location.

 -- Timo Aaltonen <email address hidden>  Thu, 16 Feb 2017 11:26:08 +0200
Superseded in zesty-proposed on 2017-02-16
freeipa (4.4.3-2) experimental; urgency=medium

  * control: Fix python-ipatests to depend on python-sss instead of
    python-sssdconfig.

 -- Timo Aaltonen <email address hidden>  Sat, 28 Jan 2017 00:15:53 +0200

Available diffs

Superseded in zesty-proposed on 2017-01-28
freeipa (4.4.3-1) experimental; urgency=medium

  * New upstream release. (Closes: #848762)
  * configure-apache-from-installer.diff: Dropped, upstream.
  * fix-cve-2016-5404.diff: Dropped, upstream.
  * patches: Refreshed.
  * work-around-apache-fail.diff: Dropped, apache supports systemd now
    so this should not be needed.
  * watch: Use https url.
  * client.postinst: Use update_ipa_nssdb(), which also removes remnants
    from /etc/pki/nssdb.
  * control: Bump depends on slapi-nis to 0.56.1.
  * control: Add python-custodia and python-requests to ipalib depends.
  * control: Use python-netifaces instead of iproute.
  * control: Add python-sssdconfig to python-ipatests depends.
  * control: Bump depends on 389-ds-base to 1.3.5.6, upstream #5396
    #2008.
  * control: Bump bind9-dyndb-ldap depends to 10, upstream #2008.
  * control: Add python-libsss-nss-idmap to build-depends.
  * control: Bump depends on sssd to 1.14.0.
  * install: Updated.
  * platform:
    - drop variables that were commented out
    - add some comments to tasks.py
    - migrate some services to use systemd
    - add & update some paths
    - add some stub services (LP: #1653245)
  * control: Add krb5-otp to server depends. (LP: #1640732)
  * control: Demote ntp to Recommends so that lxc containers can be
    enrolled without it. (LP: #1630911)

 -- Timo Aaltonen <email address hidden>  Sat, 14 Jan 2017 15:29:25 +0200

Available diffs

Superseded in zesty-release on 2017-02-17
Deleted in zesty-proposed on 2017-02-18 (Reason: moved to release)
freeipa (4.3.2-5) unstable; urgency=medium

  * fix-cve-2016-5404.diff: Fix permission check bypass (Closes: #835131)
    - CVE-2016-5404
  * ipa-kdb-support-dal-version-5-and-6.diff: Support mit-krb5 1.15.
    (Closes: #844114)

 -- Timo Aaltonen <email address hidden>  Sat, 03 Dec 2016 01:02:40 +0200

Available diffs

Superseded in zesty-release on 2016-12-26
Deleted in zesty-proposed on 2018-01-23 (Reason: moved to release)
Obsolete in yakkety-updates on 2018-01-23
Deleted in yakkety-release on 2016-09-30 (Reason: (From Debian) NPOASR; Unable to maintain; Debian bug #835163)
Deleted in yakkety-proposed on 2016-09-30 (Reason: moved to release)
freeipa (4.3.2-1) experimental; urgency=medium

  * New upstream release.
  * copyright, missing-sources, README.source: Exclude minified javascript
    that the runtime does not need. Add unminified versions of others,
    update copyright to match. (Closes: #787593)
  * source/lintian-overrides: Document minified javascript issues.

 -- Timo Aaltonen <email address hidden>  Wed, 14 Sep 2016 13:03:54 +0300
Superseded in yakkety-release on 2016-09-19
Published in xenial-release on 2016-04-19
Deleted in xenial-proposed (Reason: moved to release)
freeipa (4.3.1-0ubuntu1) xenial; urgency=medium

  * Sync from Debian.

Deleted in xenial-proposed on 2016-03-23 (Reason: Accidental upload)
freeipa (4.3.0+git20160322-0.2) xenial; urgency=medium

  * New upstream snapshot.
    - refresh patches
    - drop no-test-lang.diff, obsolete
  * fix-match-hostname.diff, control: Drop the patch and python-openssl
    deps, not needed anymore
  * *.install: Updated.
  * control: Add python-cryptography to build-deps and python-freeipa
    deps.
  * control: Add libp11-kit-dev to build-deps, p11-kit to server deps.
  * patches: Drop bits of platform.diff and other patches that are now
    upstream. Refresh others.
  * control: Depend on python-gssapi instead of python-kerberos/-krbV.
  * control: Add libini-config-dev and python-dbus to build-deps,
    replace wget with curl.
  * control: Bump libkrb5-dev build-dep.
  * control: Add pki-base to build-deps and pki-kra to server deps, bump
    pki-ca version.
  * control: Drop python-m2crypto from deps, obsolete.
  * control: Bump sssd deps to 1.13.1.
  * control: Add python-six to build-deps and python-freeipa deps.
  * control: Split python stuff from server, client, tests to python-
    ipa{server,client,tests}, rename python-freeipa to match and move
    translations to freeipa-common. Mark them Arch:all where possible,
    and add Breaks/Replaces.
  * prefix.patch: Fix ipalib install too.
  * control: Bump certmonger deps, add oddjob to server and oddjob-
    mkhomedir to client deps.
  * server.postinst: Use ipa-server-upgrade.
  * control: Add python-setuptools to python-ipalib deps.
  * control: Bump 389-ds-base* deps.
  * control, rules: Add support for kdcproxy.
  * control, server: Migrate to mod-auth-gssapi.
  * Split freeipa-server-dns from server.
  * admintools: Use the new location for bash completions.
  * rules: Fix paths in oddjob configs.
  * control, rules, fix-ipa-conf.diff, fix-custodia-conf.diff:
    Add support for custodia.
  * rules: Remove obsolete configure.jar, preferences.html.
  * platform: Fix ipautil.run stdout handling, add support for systemd.
  * control: Bump server and python-ipaserver dependency on python-ldap
    to 2.4.22 to fix a bug on ipa-server-upgrade.
  * control: Bump server dependency on oddjob to 0.34.3-2.
  * server.postinst, tmpfile: Create state directories for
    mod_auth_gssapi.
  * fix-kdcproxy-paths.diff: Fix paths in kdcproxy configs.
  * add-debian-platform.diff:
    - Update paths.py to include all variables, comment out ones we don't
      modify.
    - Use systemwide certificate store; put ipa-ca.crt in
      /usr/local/share/ca-certificates, and run update-ca-certificates
    - Map smb service to smbd (LP: #1543230)
  * rules, server.install: Install scripts under /usr/lib instead of
    multiarch path to avoid hacking the code too much.
  * fix-ipa-otpd-install.diff, rules, server.install: Put ipa-otpd in
    /usr/lib/ipa instead of directly under multiarch lib path.
  * control, server*.install: Move dirsrv plugins from server-trust-ad
    to server, needed on upgrades even if trust-ad isn't set up.
  * control: Add pki-tools to python-ipaserver deps.
  * server: Enable mod_proxy_ajp and mod_proxy_http on postinst, disable
    on postrm.
  * control: Add zip to python-ipaserver depends.
  * fix-replicainstall.diff: Use ldap instead of ldaps for conncheck.
  * ipaplatform-Move-remaining-user-group-constants-to-i.patch: Port
    various bits to use ipaplatform.constants.
  * fix-dnssec-services.diff: Debianize ipa-dnskeysyncd & ipa-ods-
    exporter units.
  * fix-opendnssec-conf-template.diff: Use ODS_USER/ODS_GROUP constants
    in the template.
  * control: Add python-systemd to server depends.
  * rules, platform, server.dirs, server.install: Add support for
    DNSSEC.
  * create-sysconfig-ods.diff: Create an empty file for opendnssec
    daemons, until opendnssec itself is fixed.
  * control: Bump dep on bind9-dyndb-ldap.
  * rules: Add SKIP_API_VERSION_CHECK, and adjust directories to clean.
  * server-dns: Package is arch:all, so chmod the data dir on postinst
    instead of during build.
  * control: Add opendnssec to freeipa-server-dns depends.
  * control: Add python-cffi to python-ipalib depends.

 -- Timo Aaltonen <email address hidden>  Sat, 03 Oct 2015 08:56:31 +0300
Superseded in xenial-release on 2016-04-19
Obsolete in wily-release on 2018-01-22
Deleted in wily-proposed on 2018-01-22 (Reason: moved to release)
freeipa (4.1.4-1) experimental; urgency=medium

  * New upstream release. (LP: #1492226)
    - Refresh patches
    - platform-support.diff: Added NAMED_VAR_DIR.
    - fix-bind-conf.diff: Dropped, obsolete with above.
    - disable-dnssec-support.patch: Disable DNSSEC-support as we're
      missing the dependencies for now.
  * control: Add python-usb to build-depends and to python-freeipa
    depends.
  * control: Bump SSSD dependencies.
  * control: Add libsofthsm2-dev to build-depends and softhsm2 to server
    depends.
  * freeipa-{server,client}.install: Add new files.
  * control: Bump Depends on slapi-nis for CVE fixes.
  * control: Bump 389-ds-base, pki-ca depends.
  * control: Drop dogtag-pki-server-theme from server depends, it's not
    needed.
  * control: Server needs newer python-ldap, bump build-dep too.
  * control: Bump certmonger depends.
  * control: Bump python-nss depends.
  * freeipa-client: Add /etc/ipa/nssdb, rework /etc/pki/nssdb handling.
  * platform: Add DebianNamedService.
  * platform, disable-dnssec-support.patch: Fix named.conf template.
  * server.postinst: Run ipa-ldap-updater and ipa-upgradeconfig on
    postinst.
  * Revert DNSSEC changes to schema and ACI, makes upgrade tools fail.
  * server.postrm: Clean logs on purge and disable apache modules on
    remove/purge.

 -- Timo Aaltonen <email address hidden>  Fri, 25 Sep 2015 14:07:40 +0300

Available diffs

Superseded in wily-release on 2015-10-05
Deleted in wily-proposed on 2015-10-06 (Reason: moved to release)
freeipa (4.0.5-5) unstable; urgency=medium


  * control: Drop selinux-policy-dev from build-depends, not needed
    anymore.
  * client.dirs,postrm: Drop removing /etc/pki/nssdb from postrm and let
    dpkg handle it. (Closes: #781114)

 -- Timo Aaltonen <email address hidden>  Thu, 09 Apr 2015 17:16:37 +0300

Available diffs

Superseded in wily-release on 2015-05-13
Obsolete in vivid-release on 2018-01-18
Deleted in vivid-proposed on 2018-01-19 (Reason: moved to release)
freeipa (4.0.5-3) unstable; urgency=medium


  * rules: Set JAVA_STACK_SIZE to hopefully avoid FTBFS on exotic archs.
  * freeipa-client.postrm: Remove nssdb files on purge. (Closes:
    #775387)
  * freeipa-client.postinst: Fix bashism with echo. (Closes: #772242)

 -- Timo Aaltonen <email address hidden>  Wed, 04 Mar 2015 14:51:35 +0200
Superseded in vivid-proposed on 2015-03-04
freeipa (4.0.5-2) unstable; urgency=medium


  * Team upload.
  * Let python-freeipa depend on python-pyasn1, because pyasn1 is imported
    by ipalib/pkcs10.py and ipalib/plugins/cert.py.
  * debian/copyright: Drop unused PD license section
  * debian/copyright: Fix paths of Javascript files

 -- Benjamin Drung <email address hidden>  Mon, 24 Nov 2014 12:32:36 +0100
Published in trusty-updates on 2014-08-26
Deleted in trusty-proposed (Reason: moved to -updates)
freeipa (3.3.4-0ubuntu3.1) trusty-proposed; urgency=medium

  * fix-ntp-paths.diff: Don't use fedora paths for ntpd options. (LP:
    #1309655)
  * add-debian-platform.diff: Let testing chronyd always return false,
    since the package already conflicts with ntp so can't be
    installed/enabled at the same time. Allows configuring ntpd without
    forcing it. (LP: #1309655)
 -- Timo Aaltonen <email address hidden>   Tue, 05 Aug 2014 18:59:50 +0300
Superseded in vivid-release on 2015-03-04
Obsolete in utopic-release on 2016-11-03
Deleted in utopic-proposed on 2016-11-03 (Reason: moved to release)
freeipa (3.3.4-0ubuntu4) utopic; urgency=medium

  * fix-ntp-paths.diff: Don't use fedora paths for ntpd options. (LP:
    #1309655)
  * add-debian-platform.diff: Let testing chronyd always return false,
    since the package already conflicts with ntp so can't be
    installed/enabled at the same time. Allows configuring ntpd without
    forcing it. (LP: #1309655)
 -- Timo Aaltonen <email address hidden>   Tue, 05 Aug 2014 18:59:50 +0300

Available diffs

Superseded in utopic-release on 2014-08-05
Published in trusty-release on 2014-04-10
Deleted in trusty-proposed (Reason: moved to release)
freeipa (3.3.4-0ubuntu3) trusty; urgency=medium

  * Merge from unreleased debian git:
    Fix ipa-client-install issues (LP: #1282818)
    - fix auth platform module
    - use new pykerberos api
    - don't install a default conf
    - use sqlite-based nssdb's instead of old
 -- Timo Aaltonen <email address hidden>   Thu, 10 Apr 2014 11:57:53 +0300

Available diffs

Superseded in trusty-release on 2014-04-10
Deleted in trusty-proposed on 2014-04-11 (Reason: moved to release)
freeipa (3.3.4-0ubuntu2) trusty; urgency=medium

  * Update build-deps for the xmlrpc-c 1.33.06 transition.
 -- Adam Conrad <email address hidden>   Sat, 22 Mar 2014 11:07:49 -0600

Available diffs

Superseded in trusty-release on 2014-03-22
Deleted in trusty-proposed on 2014-03-23 (Reason: moved to release)
freeipa (3.3.4-0ubuntu1) trusty; urgency=low

  * Merge from unreleased debian git.
 -- Timo Aaltonen <email address hidden>   Tue, 03 Sep 2013 17:13:27 +0300

Available diffs

Superseded in trusty-release on 2014-02-18
Obsolete in saucy-release on 2015-04-24
Deleted in saucy-proposed on 2015-04-28 (Reason: moved to release)
freeipa (3.2.1-0ubuntu1) saucy; urgency=low

  * Merge from unreleased debian git
    - rebase to 3.2.1
    - add ipa-client-automount to freeipa-client, and patch it so it
      works on Debian/Ubuntu
 -- Timo Aaltonen <email address hidden>   Mon, 17 Jun 2013 22:15:21 +0300

Available diffs

Superseded in saucy-release on 2013-06-17
Deleted in saucy-proposed on 2013-06-19 (Reason: moved to release)
freeipa (3.2.0-0ubuntu1) saucy; urgency=low

  * Merge from unreleased debian git
    - rebase to 3.2.0
 -- Timo Aaltonen <email address hidden>   Wed, 22 May 2013 17:42:30 +0300

Available diffs

Superseded in saucy-release on 2013-05-22
Deleted in saucy-proposed on 2013-05-23 (Reason: moved to release)
freeipa (3.1.2-0ubuntu2) saucy; urgency=low

  * Rebuild against newer ding-libs for the ABI transition.
 -- Adam Conrad <email address hidden>   Mon, 29 Apr 2013 14:45:55 -0600

Available diffs

Superseded in saucy-release on 2013-04-29
Obsolete in raring-release on 2015-04-24
Deleted in raring-proposed on 2015-04-27 (Reason: moved to release)
freeipa (3.1.2-0ubuntu1) raring; urgency=low

  * Merge from unreleased debian git.
    - new upstream release
    - doesn't use chkconfig anymore (LP: #1025018, #1124093)
    - drop -U from the ntpdate options (LP: #1149468)
 -- Timo Aaltonen <email address hidden>   Thu, 07 Mar 2013 14:10:03 +0200

Available diffs

Superseded in raring-release on 2013-03-07
Deleted in raring-proposed on 2013-03-08 (Reason: moved to release)
freeipa (2.1.4-0ubuntu2) raring; urgency=low

  * 0110-Upload-CA-cert-in-the-directory-on-install.patch
    0111-Update-plugin-to-upload-CA-certificate-to-LDAP.patch
    0112-Do-SSL-CA-verification-and-hostname-validation.patch
    0113-Use-secure-method-to-acquire-IPA-CA-certificate.patch:
    - CVE-2012-5484 - The client in FreeIPA 2.x and 3.x before 3.1.2 does
      not properly obtain the Certification Authority (CA) certificate
      from the server, which allows man-in-the-middle attackers to spoof
      a join procedure via a crafted certificate. (LP: #1104954)
  * check-through-all-ldap-servers.patch: Check through all LDAP servers
    in the domain during IPA discovery (ticket #1827). Patch from 2.2
    to aid in porting patch 0113.
 -- Timo Aaltonen <email address hidden>   Mon, 11 Feb 2013 00:32:12 +0200

Available diffs

Superseded in raring-release on 2013-02-11
Obsolete in quantal-release on 2015-04-24
Published in precise-release on 2012-03-25
freeipa (2.1.4-0ubuntu1) precise; urgency=low

  * Merge from unreleased debian git (LP: #259547, #958599).
  * Build only the client package.

156 of 56 results