Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 880097 - sys-auth/sssd-2.8.2 version bump
Summary: sys-auth/sssd-2.8.2 version bump
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal with 1 vote (vote)
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-11-06 21:15 UTC by Joakim Tjernlund
Modified: 2023-09-06 08:29 UTC (History)
5 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
sssd-9999.ebuild (sssd-9999.ebuild,7.90 KB, text/plain)
2022-11-26 18:46 UTC, Joakim Tjernlund
Details
Latest sssd-9999.ebuild (sssd-9999.ebuild,7.80 KB, text/plain)
2023-03-27 19:47 UTC, Joakim Tjernlund
Details
krb5_pw_locked.patch (krb5_pw_locked.patch,453 bytes, patch)
2023-03-27 19:48 UTC, Joakim Tjernlund
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Joakim Tjernlund 2022-11-06 21:15:13 UTC
Lots has changed since 2.6.0 currently in Gentoo
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2022-11-06 21:16:05 UTC
fwiw I think we'd really appreciate a dedicated maintainer for this who is actively using it - it's usually kind of fragile to touch and needs a fair bit of love
Comment 2 Joakim Tjernlund 2022-11-26 18:46:21 UTC
Created attachment 837285 [details]
sssd-9999.ebuild

My sssd-9999.ebuild
Comment 3 Joakim Tjernlund 2023-01-18 21:58:17 UTC
SSSD 2.8.2 Release Notes
Highlights
General information

    SSSD can be configured not to perform a DNS search during DNS name resolution. This behavior is governed by the new dns_resolver_use_search_list. This parameter can be used in the domain section. Default value is true - that means that SSSD follows the system settings.
    --enable-files-domain configure option is deprecated and will be removed in one of the next versions of SSSD.
    sssctl analyze tool doesn't require anymore to be run under root.

New features

    New mapping template for serial number, subject key id, SID, certificate hashes and DN components are added to libsss_certmap.
Comment 4 John M. Drescher 2023-03-27 19:00:16 UTC
Where can I get the krb5_pw_locked.patch to test?
Comment 5 Joakim Tjernlund 2023-03-27 19:47:51 UTC
Created attachment 859133 [details]
Latest sssd-9999.ebuild
Comment 6 Joakim Tjernlund 2023-03-27 19:48:14 UTC
Created attachment 859135 [details, diff]
krb5_pw_locked.patch
Comment 7 Joakim Tjernlund 2023-03-27 19:49:41 UTC
(In reply to John M. Drescher from comment #4)
> Where can I get the krb5_pw_locked.patch to test?

Here you go

PS.
   Stay away from net-nds/openldap-2.6.3-r7
Comment 8 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-08-27 18:38:58 UTC
(In reply to Joakim Tjernlund from comment #7)
> PS.
>    Stay away from net-nds/openldap-2.6.3-r7

If you're having a problem, please file a bug for it - or reference the bug you're talking about. Otherwise it's just scaremongering.

Maybe you mean bug 911674, but I can't really guess.
Comment 9 Joakim Tjernlund 2023-08-28 08:09:54 UTC
(In reply to Sam James from comment #8)
> (In reply to Joakim Tjernlund from comment #7)
> > PS.
> >    Stay away from net-nds/openldap-2.6.3-r7
> 
> If you're having a problem, please file a bug for it - or reference the bug
> you're talking about. Otherwise it's just scaremongering.
> 
> Maybe you mean bug 911674, but I can't really guess.

Always a pleasure!
No it is https://bugs.gentoo.org/892009, it started here though:
https://github.com/SSSD/sssd/issues/6537
It is about openldap lost -DLDAP_CONNECTIONLESS conf and it turns
out that adcli/sssd needs it to function properly.
Now Gentoo openlap has USE=experimental which will add back LDAP_CONNECTIONLESS
Comment 10 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-08-28 15:30:56 UTC
Ah, thanks.  Let's stable that then.
Comment 11 Joakim Tjernlund 2023-08-28 15:53:49 UTC
(In reply to Sam James from comment #10)
> Ah, thanks.  Let's stable that then.

Yes, stabling >=openldap-2.6.4-r2 is a good idea
Comment 12 Larry the Git Cow gentoo-dev 2023-09-06 08:29:30 UTC
The bug has been closed via the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1e446ceef146a87ec68f2629ea69674a8393dc43

commit 1e446ceef146a87ec68f2629ea69674a8393dc43
Author:     Christopher Byrne <salah.coronya@gmail.com>
AuthorDate: 2023-09-06 08:29:13 +0000
Commit:     David Seifert <soap@gentoo.org>
CommitDate: 2023-09-06 08:29:13 +0000

    sys-auth/sssd: add 2.9.1
    
    Closes: https://bugs.gentoo.org/499578
    Closes: https://bugs.gentoo.org/542324
    Closes: https://bugs.gentoo.org/592402
    Closes: https://bugs.gentoo.org/640760
    Closes: https://bugs.gentoo.org/752978
    Closes: https://bugs.gentoo.org/878177
    Closes: https://bugs.gentoo.org/880097
    Closes: https://bugs.gentoo.org/904280
    Closes: https://bugs.gentoo.org/906292
    Closes: https://github.com/gentoo/gentoo/pull/32466
    Signed-off-by: Christopher Byrne <salah.coronya@gmail.com>
    Signed-off-by: David Seifert <soap@gentoo.org>

 sys-auth/sssd/Manifest                             |   1 +
 .../sssd/files/sssd-2.8.2-krb5_pw_locked.patch     |  12 +
 ...ept-krb5-1.21-for-building-the-PAC-plugin.patch |  31 ++
 ...9.1-certmap-fix-partial-string-comparison.patch |  87 ++++++
 .../sssd-2.9.1-conditional-python-install.patch    |  19 ++
 ...-cert-show-and-cert-eval-rule-as-non-root.patch |  39 +++
 sys-auth/sssd/metadata.xml                         |  10 +
 sys-auth/sssd/sssd-2.9.1.ebuild                    | 330 +++++++++++++++++++++
 8 files changed, 529 insertions(+)