Activity log for bug #860297

Date Who What changed Old value New value Message
2011-09-27 06:47:01 Timo Aaltonen bug added bug
2011-09-27 06:58:45 Timo Aaltonen description There is a new release available from the stable branch. The latest one was release in 2011-08-29, so no showstoppers in there whereas the current version has a few. Here's a breakup of the release notes from each one since 1.5.8. So while there are a couple of new features, they are more for admin flexibility or related to FreeIPA (which is not packaged). 1.5.9: New Features Support for overriding home directory, shell and primary GID locally Properly honor TTL values from SRV record lookups Support non-POSIX groups in nested group chains (for RFC2307bis LDAP servers) Important Bugfixes Properly escape IPv6 addresses in the failover code Do not crash if inotify fails (e.g. resource exhaustion) Don't add multiple TGT renewal callbacks (too many log messages) 1.5.10: Fixed a regression introduced in 1.5.9 that could result in blocking calls to LDAP 1.5.11: Fix a serious regression that prevented SSSD from working with ldaps:// URIs IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 address being saved to the AAAA record. 1.5.12: Fixes a regression introduced in 1.5.11 with hostname resolution Fixes an issue where sssd_pam would leak file descriptors until resource exhaustion Complete rewrite of the FreeIPA Host-Based Access Control (HBAC) resolver New shared library for HBAC access-control Fixes for password expiration handling with LDAP auth New option to veto certain centrally-managed shells (Patch by John Hodrien) 1.5.13: Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) Three HBAC regressions have been fixed. There is a new release available from the stable branch. The latest one was released in 2011-08-29, so no showstoppers in there whereas the current version has a few. Here's a breakup of the release notes from each one since 1.5.8. So while there are a couple of new features, they are more for admin flexibility or related to FreeIPA (which is not packaged). 1.5.9: New Features     Support for overriding home directory, shell and primary GID locally     Properly honor TTL values from SRV record lookups     Support non-POSIX groups in nested group chains (for RFC2307bis LDAP servers) Important Bugfixes     Properly escape IPv6 addresses in the failover code     Do not crash if inotify fails (e.g. resource exhaustion)     Don't add multiple TGT renewal callbacks (too many log messages) 1.5.10:     Fixed a regression introduced in 1.5.9 that could result in blocking calls to LDAP 1.5.11:     Fix a serious regression that prevented SSSD from working with ldaps:// URIs     IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 address being saved to the AAAA record. 1.5.12:     Fixes a regression introduced in 1.5.11 with hostname resolution     Fixes an issue where sssd_pam would leak file descriptors until resource exhaustion     Complete rewrite of the FreeIPA Host-Based Access Control (HBAC) resolver     New shared library for HBAC access-control     Fixes for password expiration handling with LDAP auth     New option to veto certain centrally-managed shells (Patch by John Hodrien) 1.5.13:     Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep)     SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined     The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided.     Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory)     Three HBAC regressions have been fixed.
2011-09-27 07:21:33 Launchpad Janitor sssd (Ubuntu): status New Confirmed
2011-09-27 07:21:50 Myllynen bug added subscriber Myllynen
2011-09-27 07:33:53 Timo Aaltonen sssd (Ubuntu): status Confirmed Incomplete
2011-09-27 09:58:35 Timo Aaltonen sssd (Ubuntu): importance Undecided Wishlist
2011-09-27 09:58:35 Timo Aaltonen sssd (Ubuntu): status Incomplete Confirmed
2011-09-27 09:59:10 Timo Aaltonen sssd (Ubuntu): status Confirmed New
2011-09-27 10:06:39 Timo Aaltonen bug added subscriber Ubuntu Release Team
2011-09-28 16:57:27 Iain Lane bug added subscriber Iain Lane
2011-09-29 15:55:01 Timo Aaltonen attachment added 1.5.8vs1.5.13.diff https://bugs.launchpad.net/ubuntu/+source/sssd/+bug/860297/+attachment/2481399/+files/1.5.8vs1.5.13.diff
2011-09-30 08:03:29 Timo Aaltonen attachment removed 1.5.8vs1.5.13.diff https://bugs.launchpad.net/ubuntu/+source/sssd/+bug/860297/+attachment/2481399/+files/1.5.8vs1.5.13.diff
2011-09-30 08:04:10 Timo Aaltonen attachment added 1.5.8-1.5.13.diff https://bugs.launchpad.net/ubuntu/+source/sssd/+bug/860297/+attachment/2485611/+files/1.5.8-1.5.13.diff
2011-09-30 08:12:50 Iain Lane sssd (Ubuntu): status New Confirmed
2011-09-30 09:28:55 Launchpad Janitor sssd (Ubuntu): status Confirmed Fix Released