<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>51860</bug_id>
          
          <creation_ts>2024-10-28 13:09:39 +0300</creation_ts>
          <short_desc>Добавить зависимость на sssd-dbus к sssd-tools</short_desc>
          <delta_ts>2024-10-30 07:31:18 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>sssd-tools</component>
          <version>unstable</version>
          <rep_platform>x86_64</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P5</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Alexander Makeenkov">amakeenk</reporter>
          <assigned_to name="Evgeny Sinelnikov">sin</assigned_to>
          <cc>asheplyakov</cc>
    
    <cc>iv</cc>
    
    <cc>pashininaaa</cc>
    
    <cc>shaba</cc>
    
    <cc>sin</cc>
    
    <cc>slev</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>253527</commentid>
    <comment_count>0</comment_count>
    <who name="Alexander Makeenkov">amakeenk</who>
    <bug_when>2024-10-28 13:09:39 +0300</bug_when>
    <thetext>Без установленного пакета sssd-dbus не работает часть команд из sssd-tools, например:

```
# sssctl domain-list
InfoPipe operation failed. Check that SSSD is running and the InfoPipe responder is enabled. Make sure &apos;ifp&apos; is listed in the &apos;services&apos; option in sssd.conf.

# sssctl domain-status SAMBA.TESTDOMAIN
Unable to get online status
```</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>253623</commentid>
    <comment_count>1</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2024-10-30 07:31:18 +0300</bug_when>
    <thetext>sssd-2.9.5-alt1 -&gt; sisyphus:

 Tue Oct 29 2024 Evgeny Sinelnikov &lt;sin@altlinux&gt; 2.9.5-alt1
 - Update to latest 2.9 LTM release (fixes: CVE-2023-3758) (closes: 51860).
 - Add sssd-dbus to Requires for sssd-tools (due the InfoPipe responder using).
 - Major fixes from upstream (GitHub#5708, GitHub#7109, GitHub#7152, GitHub#7173,
                              GitHub#7197, GitHub#7250, GitHub#7319, GitHub#7375)
   + SSSD incorrectly works with AD GPO during user login (fixed a race
     condition flaw in GPO policy application).
   + gdm smartcard login fails with &quot;system error 4&quot; in case of multiple
     identities.
   + passkey cannot fall back to password, when both of user authentication
     types configured for IPA user even when user intends to do so.
   + AD users are unable to log in due to case sensitivity of user because the
     domain is found as an alias to the email address.
   + Errors in krb5_child.log every time a user authenticates:
     &quot;Pre-authentication failed: No pkinit_anchors supplied&quot;.
   + SSSD is not fully registering the domains if the cache is empty (refresh
     root domain when read directly).
   + PAC and PAM responders can crash if backend takes too long time to process
     getDomains() (use proper context if client disconnects before request is
     completed).
   + Add option &apos;failover_primary_timeout&apos; to configure timeout to reconnect to
     primary servers: minimum and default value in seconds is 31.
 - Major backported fixes from upstream (GitHub#7451, GitHub#7404, GitHub#7007,
                                         GitHub#5418, GitHub#7456, GitHub#7462,
                                         GitHub#5861, GitHub#7532, GitHub#7590,
                                         GitHub#7590, GitHub#7642)
   + sysdb: do not fail to add non-posix user to MPG domain (e.g. cause issues
     during GPO evaluation when adding a host account).
   + enhance &apos;soft_crl&apos; option (revoked certificate will now be rejected if the
     CRL is expired even if &apos;soft_crl&apos; is set).
   + pam_sss: fix passthrow of old authtok from another pam modules (issue in
     case of using &apos;use_first_pass&apos; parameter when we need to get old password
     from another module) at PAM_PRELIM_CHECK.
   + krb5_child: do not try passwords during two-factor authentication.
     It should use use the dedicated OTP auth types SSS_AUTHTOK_TYPE_2FA and
     SSS_AUTHTOK_TYPE_2FA_SINGLE exclusively and should not try password or other
     types.
   + Expose flat_name (file.file palceholder) for use in homedir path also for AD
     subdomains.
   + cert util: replace deprecated OpenSSL calls (replaces them if OpenSSL 3.0 or
     newer is used).
   + pam: only set SYSDB_LOCAL_SMARTCARD_AUTH to &apos;true&apos; but never to &apos;false&apos;.
   + sdap: allow to provide user_map when looking up group memberships of other
     objects similar to user objects but with different attribute mappings, e.g.
     host objects in AD.
   + ad: use default user_map when looking of host groups for GPO (to determine
     the group memberships of a host for GPO evaluation).
   + ad: honor ad_use_ldaps setting with ad_machine_pw_renewal passed as
     &apos;--use-ldaps&apos; argument to the adcli update command which handles the
     automatic renewal of AD machine account password.
   + Add missing &apos;dns_update_per_family&apos; option (whether DNS update of A and AAAA
     record should be performed in one update or in two separate updates).</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>