sssd-2.9.5-4.el9_5.1> M Mv ĉJ4!!%joLne)Ip-Bm5 ']g3f#releng@rockylinux.org p-Bm5 ']+1X\ڱ˓Kz!Z2F5p֣|>'t?v~Np4jD*Ia91xH#h[șlG^ܕfմ55JibW#2Krt,-{kI 꿼ٻ` G#į\51hQJ>* CxTf<;]h)93ݧNm*e?u1x)/:K!~8Fm@Pܫ3bPͨٴ6J4DyELjb,A_:Lpˁ)P+x>T.j8p!U2/ytƳbU24t726cd0aca896bbcfb5dcc7d963630584c5c565884ed0a26e50a814c69f2b592104bc735ee6da94c6bd9ef6736c111b9180528cc7^S@SnMWe>=,?,d   7 $4Y`     . 08BLlt  Q (89@: G)H)I)X)Y)\)])^)b*d+~e+f+l+t+u+v++++,,$,*,l,pCsssd2.9.54.el9_5.1System Security Services DaemonProvides a set of daemons to manage access to remote directories and authentication mechanisms. It provides an NSS and PAM interface toward the system and a pluggable back end system to connect to multiple different account sources. It is also the basis to provide client auditing and policy services for projects like FreeIPA. The sssd subpackage is a meta-package that contains the daemon as well as all the existing back ends.g3cpb-4336eed3-9ce2-437a-92f7-7a87286ed453-b-ppc64leKRocky Linux 9.5Rocky Enterprise Software FoundationGPLv3+Rocky Linux Build System (Peridot) Unspecifiedhttps://github.com/SSSD/sssd/linuxppc64leKA큤g3dfE8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903rootrootrootrootsssd-2.9.5-4.el9_5.1.src.rpmsssdsssd(ppc-64)    rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsZstd)sssd-adsssd-commonsssd-ipasssd-krb5sssd-ldapsssd-proxy3.0.4-14.6.0-14.0-15.4.18-12.9.5-4.el9_5.12.9.5-4.el9_5.12.9.5-4.el9_5.12.9.5-4.el9_5.12.9.5-4.el9_5.12.9.5-4.el9_5.14.16.1.3ffffy_fE@f/f! @fg@e!@e@e@e)eReRe@d dd@ddu@doMdbc<@c]cdAlexey Tikhonov - 2.9.5-4.1Alexey Tikhonov - 2.9.5-4Alexey Tikhonov - 2.9.5-3Alexey Tikhonov - 2.9.5-2Alexey Tikhonov - 2.9.5-1Alexey Tikhonov - 2.9.4-7Alexey Tikhonov - 2.9.4-6Alexey Tikhonov - 2.9.4-5Alexey Tikhonov - 2.9.4-4Alexey Tikhonov - 2.9.4-3Alexey Tikhonov - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-2Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-5Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1- Resolves: RHEL-59876 - EL9/CentOS Stream 9 lost offline smart card authentication - Resolves: RHEL-50912 - possible regression of rhbz#2196521- Resolves: RHEL-49711 - SYSDB: remove index on dataExpireTimestamp - Resolves: RHEL-49811 - 2FA is being enforced after upgrading 2.9.1->2.9.4- Resolves: RHEL-40742 - passkey_child with wrong owner- Resolves: RHEL-40742 - passkey_child with wrong owner - Resolves: RHEL-41047 - sssd is skipping GPO evaluation with auto_private_groups - Resolves: RHEL-40570 - GPO access the wrong memory location- Resolves: RHEL-36586 - Rebase SSSD for RHEL 9.5 - Resolves: RHEL-27716 - SSSD fails to process AD groups with 'Global Scope' correctly causing incomplete group-membership on RHEL if cache is empty - Resolves: RHEL-17659 - [RfE] SSSD Failover Enhancements - Resolves: RHEL-35781 - Passkey errors when handling multiple altSecurityIdentities values - Resolves: RHEL-30142 - sssd_pac is crashing - Resolves: RHEL-22206 - Errors in krb5_child.log every time a user authenticates - Pre-authentication failed: No pkinit_anchors supplied - Resolves: RHEL-32595 - Excessive "Domain not found' messages logged to sssd_nss & sssd_be in multidomain AD forest - Resolves: RHEL-28666 - sssctl config-check is reporting false positive error msg - Resolves: RHEL-29454 - NULL dereference in inotify handling - Resolves: RHEL-1654 - Improve documentation for allowing e-mail address as username- Relates: RHEL-33645 - Rebase Samba to the latest 4.20.x release- Resolves: RHEL-27209 - Race condition during authorization leads to GPO policies functioning inconsistently [rhel-9.4.0]- Resolves: RHEL-28161 - Passkey cannot fall back to password- Resolves: RHEL-28161 - Passkey cannot fall back to password- Resolves: RHEL-22340 - socket leak - Resolves: RHEL-28161 - Passkey cannot fall back to password- Resolves: RHEL-12503 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. - Resolves: RHEL-22288 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd - Resolves: RHEL-22194 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities- Resolves: RHEL-2632 - Rebase SSSD for RHEL 9.4 - Resolves: RHEL-18395 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users - Resolves: RHEL-17498 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') [rhel-9] - Resolves: RHEL-21079 - SSSD GPO lacks group resolution on hosts [rhel-9] - Resolves: RHEL-19211 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest [rhel-9]- Resolves: RHEL-2632 - Rebase SSSD for RHEL 9.4- Resolves: RHEL-2632 - Rebase SSSD for RHEL 9.4 - Resolves: RHEL-14427 - Expected cn in RDN, got uid - Resolves: RHEL-12229 - HANA validation on RHEL 9.2 issue possibly related to libc/nss_sss behaviour - Resolves: RHEL-3925 - SSSD goes offline when, while reading a single user, misses a required attribute (i.e. SID) - Resolves: RHEL-2319 - Passkey authentication for centrally managed users - Resolves: RHEL-4146 - Incorrect handling of reverse IPv6 update results in update failure - Resolves: RHEL-4971 - sssd-kcm does not appear to expire Kerberos tickets (RFE: sssd_kcm should have the option to automatically delete the expired tickets)- Resolves: RHEL-2319 - Passkey authentication for centrally managed users- Resolves: RHEL-2632 - Rebase SSSD for RHEL 9.4 - Resolves: RHEL-2319 - Passkey authentication for centrally managed users - Resolves: rhbz#2234829 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working) - Resolves: rhbz#2236119 - dbus and crond getting terminated with SIGBUS in sss_client code- Resolves: rhbz#2218858 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167837 - Rebase SSSD for RHEL 9.3 - Resolves: rhbz#2196816 - [RHEL9] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2162552 - sssd client caches old data after removing netgroup member on IDM - Resolves: rhbz#2189542 - [sssd] RHEL 9.3 Tier 0 Localization - Resolves: rhbz#2133854 - [RHEL9] In some cases when `sdap_add_incomplete_groups()` is called with `ignore_group_members = true`, groups should be treated as complete - Resolves: rhbz#1765354 - [RFE] - Show password expiration warning when IdM users login with SSH keys- Related: rhbz#2190415 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs.- Related: rhbz#2190415 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs.- Resolves: rhbz#2167837 - Rebase SSSD for RHEL 9.3- Resolves: rhbz#2167837 - Rebase SSSD for RHEL 9.3 - Resolves: rhbz#1765354 - [RFE] - Show password expiration warning when IdM users login with SSH keys - Resolves: rhbz#1913839 - filter_groups doesn't filter GID from 'id' output: AD + 'ldap_id_mapping = True' corner case - Resolves: rhbz#2100789 - [Improvement] sssctl config-check command does not show an error when we don't have id_provider in the domain section - Resolves: rhbz#2152177 - [RFE] Add support for ldapi:// URLs - Resolves: rhbz#2164852 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2166627 - Improvement: sss_client: add 'getsidbyusername()' and 'getsidbygroupname()' and corresponding python bindings - Resolves: rhbz#2166943 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2167728 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed)- Resolves: rhbz#2160001 - Reference to 'sssd-ldap-attributes' man page is missing in 'sssd-ldap', etc man pages - Resolves: rhbz#2143159 - automount killed by SIGSEGV- Resolves: rhbz#2127510 - Rebase SSSD for RHEL 9.2 - Resolves: rhbz#1608496 - sssd failing to register dynamic DNS addresses against an AD server due to unnecessary DNS search - Resolves: rhbz#2110091 - SSSD doesn't handle changes in 'resolv.conf' properly (when started right before network service) - Resolves: rhbz#2136791 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139684 - [sssd] RHEL 9.2 Tier 0 Localization - Resolves: rhbz#2139837 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142794 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144893 - changing password with ldap_password_policy = shadow does not take effect immediately - Resolves: rhbz#2148737 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around- Resolves: rhbz#2127510 - Rebase SSSD for RHEL 9.2 - Resolves: rhbz#1507035 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#1766490 - Use negative cache better and domain checks for lookup by SIDs - Resolves: rhbz#1964121 - RFE: Add an option to sssd config to convert home directories to lowercase (or add a new template for the 'override_homedir' option) - Resolves: rhbz#2074307 - reduce debug level in case well_known_sid_to_name() fails - Resolves: rhbz#2096031 - SSSD: sdap_handle_id_collision_for_incomplete_groups debug message missing a new line - Resolves: rhbz#2103325 - Supported AD group types should be explained in the docs - Resolves: rhbz#2111388 - authenticating against external IdP services okta (native app) with OAuth client secret failed - Resolves: rhbz#2115171 - SSSD: duplicate dns_resolver_* option in man sssd.conf - Resolves: rhbz#2127492 - sssd timezone issues sudonotafter - Resolves: rhbz#2128840 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2128883 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2136791 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139837 - Analyzer: Optimize and remove duplicate messages in verbose list2.9.5-4.el9_5.12.9.5-4.el9_5.1sssdCOPYING/usr/share/licenses//usr/share/licenses/sssd/-O2 -flto=auto -ffat-lto-objects -fexceptions -g -grecord-gcc-switches -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -fstack-protector-strong -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mcpu=power9 -mtune=power9 -fasynchronous-unwind-tables -fstack-clash-protectioncpiozstd19ppc64le-redhat-linux-gnudirectoryASCII textlogrotatepython3-sssdconfigsssd-dbus2.9.5-4.el9_5.12.9.5-4.el9_5.1utf-8e0408b4fe6afe7183bb8cef21a898f9c3231db792b253046c09fa751867066876547696aa43c6fb0d70d5227756d9c663cc6f4bf8a6d964bcf03f8d37b92b225?0(/hZ,h}L"Jvw.Ӷ@,H]aF)yup|6oB2?3EroSb'|R7fJk=tAAB&m%ݹd' m6 p37|EqJrNo篾,;9;~0_llG;/{ l=#˨I?a;hZ}\gy%W!S-C.a!PUfIwoXݹ6 T\~SUZt_YsO'dLc p,.#ekH47!r@% nYSC'AA,B \TP0`aAA%`"D (wͤ!hoH#,XЀJ Aa4+b} vq}sbJ]qm@霪hdIo¦jSSRbe;%}d0s)0NuvK[d V*Ez-|ϔ2P~oyq-KD!ShdJ@YqjJؗ.h#ȄdXvo$Yⳝ\zm@x|Vr; (ĕ@׼N%#-\z Lrq㈴ fR 6fq1\-9Q3*#US>eg* s@,kk'LƲm2{HJ k}%W."s'de;_C ;?+4̈́dZL܀n*SŶkJ WZfyĸ1 -4V(Q,ew>bQfRquwL[ss}O&my\m4,Ea8vB^\vMϕxc6fnJeM 4%r rqnBCYg3 22-)(6TAHܱZTBARL,Tɣ;r7@_<ݘ3V9eiT SBA $[RǗ5}E@BG:Me+!Ԯ)U0K:bu*,SJwX  P.f-]V[!os*Y*\A!ǨiT2E"$IS 0`lD=PS{x@1"#""#%))dPE 9#X"B\;q7Aw :˽"EpЦ&R#4qE{6>i5!S#*JXd[BA CQn.sڋ"ҟ&DQN'~&/EqHj"J}.% .?&.e%85v ")S?Y$ 3Of'vtGgxbk3CU܏%\}AV$ow 7<!G]kԙMRR!E#;ɺH⁸DG6PPB4P["DŽ 7@)BLjg ox4A'b $/VcMEequⱸAn/<|̔zȯ3u >H!:֔l;4q f{;<§၀?mci 7oPYhIS<W|}GlD2cf?`ZW=(̼plhL?(UIx:Ƣh`6~D_+ vZrT0!;|9$ʿq.YK6*ugmDj)  ƨ) Ch#w 531*mabӘWm 寃w,C HYtLz-:/qs?_ q*GsKNɐJnzOxy%b& Ml+/UnTNj2oxci?zdgjӋtmd5ԍX$xPK&M3-'n2\hJbcI9Eu)UZI fX5ӬšaH0r!vY8T:drF"#:ˑc#mD0LsB$Fĩ xԤ12ȍr,%K93Y +N'? M$t\(MJd6]pm Gzfb#N٤0̉W9Q{&*KrXˆVAU/^aSU^ `lyz<üַ(8z?}RtczsZ3sy\>JݶOli} 2L 7*x Kb?ZRfrI1wk/ɾ''Y="4QWrne_IHK=牏*OyP{v}ҼHCV3GtŀR.ʘfvj=&ǗHYʴrue^ZW8—r"A bF$PJÍԋ'Idఌ-e;yY"}3'uöiФa~ ¦eta#|Ld (Rѥ+*i*jIyg2 m@(p  J`BگZD"c;ሆ}.ڀHQ,Jz&(bhq1;kmdyhT1CpߥHk 0o3/ ĢP[^(,R}mpSufצ{Hح1`vظAlohx) 8wEzJa% s!#,| ke015׊68q؞</!ơ+@U|,G.f7c8 e^35N=P67sS)Z qRW}SRיdhĉ Lq1Q%op"-%oR>#!ɑ۬ ũBITC\v#2t"L$ÑvJ*_p \14%#SuP˜ոh H{j=GǣIEj'. ˦ZOd%l=vҶukee~Ԧi-_O, D"yXNDvPs W,Rv0Y,vT"z-2 +R(ԼZxT9 \ hOv|.QҺu曢enkfHm6 `>Id񍃖mJpf+ Jb_|L_*K?s (exH+npwhM'pI`JrNК4{dYghVuBNW–Y 9J_)uW~5dsJEl" }7$ X^!D˶gtmYnd"V[3IjY,@tU?hc熤 DQTTeF'&?(2)7As6Ar6>үyRu^`]Pp0^XV?ۢgUn5Kёr_Kow?8JEG.?M'L<͋ O>l"Vꗂ^\S­Z ofL.9'|D:YrtnUfl۩];h`ݽ&NHy䖝AP޿\ܼi.qV@MbPd52F07w$shXjڋ p-ikE&w57|m}LZB9@*\k(iznY.fKIECn`0R5Tb y Lq S z|Ԕ8r? Ep܂٣ hM~=_Iv7 -߮v63p'.?ԓ4:J7HPNm,ʬe 2Smc8SxpHu֍n.+ոa)}v $3\hfndH>!dE䂄.S-.;Nq6 E=;$Hy kYq~|Nh2(jfrw=P.pw b1s*EWgrDUQ(&gN)-J U4f mm bS;Y.ˍoI-F;jVxAss~.Y@}8dEaiFFNoVV-g6 cF;ozؓ㤺n ^o#EL3Vފ8ܷbn7EI<1 5e&x. ؜@P oDiXrF @0jRC)tNX0M?]_* 4z W)©ƋvhG@#>ȗ3F5/(AXg݄] &Mcx"t$$dzjIYyZU*n2BhR|t]ݬj&8Exp2w2aplMӂm^SNiY,l*zfZd|ʑU㜲BZ?>fhQh6Ul kdl]{}ȵLM ()iEs3zb+/_R(>`#{jYn)VLnoE-3(eiF\x}*RgF&?2QC ~/ϋ&3cz0GTR^{ffJ+o}Z7Η>YS8Jfmeq\@ wtU`n~L*-jee}2^JLUN8^12on Pq%KN v EhU/R#`1vbYՅ62W}Y+VN+紒gY[4Z'@]'gfJS/KI'(eH}2 IfɢeϘ3oaVH9'g0YGi8WxpGAƃhM\{׀ MX;Γ`t'<8Mq"z=8A$sOb8kk8hcxI DDv"(%͑0#=GO<`@aIi z 5$5E5'% D+"x{l]Á,=<(=(kR.zP?!R1hN;14@tI҃@iqRI :`!4DCOGtA @D4L pa?%W֝+k}B١N]B'q)[*ӛ^]&$A|kdz_+lE/M&q;1͂+]V`k "JÐbm<Fd!4 G,̕xPb|D" %l0$@)n ١oH."l2iK>- gc<@00*/V\](6lo'p*zZ.9A.ѣUBDCMMȋ\z`YY$ ̲5 :jdOcw_V# Dn~, tx? &kT*Ap62iD @w7"obiKgq|Vk;]lCtb7 > -N-;r,տ5:.,BC'1y~YWJ.Ծ*iћbJ B]BD}A*(ڪuл@v _-Ciiw{ٓCOsU֊Yb<1rptB|&5'۔3ޕ*2X5kμ*C ̝ [ p2]0TA}7d/$w J4'5>t3֊&3zPT]DE"/q.J@4:RbϯbȺc|cRedփmjZjUK8j ܟMEs:h^1KꩿW+XgGK u.y:u2ߩlh Ɇ7]%7>ڭtg(#s0R371{`dO1uL[ƒš.8?+&@5jd0XTNrX_vV@6$ߏ,߈9nQ[r_f`C%3+81!.5R%A(JmdsѢBfI$^% A uH*Y%pM+*⴫ṕ"kzen%CKyCb wQ"@ Z }}pADpثVǸZ9p[|zA/3m[}r=BȚ!F~K]v죉F%|IC 3FY "HYy1pjPooz֑>% T:3NGİ,,0v`4h^VSs鎐fsT= >%VܖzA 1):B0pYWԞeڑ0Nǹkpj21B;# dP ݧ*O\fwd7JbwuJe3hJ95v>6:lO K7`c%FCfRmteq8(K*YPn/|uRyH& P,v0VGb랓#|XQ] :@Sy1`ptL8CE ɠRDVDz!fy*Kap+o~=F~Ա`3iw352g@mWgl9z4jy&<8YjP{n4+\1@W_O?[d%XN0J^?Q d0ht> lMvԎ鹡#øsJ3u_xR#=Nu SU-T\Luao`q46&[ق1Fxq:%>/ JuW-("xivy G Nw-F5 6mk0u_.I\BN!:'= ?V3D=PW>k/ڼ41l!Hi},??jXqҨJùeW_X~`hI%Yiú6% hbem獺4s2:g(MV+#n; J|rʹaw?i 9/bb# 6Ww_03YML6qN0ױR)g7K^qFrSW::`3 C*4.Gg3ҧ5RRs+qߢ䞩G㎄ƬTW wU>&j[J~ C+WM !bc!nbaTgsPyn-NȘ;)R: G 'v4eN z0kn"6oD;g$x^Vq"ovdK\?LTd! Ul#ė.@ =a9GA*i)hTϦ[wBrD/T)Afpޣ,zC+a,iOl&# I5Q$Gc|jm3,X;>^Z \}KLHSkRI;:3"k9LՓQFfzj2hIq˗e׼,nAe7\V I+#`̪cΖDO܉jgDbk հh`Ōq86S.P~'C(E: *!''@~ןҪ92rbGzT% $qgC z?0?sl%6R@z`wAb0CkPUE.wcJ£*_[JʮQx$ ǂP(`hOldÆ>hxdS lki2:n]rkec=7$V\ʀ Tj܅3>:?)~rцluًʟQy*ATa_&hE86D :)ݢ<]鬼(ld %IgȞk+-]Qz>,.05{OAYV