Package sssd: Information

  • Default inline alert: Version in the repository: 2.9.4-alt2

Source package: sssd
Version: 2.9.3-alt1
Latest version according to Repology
Build time:  Nov 23, 2023, 10:06 AM in the task #333680
Category: System/Servers
Report package bug
License: GPLv3+
Summary: System Security Services Daemon
Description: 
Provides a set of daemons to manage access to remote directories and
authentication mechanisms. It provides an NSS and PAM interface toward
the system and a pluggable backend system to connect to multiple different
account sources. It is also the basis to provide client auditing and policy
services for projects like FreeIPA.

The sssd subpackage is a meta-package that contains the deamon as well as all
the existing back ends.

List of rpms provided by this srpm:
libipa_hbac (x86_64, ppc64le, i586, armh, aarch64)
libipa_hbac-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libipa_hbac-devel (x86_64, ppc64le, i586, armh, aarch64)
libsss_autofs (x86_64, ppc64le, i586, armh, aarch64)
libsss_autofs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsss_certmap (x86_64, ppc64le, i586, armh, aarch64)
libsss_certmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsss_certmap-devel (x86_64, ppc64le, i586, armh, aarch64)
libsss_idmap (x86_64, ppc64le, i586, armh, aarch64)
libsss_idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsss_idmap-devel (x86_64, ppc64le, i586, armh, aarch64)
libsss_nss_idmap (x86_64, ppc64le, i586, armh, aarch64)
libsss_nss_idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsss_nss_idmap-devel (x86_64, ppc64le, i586, armh, aarch64)
libsss_sudo (x86_64, ppc64le, i586, armh, aarch64)
libsss_sudo-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-ipa_hbac (x86_64, ppc64le, i586, armh, aarch64)
python3-module-ipa_hbac-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss-murmur (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss-murmur-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss_nss_idmap (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss_nss_idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sssd (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sssdconfig (noarch)
sssd (x86_64, ppc64le, i586, armh, aarch64)
sssd-ad (x86_64, ppc64le, i586, armh, aarch64)
sssd-ad-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-client (x86_64, ppc64le, i586, armh, aarch64)
sssd-client-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-dbus (x86_64, ppc64le, i586, armh, aarch64)
sssd-dbus-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-idp (x86_64, ppc64le, i586, armh, aarch64)
sssd-idp-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-ipa (x86_64, ppc64le, i586, armh, aarch64)
sssd-ipa-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-kcm (x86_64, ppc64le, i586, armh, aarch64)
sssd-kcm-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-krb5 (x86_64, ppc64le, i586, armh, aarch64)
sssd-krb5-common (x86_64, ppc64le, i586, armh, aarch64)
sssd-krb5-common-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-krb5-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-ldap (x86_64, ppc64le, i586, armh, aarch64)
sssd-ldap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-nfs-idmap (x86_64, ppc64le, i586, armh, aarch64)
sssd-nfs-idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-pac (x86_64, ppc64le, i586, armh, aarch64)
sssd-pac-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-passkey (x86_64, ppc64le, i586, armh, aarch64)
sssd-passkey-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-proxy (x86_64, ppc64le, i586, armh, aarch64)
sssd-proxy-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-tools (x86_64, ppc64le, i586, armh, aarch64)
sssd-tools-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-winbind-idmap (x86_64, ppc64le, i586, armh, aarch64)
sssd-winbind-idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)

Maintainer: Evgeny Sinelnikov



    1. libpcre2-devel
    2. nscd
    3. nss-utils
    4. nss_wrapper
    5. python3-devel
    6. /dev/pts
    7. cifs-utils-devel
    8. libpopt-devel
    9. libcares-devel
    10. libcheck-devel
    11. libcmocka-devel >= 1.0.0
    12. libcollection-devel >= 0.5.1
    13. libsasl2-devel
    14. libcurl-devel
    15. libselinux-devel
    16. libsemanage-devel
    17. libdbus-devel
    18. libsmbclient-devel
    19. openssh
    20. openssl
    21. /proc
    22. libdhash-devel >= 0.4.2
    23. pam_wrapper
    24. libssl-devel
    25. diffstat
    26. docbook-dtds
    27. docbook-style-xsl
    28. doxygen
    29. libfido2-devel
    30. glib2-devel
    31. findutils
    32. gnutls-utils
    33. rpm-build-python3
    34. libgnutls-devel
    35. adcli
    36. libsystemd-devel
    37. libtalloc-devel
    38. libtdb-devel >= 1.1.3
    39. bind-utils
    40. libtevent-devel
    41. po4a
    42. libunistring-devel
    43. libuuid-devel
    44. libhttp-parser-devel
    45. libini_config-devel >= 1.3.0
    46. libjansson-devel
    47. libjose-devel
    48. libkeyutils-devel
    49. libxml2-devel
    50. samba-devel
    51. samba-winbind
    52. libxslt
    53. softhsm
    54. libkrb5-devel
    55. libldap-devel
    56. libldb-devel >= 1.3.3
    57. uid_wrapper
    58. xsltproc
    59. xml-utils
    60. libnspr-devel
    61. libnss-devel
    62. libnfsidmap-devel >= 1:2.2.1-alt1
    63. libp11-kit-devel
    64. libpam-devel
    65. libnl-devel

Last changed


Nov. 20, 2023 Evgeny Sinelnikov 2.9.3-alt1
- Update to latest 2.9 major release.
  + KCM: provide mechanism to purge expired credentials.
  + Default hardening - id_provider channel defaults unencrypted with starttls.
  + sssd-sudo missing debug statement in its .service file.
  + SSSD goes offline during initgroups of trusted user if a group is
    missing SID.
  + Incorrect handling of reverse IPv6 update results in update failure.
  + sssd-2.9.2 breaks smart card authentication (on el8).
- The proxy provider is now able to handle certificate mapping and matching
  rules and users handled by the proxy provider can be configured for local
  Smartcard authentication.
- Passkey doesn't fail when using FreeIPA server-side authentication and
  require-user-verification=false.
- When adding a new credential to KCM and the user has already reached their
  limit, the oldest expired credential will be removed to free some space.
Oct. 6, 2023 Evgeny Sinelnikov 2.9.2-alt1
- Update to latest 2.9 major release.
- sss_simpleifp library removed due it deprecated.
- "Files provider" removed due it deprecated, using "Proxy provider" with
  proxy_lib_name = files instead.
- New passkey functionality, which will allow the use of FIDO2 compliant devices
  to authenticate a centrally managed user locally.
- Default value of cache_first option was changed to true.
- sssctl cert-show and cert-show cert-eval-rule can now be run as non-root user.
- certmap: Handle type change of x400Address (due to CVE-2023-0286).
- New option local_auth_policy is added to control which offline authentication
  methods will be enabled by SSSD.
- SSSD can be configured not to perform a DNS search during DNS name resolution.
  This behavior is governed by the new dns_resolver_use_search_list in the
  domain section. Default value is true (follows the system settings).
July 28, 2023 Ivan A. Melnikov 2.8.1-alt3.1
- NMU: Backport upstream commit to fix build with krb5 1.21*