Package sssd: Information

  • Default inline alert: Version in the repository: 2.9.4-alt2

Source package: sssd
Version: 2.9.4-alt1
Latest version according to Repology
Build time:  Jan 21, 2024, 10:45 PM in the task #338343
Category: System/Servers
Report package bug
License: GPLv3+
Summary: System Security Services Daemon
Description: 
Provides a set of daemons to manage access to remote directories and
authentication mechanisms. It provides an NSS and PAM interface toward
the system and a pluggable backend system to connect to multiple different
account sources. It is also the basis to provide client auditing and policy
services for projects like FreeIPA.

The sssd subpackage is a meta-package that contains the deamon as well as all
the existing back ends.

List of rpms provided by this srpm:
libipa_hbac (x86_64, ppc64le, i586, armh, aarch64)
libipa_hbac-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libipa_hbac-devel (x86_64, ppc64le, i586, armh, aarch64)
libsss_autofs (x86_64, ppc64le, i586, armh, aarch64)
libsss_autofs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsss_certmap (x86_64, ppc64le, i586, armh, aarch64)
libsss_certmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsss_certmap-devel (x86_64, ppc64le, i586, armh, aarch64)
libsss_idmap (x86_64, ppc64le, i586, armh, aarch64)
libsss_idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsss_idmap-devel (x86_64, ppc64le, i586, armh, aarch64)
libsss_nss_idmap (x86_64, ppc64le, i586, armh, aarch64)
libsss_nss_idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsss_nss_idmap-devel (x86_64, ppc64le, i586, armh, aarch64)
libsss_sudo (x86_64, ppc64le, i586, armh, aarch64)
libsss_sudo-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-ipa_hbac (x86_64, ppc64le, i586, armh, aarch64)
python3-module-ipa_hbac-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss-murmur (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss-murmur-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss_nss_idmap (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss_nss_idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sssd (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sssdconfig (noarch)
sssd (x86_64, ppc64le, i586, armh, aarch64)
sssd-ad (x86_64, ppc64le, i586, armh, aarch64)
sssd-ad-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-client (x86_64, ppc64le, i586, armh, aarch64)
sssd-client-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-dbus (x86_64, ppc64le, i586, armh, aarch64)
sssd-dbus-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-idp (x86_64, ppc64le, i586, armh, aarch64)
sssd-idp-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-ipa (x86_64, ppc64le, i586, armh, aarch64)
sssd-ipa-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-kcm (x86_64, ppc64le, i586, armh, aarch64)
sssd-kcm-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-krb5 (x86_64, ppc64le, i586, armh, aarch64)
sssd-krb5-common (x86_64, ppc64le, i586, armh, aarch64)
sssd-krb5-common-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-krb5-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-ldap (x86_64, ppc64le, i586, armh, aarch64)
sssd-ldap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-nfs-idmap (x86_64, ppc64le, i586, armh, aarch64)
sssd-nfs-idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-pac (x86_64, ppc64le, i586, armh, aarch64)
sssd-pac-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-passkey (x86_64, ppc64le, i586, armh, aarch64)
sssd-passkey-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-proxy (x86_64, ppc64le, i586, armh, aarch64)
sssd-proxy-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-tools (x86_64, ppc64le, i586, armh, aarch64)
sssd-tools-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-winbind-idmap (x86_64, ppc64le, i586, armh, aarch64)
sssd-winbind-idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)

Maintainer: Evgeny Sinelnikov



    1. /dev/pts
    2. libsemanage-devel
    3. /proc
    4. libsmbclient-devel
    5. libssl-devel
    6. diffstat
    7. adcli
    8. docbook-dtds
    9. docbook-style-xsl
    10. bind-utils
    11. doxygen
    12. libsystemd-devel
    13. findutils
    14. libtalloc-devel
    15. cifs-utils-devel
    16. libtdb-devel >= 1.1.3
    17. libtevent-devel
    18. libunistring-devel
    19. libuuid-devel
    20. libxml2-devel
    21. libxslt
    22. glib2-devel
    23. gnutls-utils
    24. nscd
    25. nss-utils
    26. nss_wrapper
    27. openssh
    28. openssl
    29. pam_wrapper
    30. po4a
    31. libcares-devel
    32. libcheck-devel
    33. libcmocka-devel >= 1.0.0
    34. libcollection-devel >= 0.5.1
    35. libcurl-devel
    36. libdbus-devel
    37. libdhash-devel >= 0.4.2
    38. libfido2-devel
    39. rpm-build-python3
    40. libkrb5-devel
    41. libnspr-devel
    42. libnss-devel
    43. libhttp-parser-devel
    44. libgnutls-devel
    45. libldap-devel
    46. libldb-devel >= 1.3.3
    47. libini_config-devel >= 1.3.0
    48. uid_wrapper
    49. libpopt-devel
    50. libp11-kit-devel
    51. libpam-devel
    52. samba-devel
    53. libsasl2-devel
    54. samba-winbind
    55. libselinux-devel
    56. libpcre2-devel
    57. python3-devel
    58. xml-utils
    59. softhsm
    60. libnfsidmap-devel >= 1:2.2.1-alt1
    61. libnl-devel
    62. libjansson-devel
    63. libjose-devel
    64. libkeyutils-devel
    65. xsltproc

Last changed


Jan. 17, 2024 Evgeny Sinelnikov 2.9.4-alt1
- Update to latest 2.9 major release in long-term maintenance (LTM) phase.
- Fixes from upstream:
  + A crash when PAM passkey processing incorrectly handles non-passkey data.
  + A workaround was implemented to handle gracefully misbehaving applications
    that destroy internal state of SSSD client librarires.
  + An error when rotating KCM's logs was fixed.
  + Group membership handling when members are coming from different forest
    domains and using ldap token groups is prohibited.
  + Files provider was erroneously taking into consideration local_auth_policy
    config option, thus breaking smartcard authentication of local user in
    setups that didn't explicitly specify this option.
Nov. 20, 2023 Evgeny Sinelnikov 2.9.3-alt1
- Update to latest 2.9 major release.
  + KCM: provide mechanism to purge expired credentials.
  + Default hardening - id_provider channel defaults unencrypted with starttls.
  + sssd-sudo missing debug statement in its .service file.
  + SSSD goes offline during initgroups of trusted user if a group is
    missing SID.
  + Incorrect handling of reverse IPv6 update results in update failure.
  + sssd-2.9.2 breaks smart card authentication (on el8).
- The proxy provider is now able to handle certificate mapping and matching
  rules and users handled by the proxy provider can be configured for local
  Smartcard authentication.
- Passkey doesn't fail when using FreeIPA server-side authentication and
  require-user-verification=false.
- When adding a new credential to KCM and the user has already reached their
  limit, the oldest expired credential will be removed to free some space.
Oct. 6, 2023 Evgeny Sinelnikov 2.9.2-alt1
- Update to latest 2.9 major release.
- sss_simpleifp library removed due it deprecated.
- "Files provider" removed due it deprecated, using "Proxy provider" with
  proxy_lib_name = files instead.
- New passkey functionality, which will allow the use of FIDO2 compliant devices
  to authenticate a centrally managed user locally.
- Default value of cache_first option was changed to true.
- sssctl cert-show and cert-show cert-eval-rule can now be run as non-root user.
- certmap: Handle type change of x400Address (due to CVE-2023-0286).
- New option local_auth_policy is added to control which offline authentication
  methods will be enabled by SSSD.
- SSSD can be configured not to perform a DNS search during DNS name resolution.
  This behavior is governed by the new dns_resolver_use_search_list in the
  domain section. Default value is true (follows the system settings).