Package sssd: Information

  • Default inline alert: Version in the repository: 2.9.4-alt1

Source package: sssd
Version: 2.9.3-alt1
Build time:  Dec 14, 2023, 07:14 PM in the task #335986
Category: System/Servers
Report package bug
License: GPLv3+
Summary: System Security Services Daemon
Description: 
Provides a set of daemons to manage access to remote directories and
authentication mechanisms. It provides an NSS and PAM interface toward
the system and a pluggable backend system to connect to multiple different
account sources. It is also the basis to provide client auditing and policy
services for projects like FreeIPA.

The sssd subpackage is a meta-package that contains the deamon as well as all
the existing back ends.

List of rpms provided by this srpm:
libipa_hbac (x86_64, ppc64le, i586, armh, aarch64)
libipa_hbac-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libipa_hbac-devel (x86_64, ppc64le, i586, armh, aarch64)
libsss_autofs (x86_64, ppc64le, i586, armh, aarch64)
libsss_autofs-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsss_certmap (x86_64, ppc64le, i586, armh, aarch64)
libsss_certmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsss_certmap-devel (x86_64, ppc64le, i586, armh, aarch64)
libsss_idmap (x86_64, ppc64le, i586, armh, aarch64)
libsss_idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsss_idmap-devel (x86_64, ppc64le, i586, armh, aarch64)
libsss_nss_idmap (x86_64, ppc64le, i586, armh, aarch64)
libsss_nss_idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
libsss_nss_idmap-devel (x86_64, ppc64le, i586, armh, aarch64)
libsss_sudo (x86_64, ppc64le, i586, armh, aarch64)
libsss_sudo-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-ipa_hbac (x86_64, ppc64le, i586, armh, aarch64)
python3-module-ipa_hbac-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss-murmur (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss-murmur-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss_nss_idmap (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sss_nss_idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sssd (x86_64, ppc64le, i586, armh, aarch64)
python3-module-sssdconfig (noarch)
sssd (x86_64, ppc64le, i586, armh, aarch64)
sssd-ad (x86_64, ppc64le, i586, armh, aarch64)
sssd-ad-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-client (x86_64, ppc64le, i586, armh, aarch64)
sssd-client-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-dbus (x86_64, ppc64le, i586, armh, aarch64)
sssd-dbus-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-idp (x86_64, ppc64le, i586, armh, aarch64)
sssd-idp-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-ipa (x86_64, ppc64le, i586, armh, aarch64)
sssd-ipa-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-kcm (x86_64, ppc64le, i586, armh, aarch64)
sssd-kcm-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-krb5 (x86_64, ppc64le, i586, armh, aarch64)
sssd-krb5-common (x86_64, ppc64le, i586, armh, aarch64)
sssd-krb5-common-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-krb5-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-ldap (x86_64, ppc64le, i586, armh, aarch64)
sssd-ldap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-nfs-idmap (x86_64, ppc64le, i586, armh, aarch64)
sssd-nfs-idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-pac (x86_64, ppc64le, i586, armh, aarch64)
sssd-pac-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-passkey (x86_64, ppc64le, i586, armh, aarch64)
sssd-passkey-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-proxy (x86_64, ppc64le, i586, armh, aarch64)
sssd-proxy-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-tools (x86_64, ppc64le, i586, armh, aarch64)
sssd-tools-debuginfo (x86_64, ppc64le, i586, armh, aarch64)
sssd-winbind-idmap (x86_64, ppc64le, i586, armh, aarch64)
sssd-winbind-idmap-debuginfo (x86_64, ppc64le, i586, armh, aarch64)

Maintainer: Evgeny Sinelnikov


    1. libp11-kit-devel
    2. libpam-devel
    3. /dev/pts
    4. nscd
    5. python3-devel
    6. nss-utils
    7. nss_wrapper
    8. libpcre2-devel
    9. cifs-utils-devel
    10. /proc
    11. libpopt-devel
    12. libcares-devel
    13. libcheck-devel
    14. libcmocka-devel >= 1.0.0
    15. libcollection-devel >= 0.5.1
    16. libcurl-devel
    17. glib2-devel
    18. adcli
    19. libdbus-devel
    20. libsasl2-devel
    21. libselinux-devel
    22. openssh
    23. openssl
    24. libsemanage-devel
    25. libdhash-devel >= 0.4.2
    26. gnutls-utils
    27. libsmbclient-devel
    28. pam_wrapper
    29. bind-utils
    30. libssl-devel
    31. libfido2-devel
    32. diffstat
    33. docbook-dtds
    34. docbook-style-xsl
    35. doxygen
    36. rpm-build-python3
    37. findutils
    38. libgnutls-devel
    39. libhttp-parser-devel
    40. po4a
    41. libini_config-devel >= 1.3.0
    42. libjansson-devel
    43. libsystemd-devel
    44. libjose-devel
    45. libtalloc-devel
    46. libtdb-devel >= 1.1.3
    47. libkeyutils-devel
    48. libtevent-devel
    49. samba-devel
    50. samba-winbind
    51. libunistring-devel
    52. libuuid-devel
    53. libkrb5-devel
    54. uid_wrapper
    55. softhsm
    56. libldap-devel
    57. xml-utils
    58. xsltproc
    59. libldb-devel >= 1.3.3
    60. libxml2-devel
    61. libxslt
    62. libnfsidmap-devel >= 1:2.2.1-alt1
    63. libnl-devel
    64. libnspr-devel
    65. libnss-devel

Last changed


Nov. 20, 2023 Evgeny Sinelnikov 2.9.3-alt1
- Update to latest 2.9 major release.
  + KCM: provide mechanism to purge expired credentials.
  + Default hardening - id_provider channel defaults unencrypted with starttls.
  + sssd-sudo missing debug statement in its .service file.
  + SSSD goes offline during initgroups of trusted user if a group is
    missing SID.
  + Incorrect handling of reverse IPv6 update results in update failure.
  + sssd-2.9.2 breaks smart card authentication (on el8).
- The proxy provider is now able to handle certificate mapping and matching
  rules and users handled by the proxy provider can be configured for local
  Smartcard authentication.
- Passkey doesn't fail when using FreeIPA server-side authentication and
  require-user-verification=false.
- When adding a new credential to KCM and the user has already reached their
  limit, the oldest expired credential will be removed to free some space.
Oct. 6, 2023 Evgeny Sinelnikov 2.9.2-alt1
- Update to latest 2.9 major release.
- sss_simpleifp library removed due it deprecated.
- "Files provider" removed due it deprecated, using "Proxy provider" with
  proxy_lib_name = files instead.
- New passkey functionality, which will allow the use of FIDO2 compliant devices
  to authenticate a centrally managed user locally.
- Default value of cache_first option was changed to true.
- sssctl cert-show and cert-show cert-eval-rule can now be run as non-root user.
- certmap: Handle type change of x400Address (due to CVE-2023-0286).
- New option local_auth_policy is added to control which offline authentication
  methods will be enabled by SSSD.
- SSSD can be configured not to perform a DNS search during DNS name resolution.
  This behavior is governed by the new dns_resolver_use_search_list in the
  domain section. Default value is true (follows the system settings).
July 28, 2023 Ivan A. Melnikov 2.8.1-alt3.1
- NMU: Backport upstream commit to fix build with krb5 1.21*