stable

krb5-1.21-2.fc38

FEDORA-2023-f7841e7a29 created by jrische a year ago for Fedora 38
  • New upstream version (1.21)
  • #2216903 Replace file dependency with package name
  • #2214297 Do not disable PKINIT if some of the well-known DH groups are unavailable
  • #2214300 Make PKINIT CMS SHA-1 signature verification available in FIPS mode
  • #2181311 Allow to set PAC ticket signature as optional
  • #2166001 Add support for MS-PAC extended KDC signature (CVE-2022-37967)
  • #2143306 Fix syntax error in aclocal.m4

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2023-f7841e7a29

This update has been submitted for testing by jrische.

a year ago

This update's test gating status has been changed to 'waiting'.

a year ago

This update's test gating status has been changed to 'failed'.

a year ago

This update has been pushed to testing.

a year ago
User Icon bojan commented & provided feedback a year ago
karma

Works.

User Icon besser82 commented & provided feedback a year ago
karma

Works great! LGTM! =)

This update is passing FreeIPA PRCI tests:

https://github.com/freeipa-pr-ci2/freeipa/pull/2804

The failure of the "rpminspect.static-analysis" test is due to the content of krb5-tests. This package include the full content of the build directory. It is used to run upstream tests in TMT. This package is only meant for testing purpose.

User Icon frenaud commented & provided feedback a year ago
karma

Tested the installation of an IPA server, create user and obtain a TGT, use ipa * commands. Works well.

OpenQA tests are running now. The remaining failure is from Fedora CI, I can't help with that - it must be fixed or waived. It is the "functional" test that's gating, not the static analysis one.

User Icon abhis3k commented & provided feedback a year ago
karma

Works without issues till now

User Icon rai510 provided feedback a year ago
karma
karma
User Icon kparal commented & provided feedback a year ago
karma

I can use company kerberos ok

This update's test gating status has been changed to 'waiting'.

a year ago

jrische edited this update.

a year ago

This update's test gating status has been changed to 'passed'.

a year ago

This update can be pushed to stable now if the maintainer wishes

a year ago

This update has been submitted for stable by jrische.

a year ago
User Icon filiperosset commented & provided feedback a year ago
karma

no regressions noted

This update has been pushed to stable.

a year ago

Please login to add feedback.

Metadata
Type
enhancement
Karma
8
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
a year ago
in testing
a year ago
in stable
a year ago
modified
a year ago
approved
a year ago
BZ#2143306 FTBFS with autoconf 2.72
0
0
BZ#2166001 CVE-2022-37967: MS-PAC extended KDC signature [rawhide,f38]
0
0
BZ#2181311 Make ticket signature optional during PAC verification [rawhide,f38]
0
0
BZ#2214297 PKINIT module initialization fails if a well-known MODP group cannot be loaded [rawhide]
0
0
BZ#2214300 PKINIT: CMS SHA-1 signature verification cannot be allowed in FIPS mode [rawhide]
0
0
BZ#2216903 dnf5 fails to install freeipa-server that dnf installs with no problem
0
0

Automated Test Results