What's Changed
- IPA: memory leak fixed by @alexey-tikhonov in #8632
- krb5: restart krb5_child for Smartcard authentication by @sumit-bose in #8629
- Translations update from Fedora Weblate by @weblate in #8635
- scripts: fix release notes generation by @pbrezina in #8639
- release: install jq as needed dependency by @pbrezina in #8640
- tests: mark KCM TGT renewal test as flaky by @madhuriupadhye in #8638
- Tests: LDAP+KRB5 krb_misc tests by @madhuriupadhye in #8612
- tests: poll for KCM TGT renewal instead of fixed sleep by @madhuriupadhye in #8650
- Smartcard multi token tests by @krishnavema in #8519
- refactoring ipa tests for hostname framework changes. by @danlavu in #8611
- Update version in version.m4 to track the next release by @pbrezina in #8676
- ci: bump cross-platform-actions/action from 0.32.0 to 1.0.0 by @dependabot[bot] in #8670
- Add support for openSUSE UsrEtc by @scabrero in #8504
- KRB5: read keytab copy in offline mode too by @alexey-tikhonov in #8671
- tests: avoid fixed sleep in KCM timestamp refresh test by @jakub-vavra-cz in #8678
- pam: handle protected authentication path by @sumit-bose in #8599
- sdap: Reduce log level when get_naming_context() fails by @scabrero in #8697
- sdap: let callers mark SSSD as offline if kinit fails by @pbrezina in #8675
- ipa: fix memory leak in ipa_s2n_get_list iteration by @alexey-tikhonov in #8654
- Openssl 4 fixes by @simo5 in #8667
- Release script improvements by @pbrezina in #8641
- Tests: fix the tests to check the new pattern by @aborah-sudo in #8719
- build: replace deprecated setup.py with direct file installation by @alexey-tikhonov in #8711
- ci: add TMT plan for passkey testing in PRCI by @ikerexxe in #8672
- tests: Clarify approx match filter by @justin-stephenson in #8714
- sdap: handle missing rootDSE gracefully by @pbrezina in #8706
- Fix: sss_analyze.py modified to print correct command in usage field by @asakure in #8723
- Get rid of Python2 support by @alexey-tikhonov in #8732
- Plug memory leak: add missing dbus_message_unref by @kkzhsh in #8707
- sdap: defer libldap global options setup to first connection by @alexey-tikhonov in #8709
- Tests: Update LdapOperations to fail on bind immediately by @jakub-vavra-cz in #8740
- sssd man-page: Improve man-page for override_gid by @asakure in #8741
- Pkcs11 soft ocsp tests by @krishnavema in #8557
- Makefile: krb5 plugins: don't export internal symbols by @alexey-tikhonov in #8754
- Tests: Disable test_authentication_indicators by @aborah-sudo in #8717
- tests: fixing mypy linting errors by @danlavu in #8762
- oidc_child: add JWT and mTLS authentication by @sumit-bose in #8708
- RESOLV: handle empty addr list properly by @alexey-tikhonov in #8773
- ci: bump cross-platform-actions/action from 1.0.0 to 1.2.0 by @dependabot[bot] in #8767
- sssd man-page: Fix man-page for offline_timeout* by @asakure in #8755
- oidc_child: add missing NULL checks and avoid double-free by @sumit-bose in #8785
- ci: update passkey TMT plan for native CentOS Stream 10 execution by @ikerexxe in #8731
- scripts: correctly authenticate git commands by @pbrezina in #8788
- resolv: Fix incorrect variable used in ares_parse_txt_reply() error c… by @kkzhsh in #8791
- sssd man-page: Add reference to FAILOVER section by @asakure in #8760
- sssd man-page: Add missing data type in man-page by @asakure in #8768
- Update/autoskip tests in image mode. by @jakub-vavra-cz in #8798
- Drop support of OpenSSL < 3.0.8 by @alexey-tikhonov in #8761
- Make: don't compile 'oidc_child_get_jwk.c' by @alexey-tikhonov in #8804
- Tests: Switch tests using ldap adparameters ported to ldifde by @jakub-vavra-cz in #8805
- ci: Clear cache before installing built rpms by @justin-stephenson in #8811
- ci: Remove dnf workaround during rpm install by @justin-stephenson in #8812
- tests: updating pysss_nss_idmap error with more detail by @danlavu in #8797
- man: Remove obsolete RHEL 5 krb5.conf note from sssd-ad by @asakure in #8842
- sssd man-page: Add headings [ ] for all services by @asakure in #8820
- sssd-ipa man: Improvement in sssd-ipa(5) man-page by @asakure in #8822
- oidc_child: change default with no auth method by @sumit-bose in #8819
- sssd man-page: Add Default for id_provider by @asakure in #8836
- mh-tests: fix GSSAPI SSH test setup for krb5_confd_path by @madhuriupadhye in #8814
- Tests: Adding flaky marker to retry GDM critical by @spoore1 in #8859
- PAM: fix use-after-free during p11_child processing by @alexey-tikhonov in #8861
- man: Add note about description/debug* for [session_recording] by @asakure in #8854
- sssd man-page: Improve FILE FORMAT section by @asakure in #8745
- cfg_rules: allow ldap_sasl_authid/ldap_krb5_keytab/krb5_keytab by @alexey-tikhonov in #8864
- ci: bump cross-platform-actions/action from 1.2.0 to 1.3.0 by @dependabot[bot] in #8874
- ci: bump actions/checkout from 6 to 7 by @dependabot[bot] in #8875
- FreeBSD CI: Stop installing Python setuptools as a dependency by @arrowd in #8891
- Tests: Smart card authentication tests for SSSD's CKF_PROTECTED_AUTH… by @krishnavema in #8744
- ci: drop 'analyze-target.yml' by @alexey-tikhonov in #8899
- gpo: reject path traversal in gPCFileSysPath by @alexey-tikhonov in #8896
- sudo: warn when ldap_sudo_search_base falls back to root DN by @alexey-tikhonov in #8897
- man: Replace ldap_opt_timout -> ldap_opt_timeout by @asakure in #8913
- man: Add Default for vetoed_shells in sssd.conf(5) by @asakure in #8901
- man: Replace bool -> boolean across sssd man-pages by @asakure in #8898
- tests: improving offline authentication tests by @danlavu in #8876
- man: Correct typos in sssd.conf(5) man-page by @asakure in #8900
- Tests: skip nonposix nested test for older sssd by @spoore1 in #8931
- enable file caching in OpenSC by @mvogt1 in #8799
- man: Correct default for ldap_user_nds_login_expiration_time and ldap_host_object_class options by @asakure in #8915
- tests: parametrizing group lookup by names test by @danlavu in #8789
- man: Remove duplicate sentence from intro sssd-kcm(8) by @asakure in #8943
- Revert "tests: parametrizing group lookup by names test" by @danlavu in #8953
- man: Correction of typo in pam_sss(8) by @asakure in #8942
- Tests: add ldap_sudo_search_base warning test by @spoore1 in #8902
- sssd.conf man: Improve explanation for cached_auth_timeout by @asakure in #8835
- CI: don't specify 'push:'/'pull_request:' branches by @alexey-tikhonov in #8954
- adding dynamic dns tests by @danlavu in #8415
- oidc_child: Fix logic error and URL-encode short_name in Keycloak lookup by @kkzhsh in #8950
- krb5: Fix logic error in OAuth2 code verification by @kkzhsh in #8948
- ci: serialize make distcheck by @pbrezina in #8983
- tests: Update ds tests to rely less on hostname by @jakub-vavra-cz in #8991
- man: Correct the ports for ad_use_ldaps option by @asakure in #9012
- KCM: fix TGT renewal use-after-free and stabilize test by @danlavu in #9005
- Multihost tests ldap fix by @spoore1 in #9011
- cfg_rules: add pwfield to allowed_domain_options by @mmatsuya in #9034
- tests: remove multihost tests covered by system tests by @danlavu in #9042
- test: Add smart card unlock console test with vlock by @krishnavema in #8895
- pam: Forward environment variables from PAM client to p11_child by @joantolo in #8837
- tests: Fix regex warnings by @jakub-vavra-cz in #9015
- Tests: use client IP instead of sys_hostname for SSH login by @aborah-sudo in #9055
- ci: bump actions/setup-python from 6 to 7 by @dependabot[bot] in #9032
- NSS: fix initgroups packet heap disclosure by @alexey-tikhonov in #9036
- nss: validate addrlen in sss_nss_protocol_parse_addr() by @alexey-tikhonov in #9039
- pam: validate auth_token_length in extract_authtok_v1() by @alexey-tikhonov in #9040
- sudo: don't warn about search base when it was set by provider by @alexey-tikhonov in #9031
- tests: adding gpo test case for traversal bug by @danlavu in #8952
- Fix FTBFS with GDM 51 PAM extension headers by @renanrodrigo in #9076
- man: fix TENNANT-ID typo in sssd-idp(5) example by @hagaikwa-redhat in #9111
- Ad stig 1 by @madhuriupadhye in #9115
- tests: add GPO regression tests for local group collision and verbose Samba logging by @danlavu in #9043
- man: fix doubled "are" in sssd-ldap(5) by @hbhadaur in #9116
- ci: Swap flake and isort for ruff and reorder jobs by @jakub-vavra-cz in #9056
- man: fix YOUR-CLIENT-SCERET typo in sssd-idp(5) by @hbhadaur in #9118
- man: Improvement in desc for smart refresh in sssd-sudo by @asakure in #9114
- tests: add sudo search base warning suppression test by @madhuriupadhye in #9106
- tests: Fix test used in c-ares gating to be more resilient by @jakub-vavra-cz in #9143
- test rewrite: legacy intg test_pam_responder.py - first batch by @danlavu in #9004
- pam_sss: cast to GdmPamExtensionMessage in binary prompt macro by @alexey-tikhonov in #9161
- man: Improve description for dns_resolver_server_timeout by @asakure in #9014
- FreeBSD CI: Explicitly pass --datadir and --sysconfdir to configure by @arrowd in #9110
- test_kcm: use config_apply instead of start to avoid proxy domain auth issue by @mmatsuya in #9113
- ci: Fix duplicated python-system-tests in static-code-analysis.yml by @jakub-vavra-cz in #9169
- man: Fix filter_users_in_groups and pam_gssapi_check_upn options. by @sjawale-03 in #9080
- Security.md by @sumit-bose in #8955
- p11_child: use X509_STORE_get1_objects() is available by @sumit-bose in #9192
- ci: actually run the whitespace test by @pbrezina in #9092
- ci: workaround PR CI issues on ubuntu-24-04 by @pbrezina in #9183
- nss: fix potential memory leak if packet grow fails by @pbrezina in #9103
- fix potential memory leak by @xiaoge1001 in #9108
- Remove obsolete entry_cache_computer_timeout option by @asakure in #9088
- fix(docs): repair malformed quote tag in Spanish sssd-ifp.5 translation by @madhuriupadhye in #9218
- Tests: add socket activation tests for all-responder and sudo scenarios by @aborah-sudo in #9105
- tests: migrates sss_override per-user home override test into the new test framework by @PetoSisan in #9145
- tests: convert cached_auth_timeout bash tests to system tests by @aborah-sudo in #9188
- tests: convert multihost failover and connection timeout tests to sys… by @aborah-sudo in #9160
- Fix: Remove an orphaned include local.xml by @asakure in #9198
- tests: removes legacy test testing tevent C library by @PetoSisan in #9249
- IDP: fix user matching in
eval_access_token_buf()by @alexey-tikhonov in #9250 - Man: Remove note about obsolete option ipa_dyndns_iface by @asakure in #9176
- Test: add sssd conf backup to test_0002_1736796 by @spoore1 in #9259
- tests: remove tevent_loop.c by @PetoSisan in #9256
- Man page sssd_ad improvements by @asakure in #9168
- ci: Install libssh-devel for the passkey TMT plan by @ptomsich in #9276
- Man: Improvement in max_ccache_size parameter by @rakkumar607 in #9213
- tests: migrate KCM to system tests by @krishnavema in #9159
- krb5 locator: use specific KDC if requested by @pbrezina in #9135
- ci: bump cross-platform-actions/action from 1.3.0 to 1.5.0 by @dependabot[bot] in #9195
- ci: bump vapier/coverity-scan-action from 1.8.0 to 1.9.0 by @dependabot[bot] in #9196
- ci: Dont run system tests for man page only PRs by @justin-stephenson in #9194
- pam: add cert_auth prompting options by @sumit-bose in #7908
- tests:
test_ldap_password_policy.pymigration: removetest_bz1146198_bz1144011by @PetoSisan in #9285 - Man: Improve description for selinux_provider option by @asakure in #9182
- tests: convert sudo offline and full_refresh bash tests to system tests by @aborah-sudo in #9248
- tests: convert offline auth bash tests to system tests by @aborah-sudo in #9247
- ipa: error out during issues reading IPA configuration by @sumit-bose in #9246
- tests: migrate multihost/test_automount.py to system tests by @krishnavema in #9081
- tests: adding rewritten journald logging tests by @krishnavema in #9086
- test rewrite: legacy intg test_pam_responder.py - remaining batch by @danlavu in #9028
- Tests: Convert ldap failover uri list bash tests to system tests by @aborah-sudo in #9303
- Emit journal alert about ldap_sudo_search_base only if sudo provider is enabled by @scabrero in #9079
- Man: Fix krb5_use_fast demand option description by @rakkumar607 in #9335
- Tests: multihost change passwd setting for STIG by @spoore1 in #9295
- Servicemap by @madhuriupadhye in #9329
- oidc_child: support Entra onPremisesImmutableId identifiers by @mmpleake in #9038
- tests:
test_ldap_password_policy.py::test_bz748856migration by @PetoSisan in #9318 - LDAP: fix fail-open in ppolicy access check on zero results by @alexey-tikhonov in #9331
- PAM: avoid NULL deref when service item is missing by @alexey-tikhonov in #9328
- Tests: multihost passwd change remove comments by @spoore1 in #9361
- tests: migrate multihost/alltests/test_default_debug_level.py by @krishnavema in #9313
- PAM: fix out-of-bounds read in v1 request parser by @alexey-tikhonov in #9327
- SYSDB: sanitize SID string in
sysdb_search_entry_by_sid_str()by @alexey-tikhonov in #9345 - NSS: reject empty request body before body[blen - 1] access by @alexey-tikhonov in #9330
- Refactor backend return code by @justin-stephenson in #8862
- Improve pre-release support in the release script by @pbrezina in #9383
- sdap: Remove unused value error code assignment by @justin-stephenson in #9384
- Translations update from Fedora Weblate by @weblate in #9385
- Fixes missed microsoft graph hardcode url and switch to batching group id requests by @ezrizhu in #9284
New Contributors
- @simo5 made their first contribution in #8667
- @kkzhsh made their first contribution in #8707
- @mvogt1 made their first contribution in #8799
- @joantolo made their first contribution in #8837
- @renanrodrigo made their first contribution in #9076
- @hagaikwa-redhat made their first contribution in #9111
- @hbhadaur made their first contribution in #9116
- @sjawale-03 made their first contribution in #9080
- @xiaoge1001 made their first contribution in #9108
- @PetoSisan made their first contribution in #9145
- @ptomsich made their first contribution in #9276
- @rakkumar607 made their first contribution in #9213
- @mmpleake made their first contribution in #9038
Full Changelog: 2.13.0...2.14.0-beta1