IPA is an integrated solution to provide centrally managed Identity (users,
hosts, services), Authentication (SSO, 2FA), and Authorization
(host access control, SELinux user roles, services). The solution provides
features for further integration with Linux based clients (SUDO, automount)
and integration with Active Directory based infrastructures (Trusts).
If you are using IPA, you need to install this package.
Provides
Requires
License
GPL-3.0-or-later
Changelog
* Mon Aug 24 2026 David Hanina <dhanina@redhat.com> - 4.13.3-1
- Resolves: RHEL-245629 CVE-2026-19550 ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes [rhel-10.3]
- Resolves: RHEL-240899 CVE-2026-13097 ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore [rhel-10.3]
- Resolves: RHEL-240837 CVE-2026-11861 ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships [rhel-10.3]
- Resolves: RHEL-240820 CVE-2026-73197 ipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbound