IPA is an integrated solution to provide centrally managed Identity (users,
hosts, services), Authentication (SSO, 2FA), and Authorization
(host access control, SELinux user roles, services). The solution provides
features for further integration with Linux based clients (SUDO, automount)
and integration with Active Directory based infrastructures (Trusts).
This package contains tests that verify IPA functionality under Python 3.
Provides
Requires
License
GPL-3.0-or-later
Changelog
* Mon Aug 24 2026 David Hanina <dhanina@redhat.com> - 4.13.3-1
- Resolves: RHEL-245629 CVE-2026-19550 ipa: FreeIPA: trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes [rhel-10.3]
- Resolves: RHEL-240899 CVE-2026-13097 ipa: Privilege escalation via krbCanonicalName manipulation due to realm-unaware uniqueness enforcement in FreeIPA LDAP datastore [rhel-10.3]
- Resolves: RHEL-240837 CVE-2026-11861 ipa: FreeIPA: Obtaining TGS with impersonating cname through trust relationships [rhel-10.3]
- Resolves: RHEL-240820 CVE-2026-73197 ipa: FreeIPA: Unauthenticated DoS in `/ipa/migration/migration.py` via Unbounded Request Body Read [rhel-10.3]
- Resolves: RHEL-240797 CVE-2026-73198 ipa: FreeIPA: Unauthenticated DoS in `/ipa/i18n_messages` via Unbounded Request Body Read [rhel-10.3]
- Resolves: RHEL-238683 Rebase ipa to latest 4.13.x version [rhel-10.3]
- Resolves: RHEL-174346 Release Modern UI progress to RHEL 10.3
- Resolves: RHEL-238699 ipa-migrate: require Replication Administrator privilege [rhel-10]
- Resolves: RHEL-238698 ipa-epn: drop_privileges method is mixing uid and gid [rhel-10]
- Resolves: RHEL-238697 ipa env: support only simple * wildcard [rhel-10]
- Resolves: RHEL-238696 host-mod: handle the password attribute when set with --setattr userpassword= [rhel-10]
- Resolves: RHEL-238695 ipa-otptoken-import hardening [rhel-10]
- Resolves: RHEL-238694 WebUI Hardening [rhel-10]
- Resolves: RHEL-235490 IdM modern-ui user profile drop-down manual not responsive
- Resolves: RHEL-219085 Unable to create users with spaces in the Last Name field in the Modern UI.
- Resolves: RHEL-114530 Remove NetBIOS dependencies in Identity Manager
* Mon Aug 03 2026 Florence Blanc-Renaud <flo@redhat.com> - 4.13.2-2
- Resolves: RHEL-222810 ipa-server-trust-ad package installation failing for samba dependency
* Thu Jul 16 2026 Florence Blanc-Renaud <flo@redhat.com> - 4.13.2-1
- Resolves: RHEL-178898 Rebase ipa to latest version for RHEL 10.3
- Resolves: RHEL-179217 ipa-migrate tool is renaming host records & host info in automount information
- Resolves: RHEL-178538 [Cursor Automated] Include latest fixes in python3-ipatests package
- Resolves: RHEL-174346 Release Modern UI progress to RHEL 10.3
- Resolves: RHEL-153857 ipa-migrate doesn't properly handle replication conflicts
- Resolves: RHEL-153852 ipa-migrate doesn't migrate IPA locations
- Resolves: RHEL-151578 Extend SELinux policy to allow use of SSSD authentication helpers on non-enrolled hosts
- Resolves: RHEL-151326 freeipa-client %triggerin and %post can fail (rpm scriptlets should never fail, by policy)
- Resolves: RHEL-147173 ipa-migrate doesn't process users' sshpublickeys
- Resolves: RHEL-107899 [RFE] X-Content-Type-Options header in IdM WebUI
- Resolves: RHEL-107897 [RFE] Implement Referrer-Policy on IdM WebUI
- Resolves: RHEL-107045 [RFE] CSP not implemented in IdM WebUI
- Resolves: RHEL-105139 IPA compatibility with tomcat 10
- Resolves: RHEL-103492 ipalockout_postop is incorrectly warning about locked user
- Resolves: RHEL-70229 To add "SameSite" flag to ipa_session cookies
- Resolves: RHEL-29029 Webui 3007 Requirement error "userCertificate" is required (not allowing certificate manage
- Resolves: RHEL-154589 FreeIPA JSON-RPC CSRF Referer Validation Uses Naive Prefix Match
* Tue Jun 02 2026 Florence Blanc-Renaud <flo@redhat.com> - 4.13.1-4
- Related: RHEL-175123 Rebuilt for samba
* Wed Apr 15 2026 Florence Blanc-Renaud <flo@redhat.com> - 4.13.1-3.2
- Resolves: RHEL-168516 TestIPAMigrationProdMode tests are missing
* Fri Apr 10 2026 Florence Blanc-Renaud <flo@redhat.com> - 4.13.1-3.1
- Resolves: RHEL-155027 Adding a group with 32Bit Idrange fails
- Resolves: RHEL-153145 IdM password policy Min lifetime is not enforced when high minlife is set
- Resolves: RHEL