Repository navigation
Tags: simp/pupmod-simp-sssd
Tags
Release of 10.2.0
* Wed Sep 09 2026 Hazel Caballero <hcaballero02@gmail.com> - 10.2.0
- Add `sssd::app_pki_group` to control the group ownership of the
certificates copied by `pki::copy` (#212, reported by Steven Pritchard).
On EL10+ sssd runs its backend as the unprivileged `sssd` user, which
could not read the root-only copied TLS private key, so StartTLS to the
LDAP server failed and the domain stayed offline. The new parameter
defaults to `sssd` on EL10+ and remains `root` on releases where sssd
runs as root, leaving EL8/9 behavior unchanged.
Release of 10.1.2
* Wed Sep 02 2026 Hazel Caballero <hcaballero02@gmail.com> - 10.1.2
- Test hardening only, no functional change. Investigating whether EL10
needs the sssd-sudo run-as-root systemd drop-in (raised by Sergey Ivanov
in #198) showed the opposite: EL10's shipped sssd-sudo.service runs the
whole stack as sssd and sets CapabilityBoundingSet= (empty), so a
User=root override cannot read the sssd-owned 0600 config.ldb and the
responder crash-loops. EL10 keeps the common.yaml defaults; the drop-in
stays EL8/9-only.
- Add explicit per-OS-release spec assertions (sudo drop-in presence,
sssd.conf and config directory permissions, LOCAL base domain) instead of
expectations derived from the module's own Hiera data.
- Strengthen the acceptance suite: verify sssd.conf ownership/mode, the
per-release drop-in state, and that a socket-triggered sssd-sudo responder
actually starts and stays up (the socket unit alone is 'active' even when
the responder cannot start).
Release of 10.1.0
* Wed Jul 29 2026 Nicholas Markowski <nicholas.markowski@onyxpoint.com> - 10.1.0
- Support multiple servers and a backup server in `sssd::provider::krb5`:
`krb5_server` now accepts one or more hosts (optionally `host:port`), and a
new `krb5_backup_server` parameter was added. Both render as comma-separated
lists.
- Add the `Sssd::Krb5Server` type and use it for the `krb5_server` /
`krb5_backup_server` parameters of both `sssd::provider::krb5` and
`sssd::provider::ldap`, harmonizing their types.
Release of 10.0.0
* Thu Jul 16 2026 Nicholas Markowski <nmarkowski17.misc@gmail.com> - 10.0.0
- Rename the ldap provider parameter `ldap_user_cert` to `ldap_user_certificate`
so that the value is emitted under the correct `sssd-ldap(5)` key (#206).
This is a breaking change for callers that set `ldap_user_cert`.
- Add the `ldap_user_certificate` parameter to the ad provider (#206).
- Add the `certificate_verification` parameter to the `[sssd]` section
via `sssd::certificate_verification` (#146).
- Add `sssd::force_ipa_domain`, `sssd::ipa_domain_name`, and `sssd::ipa_servers`
so that the IPA domain can be pre-staged before the host has joined (#115).
Release of 9.0.0 * Mon May 11 2026 Steven Pritchard <steve@sicura.us> - 9.0.0 - Remove unmaintained Compliance Engine data - Drop support for Puppet 7 - Switch `requirements` from `puppet` to `openvox` (>= 8 < 9) - Add `openvox` to the test Gemfile alongside `puppet` - Update `issues_url` to point at GitHub issues - Widen `simp/simplib` dependency upper bound to allow 5.x
PreviousNext