Skip to content

Tags: simp/pupmod-simp-sssd

Tags

10.2.0

Toggle 10.2.0's commit message
Release of 10.2.0

* Wed Sep 09 2026 Hazel Caballero <hcaballero02@gmail.com> - 10.2.0
  - Add `sssd::app_pki_group` to control the group ownership of the
    certificates copied by `pki::copy` (#212, reported by Steven Pritchard).
    On EL10+ sssd runs its backend as the unprivileged `sssd` user, which
    could not read the root-only copied TLS private key, so StartTLS to the
    LDAP server failed and the domain stayed offline.  The new parameter
    defaults to `sssd` on EL10+ and remains `root` on releases where sssd
    runs as root, leaving EL8/9 behavior unchanged.

10.1.2

Toggle 10.1.2's commit message
Release of 10.1.2

* Wed Sep 02 2026 Hazel Caballero <hcaballero02@gmail.com> - 10.1.2
  - Test hardening only, no functional change.  Investigating whether EL10
    needs the sssd-sudo run-as-root systemd drop-in (raised by Sergey Ivanov
    in #198) showed the opposite: EL10's shipped sssd-sudo.service runs the
    whole stack as sssd and sets CapabilityBoundingSet= (empty), so a
    User=root override cannot read the sssd-owned 0600 config.ldb and the
    responder crash-loops.  EL10 keeps the common.yaml defaults; the drop-in
    stays EL8/9-only.
  - Add explicit per-OS-release spec assertions (sudo drop-in presence,
    sssd.conf and config directory permissions, LOCAL base domain) instead of
    expectations derived from the module's own Hiera data.
  - Strengthen the acceptance suite: verify sssd.conf ownership/mode, the
    per-release drop-in state, and that a socket-triggered sssd-sudo responder
    actually starts and stays up (the socket unit alone is 'active' even when
    the responder cannot start).

10.1.1

Toggle 10.1.1's commit message
Release of 10.1.1

* Mon Aug 24 2026 Steven Pritchard <steve@sicura.us> - 10.1.1
  - [puppetsync] Update metadata.json dependency ranges from the Forge

10.1.0

Toggle 10.1.0's commit message
Release of 10.1.0

* Wed Jul 29 2026 Nicholas Markowski <nicholas.markowski@onyxpoint.com> - 10.1.0
  - Support multiple servers and a backup server in `sssd::provider::krb5`:
    `krb5_server` now accepts one or more hosts (optionally `host:port`), and a
    new `krb5_backup_server` parameter was added. Both render as comma-separated
    lists.
  - Add the `Sssd::Krb5Server` type and use it for the `krb5_server` /
    `krb5_backup_server` parameters of both `sssd::provider::krb5` and
    `sssd::provider::ldap`, harmonizing their types.

10.0.0

Toggle 10.0.0's commit message
Release of 10.0.0

* Thu Jul 16 2026 Nicholas Markowski <nmarkowski17.misc@gmail.com> - 10.0.0
  - Rename the ldap provider parameter `ldap_user_cert` to `ldap_user_certificate`
    so that the value is emitted under the correct `sssd-ldap(5)` key (#206).
    This is a breaking change for callers that set `ldap_user_cert`.
  - Add the `ldap_user_certificate` parameter to the ad provider (#206).
  - Add the `certificate_verification` parameter to the `[sssd]` section
    via `sssd::certificate_verification` (#146).
  - Add `sssd::force_ipa_domain`, `sssd::ipa_domain_name`, and `sssd::ipa_servers`
    so that the IPA domain can be pre-staged before the host has joined (#115).

9.0.2

Toggle 9.0.2's commit message
Release of 9.0.2

* Thu Jul 09 2026 Steven Pritchard <steve@sicura.us> - 9.0.2
  - Remove duplicate `@param strip_128_bit_ciphers` doc block in
    `sssd::provider::ldap` that was tripping the puppet-lint
    parameter_documentation check
  - Regenerate REFERENCE.md

9.0.1

Toggle 9.0.1's commit message
Release of 9.0.1

* Thu Jun 18 2026 Mike Riddle <mike@sicura.us> - 9.0.1
  - Manage mode under /etc/sssd/conf.d recursively

9.0.0

Toggle 9.0.0's commit message
Release of 9.0.0

* Mon May 11 2026 Steven Pritchard <steve@sicura.us> - 9.0.0
  - Remove unmaintained Compliance Engine data
  - Drop support for Puppet 7
  - Switch `requirements` from `puppet` to `openvox` (>= 8 < 9)
  - Add `openvox` to the test Gemfile alongside `puppet`
  - Update `issues_url` to point at GitHub issues
  - Widen `simp/simplib` dependency upper bound to allow 5.x

8.1.0

Toggle 8.1.0's commit message
Release of 8.1.0

* Mon Mar 16 2026 Mike Riddle <mike@sicura.us> - 8.1.0
  - Cleaned up ownership for sssd config file and dir

7.13.2

Toggle 7.13.2's commit message
Release of 7.13.2

* Mon Nov 24 2025 Steven Pritchard <steve@sicura.us> - 7.13.2
  - Update module dependencies